NeuroCheckout Data Processing Addendum
Last updated: 12 August 2026 Effective date: the date on which the Customer accepts this DPA by signature, online acceptance, account registration, order form, or another authenticated contracting flow. Document owner: Merina LLC, operator of NeuroCheckout
This Data Processing Addendum (the DPA) forms part of the agreement governing Customer's use of NeuroCheckout, including the NeuroCheckout Terms of Use, any Order Form, subscription checkout, online acceptance flow, or other written agreement between the parties (the Main Agreement).
Parties and Background
This DPA is entered into between:
1. Customer: the legal entity, business, merchant, or other person using NeuroCheckout under the Main Agreement, as identified in the Customer's account, order form, billing records, online acceptance record, or signature block (Customer); and
2. Processor: Merina LLC, operator of NeuroCheckout, a limited liability company registered under number 3636440. (NeuroCheckout).
The Customer determines the purposes and essential means of Processing Personal Data from its connected e-commerce store and related systems. NeuroCheckout processes Customer Personal Data on the Customer's documented instructions to provide, secure, support, and improve the NeuroCheckout services.
The parties intend this DPA to operate as a global data processing addendum and to satisfy applicable processor, service provider, contractor, outsourcing, comparable-protection, consumer privacy, electronic communications, direct-marketing, security, breach-notification, assistance, audit, and international-transfer contract requirements under Applicable Data Protection Law, including GDPR processor-contract requirements where they apply.
1. Definitions
1.1 Applicable Data Protection Law means all data protection, privacy, consumer privacy, electronic communications, direct-marketing, security, breach-notification, international-transfer, and comparable laws or regulations that apply to the Processing of Customer Personal Data under the Main Agreement.
1.2 Controller, Processor, Data Subject, Personal Data, Processing, Personal Data Breach, and Supervisory Authority have the meanings given in Applicable Data Protection Law. Where Applicable Data Protection Law uses equivalent terms, including "business", "service provider", "contractor", "controller", "processor", "organization", or "third party processor", those terms are interpreted consistently with the parties' actual roles and the purposes of this DPA. The terms "process", "processed", and "processing" are interpreted accordingly.
1.3 Customer Personal Data means Personal Data processed by NeuroCheckout on behalf of Customer through the Services under the Main Agreement. It does not include data for which NeuroCheckout independently determines the purposes and essential means of processing.
1.4 Restricted Transfer means a transfer of, or remote access to, Customer Personal Data that requires a contractual transfer mechanism, transfer impact assessment, comparable-protection commitment, or other safeguard under Applicable Data Protection Law.
1.5 Services means the NeuroCheckout services ordered, configured, or enabled by Customer, including connected-store ingestion, analytics, cart recovery, product recommendations, segmentation, email orchestration, conversion attribution, monitoring, support, and related operational features.
1.6 Transfer Terms means standard contractual clauses, data transfer addenda, approved certifications, adequacy frameworks, contractual commitments, or comparable transfer mechanisms required or recognised by Applicable Data Protection Law for Restricted Transfers. Where the European Commission standard contractual clauses for transfers to third countries adopted by Decision (EU) 2021/914 are required, the completed terms in Annex V apply.
1.7 Subprocessor means another processor engaged by NeuroCheckout to process Customer Personal Data on behalf of Customer in order to provide the Services.
2. Scope, Roles, and Precedence
2.1 For Customer Personal Data, Customer is the Controller and NeuroCheckout is the Processor, except where Customer itself acts as a Processor for another Controller. In that case, Customer appoints NeuroCheckout as its Subprocessor and confirms that it is authorised to do so.
2.2 NeuroCheckout acts as an independent Controller for Personal Data that it processes for its own legitimate business purposes, such as account administration, authentication, subscription billing, payment administration, fraud prevention, service analytics about its own business, compliance, legal claims, direct business communications, and operation of the NeuroCheckout website. That processing is outside this DPA and is governed by the NeuroCheckout privacy notice and Applicable Data Protection Law.
2.3 Security logs, audit records, incident records, and operational telemetry containing Customer Personal Data remain within this DPA unless, and only to the extent that, applicable law independently requires NeuroCheckout to determine a separate purpose for that Processing.
2.4 The subject matter, duration, nature and purpose of Processing, categories of Data Subjects, categories of Personal Data, and Customer instructions are set out in Annex I.
2.5 If this DPA conflicts with the Main Agreement on matters concerning the protection of Customer Personal Data, this DPA prevails. The applicable Transfer Terms prevail over both documents to the extent of a conflict concerning Restricted Transfers.
3. Documented Instructions
3.1 NeuroCheckout shall process Customer Personal Data only:
on Customer's documented instructions;
to provide, secure, maintain, support, and improve the Services selected by Customer;
as described in the Main Agreement, this DPA, an Order Form, Customer's authenticated configuration, or Annex I;
as necessary to comply with Applicable Data Protection Law; or
as otherwise agreed in writing by the parties.
3.2 Customer's documented instructions include the Main Agreement, this DPA, account and connector configuration, dashboard settings, authenticated API calls, selected feature toggles, support requests from authorised Customer contacts, and other written instructions agreed by the parties.
3.3 NeuroCheckout shall promptly inform Customer if, in its opinion, an instruction infringes Applicable Data Protection Law. NeuroCheckout may suspend the affected Processing until Customer confirms, withdraws, or lawfully modifies the instruction.
3.4 NeuroCheckout shall promptly inform Customer if it becomes unable to comply with this DPA or a lawful documented instruction.
3.5 NeuroCheckout shall not:
sell, rent, or share Customer Personal Data for cross-context behavioural advertising, targeted advertising, or other purposes that constitute a sale or sharing under Applicable Data Protection Law;
use Customer Personal Data for advertising unrelated to Customer's Services;
combine identifiable Customer Personal Data with another customer's identifiable data for an unrelated purpose;
disclose Customer Personal Data except as authorised by this DPA, the Main Agreement, Customer's instructions, or law; or
use Customer Personal Data to train a shared, foundation, or general-purpose AI model.
3.6 NeuroCheckout may perform Customer-specific ranking, segmentation, adaptation, analytics, and operational learning solely to provide or improve that Customer's enabled Services. Such Processing must remain logically isolated by Customer or shop and must not make identifiable Customer Personal Data available to another customer.
3.7 External AI or model providers may process Customer Personal Data only if:
the provider is listed and authorised as a Subprocessor or separately approved by Customer;
Customer has been informed of the relevant purpose and data categories;
the Processing is necessary for an enabled feature;
appropriate contractual, security, and transfer safeguards are in place; and
the provider is contractually prohibited from using the data to train shared or general-purpose models unless Customer gives a separate, explicit, documented, and lawful instruction.
3.8 Where Applicable Data Protection Law uses service-provider, contractor, processor, operator, organisation, or comparable outsourcing concepts, Customer makes Customer Personal Data available to NeuroCheckout only for the limited and specified purposes described in this DPA, the Main Agreement, Customer's authenticated configuration, and Annex I. NeuroCheckout shall not retain, use, or disclose Customer Personal Data outside those purposes except as permitted by Applicable Data Protection Law and Customer's documented instructions.
3.9 To the extent required by Applicable Data Protection Law, NeuroCheckout shall provide the same or comparable level of privacy protection required of Customer for Customer Personal Data, notify Customer if NeuroCheckout determines it can no longer meet its obligations, allow Customer to take reasonable and appropriate steps to verify compliance under Section 14, and cooperate with reasonable steps to stop and remediate unauthorised Processing.
4. Customer Obligations
4.1 Customer shall:
comply with Applicable Data Protection Law as Controller or, where applicable, Processor;
provide transparent information to Data Subjects about its use of NeuroCheckout;
ensure that each instruction and transfer of Customer Personal Data to NeuroCheckout has a valid legal basis;
obtain and transmit accurate consent, objection, unsubscribe, and suppression signals where required;
configure only the features and data fields necessary for its lawful purposes;
avoid submitting prohibited data under Section 5;
protect its accounts, credentials, connector secrets, API keys, and authorised-user access; and
respond to Data Subjects, Supervisory Authorities, and third-party controllers where Customer is responsible for doing so.
4.2 Customer retains control over the purposes of Processing, enabled features, authorised users, connected stores, recipient eligibility, marketing rules, and content approvals, subject to the Main Agreement.
4.3 Customer is responsible for deciding whether a marketing communication is lawful. NeuroCheckout's consent, opt-in, unsubscribe, complaint, bounce, throttling, and deliverability safeguards are technical safeguards and do not replace Customer's assessment of legal basis, local ePrivacy rules, audience eligibility, or message content.
4.4 Where Customer acts as a Processor for another Controller, Customer warrants that its Controller has authorised Customer's instructions, the appointment of NeuroCheckout as Subprocessor, the use of Subprocessors listed in Annex III, and the transfers described in Section 11 and Annex V.
5. Data Minimisation and Prohibited Data
5.1 NeuroCheckout shall limit Processing to data reasonably necessary for the enabled Services and configured retention periods.
5.2 The Services are not designed to process:
sensitive or special-category Personal Data under Applicable Data Protection Law;
Personal Data relating to criminal convictions, offences, or comparable criminal-history data;
full payment-card numbers or card-security codes;
government identity documents;
account passwords or authentication secrets as store event payloads;
precise geolocation beyond what is necessary for enabled store, tax, shipping, fraud, or analytics features; or
data intentionally collected from children.
5.3 Customer shall not submit, upload, disclose, or otherwise make available to NeuroCheckout any prohibited data under Section 5.2 unless the parties first sign a specific written addendum describing the data, lawful basis, purpose, access controls, retention, safeguards, and any required data protection impact assessment.
5.4 If prohibited data is inadvertently received, NeuroCheckout shall restrict further Processing, notify Customer without undue delay where the incident is material or reasonably apparent, and securely delete or return the affected data in accordance with Customer's documented instructions and applicable law.
6. Personnel and Confidentiality
6.1 NeuroCheckout shall ensure that persons authorised to process Customer Personal Data:
are bound by confidentiality obligations or an appropriate statutory duty;
receive access only where necessary for their role;
receive appropriate privacy and security guidance; and
process Customer Personal Data only on documented instructions, except where law requires otherwise.
6.2 Confidentiality obligations survive termination of access and of this DPA.
7. Security of Processing
7.1 Taking into account the state of the art, implementation costs, the nature, scope, context, and purposes of Processing, and the risks to Data Subjects, NeuroCheckout shall implement and maintain appropriate technical and organisational measures in accordance with Applicable Data Protection Law.
7.2 The current baseline measures are described in Annex II. NeuroCheckout may update those measures provided the overall level of protection is not materially reduced.
7.3 NeuroCheckout shall maintain a process for assessing the effectiveness of relevant security controls and addressing material findings within a risk-based timeframe.
7.4 Customer is responsible for securely configuring its own systems, user accounts, connector permissions, consent tools, and endpoints that interact with the Services.
8. Data Subject Rights
8.1 Taking into account the nature of Processing, NeuroCheckout shall assist Customer through appropriate technical and organisational measures, insofar as possible, to fulfil requests to exercise Data Subject rights.
8.2 If NeuroCheckout receives a request relating to Customer Personal Data directly from a Data Subject, it shall not respond on Customer's behalf unless authorised by Customer or legally required. NeuroCheckout shall redirect or forward the request to Customer without undue delay where the Customer can be identified.
8.3 Customer shall submit assistance requests by email to [email protected] with the subject line "Data Subject Request Assistance", or through another support channel designated by NeuroCheckout. The request must be sent by an authorised Customer account administrator or another verified Customer contact.
8.4 Customer shall provide only the information necessary to identify the relevant account, shop, verified Data Subject, right being exercised, requested action, scope, and applicable deadline.
8.5 Routine assistance reasonably available through the Services or NeuroCheckout's standard operational procedures shall not incur an additional charge. Where assistance is manifestly excessive, repetitive, or outside standard procedures, including custom development, restoration from backups, complex cross-system searches, or a non-standard export format, NeuroCheckout may charge a reasonable fee based on documented administrative and technical costs after providing Customer with a written explanation and cost estimate.
8.6 No additional fee shall apply where the exceptional effort results from NeuroCheckout's breach of this DPA or failure to comply with its documented obligations. NeuroCheckout shall not charge the Data Subject directly.
9. Compliance Assistance
9.1 Taking into account the nature of Processing and information available to NeuroCheckout, NeuroCheckout shall reasonably assist Customer with applicable security, Personal Data Breach notification, data protection impact assessment, prior consultation, risk assessment, and comparable compliance obligations under Applicable Data Protection Law.
9.2 Customer remains responsible for determining whether a data protection impact assessment or prior consultation is required and for documenting its legal basis and risk assessment.
9.3 NeuroCheckout shall make available the information reasonably necessary to demonstrate compliance with its processor, service provider, contractor, or comparable obligations under Applicable Data Protection Law, subject to confidentiality, security, legal privilege, and protection of other customers.
10. Subprocessors
10.1 Customer grants NeuroCheckout general written authorisation to use the Subprocessors listed in Annex III to provide the Services.
10.2 NeuroCheckout shall:
conduct proportionate due diligence before appointing a Subprocessor;
enter into a written agreement imposing data protection obligations no less protective in substance than those applicable to NeuroCheckout under this DPA;
provide, on Customer's reasonable request, information about the relevant Subprocessor data protection terms, with commercially sensitive, privileged, or unrelated information redacted where necessary;
remain liable to Customer for the Subprocessor's performance of its data protection obligations to the extent required by Applicable Data Protection Law; and
maintain an up-to-date Subprocessor list.
10.3 NeuroCheckout shall notify Customer at least thirty (30) calendar days before authorising a new Subprocessor that will process Customer Personal Data, except where urgent replacement is necessary to maintain security, availability, or continuity. Notices may be sent through the Customer's registered account email, dashboard notice, legal page update, or the contact channel in Section 18.
10.4 Customer may object to the appointment of a new or replacement Subprocessor on reasonable and documented data protection grounds by contacting [email protected] within fifteen (15) calendar days of receiving the notice.
10.5 The objection shall identify the relevant Subprocessor and explain the specific data protection risks. The parties shall work in good faith to resolve the objection. NeuroCheckout may address the objection by not appointing the Subprocessor, implementing additional safeguards, or offering a commercially reasonable alternative.
10.6 If the parties cannot resolve the objection within thirty (30) calendar days after NeuroCheckout receives it, either party may terminate the affected feature or, where separation is not technically or commercially feasible, the affected Services by written notice.
10.7 Where Customer terminates because of a valid and unresolved objection, NeuroCheckout shall refund prepaid fees attributable to the unused period following the effective termination date. No refund shall be due for Services already provided, usage already consumed, free-trial periods, promotional credits, or termination resulting from Customer's breach.
11. International Transfers and Transfer Safeguards
11.1 NeuroCheckout shall transfer Customer Personal Data, or permit remote access to Customer Personal Data, only on Customer's documented instructions, as necessary to provide the Services, and in compliance with Applicable Data Protection Law.
11.2 Customer acknowledges and instructs that Customer Personal Data may be transferred to and accessed from the jurisdictions where NeuroCheckout, its infrastructure, support, security operations, and authorised Subprocessors operate, as described in this DPA and Annex III.
11.3 Where a Restricted Transfer requires Transfer Terms, the parties incorporate the applicable Transfer Terms as set out in Annex V. Those terms are deemed executed by the parties when this DPA is accepted.
11.4 If applicable Transfer Terms require role-based modules, party designations, or similar selections, the selected terms shall match the parties' actual roles and the relevant Processing activity.
11.5 Any regional addendum, amendment, or local modification to the Transfer Terms applies only to the extent required by Applicable Data Protection Law.
11.6 NeuroCheckout shall implement appropriate supplementary measures for transfers, taking into account the nature of the data, destination, transfer route, Subprocessor safeguards, technical and organisational measures, and any transfer impact assessment reasonably required by Applicable Data Protection Law.
11.7 NeuroCheckout shall not knowingly make an onward Restricted Transfer unless a valid transfer mechanism and appropriate safeguards are in place.
12. Personal Data Breaches
12.1 NeuroCheckout shall notify Customer without undue delay after becoming aware of a Personal Data Breach affecting Customer Personal Data.
12.2 NeuroCheckout's contractual target for notice after confirmation of an incident affecting Customer Personal Data is within twenty-four (24) hours. This target does not replace the obligation to notify without undue delay.
12.3 Notice shall be sent to the Customer privacy, security, or account administrator contact available in the Customer account, Order Form, support record, or signature block. To the extent known at the time, the notice shall include:
the nature of the breach and affected systems;
the categories and approximate number of affected Data Subjects and records;
the likely consequences;
measures taken or proposed to contain, investigate, and remediate the breach;
the contact point for follow-up; and
updates as material information becomes available.
12.4 NeuroCheckout shall document relevant facts, effects, and remedial action, cooperate reasonably with Customer, and not notify Data Subjects or authorities on Customer's behalf unless instructed or legally required.
12.5 Notification or cooperation does not constitute an admission of fault or liability.
13. Return, Export, and Deletion
13.1 During the term, Customer may use available export, deletion, disconnect, and revocation controls described in the Services. NeuroCheckout shall provide reasonable assistance where self-service controls are insufficient.
13.2 On termination or expiry, and at Customer's choice, NeuroCheckout shall return or delete Customer Personal Data and existing copies, unless applicable law requires continued storage.
13.3 Customer may request an export at any time during the term and within thirty (30) calendar days after termination. Unless Customer submits a verified request for earlier deletion, NeuroCheckout shall delete Customer Personal Data from active databases, queues, caches, files, and operational systems no later than thirty (30) calendar days after the export window expires.
13.4 Following a verified deletion request, NeuroCheckout shall complete deletion from active systems within thirty (30) calendar days. After deletion has been completed, the affected data may no longer be available for export.
13.5 Customer Personal Data remaining in backups shall be isolated from ordinary use, protected by restricted access, and deleted or overwritten through the applicable backup rotation process within ninety (90) calendar days after deletion from active systems.
13.6 Backups shall not be restored for ordinary business purposes. Where restoration is necessary for disaster recovery, NeuroCheckout shall reapply relevant deletion instructions before the restored data is returned to ordinary Processing.
13.7 NeuroCheckout may retain only:
data required by applicable law, subject to restricted access and no further Processing except for that legal purpose;
security, anti-abuse, billing, legal, and audit records that NeuroCheckout processes as an independent Controller under Section 2.2; and
irreversibly anonymised aggregate information that can no longer identify a Data Subject or Customer.
13.8 Upon written request from an authorised Customer account administrator, NeuroCheckout shall acknowledge a deletion or export request within five (5) business days.
13.9 Within ten (10) business days after deletion from active systems has been completed, NeuroCheckout shall provide a written deletion statement identifying the Customer account, affected shop identifiers, request reference, completion date for active-system deletion, categories of systems covered, scheduled backup deletion or overwrite date, and any retained data required by law.
13.10 Where backup copies have not yet reached the end of their retention period, the statement shall be identified as an active-system deletion confirmation and not as a final backup deletion certificate. Upon completion of backup deletion or overwriting, NeuroCheckout shall, on written request, provide a final deletion confirmation within ten (10) business days.
14. Audits and Inspections
14.1 NeuroCheckout shall provide information reasonably necessary to demonstrate compliance with this DPA, including relevant policies, security summaries, Subprocessor information, retention information, and available independent reports or assessment summaries.
14.2 If that information is insufficient, Customer may conduct an audit itself or through an independent auditor bound by confidentiality, subject to:
at least thirty (30) calendar days' prior written notice;
no more than once per twelve-month period, unless required by a Supervisory Authority or justified by a Personal Data Breach or credible material compliance concern;
normal business hours and reasonable scope;
safeguards protecting other customers, security secrets, privileged data, and commercially sensitive information; and
no material disruption to the Services.
14.3 Customer shall bear its own internal costs and the fees and expenses of any auditor appointed by Customer.
14.4 NeuroCheckout shall provide its standard compliance materials without additional charge, including this DPA, the current Subprocessor list, available security documentation, relevant policies, and existing audit or assessment summaries. NeuroCheckout shall also provide up to four (4) hours of reasonable remote audit assistance during each twelve-month period without additional charge.
14.5 Assistance beyond the standard scope, including extensive questionnaires, custom evidence collection, repeated interviews, on-site assistance, or technical work specifically requested by Customer, may be charged based on NeuroCheckout's documented personnel time and reasonable out-of-pocket expenses after NeuroCheckout provides a written scope and cost estimate and obtains Customer's written approval.
14.6 NeuroCheckout shall not charge Customer for audit assistance where the audit is required by a competent Supervisory Authority, reasonably triggered by a Personal Data Breach attributable to NeuroCheckout, based on credible evidence of material non-compliance by NeuroCheckout, or identifies a material breach of this DPA by NeuroCheckout.
14.7 NeuroCheckout shall promptly inform Customer if it believes an audit instruction infringes Applicable Data Protection Law or would compromise another customer's rights, security, trade secrets, legal privilege, or the security of the Services, and the parties shall agree a lawful alternative.
15. Records, Government Requests, and Disclosure
15.1 NeuroCheckout shall maintain records required by Applicable Data Protection Law and make them available to a competent Supervisory Authority on request.
15.2 NeuroCheckout shall not disclose Customer Personal Data to a government, authority, or third party unless instructed by Customer, authorised under this DPA, or legally required.
15.3 Where legally permitted, NeuroCheckout shall notify Customer before disclosure and limit disclosure to what is legally required.
15.4 NeuroCheckout shall refer requests that should properly be directed to Customer, where legally permitted.
16. Term and Termination
16.1 This DPA begins on the Effective Date and continues while NeuroCheckout processes Customer Personal Data.
16.2 Obligations intended to survive termination, including confidentiality, security, deletion, audit cooperation, and transfer safeguards, remain effective for as long as NeuroCheckout retains Customer Personal Data.
16.3 Where either party materially breaches this DPA, the non-breaching party shall provide written notice describing the breach in reasonable detail. The breaching party shall remedy the breach within thirty (30) calendar days after receiving the notice.
16.4 Where the breach creates a material and imminent risk to Personal Data or Data Subjects, involves unlawful Processing, results from a failure to comply with a binding decision of a competent court or Supervisory Authority, or is not reasonably capable of remedy, the non-breaching party may immediately suspend the affected Processing pending resolution.
16.5 If compliance is not restored within thirty (30) calendar days after notice or suspension, the non-breaching party may terminate the affected feature or Services by written notice. A substantial, persistent, or repeated material breach, or a breach that is not capable of remedy, may permit termination without an additional cure period.
16.6 Any suspension or termination shall, where technically and legally feasible, be limited to the affected Processing or Services. The parties shall cooperate to minimise unnecessary disruption and protect Data Subjects.
16.7 Termination shall not affect accrued rights, payment obligations for Services already provided, or NeuroCheckout's obligations concerning return, export, deletion, and protection of Customer Personal Data.
17. Liability
17.1 Each party remains responsible for complying with the obligations that apply to it under Applicable Data Protection Law.
17.2 Except where a limitation is prohibited by Applicable Data Protection Law or conflicts with applicable Transfer Terms, each party's aggregate liability under this DPA is subject to the liability limitations in the Main Agreement. If the Main Agreement contains no applicable aggregate cap, each party's aggregate contractual liability under this DPA shall not exceed the fees paid or payable by Customer for the Services during the twelve (12) months preceding the event giving rise to the claim. This cap does not apply to fraud, wilful misconduct, or liability that cannot lawfully be limited.
17.3 Nothing in this DPA limits a Data Subject's rights or the powers of a Supervisory Authority.
18. Notices and Contact Points
18.1 Notices under this DPA shall be sent to:
Customer privacy contact: the privacy, security, account owner, or administrator contact identified in the Customer account, Order Form, support record, online acceptance record, or signature block.
Customer security incident contact: the security, privacy, account owner, or administrator contact identified in the Customer account, Order Form, support record, online acceptance record, or signature block.
NeuroCheckout privacy contact: [email protected].
NeuroCheckout security incident contact: [email protected].
18.2 Each party shall keep its contact details current. Incident notices may be sent by email and followed by the support or incident channel agreed by the parties.
18.3 NeuroCheckout's privacy contact is [email protected]. This contact does not, by itself, constitute the appointment of a statutory data protection representative in any jurisdiction. If NeuroCheckout is legally required to appoint such a representative, NeuroCheckout will publish that representative's contact details in its Privacy Policy, on a dedicated legal page, or in an equivalent notice. Nothing in this Section limits mandatory rights of Data Subjects or Supervisory Authorities.
19. Governing Law
19.1 This DPA is governed by the law that governs the Main Agreement, except where applicable Transfer Terms or mandatory law require otherwise.
19.2 Any dispute relating to this DPA shall be subject to the jurisdiction stated in the Main Agreement, without limiting the mandatory rights of Data Subjects, Supervisory Authorities, or jurisdiction rules applicable to mandatory transfer or privacy terms.
20. Execution and Electronic Acceptance
20.1 This DPA may be signed electronically and in counterparts. It may also be accepted through an authenticated electronic contracting flow that records the accepting person, entity or account, DPA version, timestamp, IP or session evidence, and evidence of authority.
20.2 Customer's acceptance of the Main Agreement, creation of a business account, execution of an Order Form incorporating this DPA, or continued use of the Services after being presented with this DPA constitutes acceptance of this DPA where permitted by applicable law.
20.3 No change to this DPA is effective unless documented in writing, except for non-material updates to Annex III made under the Subprocessor notice procedure and security improvements that do not reduce the overall level of protection.
Annex I - Description of Processing and Customer Instructions
1. Subject Matter
Processing of Customer Personal Data necessary to operate NeuroCheckout for one or more connected e-commerce stores.
2. Duration
For the term of the Main Agreement and the limited return, export, deletion, backup, audit, and legal retention periods described in Section 13 and Annex IV.
3. Nature and Purposes
Depending on Customer's enabled features and instructions, Processing may include:
receiving and synchronising store, customer, product, cart, order, and event data;
normalising, validating, indexing, storing, and retrieving data;
maintaining Customer-specific profiles and segments;
detecting abandoned carts and other journey signals;
generating and ranking product or cart-recovery recommendations;
preparing, scheduling, sending, and tracking Customer-authorised emails;
applying consent, suppression, unsubscribe, bounce, complaint, and frequency-limit signals;
attributing conversions and calculating performance indicators;
displaying dashboards, reports, audit trails, and operational alerts;
preventing fraud, abuse, and unauthorised access to the Services;
troubleshooting, customer support, continuity, backup, and recovery; and
deleting, anonymising, aggregating, or exporting data under the applicable retention rules.
4. Categories of Data Subjects
Customer's store customers and prospective customers;
visitors to Customer's connected storefront;
recipients of Customer-authorised transactional, cart-recovery, or marketing communications;
Customer's authorised staff, administrators, and support contacts; and
other individuals whose Personal Data Customer submits to the Services through configured store connectors or authenticated API calls.
5. Categories of Personal Data
The exact fields depend on connector capabilities, Customer configuration, and enabled Services. They may include:
Identity and Contact Data
internal customer, visitor, cart, and order identifiers;
first and last name;
email address;
telephone number, if supplied by the connected store and necessary for an enabled feature;
guest or registered-customer status; and
Customer account and authorised-user identifiers.
Store and Transaction Data
cart, order, and product identifiers;
product names, variants, categories, prices, and quantities;
cart and order totals, currency, status, and timestamps;
discounts, recovery codes, and conversion-attribution signals;
store identifier, platform, locale, and language; and
limited shipping-related fields where supplied and required for an enabled feature, such as country code, postcode, city, and masked shipping-address information.
Behavioural and Technical Data
store events, viewed pages, and journey steps;
source page, landing page, and referrer;
event and session timestamps;
IP address or truncated, hashed, or IP-derived signals where enabled;
user-agent, device, browser, and operating-system information;
cookie-consent choices and evidence; and
pseudonymous visitor fingerprints or hashed identifiers.
Communication and Preference Data
email subject, template, rendered body, or preview for a limited period;
send, delivery, open, click, and conversion events;
marketing opt-in status, source, and recorded time;
unsubscribe, objection, and suppression status;
hard-bounce, soft-bounce, and complaint signals; and
Customer-defined campaign and recommendation rules.
Support and Security Data
support messages relating to a store operation;
API-key identifier and rotation metadata, not plaintext secrets after creation;
authentication, audit, diagnostic, and security event logs; and
incident and remediation records.
6. Sensitive Data and High-Risk Processing
Special-category data: prohibited unless a separate written addendum is signed.
Criminal-offence data: prohibited unless separately agreed in writing.
Full payment-card data: not intended to be collected by NeuroCheckout; payment processing is handled through the designated payment provider.
Children: the Services are not designed to intentionally identify or target children.
Solely automated decisions with legal or similarly significant effects: not an intended purpose of the Services.
7. Frequency and Scale
Frequency: continuous or event-driven while a connector and relevant features are enabled.
Estimated Data Subjects: determined by Customer's connected store size, plan, event volume, and enabled features.
Estimated event and email volume: determined by Customer's subscription plan, account limits, store traffic, and feature configuration.
Geographic scope of Data Subjects: determined by Customer's store, audience, and shipping or selling markets.
8. Standard Customer Instructions
Unless otherwise stated in an Order Form or written instruction:
store connector and event ingestion are authorised when Customer connects a store or API source;
cart recovery, recommendation, segmentation, attribution, and reporting activities are authorised when Customer enables the relevant feature;
automated marketing email sending is authorised only for recipients for whom Customer has established and recorded a valid legal basis and has not recorded an unsubscribe, objection, hard bounce, or complaint signal;
visitor and customer-journey tracking is subject to Customer's consent configuration and applicable ePrivacy rules;
external AI processing of Customer Personal Data is disabled by default and requires separate written activation or a documented product setting that identifies the relevant provider and purpose; and
Customer may narrow, disable, or revoke these instructions through available dashboard controls, connector settings, support requests, or written notice.
Annex II - Technical and Organisational Measures
The following measures describe NeuroCheckout's standard security baseline for Customer Personal Data.
1. Governance and Risk Management
Defined responsibility for privacy, infrastructure, and security operations.
Risk-based review of material system changes and security findings.
Documented operational ownership for incident response, retention, deletion, and Subprocessor review.
2. Access Control
Role-based access to Customer and internal administration functions.
Least-privilege access limited to operational, support, and security needs.
Session controls and revocation of access when no longer required.
API keys stored as hashes after issuance, with rotation and revocation controls.
Logging of sensitive administrative and supervisory actions.
Administrative access paths protected by secret management, restricted accounts, and additional authentication controls where available.
3. Tenant and Data Isolation
Logical separation by Customer, shop, or account identifier in application processing.
Application-layer authorisation checks on Customer-facing and internal endpoints.
Segregation of production administration from ordinary Customer access.
Customer-specific operational ranking and adaptation isolated from other shops.
4. Encryption and Secrets
TLS encryption for data in transit over public networks.
Restricted handling of connector secrets, API credentials, signing keys, and SMTP credentials.
Hashed storage for supported authentication credentials and issued API keys.
Production secrets stored outside source code and limited to authorised runtime environments.
5. Availability, Resilience, and Recovery
Runtime monitoring of infrastructure, database, cache, workers, and processing queues.
Capacity and saturation monitoring for CPU, memory, disk, and core dependencies.
Queue retry, failure visibility, and supervisor remediation controls.
Backup and recovery procedures designed to preserve service continuity and support the deletion commitments in Section 13.
6. Logging, Detection, and Incident Response
Security telemetry for authentication failures, access anomalies, and sensitive administrative endpoints.
Operational and security alerts with deduplication and remediation tracking.
Audit trails for selected high-risk actions.
Retention limits for telemetry and incident records under Annex IV.
Incident response process with containment, investigation, remediation, Customer notification, and post-incident review.
7. Secure Development and Change Management
Source-controlled changes and targeted automated tests for material features.
Review and staged deployment appropriate to change risk.
Dependency, secret, and security scanning in CI for covered paths.
Separation of development, testing, and production configuration where technically feasible.
8. Data Minimisation, Retention, and Deletion
Configured retention worker for operational, email, visitor, journey, supervisory, and telemetry data.
Earlier compaction of raw payloads and email preview bodies.
Batch deletion or anonymisation to reduce operational impact.
Customer and shop-scoped active-system deletion and connector-disconnect procedures.
9. Email and Consent Safeguards
Suppression checks for opt-out, unsubscribe, known hard bounce, and complaint.
Explicit opt-in enforcement where configured or required for marketing sends.
Unsubscribe mechanisms and processing of suppression events.
Separation of billing, general transactional, and marketing sender identities.
Deliverability monitoring and automatic pausing or throttling on material complaint or bounce signals where configured.
Safeguards support, but do not determine, Customer's legal basis.
10. Subprocessor and Physical Security
Physical data-centre security inherited from authorised hosting providers.
Subprocessor access limited to the functions necessary to provide the contracted service.
Written data protection terms required for Subprocessors processing Customer Personal Data.
Annex III - Authorised Subprocessors and Locations
This inventory lists the services currently identified as processing Customer Personal Data on NeuroCheckout's behalf. NeuroCheckout may update this list under Section 10.
Subprocessor / service | Purpose | Customer Personal Data | Processing location and transfer status |
|---|---|---|---|
netcup GmbH | VPS hosting, network, and primary infrastructure | Service database, event data, operational records, logs, and hosted application data | Primary production VPS known at this version date: Manassas, Virginia, United States and Nuremberg, Germany. Provider contracting and support operations may involve Germany or the EEA. Transfers are governed by provider data protection terms and, where required, Transfer Terms or equivalent safeguards. |
Cloudflare, Inc. | DNS, CDN, TLS proxy, WAF, bot and abuse protection, and edge security | IP addresses, request metadata, security logs, and transient web traffic | Global edge network. Transfers are governed by Cloudflare data protection terms and, where required, Transfer Terms, adequacy frameworks, or equivalent safeguards. |
Processor-Operated Components
NeuroCheckout marketing and transactional email may use a Processor-operated Postfix/SMTP path on the primary infrastructure. That component is not a separate Subprocessor when it runs on NeuroCheckout-controlled infrastructure.
Services Not Listed as Subprocessors for Customer Personal Data
Stripe, Shopify, Google authentication, and similar account, billing, connector, or customer-controlled platform services are not listed in this Annex to the extent they process NeuroCheckout account data, billing data, or Customer's own platform data outside NeuroCheckout's Processing of Customer Personal Data. If any such provider is later used by NeuroCheckout to process connected-store Customer Personal Data on Customer's behalf, NeuroCheckout shall list it or obtain Customer authorisation before enabling that processing.
External AI Providers
As of 12 August 2026:
Active external AI provider for Customer Personal Data: none.
Production processing mode for Customer Personal Data: internal NeuroCheckout agents, rules, analytics, and Customer-specific operational learning.
This statement does not mean that NeuroCheckout AI agents are disabled. NeuroCheckout AI agents are internal platform models operated by NeuroCheckout on Customer's behalf. As of this DPA date, no Customer Personal Data is transmitted to an external AI provider such as OpenAI, Anthropic/Claude, or an equivalent provider to operate those agents, unless a later activation is documented and authorised in accordance with this DPA.
Any later activation of an external AI or model provider for Customer Personal Data must follow Sections 3.7, 10, and 11.
Annex IV - Retention and Deletion Schedule
The post-termination schedule is governed by Section 13. Shorter product-specific retention may apply where configured.
Data category | Service default | End-of-period action |
|---|---|---|
Raw event payload content | 7 days | Compact or remove raw payload while retaining only necessary structured data |
Operational events and terminal actions | 30 days | Delete or anonymise when no longer needed; preserve only defined aggregates |
System telemetry | 14 days | Delete or anonymise |
Resolved business-alert incidents | 90 days | Delete or retain anonymised aggregate |
Email delivery records | 180 days | Delete or anonymise |
Email preview body/content | 15 days | Remove body; retain limited delivery metadata if still in retention |
Detailed email-attempt diagnostics | 30 days | Roll up and remove detail |
Aggregated email-attempt metrics | 365 days | Delete or anonymise |
Duplicate email-variant detection data | 30 days | Delete |
Bounce and complaint records | 180 days, subject to lawful suppression needs | Delete, minimise, or retain only the suppression signal required to prevent unlawful or unwanted sends |
Operational metrics | 90 days | Delete or aggregate |
Visitor traces | 90 days | Delete or anonymise |
Customer-journey raw data | 14 days | Roll up or remove raw detail |
Customer-journey daily aggregates | 180 days | Delete or roll up |
Customer-journey monthly aggregates | 730 days | Delete or retain only if irreversibly anonymised |
Supervisor audit detail | 30 days | Delete |
Supervisor remediation records | 365 days | Delete or anonymise |
Supervisor notifications | 90 days | Delete |
Supervisor inter-component messages | 30 days | Delete |
Customer, cart, order, and product records needed for active Services | For the active subscription and only as necessary for enabled features | Delete, return, or anonymise under Section 13 |
Customer support records containing store data | 30 days after ticket closure unless needed for an active legal, security, or support purpose | Delete or redact Customer Personal Data not required for the retained purpose |
Cache and transient queue data | Configured TTLs, no later than 15 days for ordinary transient data | Expire automatically or delete during queue cleanup |
Application and infrastructure logs not listed above | 15 days for ordinary logs unless needed for security, fraud, abuse, legal, or incident purposes | Delete or irreversibly anonymise |
Backups | Up to 90 calendar days after deletion from active systems | Isolate from ordinary use and expire through rotation; reapply deletion instructions if restored |
Post-Termination Schedule
Milestone | Contractual period |
|---|---|
Customer export request window | 30 calendar days after termination |
Disconnect connectors and revoke NeuroCheckout-held API access | Promptly and no later than 5 business days after effective termination |
Delete from active databases, queues, caches, and files | Within 30 calendar days after the export window expires, or within 30 calendar days after a verified earlier deletion request |
Delete or overwrite backups | Within 90 calendar days after deletion from active systems |
Provide deletion confirmation on request | Active-system statement within 10 business days after active deletion; final backup confirmation within 10 business days after a written request made following backup expiry |
Annex V - International Transfer Safeguards
1. Transfer Mechanism
Where Applicable Data Protection Law requires specific contractual safeguards for a Restricted Transfer, the parties incorporate the Transfer Terms required or recognised for that transfer. Where the European Commission standard contractual clauses are the relevant Transfer Terms, the following terms complete those clauses:
Transfer item | Completed term |
|---|---|
Module | Module Two (Controller to Processor) where Customer is Controller; Module Three (Processor to Processor) where Customer is Processor |
Data exporter | Customer |
Data importer | Merina LLC, operator of NeuroCheckout |
Docking clause | Clause 7 applies only if the parties expressly agree in writing |
Subprocessor authorisation | Clause 9, Option 2: general written authorisation |
Prior notice for new Subprocessors | 30 calendar days, except urgent replacement under Section 10 |
Supervisory authority | Customer's competent Supervisory Authority; if no single authority is clearly competent, the authority associated with the valid governing-law selection for transfer administration |
Governing law and courts for transfer administration | The valid law and courts selected in the applicable transfer record; if Transfer Terms require a specific eligible forum not already selected, the parties will complete that selection in an Order Form, online transfer record, legal notice, or equivalent written notice before the relevant Restricted Transfer starts |
Appendix I | Annex I of this DPA |
Appendix II | Annex II of this DPA |
Appendix III | Annex III of this DPA |
The parties agree that Customer's acceptance of this DPA constitutes execution of the applicable Transfer Terms, including the information completed in this Annex V.
2. Required Regional Adaptations
Any legally required addendum, amendment, or interpretive modification to the Transfer Terms is incorporated only to the extent required by Applicable Data Protection Law. Where such terms require completed appendices, Annexes I, II, and III provide the required description, security measures, and Subprocessor information unless a signed Order Form or later written notice provides more specific details.
3. Supplementary Measures
NeuroCheckout's supplementary measures include the security measures in Annex II, logical tenant isolation, minimisation of raw payload retention, restricted production access, TLS in transit, secret management, customer-scoped deletion procedures, and Subprocessor due diligence. NeuroCheckout shall review transfer risks when there is a material change to transfer routes, Subprocessors, processing locations, or Applicable Data Protection Law.
Annex VI - Assistance Procedure
1. Data Subject Requests
Customer should provide:
Customer legal name and NeuroCheckout account identifier;
affected shop identifier;
verified Data Subject identifier, using the minimum data needed;
right being exercised and scope or date range;
deadline and relevant Supervisory Authority correspondence; and
requested output format or deletion instruction.
NeuroCheckout's response target is to acknowledge the assistance request within five (5) business days and complete routine assistance within fifteen (15) business days after receiving sufficient and verified information, where reasonably feasible.
If the request is incomplete, complex, or requires exceptional technical work, NeuroCheckout shall inform Customer of the missing information, current status, and estimated completion date within that same fifteen-business-day period. NeuroCheckout shall use reasonable efforts to meet any applicable statutory deadline notified by Customer.
2. Security Incidents
NeuroCheckout incident notices should use the contact in Section 18 and include the information in Section 12 as it becomes available. Customer should maintain a monitored incident address and promptly confirm receipt.
3. DPIA and Consultation
Customer should identify the contemplated feature, Data Subjects, countries, data categories, scale, legal basis, and risk questions. NeuroCheckout will provide information reasonably available about architecture, safeguards, locations, Subprocessors, and relevant Processing.