Product Genius data processing agreement
Version 2.0 — Effective
Parties and background
(A) Customer (“Customer”) has entered into an agreement with Gamalon, Inc. d/b/a Product Genius, a Delaware corporation with offices at 1 Washington Mall #1086, Boston, MA 02108 (“Product Genius”) under which Product Genius provides the Services (the “Agreement”). Each is a “Party.”
Product Genius contracts, issues notices, and receives notices under a single legal entity name: Gamalon, Inc. d/b/a Product Genius. References in any Product Genius document to “Product Genius, Inc.”, “ProductGenius, Inc.”, “Product Genius AI”, or “Product Genius Ltd” mean Gamalon, Inc. d/b/a Product Genius and are references to the same entity. Product Genius’s brand and website use the domain productgenius.ai; its correspondence uses the domain productgenius.io. Both are operated by the same entity.
(B) This Data Processing Agreement (this “DPA”) is incorporated into and forms part of the Agreement and is effective on the effective date of the Agreement. For customers whose Agreement predates the effective date above, this DPA replaces the DPA dated 9 December 2022 and any previously agreed data processing and security terms with effect from July 30, 2026, except where a dated version of the prior DPA is attached to an executed Order Form.
(C) To the extent Product Genius processes Customer Personal Data on behalf of Customer or a Customer Affiliate in connection with the Services, it does so on the terms of this DPA.
1. Definitions
1.1 Capitalized terms not defined here have the meaning given in the Agreement. In this DPA:
“Affiliate” means an entity that controls, is controlled by, or is under common control with a Party.
“Applicable Data Protection Laws” means all laws and regulations relating to the privacy, confidentiality, or security of Personal Data applicable to a Party’s processing under this DPA, as amended from time to time.
“Approved Addendum” means the template addendum, version B.1.0, issued by the UK Information Commissioner under s119A(1) Data Protection Act 2018 and laid before the UK Parliament on 2 February 2022, as revised in accordance with Section 18 of the Mandatory Clauses.
“Customer Personal Data” means Personal Data processed by Product Genius on behalf of Customer or a Customer Affiliate in connection with the Services.
“DPF” means the EU-US Data Privacy Framework, together with the UK Extension and the Swiss-US Data Privacy Framework, administered by the US Department of Commerce.
“EEA” means the European Economic Area.
“GDPR” means Regulation (EU) 2016/679 (the “EU GDPR”) or, where applicable, the “UK GDPR” as defined in section 3 of the Data Protection Act 2018.
“Mandatory Clauses” means Part 2 of the Approved Addendum.
“Personal Data” means information relating to an identified or identifiable individual or device, and includes “personal data,” “personal information,” and “personally identifiable information” as those terms are defined in Applicable Data Protection Laws.
“Pseudonymous Identifier” means a randomly generated or platform-assigned identifier — such as a session identifier, device identifier, or e-commerce platform customer identifier — that Product Genius uses to associate behavioral data with a Shopper, and which cannot be resolved to a natural person using information held within Product Genius’s own data stores. Section 4.5(d) addresses Customer-granted API credentials.
“Security Measures” means the technical and organizational measures set out in Schedule 2 to this DPA.
“Security Incident” means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or unauthorized access to Customer Personal Data. Unsuccessful attempts and events that do not compromise the security of Customer Personal Data — such as pings, port scans, failed log-in attempts, and denial-of-service attempts that do not result in access — are not Security Incidents.
“Sensitive Data” means Personal Data that Applicable Data Protection Laws afford heightened protection, including special categories of personal data under Article 9 GDPR, precise geolocation, government identifiers, financial account credentials, biometric identifiers, protected health information, and data concerning children.
“Shopper” means an individual visitor to or customer of Customer’s online store.
“Standard Contractual Clauses” or “SCCs” means Module Two (controller to processor) and Module Three (processor to processor) of the clauses annexed to Commission Implementing Decision (EU) 2021/914.
“Sub-processor” means a Product Genius Affiliate or third-party processor engaged by Product Genius to process Customer Personal Data.
“US State Privacy Laws” means any law of a State of the United States governing the privacy or processing of Personal Data that is applicable to the processing under this DPA, as amended or replaced from time to time. These include, by way of example and without limitation, the California Consumer Privacy Act as amended by the California Privacy Rights Act (“CCPA”) and the comprehensive consumer privacy statutes of Virginia, Colorado, Connecticut, Texas, Oregon, and other States that have enacted or may enact such statutes. This definition operates by reference to applicability rather than by closed enumeration, so that it captures statutes coming into force after the date of this DPA without amendment.
1.2 “Controller,” “processor,” “data subject,” “process,” “supervisory authority,” “sell,” “share,” “service provider,” and “contractor” have the meanings given in Applicable Data Protection Laws.
2. Interaction with the Agreement
2.1 This DPA supplements and, in case of conflict as to the processing of Personal Data, supersedes the Agreement.
2.2 Customer warrants that it is authorized to enter into this DPA on behalf of any Customer Affiliate whose Personal Data Product Genius processes, and each such Affiliate is bound as if it were Customer.
2.3 Customer warrants that it is mandated by any such Customer Affiliate to enforce this DPA and to receive and respond to notices on the Affiliate’s behalf. Notice to Customer satisfies any obligation to notify a Customer Affiliate.
3. Role of the Parties
3.1 For the purposes of the GDPR, Product Genius acts as processor or sub-processor, determined by Customer’s role:
- (a) in general, Customer acts as controller and Product Genius as processor; and
- (b) where Customer acts as processor on behalf of its own customers under a data processing agreement with them, Product Genius acts as sub-processor.
3.2 For the purposes of US State Privacy Laws, Product Genius acts as a “service provider,” “processor,” or “contractor” (as those terms apply) in performing its obligations under the Agreement.
3.3 Product Genius does not act as a controller or as a “third party” with respect to Customer Personal Data. Product Genius’s processing of Personal Data for its own purposes — for example, Personal Data of Customer’s own personnel collected in the course of account administration and marketing — is governed by the Product Genius Privacy Policy and is outside the scope of this DPA.
4. Details of processing and data minimization
4.1 Instructions. Product Genius will process Customer Personal Data only on behalf of and under the documented instructions of Customer. The Agreement and this DPA are Customer’s complete instructions. Customer may issue further written instructions consistent with the Services.
4.2 Unlawful instructions. If an instruction would cause Product Genius to process Customer Personal Data in violation of Applicable Data Protection Laws, Product Genius will promptly inform Customer and may suspend the affected processing, unless prohibited from informing Customer by law.
4.3 Description. Schedule 1 describes the subject matter, nature, purpose, and duration of the processing, the categories of data subjects, and the categories of Personal Data.
4.4 Processing locations. Subject to Section 12 and any residency election recorded in an Order Form or Enterprise Terms Exhibit, Product Genius may process Customer Personal Data in the locations identified in Schedule 7. Product Genius will notify Customer before adding a processing location for Customer Personal Data.
4.5 Data minimization — Shopper direct identifiers. Product Genius operates the Subscription Service on a data-minimization basis. Specifically:
- (a) Product Genius is designed not to persist Shopper direct identifiers — name, email address, postal address, or telephone number — in its systems. Where such a field is present in a response from Customer’s e-commerce platform, it is discarded and is not written to Product Genius’s persistent storage.
- (b) Product Genius persists only a Pseudonymous Identifier together with behavioral, session, and catalogue interaction data as described in Schedule 1.
- (c) A Pseudonymous Identifier can be resolved to an identified Shopper only by reference to information held in Customer’s own systems or in Customer’s e-commerce platform. Product Genius maintains no key, mapping, or lookup table within its own data stores that would enable it to resolve a Pseudonymous Identifier to an identified Shopper.
- (d) Customer acknowledges that Product Genius holds API credentials granted by Customer for the purpose of delivering the Services, and that where the Pseudonymous Identifier is, or is linked to, an identifier assigned by Customer’s e-commerce platform (such as Shopify customer identifier), those credentials could in principle be used to query that platform. Product Genius will not use Customer’s API credentials, or any other means, to resolve a Pseudonymous Identifier to an identified Shopper, and will not combine Customer Personal Data with data from any other source for the purpose of re-identification. Product Genius requests only the API scopes required to deliver the subscribed functionality, as stated in Section 5.6 of Schedule 2.
- (e) Product Genius maintains logging, caching, and log-retention controls, described in Schedule 2, designed to prevent Shopper direct identifiers from being retained in application logs, error traces, or caches beyond the transient processing window.
- (f) Inadvertent receipt or retention. If, despite these measures, Product Genius becomes aware that it has persisted, logged, or otherwise retained a Shopper direct identifier other than as described in this Section, it will: (i) notify Customer without undue delay where the retention is material or affects Customer's own compliance obligations; (ii) not use the affected data for any purpose other than its containment and deletion; (iii) delete or irreversibly de-identify it promptly, unless legally required to retain it; and (iv) take reasonable steps to remediate the underlying cause and prevent recurrence. Isolated, transient, or immaterial instances that Product Genius identifies and remediates through its ordinary controls, and handles in accordance with this Section 4.5(f), will not be treated as a breach of subsections (a), (b), or (e).
- (g) This Section 4.5 is a material term. Product Genius will notify Customer at least thirty (30) days before any change to the Subscription Service that would cause it to persist Shopper direct identifiers, and Customer may terminate the affected Order Form on notice if it does not accept the change.
4.6 Sensitive Data. The Subscription Service is not designed to process Sensitive Data and Product Genius does not require Sensitive Data to deliver personalization. Accordingly:
- (a) Customer will not configure the Services to transmit Sensitive Data to Product Genius, and will use reasonable measures to prevent its transmission. For the avoidance of doubt and without limiting the definition in Section 1.1, this includes payment card data, financial account credentials, protected health information, government-issued identifiers, biometric or genetic identifiers, precise geolocation, and special categories of personal data within Article 9 GDPR. Product Genius’s Acceptable Use Policy at https://www.productgenius.ai/legal/aup states the same prohibition, but this Section 4.6 is operative independently of it.
- (b) Product Genius will not intentionally process Sensitive Data. If Product Genius becomes aware that it has received Sensitive Data, it will notify Customer without undue delay, will not use that data for any purpose, and will delete it promptly unless legally required to retain it.
- (c) Inference risk. Product Genius recognizes that a product catalogue can itself carry inference risk — for example, browsing behavior across health, wellness, pregnancy, or similar categories may support inferences about an individual’s health, even where no Sensitive Data is transmitted. Where Customer’s catalogue presents this risk, the Parties will agree appropriate additional safeguards in the Order Form, and Product Genius will engage in good faith on measures such as category exclusions, shortened retention, or restricted inference. Paragraph (a) is not intended to allocate the whole of this risk to Customer without that engagement.
4.7 No sale or sharing. Product Genius will not sell or share Customer Personal Data, and will not use it for cross-context behavioral advertising or targeted advertising. Section 14 and Schedule 6 state this obligation in the form required by US State Privacy Laws.
4.8 No model training on Customer Personal Data. Product Genius will not use Customer Personal Data to train, fine-tune, or improve any machine learning model that is made available to any other customer, and will not disclose Customer Personal Data to any third-party model provider for that provider’s own training purposes. Product Genius may use Customer Personal Data to operate models that serve Customer’s own storefront, and may use aggregated or de-identified data that is not Customer Personal Data as permitted by the Agreement.
5. Sub-processors
5.1 Authorization. Customer grants Product Genius general authorization to engage Sub-processors. Product Genius’s current Sub-processors are listed in Schedule 7 and maintained at https://www.productgenius.ai/legal/subprocessors. Customer may subscribe at that page to receive notice of changes.
5.2 Obligations. Product Genius will: (a) enter into a written agreement with each Sub-processor imposing data protection obligations no less protective than those in this DPA, to the extent applicable to the services the Sub-processor provides; and (b) remain liable to Customer for each Sub-processor’s performance of those obligations to the same extent as if Product Genius had performed them itself.
5.3 Notice and objection. Product Genius will give Customer at least thirty (30) days’ notice before adding or replacing a Sub-processor that will process Customer Personal Data. Customer may object on reasonable data protection grounds within fifteen (15) days of that notice. The Parties will work in good faith to resolve the objection — for example by Product Genius offering an alternative or additional safeguards. If they cannot resolve it within thirty (30) days, Customer may terminate the affected Order Form without penalty and receive a pro-rata refund of prepaid, unused Fees. Product Genius will not engage the objected-to Sub-processor for Customer Personal Data during the objection period.
5.4 Sub-processor audits. Product Genius audits its Sub-processors’ compliance with data protection obligations on a regular basis and will confirm the results to Customer on request.
5.5 Model and inference providers. Any third-party model, inference, or AI service provider that processes Customer Personal Data is a Sub-processor and is disclosed in Schedule 7. Section 4.8 applies to each such provider.
6. Data subject requests
6.1 As between the Parties, Customer is responsible for responding to requests from individuals exercising rights in relation to Customer Personal Data (each a “Data Subject Request”).
6.2 Product Genius will notify Customer without undue delay, and in any event within five (5) business days, of any Data Subject Request it or a Sub-processor receives directly, and will not respond to it other than to direct the individual to Customer, unless Customer instructs otherwise or law requires otherwise.
6.3 Product Genius will provide self-service functionality through the Services, or other reasonable assistance, to enable Customer to respond to Data Subject Requests, including access, correction, deletion, and opt-out requests. Because Product Genius holds only Pseudonymous Identifiers, Customer will supply the relevant Pseudonymous Identifier when a request requires Product Genius to locate records.
6.4 Product Genius will provide the assistance in Section 6.3 at no charge. Product Genius may charge for assistance that materially exceeds the self-service functionality and standard support included in the Services, on reasonable prior notice of the anticipated cost.
7. Security, audits, and certification
7.1 Security measures. Product Genius will implement and maintain appropriate technical and organizational measures designed to protect Customer Personal Data against unauthorized or unlawful processing and against accidental loss, destruction, or damage, taking into account the state of the art, the costs of implementation, and the nature, scope, context, and purposes of the processing.
7.2 Security Measures and changes. The measures Product Genius maintains are set out in Schedule 2. Product Genius may update Schedule 2 to reflect improvements or changes in practice, provided that no update will materially reduce the overall level of security afforded to Customer Personal Data during a subscription term. Product Genius will give Customer at least thirty (30) days’ notice of any change that would materially affect Customer, and will maintain dated archived versions of Schedule 2. Where a dated Security Exhibit is attached to an executed Order Form, that version governs for the Initial Term.
7.3 Audit right. Customer, or an independent third-party auditor engaged by Customer and reasonably acceptable to Product Genius (excluding a competitor of Product Genius), may audit Product Genius’s compliance with this DPA once per year, and more frequently following a Security Incident affecting Customer Personal Data or where required by Applicable Data Protection Laws or by Customer’s regulator.
7.4 Audit procedure. Customer will submit a proposed audit plan at least two weeks before the proposed date, and the Parties will agree a final plan. Audits will be conducted during business hours, in accordance with the agreed plan and Product Genius’s safety and security policies, and without unreasonably interfering with Product Genius’s operations. Nothing in this Section requires Product Genius to breach a duty of confidentiality owed to a third party or to disclose another customer’s data.
7.5 Reports in lieu of audit. Where the requested audit scope is addressed in a SOC 2 Type II report, ISO 27001 certification, or comparable report issued by a qualified independent auditor within the preceding twelve (12) months, and Product Genius confirms there has been no known material change in the controls covered, Customer will accept those findings in lieu of an on-site audit of the covered controls.
7.6 Certification status.As of the Effective Date, Product Genius does not yet hold a SOC 2 report. Product Genius is in the process of engaging a qualified independent auditor and is targeting the following timeline: Type I report by September 1st, 2026 and a Type II report by January 31st, 2027. These are target dates based on current planning and are not guarantees of a specific completion date. Product Genius publishes its current status at https://trust.productgenius.ai and will notify Customer of material changes to this roadmap. If Product Genius does not meet a target date, it will (a) inform affected Customers, (b) provide a revised timeline, and (c) continue to make available Customer's audit rights under Section 7.3, together with interim assurance materials (such as a completed security questionnaire, architecture description, or auditor's readiness/gap assessment), until a report meeting Section 7.5 is delivered. Where the reporting period of a delivered report has closed, Product Genius will provide a bridge letter on request covering the period to the date of the request.
7.7 Audit findings. Customer will notify Product Genius of any non-compliance identified and provide any audit report generated, unless prohibited by law. Customer may use audit reports only to meet its regulatory and audit obligations and to confirm compliance with this DPA. Where an audit identifies a material deficiency affecting Customer Personal Data, Product Genius will provide a written remediation plan within thirty (30) days and remediate at its own cost.
7.8 Audit costs. Each Party bears its own costs of an audit under Section 7.3. Where Customer requests an audit more than once per year other than following a Security Incident or as required by law or a regulator, Customer will reimburse Product Genius’s reasonable documented costs.
7.9 Adequacy of measures. Customer acknowledges that the measures in Schedule 2, taken together with the data minimization commitments in Section 4.5, are appropriate to the risk presented by the processing described in Schedule 1.
8. Security Incidents
8.1 Notification deadline. Product Genius will notify Customer in writing of a Security Incident affecting Customer Personal Data without undue delay, and in any event within seventy-two (72) hours of Product Genius becoming aware of the Security Incident.
8.2 Content of notice. Each notification will include, to the extent known at the time and updated as further information becomes available: the nature and scope of the Security Incident; the categories and approximate volume of Customer Personal Data and data subjects affected; the likely consequences; the measures taken or proposed to contain, investigate, and mitigate it; and a point of contact at Product Genius. Where Product Genius cannot provide full information within seventy-two (72) hours, it will provide the information it has within that period and the remainder without further undue delay, and will not delay initial notification in order to complete its investigation.
8.3 Containment and cooperation. Product Genius will take prompt steps to contain, investigate, and remediate the Security Incident, and will cooperate reasonably with Customer in Customer’s investigation and in meeting Customer’s own obligations to notify individuals, supervisory authorities, other regulators, or the public.
8.4 Coordination of notifications. Product Genius will not notify any affected individual or supervisory authority in respect of Customer Personal Data on Customer’s behalf without Customer’s prior written consent, unless required by law, in which case it will inform Customer first where legally permitted.
8.5 Post-incident report. On Customer’s request, Product Genius will provide a written post-incident report describing root cause and corrective actions within thirty (30) days of closing its investigation.
8.6 No admission. Notification of a Security Incident is not an acknowledgement by Product Genius of fault or liability.
9. Deletion and return
9.1 Return.The Customer Personal Data Product Genius holds consists principally of pseudonymous behavioral and event data that Product Genius generates through operation of the Services. The underlying source data — including Shopper, customer, and order records — resides in Customer's own systems and e-commerce platform, to which Customer retains independent access. Accordingly, on termination or expiry Product Genius deletes Customer Personal Data in accordance with Section 9.2 and does not return, reconstruct, or export behavioral or event data, whether or not Customer requests it. Where Customer requests the return of other Customer Personal Data that Product Genius holds in a readily returnable form, Product Genius will provide a copy on written request made on or before termination or expiry.
9.2 Deletion. Product Genius will delete all Customer Personal Data in its possession or control, and will procure the deletion of all copies held by its Sub-processors, within sixty (60) days after termination or expiry of the Agreement. Deletion of routine encrypted backups is governed by Section 9.3.
9.3 Backups and legal retention. Customer Personal Data held in routine encrypted backups will be deleted in accordance with Product Genius’s documented backup rotation schedule, which does not exceed ninety (90) days from termination. Product Genius may retain Customer Personal Data where and for so long as required by law, in which case it will inform Customer, will retain only what is required, will continue to protect it in accordance with this DPA, and will delete it when the requirement lapses.
9.4 Certification. Product Genius will certify deletion in writing on Customer’s request.
10. Contract period
This DPA takes effect on the effective date of the Agreement and, notwithstanding termination of the Agreement, remains in effect until Product Genius has deleted all Customer Personal Data in accordance with Section 9.
11. Liability
11.1 Where liability is governed. Liability arising from this DPA, including liability for a Security Incident, is governed by the limitation of liability provisions of the Agreement — Section 11 of the Product Genius Subscription Terms and, where an Order Form selects Track B, Section 1 of the Product Genius Enterprise Terms Exhibit. This DPA does not create a separate or additional cap.
11.2 Aggregate. The Parties’ aggregate liability under the Agreement and this DPA taken together is subject to a single cap. Claims under this DPA and claims under the Agreement do not stack, and an amount recovered in respect of a loss under one reduces the amount recoverable in respect of the same loss under the other.
11.3 Data subject rights preserved. Nothing in Section 11.1 or 11.2 limits any liability a Party has directly to a data subject or a supervisory authority under Applicable Data Protection Laws, or limits the rights of data subjects under the SCCs.
12. International transfers
12.1 Primary mechanism. Where Product Genius processes Customer Personal Data subject to the GDPR and transfers it outside the EEA to a country not covered by an adequacy decision, the SCCs apply as specified in Schedule 3 and are incorporated into this DPA by reference. The Parties agree the SCCs are deemed executed by them, with Customer as data exporter and Product Genius as data importer. Customer’s entry into the Agreement constitutes its signature of the SCCs and their Appendices.
12.2 Data Privacy Framework. Product Genius does not currently hold a self-certification under the DPF. Where and for so long as Product Genius maintains an active DPF certification covering the relevant transfer, that certification operates as an additional transfer mechanism alongside the SCCs.
The SCCs remain the primary transfer mechanism under this DPA and continue to apply regardless of DPF status. The Parties have adopted this approach deliberately: the European Commission’s DPF adequacy decision was upheld by the General Court of the European Union in September 2025, and an appeal is pending before the Court of Justice. Relying on the SCCs as the primary mechanism means the lawfulness of transfers under this DPA does not depend on the outcome of that appeal or on the continued validity of the adequacy decision.
12.3 UK and Switzerland. Where processing is subject to UK or Swiss data protection law, the UK Addendum and Swiss Addendum in Schedule 5 apply.
12.4 Transfer and impact assessment support. Product Genius will provide Customer with information reasonably necessary to complete a transfer impact assessment, and will implement the supplementary measures in Schedule 4. Product Genius will also provide Customer with information reasonably necessary for Customer to carry out a data protection impact assessment under Article 35 GDPR or an equivalent assessment under other Applicable Data Protection Laws, and will assist Customer in any prior consultation with a supervisory authority required under Article 36 GDPR, in each case to the extent the assistance relates to Product Genius’s processing. Product Genius will provide this information and any pre-completed transfer impact assessment materials at no charge. Product Genius may charge for bespoke assistance that materially exceeds this, on reasonable prior notice of the cost.
12.5 Residency election. Where an Order Form or Enterprise Terms Exhibit records a data residency election, that election governs the location of Customer Personal Data at rest and prevails over Section 4.4.
13. Governing law of this DPA
This DPA is governed by the law and subject to the forum stated in the Agreement. For clarity: the governing law and forum specified in Schedule 3 for the SCCs apply only to the SCCs and to disputes arising under them, as those clauses require the law of an EU Member State. They do not affect the governing law or forum of the Agreement, of this DPA, or of any other dispute between the Parties.
14. US State Privacy Laws
Where processing is subject to US State Privacy Laws, the U.S. Addendum in Schedule 6 applies.
15. General
15.1 Each Party certifies that it understands and will comply with the requirements of this DPA.
15.2 This DPA and the Agreement are the entire agreement between the Parties on the subject matter of this DPA.
15.3 If any provision of this DPA is held invalid or unenforceable, it will be modified to the minimum extent necessary to make it enforceable, or severed, and the remainder continues in effect.
15.4 Product Genius’s data protection contact is privacy@productgenius.io. Legal notices under this DPA follow Section 13.6 of the Subscription Terms.
Schedule 1 — Details of processing
Part 1: List of parties
Data exporter. Customer, and any Customer Affiliate established in the EEA, the UK, or Switzerland, or otherwise within the territorial scope of the GDPR or corresponding UK or Swiss law. Customer will notify Product Genius of its contact person and, where appointed, its data protection officer and Article 27 representative, by email to privacy@productgenius.io or through the Services. The exporter’s activities relevant to the transfer are its use of the Services as described in the Agreement, and the exporter determines the scope of processing through its configuration of the Services.
Data importer. Gamalon, Inc. d/b/a Product Genius, 1 Washington Mall #1086, Boston, MA 02108, United States. Tel: +1 (617) 308-4169. Contact: privacy@productgenius.io. The importer’s activities relevant to the transfer are the processing of Personal Data on behalf of the exporter to provide the Services, as described in this Schedule and the Agreement.
Part 2: Description of transfer
1. Categories of data subjects. (a) Shoppers — individual visitors to and customers of Customer’s online store; (b) Authorized Users — employees and contractors of Customer and its Affiliates who access the Services.
2. Categories of Personal Data.
Persisted by Product Genius:
| Category | Detail |
|---|---|
| Pseudonymous Identifier | Session identifier, device identifier, a Product Genius-generated identifier, and/or e-commerce platform (e.g. Shopify) customer identifier. Not resolvable to a natural person by Product Genius using information held in its own data stores; see Section 4.5(c)-(d). |
| Online identifiers | IP address - used transiently as one signal to associate checkout events with the corresponding session events, so that Product Genius can produce conversion analytics and reporting for Customer; the IP address is not retained for this purpose once the association is made. Where IP addresses appear in operational and security logs, they are retained only for the log-retention period stated in Schedule 2. Also collected: browser and operating system type and version, referrer URL. |
| Behavioral and interaction data | Pages, products, categories, and content viewed or interacted with; search and filter terms entered on Customer’s store; add-to-cart and cart events; session timing and sequence; interactions with Product Genius-served content |
| Commercial data | Purchase and order history associated with the Pseudonymous Identifier, including products, quantities, and values |
| Authorized User account data | Name, business email address, business telephone number, role, and account activity |
Not persisted by Product Genius: Shopper name, email address, postal address, and telephone number. Where these fields are present in a response from Customer’s e-commerce platform, they are discarded and not written to persistent storage, in accordance with Section 4.5 of the DPA.
3. Sensitive Data. None. The Services are not designed to process Sensitive Data, Product Genius does not require it to deliver personalization, the Acceptable Use Policy prohibits transmitting it, and Section 4.6 of the DPA governs inadvertent receipt.
4. Frequency of transfer. Continuous, determined by Customer’s configuration of the Services and by Shopper traffic to Customer’s store.
5. Subject matter and nature of the processing. Provision of an AI personalization and merchandising platform that analyses Shopper behavior and Customer’s product catalogue in order to select and rank product recommendations, adapt on-site content and merchandising, and report on the resulting performance.
6. Purposes. To provide the Services under the Agreement, namely: generating and serving personalized product recommendations and merchandising content on Customer’s storefront; producing analytics and reporting on storefront and Shopper behavior for Customer; and supporting, securing, and maintaining the Services.
7. Duration. Behavioral and interaction data is retained during the subscription term for the purpose of improving the service for Customer. Sections 9 and 10 of the DPA cover additional details of data retention policies.
8. Sub-processors. As set out in Schedule 7 and Section 5 of the DPA. Sub-processors may access Customer Personal Data for the term of the DPA or until the relevant Sub-processor engagement ends.
Part 3: Competent supervisory authority
Where the data exporter is established in an EU Member State: the supervisory authority of that Member State.
Where the data exporter is not established in an EU Member State but falls within the territorial scope of the GDPR under Article 3(2) and has appointed a representative under Article 27(1): the supervisory authority of the Member State in which the representative is established.
Where the data exporter is not established in an EU Member State, falls within Article 3(2), and is not required to appoint a representative under Article 27(2): the Irish Data Protection Commission.
Schedule 2 — Technical and organizational measures
This Schedule constitutes Annex II to the Standard Contractual Clauses and Annex II to the UK Approved Addendum.
Product Genius also publishes these measures as a standalone Security Exhibit at https://www.productgenius.ai/legal/security. The version bound into this Schedule is the version that governs this DPA.
Changes to this Schedule. Product Genius may update these measures to reflect improvements or changes in practice, provided that no update will materially reduce the overall level of security afforded to Customer Personal Data during a subscription term. Product Genius will give Customer at least thirty (30) days’ notice of any change that would materially affect Customer. Where this DPA is attached in a dated form to an executed Order Form, this Schedule governs for the Initial Term and is not subject to unilateral update.
1. Security governance
1.1 Product Genius maintains a written information security program, reviewed at least annually and approved by the Chief Information Security Officer.
1.2 Product Genius maintains written policies covering access control, acceptable use, encryption, change management, incident response, vendor management, business continuity, and secure development.
1.3 Risk assessments covering the Subscription Service and its supporting infrastructure are performed at least annually and following material changes to the architecture.
1.4 Certifications: none currently held. SOC 2 Type I and II targeted — see Section 7.6 of this DPA for additional details on certifications.
2. Personnel security
2.1 Background screening is performed on personnel with access to production systems containing Customer Data, to the extent permitted by applicable law.
2.2 All personnel are bound by written confidentiality obligations that survive termination of employment or engagement.
2.3 Security and privacy awareness training is required at onboarding and at least annually thereafter. Engineers with production access receive additional secure-development training.
2.4 Access is revoked promptly on termination of employment or engagement, and adjusted promptly on change of role. Target revocation time for production access is within 24 hours of termination.
2.5 Personnel are subject to a documented disciplinary process for security policy violations.
3. Access control
3.1 Multi-factor authentication. MFA is required for all Product Genius personnel access to: production infrastructure, source code repositories, cloud provider consoles, and any system that stores or processes Customer Personal Data. MFA is required for Product Genius’s identity provider and cannot be bypassed by personnel.
3.2 Least privilege. Access to Customer Data is granted on a need-to-know, least-privilege basis, by defined role, and is limited to personnel who require it to deliver, support, or secure the Services.
3.3 Unique accounts. Each individual is assigned a unique account. Shared or generic accounts are not permitted for access to production systems or Customer Data.
3.4 Password standards. Where passwords are used, Product Genius requires that passwords: (a) be at least twelve (12) characters in length; (b) be checked against a list of known-compromised credentials; (c) be stored only as a salted cryptographic hash, never in reversible or readable form; (d) not be reused across accounts; and (e) be changed promptly on any indication of compromise. Product Genius does not require arbitrary periodic password rotation. This is consistent with NIST SP 800-63B, which recommends against routine forced rotation on the basis that it leads users to choose weaker, more predictable passwords; Product Genius instead requires length, compromised-credential screening, and rotation on any indication of compromise, together with the mandatory MFA in Section 3.1.
3.5 Privileged access. Administrative and privileged access is separately approved, logged, and reviewed. Privileged access is granted on a time-limited, just-in-time basis where technically supported.
3.6 Access reviews. Access to production systems and Customer Data is reviewed at least quarterly, and entitlements not justified by current role are removed.
3.7 Customer-side access. Customers that utilize Shopify can access the Subscription Service via a Shopify User Interface using their Shopify Credentials.
3.8 Remote access. Access to production environments requires authenticated, encrypted connections.
4. Encryption and key management
4.1 In transit. Customer Data is encrypted in transit over public networks using TLS 1.2 or higher, with modern cipher suites. Plaintext protocols are not used for Customer Data. This applies to traffic between Customer’s storefront and Product Genius, between Product Genius and its Sub-processors, and between Product Genius environments.
4.2 At rest. Customer Data at rest is encrypted using AES-256 or an equivalent or stronger algorithm, including in primary datastores, backups, and any portable or removable media.
4.3 Key management. Encryption keys are managed using the cloud provider’s managed key service, with access restricted to authorized personnel and roles, logged, and rotated regularly. Keys are not stored alongside the data they protect.
4.4 Secrets. Application secrets and credentials are stored in a dedicated secrets manager, not in source code, configuration files, or environment variables committed to version control. Automated scanning for committed secrets runs on the source repositories.
5. Data minimization and identifier handling
This Section implements Section 4.5 of the Data Processing Agreement and is the control set that supports Product Genius’s commitment not to persist Shopper direct identifiers.
5.1 No persistence of direct identifiers. Product Genius’s data pipeline is designed so that Shopper direct identifiers — name, email address, postal address, telephone number — are not written to persistent storage. Where such a field is present in a response from a customer’s e-commerce platform, it is dropped at the ingestion boundary.
5.2 Pseudonymization. Behavioral, session, and commercial data is associated with a Pseudonymous Identifier. Product Genius holds no key or lookup table capable of resolving a Pseudonymous Identifier to a natural person.
5.3 Log hygiene. Application logs, error traces, and request logs are configured to redact or omit direct identifiers. Automated scanning checks log output for identifier patterns. Log retention is up to 90 days.
5.4 Caches and ephemeral stores. Transient caches that may contain direct identifiers during in-request processing are memory-resident, not persisted to disk, and expire within 48 hours.
5.5 Model inputs. Prompts, feature vectors, and other inputs sent to any model or inference provider exclude Shopper direct identifiers.
5.6 Scope minimization. Product Genius requests only the e-commerce platform API scopes required to deliver the subscribed functionality, and periodically reviews granted scopes to remove any that are not required. Customer can verify the scopes granted to the Product Genius application through its e-commerce platform’s application permissions screen.
6. Infrastructure and network security
6.1 The Subscription Service is hosted on the infrastructure of the cloud providers listed in Schedule 7 to this DPA. Product Genius does not operate its own data centres.
6.2 Production environments are logically segregated from development, test, and staging environments. Customer Data is not used in non-production environments except in de-identified form.
6.3 Customer Data is logically segregated between customers, with tenant isolation enforced at the application layer and access scoped by tenant identifier.
6.4 Network access controls, security groups, and firewall rules restrict inbound and outbound traffic to what is required. Administrative interfaces are not exposed to the public internet.
6.5 DDoS protection and a web application firewall are in place at the network edge.
6.6 Endpoint protection and disk encryption are enforced on devices used to access production systems or Customer Data.
7. Secure development and application security
7.1 Product Genius follows a documented secure development lifecycle. Changes to production code require peer review and approval before merge.
7.2 Automated static analysis and dependency vulnerability scanning run on the source repositories, with a documented process for triaging and remediating findings.
7.3 Product Genius engages a qualified independent third party to perform penetration testing of the Subscription Service at least annually. A summary of findings and remediation status is available to customers on request, subject to confidentiality.
7.4 Product Genius operates a channel for reporting suspected vulnerabilities at security@productgenius.io and commits to acknowledging reports within five (5) business days.
8. Logging, monitoring, and detection
8.1 Product Genius records audit logs of authentication events, privileged actions, administrative changes, and access to Customer Data.
8.2 The audit logs described in Section 8.1 are retained for at least 90 days and no longer than 12 months, and are protected against unauthorized modification or deletion.
8.3 These logs are available to Product Genius to investigate suspected security events and to support incident response, and Product Genius may review them for anomalous or unauthorized activity.
8.4 Log content is subject to the redaction requirements in Section 5.3.
9. Vulnerability and patch management
9.1 Product Genius performs regular vulnerability scanning of its infrastructure and application dependencies.
9.2 Identified vulnerabilities are remediated on a risk-based schedule. Target remediation times: critical: 7 days, high: 30 days, medium: 90 days.
9.3 Operating system and platform patching is applied on the schedule maintained by Product Genius’s cloud providers and by Product Genius for components under its control.
10. Incident response
10.1 Product Genius maintains a written incident response plan defining severity classification, roles, escalation paths, containment and eradication steps, communications, and post-incident review.
10.2 The plan is tested at least annually, including a tabletop exercise.
10.3 Customer notification obligations, including the seventy-two (72) hour deadline for notifying a Security Incident, are governed by Section 8 of this DPA. Product Genius’s internal escalation targets are set so that the external notification deadline can be met.
10.4 Product Genius conducts a root cause analysis following each Security Incident and documents corrective actions.
11. Resilience, backup, and business continuity
11.1 Customer Data is backed up on a daily schedule. Backups are encrypted at rest per Section 4.2 and access to them is restricted and logged.
11.2 Backup restoration is tested at least annually.
11.3 Product Genius maintains a business continuity and disaster recovery plan with a recovery time objective of 24 hours and a recovery point objective of 24 hours for the Subscription Service, tested at least annually.
11.4 Backup retention and post-termination deletion are governed by Section 9 of this DPA.
12. Physical and environmental security
Physical and environmental security for the infrastructure hosting the Subscription Service is provided by the cloud providers listed in Schedule 7 to this DPA, under their own certified control frameworks (including SOC 2 and ISO 27001). Product Genius reviews those providers’ attestations as part of its vendor management process. Product Genius offices do not host production systems or persistent Customer Data.
13. Vendor and Sub-processor management
13.1 Product Genius performs a security review of each vendor and Sub-processor before it is granted access to Customer Data, and periodically thereafter.
13.2 Each Sub-processor is bound by written data protection obligations no less protective than those in the DPA, as required by Section 5.2 of this DPA.
13.3 The current Sub-processor list, including processing locations, is maintained at https://www.productgenius.ai/legal/subprocessors.
14. Change control
14.1 Changes to production systems follow a documented change management process including review, approval, testing, and the ability to roll back.
14.2 Product Genius will not implement a change that materially reduces the overall level of security described in this Exhibit during a subscription term, consistent with Section 7.2 of this DPA.
15. Customer responsibilities
Security is shared. Customer is responsible for: managing its own Authorized User accounts and credentials; configuring role-based permissions appropriately; promptly notifying Product Genius of suspected credential compromise; securing its own storefront, systems, and integrations; and not transmitting Sensitive Data to the Services contrary to Section 4.6 of this DPA.
Schedule 3 — Standard Contractual Clauses
For the purposes of the SCCs:
1. Module Two applies to processing under Section 3.1(a) of the DPA; Module Three applies to processing under Section 3.1(b).
2. Clause 7 (Docking clause) does not apply.
3. Clause 9(a): Option 2 (general written authorization) applies. The notice period is thirty (30) days, as stated in Section 5.3 of the DPA.
4. Clause 11(a): the optional independent dispute resolution body language does not apply.
5. Clause 13 and Annex I.C: the competent supervisory authority is identified in Schedule 1, Part 3.
6. Clause 17 (Governing law): Option 1 applies. The governing law is the law of Ireland, save that where the data exporter is established in an EU Member State whose law allows for third-party beneficiary rights, the Parties may instead agree in the Order Form that the law of that Member State governs, and that agreement will apply. Ireland is specified as the default because Irish law allows for third-party beneficiary rights as Clause 17 requires.
7. Clause 18(b) (Choice of forum and jurisdiction): the courts of Ireland, or, where the Parties have agreed a different governing law under paragraph 6, the courts of that Member State.
8. For clarity, paragraphs 6 and 7 apply only to the SCCs and to disputes arising under them. Section 13 of the DPA governs the law and forum applicable to the DPA and the Agreement generally.
9. Annex I (parties, description of transfer, competent supervisory authority): Schedule 1.
10. Annex II (technical and organizational measures): Schedule 2, per Schedule 2.
11. Annex III (list of sub-processors): Schedule 7. Sub-processor contact details are available from privacy@productgenius.io.
Schedule 4 — Supplementary measures
Product Genius implements the following supplementary measures, consistent with guidance issued by EU supervisory authorities, to enhance the protection of Customer Personal Data transferred to a third country.
1. Technical measures
1.1 Customer Personal Data is transmitted between the Parties, between Product Genius data centres, and to and from Sub-processors using strong encryption, as specified in Schedule 2.
1.2 Customer Personal Data at rest is encrypted, as specified in Schedule 2.
1.3 Product Genius does not persist Shopper direct identifiers, per Section 4.5 of the DPA. The data Product Genius holds in its own systems comprises pseudonymous identifiers and behavioral data rather than Shopper direct identifiers, which materially reduces the utility of any compelled disclosure from Product Genius’s systems. Product Genius maintains no internal key, mapping, or lookup table that on its own resolves a Pseudonymous Identifier to a natural person; such resolution would require a reference to Customer’s e-commerce platform, and Product Genius is committed under Section 4.5(d) not to use Customer’s API credentials or any other means to do so.
2. Contractual measures
2.1 Transparency. Product Genius declares that: (a) it has not created back doors or similar means of access to its systems or to Personal Data; (b) it has not created or altered its business processes to facilitate access to Personal Data or systems; and (c) to the best of its knowledge, it has not received, and is not currently subject to, any order or legal requirement to create or maintain such access, or to be in possession of or to hand over encryption keys. Product Genius does not represent that no law of the United States could ever require disclosure; the safeguards in Section 3 of this Schedule address how Product Genius responds if such a demand is made.
2.2 Verification. Product Genius will verify the accuracy of information it provides for a transfer impact assessment on a regular basis and will notify Customer of material changes without delay. Clause 14(e) of the SCCs is unaffected.
2.3 Conflicting orders. If Product Genius receives an order to disclose or grant access to Customer Personal Data, it will inform the requesting public authority of the incompatibility of the order with the safeguards in the Article 46 GDPR transfer tool and of the resulting conflict of obligations.
2.4 Data subject remedies. Product Genius will fairly compensate a data subject for material and non-material damage suffered as a result of disclosure of their Personal Data in violation of the commitments in the applicable transfer tool. Product Genius has no obligation to compensate to the extent the data subject has already been compensated for the same damage. Compensation is limited to material and non-material damage as provided in the GDPR and excludes damage not resulting from Product Genius’s infringement.
3. Government access requests
3.1 Product Genius will promptly inform Customer of:
- (a) any legally binding request from a law enforcement or other government authority to disclose Customer Personal Data, including the data requested, the requesting authority, the legal basis, and the response provided. Notification will occur before disclosure wherever legally permitted;
- (b) any direct access by public authorities to Customer Personal Data of which it becomes aware, with all information available to it; and
- (c) where prohibited from notifying Customer, Product Genius will use its best efforts to obtain a waiver of the prohibition in order to communicate as much information as soon as possible, and will document those efforts.
3.2 Product Genius will review the legality of each request under the law of the country of destination — including requests under section 702 of the US Foreign Intelligence Surveillance Act and Executive Order 12333 — and will exhaust available remedies to challenge it where it concludes there are grounds to do so, seeking interim measures to suspend the effect of the request pending decision. Product Genius will not disclose Customer Personal Data until required under applicable procedural rules and will then disclose only the minimum required on a reasonable interpretation of the request.
3.3 Product Genius will retain records demonstrating compliance with this Schedule for the term of the Agreement and will make them available to the competent supervisory authority on request where required by law.
3.4 Product Genius will publish a transparency report, or otherwise make available on request, aggregate information about the government access requests it has received.
Schedule 5 — UK and Swiss Addendum
1. UK Addendum
Where Customer Personal Data is transferred from Customer as data exporter to Product Genius as data importer within the scope of the UK GDPR:
1.1 The Approved Addendum forms part of this DPA, and the SCCs are read and interpreted in light of the Approved Addendum to the extent required by Section 12 of the Mandatory Clauses.
1.2 In place of Table 1 of the Approved Addendum, and in accordance with Section 17 of the Mandatory Clauses, the parties are as specified in Schedule 1, Part 1.
1.3 The Modules and Clauses selected under Table 2 are as specified in Schedule 3, as amended by the Mandatory Clauses.
1.4 Table 3 is completed as follows: Annex 1A and 1B by Schedule 1; Annex II by Schedule 2; Annex III by Schedule 7.
1.5 For Table 4, neither Party may end the Approved Addendum as set out in Section 19 of the Mandatory Clauses, except that Product Genius may do so where required by Section 19.
1.6 The competent authority is the UK Information Commissioner.
2. Swiss Addendum
Where Customer Personal Data is processed subject to Swiss data protection law, or to both Swiss data protection law and the GDPR:
2.1 Interpretation. Terms defined in the SCCs have the same meaning here. “Swiss Data Protection Laws” means the Swiss Federal Act on Data Protection of 25 September 2020 and the Ordinance on Data Protection of 31 August 2022, together with any successor legislation. This Addendum is read so as to provide the safeguards required by Article 46 GDPR and the corresponding provisions of Swiss Data Protection Laws, and will not be interpreted in a way that conflicts with rights and obligations under Swiss Data Protection Laws. References to legislation include that legislation as amended, consolidated, or replaced.
2.2 Hierarchy. Where this Addendum conflicts with the SCCs or another agreement between the Parties, the provision affording the greater protection to data subjects prevails.
2.3 Amendments to the SCCs. Where processing is subject exclusively to Swiss Data Protection Laws, the SCCs are amended so that:
- (a) references to the “Clauses” or “SCCs” mean this Swiss Addendum as it amends the SCCs;
- (b) Clause 6 is replaced with: “The details of the transfers, and in particular the categories of personal data transferred and the purposes for which they are transferred, are those specified in Schedule 1 of this DPA where Swiss Data Protection Laws apply to the data exporter’s processing when making that transfer.”;
- (c) references to “Regulation (EU) 2016/679” or the “GDPR” are replaced with “Swiss Data Protection Laws,” and references to specific Articles are replaced with the equivalent provisions of Swiss Data Protection Laws to the extent applicable;
- (d) references to Regulation (EU) 2018/1725 are removed;
- (e) references to the “European Union,” “Union,” “EU,” and “EU Member State” are replaced with “Switzerland”;
- (f) Clause 13(a) and Annex I.C are not used; the competent supervisory authority is the Swiss Federal Data Protection and Information Commissioner;
- (g) Clause 17 is replaced with: “These Clauses are governed by the laws of Switzerland insofar as the transfers are governed by Swiss Data Protection Laws.”; and
- (h) Clause 18 is replaced with: “Any dispute arising from these Clauses relating to Swiss Data Protection Laws will be resolved by the courts of Switzerland. A data subject may also bring proceedings against the data exporter and/or data importer before the courts of Switzerland in the place of their habitual residence. The Parties submit to the jurisdiction of those courts.”
2.4 Dual application. Where processing is subject to both Swiss Data Protection Laws and the GDPR, the SCCs as specified in Schedule 3 apply as written and, additionally to the extent a transfer is subject to Swiss Data Protection Laws, as amended by this Addendum, except that Clause 17 is not replaced as provided in Section 2.3(g).
2.5 Notifications. Customer warrants that it and its Affiliates have made any notifications to the Swiss Federal Data Protection and Information Commissioner required under Swiss Data Protection Laws.
Schedule 6 — U.S. Addendum
Where Customer Personal Data is processed subject to US State Privacy Laws, this Addendum applies.
1. Role. Product Genius acts as a “service provider,” “processor,” or “contractor” and processes Customer Personal Data only on Customer’s behalf for the business purposes specified in the Agreement.
2. Restrictions. Product Genius will not:
- (a) sell Customer Personal Data, or otherwise make it available to a third party for monetary or other valuable consideration;
- (b) share Customer Personal Data with a third party for cross-context behavioral advertising, or process it for targeted advertising;
- (c) retain, use, or disclose Customer Personal Data for any purpose other than the business purposes specified in the Agreement, including for any commercial purpose of its own, except as permitted by US State Privacy Laws;
- (d) retain, use, or disclose Customer Personal Data outside the direct business relationship between the Parties;
- (e) combine Customer Personal Data with Personal Data received from or on behalf of another person, or collected from its own interaction with a data subject, except as permitted by US State Privacy Laws for a service provider; or
- (f) process Customer Personal Data for the purpose of profiling in furtherance of decisions producing legal or similarly significant effects, except on Customer’s instruction.
3. Compliance. Product Genius will comply with the obligations applicable to it as a service provider, processor, or contractor under US State Privacy Laws, will provide the same level of privacy protection as those laws require of Customer, and will notify Customer promptly if it determines it can no longer meet its obligations.
4. Assistance. Product Genius will assist Customer in responding to consumer requests, including requests to know, correct, delete, and opt out, in accordance with Section 6 of the DPA, and will pass any opt-out signal it receives to Customer.
5. Deidentified data. Where Product Genius processes deidentified data, it will not attempt to reidentify it, will maintain reasonable measures to prevent reidentification, and will contractually obligate any recipient to the same.
6. Sensitive personal information. Product Genius will not process sensitive personal information except as permitted by Section 4.6 of the DPA.
7. Right to take reasonable steps. Customer may take reasonable and appropriate steps to confirm that Product Genius uses Customer Personal Data consistently with Customer’s obligations, including through the audit and reporting rights in Section 7 of the DPA, and to stop and remediate any unauthorized use.
Schedule 7 — Sub-processors and processing locations
Current as of July 30, 2026. The authoritative, current list is maintained at https://www.productgenius.ai/legal/subprocessors, where Customer may subscribe to change notifications.
| Sub-processor | Legal entity | Service provided | Data processed | Processing location(s) |
|---|---|---|---|---|
| Google Cloud Platform | Google LLC | Cloud infrastructure | Customer order data; Customer behavioral event data | us-central1 |
| Cloudflare | Cloudflare, Inc | Event ingestion, edge-processing en route to storage, Workers, queues | Behavioral/event data in transit | Global Edge |
| Google Workspace | Google LLC | Email and documents | Authorized User account data; support and contract correspondence | Global |
| Datadog | Datadog Inc | Application monitoring, including logfile storage and processing | Application usage logs, logs may include IP and anonymized PII | US1 (North Virginia) |
| OpenAI | OpenAI Group PBC | AI Model Inference | Behavioral/Session/Catalog data in prompts; no direct identifiers; not used for training | US |
| Google (Gemini) | Google LLC | AI Model Inference | Behavioral/Session/Catalog data in prompts; no direct identifiers; not used for training | us-central1 |