Data Processing Agreement
The UK GDPR Article 28 processor terms that apply whenever BroomAI processes your customers' personal data on your instructions. This DPA forms part of, and is incorporated by reference into, the Terms of Service.
Draft pending legal sign-off. This DPA is provided so the cross-references in the Terms, Privacy Policy, and Data Handling Reference resolve to real content. Its terms are intended to satisfy UK GDPR Art.28, but it must be reviewed by a qualified UK data-protection solicitor — and the operating entity's company number inserted — before it is relied upon as the binding processor agreement. An enterprise customer requiring a counter-signed DPA on its own paper should contact legal@broom-ai.com.
1. Parties and roles
1.1 This Data Processing Agreement ("DPA") is between BroomAI Ltd (company number: [to be inserted upon incorporation]) ("BroomAI", "Processor") and the business that accepts the Terms of Service ("Customer", "Controller").
1.2 In respect of Customer Personal Data, the Customer is the controller and BroomAI is the processor. Where BroomAI engages another organisation to process Customer Personal Data, that organisation is a sub-processor.
1.3 This DPA applies only to BroomAI's processing of personal data on the Customer's behalf. For account, billing, and audit data, BroomAI acts as an independent controller as described in the Privacy Policy; that processing is governed by the Privacy Policy, not this DPA.
2. Definitions
2.1 "UK GDPR", "controller", "processor", "data subject", "personal data", "processing", and "personal data breach" have the meanings given in the UK GDPR and the Data Protection Act 2018 ("DPA 2018").
2.2 "Customer Personal Data" means personal data within the Customer's store, email, and communication data that BroomAI processes on the Customer's behalf under the Terms of Service.
2.3 "Applicable Data Protection Law" means the UK GDPR, the DPA 2018, and any other data protection law applicable to BroomAI's processing under this DPA.
2.4 Capitalised terms not defined here have the meaning given in the Terms of Service.
3. Subject matter and details of processing
3.1 Subject matter and duration. BroomAI processes Customer Personal Data to provide the Platform and the AI Agents the Customer has hired, for the duration of the Customer's use of the Platform and until deletion in accordance with Section 12.
3.2 Nature and purpose. Processing consists of collecting, storing, organising, retrieving, transmitting to sub-processors, and deleting Customer Personal Data so that AI Agents can triage messages, look up and fulfil orders, draft and (on approval) send communications, monitor inventory, and surface analytics, all under the propose → approve → execute model.
3.3 Categories of data subjects. The Customer's end customers, the Customer's suppliers and vendor contacts, and the Customer's own personnel who use the Platform.
3.4 Categories of personal data. Names, email addresses, postal addresses, phone numbers, order and fulfilment details, support correspondence, and messaging identifiers. The Customer must not submit special-category data (UK GDPR Art.9) without BroomAI's prior written agreement.
3.5 The specific scopes and data flows are described in the Data Handling Reference, which forms Annex A to this DPA.
4. Processing on documented instructions
4.1 BroomAI processes Customer Personal Data only on the Customer's documented instructions, which are given through the Terms of Service, this DPA, and the Customer's configuration and use of the Platform, including hiring agents, granting OAuth scopes, and approving actions.
4.2 BroomAI informs the Customer if, in its opinion, an instruction infringes Applicable Data Protection Law, unless legally prohibited from doing so.
4.3 BroomAI does not use Customer Personal Data for any purpose other than providing and supporting the Platform. BroomAI may use anonymised or aggregated data (which cannot identify any data subject) to maintain, secure, and improve the Platform.
5. Confidentiality
5.1 BroomAI ensures that persons authorised to process Customer Personal Data are bound by appropriate confidentiality obligations and process the data only as necessary to provide the Platform.
6. Security measures
6.1 BroomAI implements appropriate technical and organisational measures to ensure a level of security appropriate to the risk, as required by UK GDPR Art.32. These measures are described in Annex B (Technical and Organisational Measures) and include, in summary:
- AES-256-GCM encryption of OAuth credentials at rest; TLS/HTTPS in transit;
- HMAC-SHA256 verification of inbound webhooks; short-lived, shop-scoped Bearer JWT API authentication;
- PII redaction before any observability trace leaves BroomAI's environment;
- the propose → approve → execute human-in-the-loop control over all store mutations and outbound communications;
- audit logging of every executed write; data-minimised, field-whitelisted views for customer-facing lookups; and
- role-based access controls and separation of production from development environments.
6.2 The full Annex B specification is the Security practices and Storage & encryption sections of the Data Handling Reference. A more detailed specification is available under NDA via legal@broom-ai.com.
7. Sub-processors
7.1 The Customer provides general written authorisation for BroomAI to engage the sub-processors listed below, each engaged under a written contract imposing data-protection obligations equivalent to those in this DPA.
| Sub-processor | Purpose | Location |
|---|---|---|
| Anthropic (Claude API) | AI agent reasoning, triage, reply generation (no training on submitted data) | USA |
| Railway | Application hosting, PostgreSQL, Redis | EU / US |
| Google (Gmail / OAuth / Pub/Sub / Analytics) | Email integration, owner sign-in, GA4 analytics | USA |
| Shopify | Store data source and write target | Canada / USA |
| Stripe | Token top-up payment processing (no card data received by BroomAI) | USA |
| Braintrust | AI observability — redacted traces only (can be disabled) | USA |
| Telegram | Owner messaging channel (if connected) | UAE |
7.2 BroomAI gives the Customer prior notice of any intended addition or replacement of a sub-processor, allowing the Customer to object on reasonable data-protection grounds. If the Customer objects and the parties cannot resolve the matter, the Customer may terminate by ceasing use of the affected functionality or the Platform.
7.3 BroomAI remains liable to the Customer for the performance of each sub-processor's data-protection obligations.
8. Assisting with data subject rights
8.1 Taking into account the nature of the processing, BroomAI assists the Customer by appropriate technical and organisational measures, insofar as possible, to respond to data subject requests under UK GDPR Chapter III (access, rectification, erasure, restriction, portability, objection).
8.2 The Platform's controls — hire/fire, connect/disconnect, export, and deletion — together with BroomAI's handling of Shopify's customers/data_request, customers/redact, and shop/redact webhooks, are the primary means by which this assistance is provided. If BroomAI receives a request directly from a data subject, it refers that data subject to the Customer.
9. Personal data breach
9.1 BroomAI notifies the Customer without undue delay after becoming aware of a personal data breach affecting Customer Personal Data, and provides the information reasonably available to enable the Customer to meet its obligations under UK GDPR Art.33 and 34.
9.2 The Customer, as controller, is responsible for any notification to the ICO and to affected data subjects. BroomAI's notification is not an admission of liability.
10. DPIA and prior consultation
10.1 BroomAI provides reasonable assistance to the Customer with data protection impact assessments and prior consultations with the ICO under UK GDPR Art.35–36, taking into account the nature of the processing and the information available to BroomAI.
11. International transfers
11.1 BroomAI does not transfer Customer Personal Data outside the United Kingdom except in accordance with the safeguards described in the Privacy Policy §7 — UK adequacy regulations, UK International Data Transfer Agreements (IDTAs), or UK Addendums to the EU Standard Contractual Clauses, as applicable to each sub-processor.
12. Return and deletion
12.1 On disconnection of an integration, BroomAI revokes the relevant token and clears the stored credentials, ending access immediately.
12.2 On Shopify uninstall, BroomAI honours the shop/redact webhook and purges the store's personal and operational data within approximately 48 hours.
12.3 On termination of the Terms of Service or full account closure, BroomAI deletes Customer Personal Data within 30 days, except where retention is required by law (for example, billing records retained for the statutory 7-year period) or in anonymised/aggregated form.
12.4 The Customer is responsible for exporting any Customer Personal Data it requires before termination; BroomAI has no obligation to retain data afterwards.
13. Audits and information
13.1 BroomAI makes available to the Customer the information reasonably necessary to demonstrate compliance with Art.28, and contributes to audits conducted by the Customer or an auditor mandated by the Customer.
13.2 To protect the confidentiality and security of BroomAI's systems and other customers' data, audits are satisfied first by BroomAI's documentation (including the Data Handling Reference and the NDA-gated security specification). On-site or bespoke audits are limited to once per year (absent a specific regulatory requirement or a confirmed breach), on reasonable prior notice, during business hours, and subject to confidentiality.
14. Liability
14.1 Each party's liability arising out of or related to this DPA is subject to the limitations and exclusions of liability in Section 13 of the Terms of Service. This DPA does not increase a party's aggregate liability beyond those limits.
15. General and governing law
15.1 If there is any conflict between this DPA and the Terms of Service regarding the processing of personal data, this DPA prevails.
15.2 This DPA is governed by the laws of England and Wales, and the courts of England and Wales have exclusive jurisdiction, consistent with Section 21 of the Terms of Service.
15.3 Annex A — details of processing: the Data Handling Reference. Annex B — technical and organisational measures: the Security practices and Storage & encryption sections of the Data Handling Reference.
© 2026 BroomAI Ltd. All rights reserved. | broom-ai.com | legal@broom-ai.com | Data Processing Agreement v1.0