GDPR Compliance
Last updated: 21 August 2026
At GoPrimy, we are fully committed to complying with the General Data Protection Regulation (GDPR) (EU) 2016/679. This page outlines our principles, legal bases for processing data, and the rights available to users and store owners under GDPR.
1. Who We Are
GoPrimy is an AI-powered Shopify app. Merchants install AI employees that act on their store — recovering abandoned checkouts, answering order questions, recommending products, and re-engaging past customers — across WhatsApp and email, within limits the merchant configures. We are the controller for merchant account data and a processor for the customer personal data we handle on a merchant’s behalf.
2. Legal Bases for Data Processing
Under GDPR, we process personal data on the following legal grounds:
- Contractual necessity: To deliver services merchants sign up for
- Legitimate interest: To enhance product functionality and maintain security
- Consent: For optional features or marketing communication, when applicable
- Legal obligation: To comply with applicable laws or respond to lawful requests
3. Data We Process
We collect and process the following types of personal data:
- Merchant account details (name, email, store domain)
- Store activity and customer interaction data (for app functionality)
- Analytics and usage data (for service improvement)
- Customer conversation content, contact details, and order history, processed on the merchant’s instructions
- Context passed to third-party AI providers to generate replies and decide actions — see our Privacy Policy, “Automated Processing and AI”
We do not collect more data than necessary for the stated purposes.
4. Your GDPR Rights
As a data subject, you have the following rights:
- Right to Access: Request a copy of the data we hold about you
- Right to Rectification: Correct inaccurate or incomplete information
- Right to Erasure: Request deletion of your data when no longer necessary
- Right to Restrict Processing: Limit how we use your data under certain conditions
- Right to Data Portability: Request a transferable copy of your data
- Right to Object: Object to certain uses, including direct marketing
To exercise any of these rights, contact us at: contact@goprimy.com
5. Data Transfers
GoPrimy operates globally. When transferring personal data outside the EU/EEA, we ensure adequate protection via:
- Standard Contractual Clauses (SCCs)
- Agreements with third-party processors aligned with GDPR standards
6. Data Retention
We retain personal data only for as long as needed to fulfill service purposes or comply with legal obligations. Merchants may request deletion at any time.
7. Data Processors and Subprocessors
We work with trusted service providers who process data on our behalf under strict confidentiality and data protection agreements. These subprocessors only have access to the minimum necessary data.
8. Security Measures
We use technical and organizational measures, including encryption, access controls, and secure infrastructure, to protect personal data from unauthorized access or disclosure.
9. Contact Information
If you have any questions about this GDPR Compliance Statement or how we handle personal data, please contact:
This statement is intended to supplement our Privacy Policy and is updated to reflect our ongoing GDPR compliance efforts.