Otengo

Data Processing Agreement

Last updated: 2026-08-25

This agreement governs our processing of personal data about your customers. It applies automatically when you install Otengo and forms part of the Terms of Service. You do not need to sign anything, though we will provide a signed copy on request if your own compliance process needs one - email info@otengo.com.

1. Parties and roles

  1. 1.1You - the merchant operating the Shopify store on which Otengo is installed. You are the controller.
  2. 1.2Us - Frominbox, MB (mažoji bendrija), company code 307162506, A. Juozapavičiaus g. 28, LT-09311 Vilnius, Lithuania. We are the processor.
  3. 1.3You decide which of your customers are contacted, why, and what the assistant says. We provide the means and act on your instructions. That division is not a formality - it is what makes it lawful for us to call your customers at all.
  4. 1.4There is one narrow exception, and we would rather state it than hide it. For the record of who has opted out of being contacted, we act as a controller in our own right as well as your processor, so that an opt-out survives you deleting your data. It is described in section 10.
  5. 1.5Where we are required to designate a representative in the United Kingdom under Article 27 of the UK GDPR, we will do so and publish the details here.

2. What we process, and why

  1. 2.1Subject matter. Answering telephone calls to your store, placing calls and sending text messages to your customers on your instruction, and giving you the records of what happened.
  2. 2.2Duration. For as long as Otengo is installed, and then for the periods in section 10.
  3. 2.3Nature and purpose. Receiving and making calls, converting speech to text and text to speech, matching a caller to your Shopify records, recording where you have switched recording on, storing the results, and keeping the record of who agreed to be contacted.
  4. 2.4Types of personal data and categories of data subject. Set out in Annex A.
  5. 2.5Special category data. Otengo is not intended for it, and we ask you not to configure the assistant to collect it. A caller may nonetheless volunteer something sensitive in conversation, and where that reaches a transcript it is protected the same way as everything else and removed on the same schedule.

3. Your instructions

  1. 3.1We process your customers’ personal data only on your documented instructions. Your instructions are: this agreement, the Terms, and what you configure in the app - your flows, audiences, greetings and settings.
  2. 3.2Contacting your customers is one of those instructions. When you switch on a flow or start a campaign you are instructing us to contact those people on your behalf, in your name, from a number that identifies you. We do not contact your customers for our own purposes, ever.
  3. 3.3We will tell you if we think an instruction breaks data protection law, and we may decline to act on it. We are not obliged to check whether you have permission for a particular audience, and it remains your responsibility under the Acceptable Use and Calling Policy.
  4. 3.4Some safeguards are not subject to your instructions, because they are duties owed to the person being called rather than services provided to you: the disclosure that the caller is speaking with an AI assistant, the suppression of anyone who has opted out, and legally mandated quiet hours and screening.
  5. 3.5Where we are required by law to process data beyond your instructions, we will tell you first unless that law prohibits it.

4. Our obligations

  1. 4.1We process only what is needed to provide the service, and only for the purposes in this agreement.
  2. 4.2We do not sell your customers’ data, share it with anyone for their own purposes, or use it to build products for other merchants.
  3. 4.3We do not use your data, or your customers’ data, to train or improve any artificial intelligence or machine learning model - not ours, and not our suppliers’. This is a contractual commitment we hold our suppliers to as well, and it does not have an exception for anonymised or aggregated data.
  4. 4.4Everyone with access is bound by confidentiality and trained on handling personal data.
  5. 4.5We help you meet your own obligations - security, breach notification, impact assessments and prior consultation - to the extent the information is ours to give. A pre-completed impact assessment for a typical Otengo deployment is available on request.

5. Security

We implement appropriate technical and organisational measures, described in Annex B and summarised on our security page. We review them as the service changes, and we will not lower them during your agreement.

6. Sub-processors

  1. 6.1You give us general authorisation to engage sub-processors. The current list is published at otengo.com/subprocessors and forms part of this agreement.
  2. 6.2We give you 30 days’ notice before a new sub-processor begins processing, so you have time to object.
  3. 6.3If you object on reasonable data-protection grounds and we cannot provide an alternative, you may terminate the affected service without penalty and without paying for the unused remainder of your term.
  4. 6.4Each sub-processor is under written terms no less protective than these, and we remain fully liable to you for what they do.

7. Your customers' rights

  1. 7.1Requests come to you, because you are the controller. If one reaches us directly we will not answer it on your behalf; we will pass it to you promptly, and tell the person we have done so.
  2. 7.2We help you answer it. Access, export, correction and deletion are available to you in the app, so most requests need nothing from us at all.
  3. 7.3One thing we will always act on immediately, whoever it reaches: a request to stop being contacted. We suppress the number at once and tell you. Waiting for you to action it would mean calling someone who has asked us not to.
  4. 7.4Shopify’s own customer data request and erasure notifications are handled automatically, on Shopify’s timetable rather than ours.

8. Personal data breaches

  1. 8.1We tell you without undue delay and within 48 hoursof becoming aware of a breach affecting your customers’ data - not at the end of an investigation, but as soon as we know there is one.
  2. 8.2The notice covers what happened, which categories of data and roughly how many people are affected, the likely consequences, what we have done, and who to contact. Where we do not yet know something, we say so and follow up.
  3. 8.3Reporting to a regulator, and telling affected individuals, is yours to decide as controller. We give you what you need to make that decision inside your own 72-hour window, which is why our own deadline is shorter.
  4. 8.4We keep a register of breaches, including ones we decide are not notifiable and why.

9. International transfers

  1. 9.1Your records are stored in the European Union.
  2. 9.2Live call audio and speech processing may involve providers outside the EEA, because a phone call happens in real time and cannot be queued until it reaches a preferred jurisdiction. We say this plainly rather than claiming everything stays in Europe.
  3. 9.3Those transfers rely on the Standard Contractual Clauses approved by the European Commission, Module Two (controller to processor) and Module Three (processor to processor) as applicable, which are incorporated into this agreement by reference. Your acceptance of this agreement is your entry into them as data exporter.
  4. 9.4For data about people in the United Kingdom, the International Data Transfer Addendum issued by the ICO applies on top of those Clauses.
  5. 9.5Where a supplier also holds an EU-US Data Privacy Framework certification, we treat it as an additional safeguard rather than the primary one. Arrangements of that type have twice been annulled, and the current one is under appeal; the Clauses do not depend on it.
  6. 9.6We carry out and record a transfer risk assessment for each provider, and will share it with you on request.

10. Return and deletion

  1. 10.1You can export your call records and contacts at any time while your account is active, without asking us.
  2. 10.2When you uninstall Otengo, your customers’ personal data - transcripts, recordings, caller names and numbers, and the copies we hold of your Shopify orders and customers - is deleted within 48 hours.
  3. 10.3Your own configuration - agent settings, flows, greetings - is kept for up to 30 days so that reinstalling restores your setup rather than starting from nothing, then deleted.
  4. 10.4While your account is open, recordings and transcripts are deleted on the schedule you choose: 30, 90, 180, 365 days, 90 by default. There is no option to keep them indefinitely.
  5. 10.5Two things are deliberately kept. Consent records are kept for as long as the account exists, because they are the evidence that a call was permitted, and deleting them would leave you unable to answer a challenge.
  6. 10.6The suppression list is kept indefinitely, and it is not deleted when you uninstall. It holds phone numbers and nothing else. If we deleted it, the only record that someone asked never to be called again would be gone, and the first thing a reinstall would do is call them. Keeping it protects the individual, not us, and it is why we act as a controller for that one record.
  7. 10.7Aggregate billing records - dates, durations, amounts, with no names or numbers - are kept as long as tax law requires.

11. Audits

  1. 11.1We give you the information you need to show that we meet these obligations, including our security documentation and the transfer assessments.
  2. 11.2You may audit us, yourself or through an independent auditor who is not our competitor, on 30 days’ notice, once in any 12 months, during business hours, and without disrupting the service or exposing another merchant’s data. A regulator’s instruction lifts the notice period and the limit.
  3. 11.3You bear your own costs unless the audit finds a material breach on our side, in which case we bear ours and fix it.

12. California and other US states

Most Otengo merchants sell in the United States, so this section applies to the personal information of California residents and, on the same terms, to equivalent state laws elsewhere.

  1. 12.1We act as a service provider under the California Consumer Privacy Act. You are the business.
  2. 12.2We do not sell or share personal information, as those terms are defined in that Act. No exchange for money, and none for cross-context behavioural advertising.
  3. 12.3We do not retain, use or disclose personal information for any purpose other than performing the service, and never for a commercial purpose of our own.
  4. 12.4We do not combine your customers’ personal information with information we receive from anyone else, except as that Act permits a service provider to do.
  5. 12.5We will tell you if we determine we can no longer meet these obligations, and you may take reasonable steps to stop and remediate any unauthorised use.
  6. 12.6Consumer requests to know, delete, correct or opt out come to you as the business; we help you honour them, and an opt-out of contact is acted on immediately as described above.

13. Shopify terms we pass through

Shopify imposes obligations on apps that we owe to you as well as to Shopify. They are repeated here so that they are enforceable between us:

  1. 13.1We contact your customers only as your processor, on your instruction and in your name, under the authority you give us in section 3. We never contact them for our own purposes.
  2. 13.2We never use your data or your customers’ data to develop or train artificial intelligence or machine learning systems, including in anonymised, aggregated or derived form.
  3. 13.3We delete your data within 30 days of you uninstalling, of it no longer being needed, or of an enforceable request from you, a customer or Shopify. In practice we do it in 48 hours.
  4. 13.4We access only the Shopify data our stated features need, and we ask for each protected field individually with a reason.

14. Annex A - processing details

Categories of data subject and personal data processed
WhoWhat we processWhy
Your customers who call youPhone number, anything they say, the transcript, a recording where you have enabled it, the outcome of the call, and any order or account we matched them toTo answer the call and give you the record of it
Your customers we call or textName, phone number, order and delivery details relevant to the call, consent and contact history, conversation content and outcomeTo carry out the flow or campaign you configured
People who ask not to be contactedPhone number onlyTo make sure they are never contacted again
Your staffName, email, role, and a log of administrative actionsTo run your account and keep it secure

Frequency: continuous, for as long as the app is installed. Duration: as set out in section 10.

15. Annex B - security measures

  1. 15.1Encryption in transit and at rest, including backups.
  2. 15.2Recordings held in private storage, reachable only through short-lived signed links after an entitlement check - never a public URL.
  3. 15.3Each merchant’s data isolated at the database level, so one store cannot read another’s even if application code is wrong.
  4. 15.4Access limited to the few people who need it, with individual accounts, strong authentication, and a log of any access to a merchant’s account.
  5. 15.5Separate test and production environments, with no production personal data in testing.
  6. 15.6Personal data is never written to application logs - not transcripts, phone numbers, names or whole webhook payloads. Identifiers and metrics only.
  7. 15.7Automatic deletion runs daily against the retention schedule, rather than depending on anyone remembering.
  8. 15.8Documented incident response and data loss prevention procedures, reviewed at least annually.
A fuller description is on our security page, and the underlying documents are available to merchants under an existing agreement on request.

16. Annex C - sub-processors

The current list, with what each one does, where it is, and the basis for any transfer, is published at otengo.com/subprocessors and forms part of this agreement. Changes are notified as described in section 6.