Last updated: 22 August 2026
This Agreement governs the processing of personal data carried out by ORGANIC ECOM LLC (EIN 30-1338491, 1342 NM 333, Ste C 5130, Tijeras, NM 87059, United States) («the Processor», mailipy) on behalf of the merchant using the Service («the Controller», you), pursuant to Article 28 of Regulation (EU) 2016/679 (GDPR). It forms part of the Terms of Service.
The Processor processes data for the sole purpose of providing the Service, for two distinct purposes:
Processing lasts for the duration of the contractual relationship.
| Categories of data | Categories of data subjects |
|---|---|
| Identification and contact data (name, email address), order data (number, status, tracking, amount), the content of support communications and abandoned checkout data (email, cart items, amount, currency and recovery link). | End customers and contacts of the Controller's store who write to the support mailbox, and people who started a checkout in the store without completing it. |
The Processor shall process the data solely on the Controller's documented instructions (including the Service configuration and these Terms), unless legally required otherwise. If an instruction infringes applicable law, the Processor shall inform the Controller.
The Processor ensures that persons authorised to process the data have committed themselves to confidentiality.
The Processor applies appropriate technical and organisational measures: encryption in transit (TLS), encryption at rest of sensitive credentials, secret management, access control and logical isolation of data per account.
The Controller authorises the Processor to engage the following sub-processors. The Processor imposes equivalent protection obligations on them and remains liable for their performance.
| Sub-processor | Activity | Location |
|---|---|---|
| Anthropic | Generation of the draft text (Claude API). Does not train on API data. | USA (standard contractual clauses) |
| Google Cloud / Firebase | Storage, authentication and execution. | EU (europe-west1) |
| Resend | Delivery of outgoing emails: support replies approved by the Controller and cart recovery emails sent automatically. | USA (standard contractual clauses) |
The Processor shall give notice of any intended change of sub-processors, giving the Controller the opportunity to object.
The Processor shall assist the Controller, insofar as possible, in responding to data subjects' requests to exercise their rights and in complying with its obligations regarding security, breach notification and impact assessments (Arts. 32 to 36 GDPR).
The Processor shall notify the Controller without undue delay after becoming aware of a personal data breach, with the information available so that the Controller can comply with its notification obligations.
On termination of the Service, the Processor shall delete or return the personal data to the Controller and delete existing copies, unless legally required to retain them.
The Processor shall make available to the Controller the information necessary to demonstrate compliance with the obligations of Art. 28 and shall allow for reasonable audits.
The Processor is established in the United States, outside the European Economic Area, although the data is stored in the European Union (Google Cloud, europe-west1). Where the Controller is subject to the GDPR, the transfer to the Processor and to sub-processors located outside the EEA relies on the European Commission's standard contractual clauses (Implementing Decision (EU) 2021/914), module 2 (controller to processor), which the parties incorporate by reference into this Agreement, together with the technical measures described in clause 6.