Skip to content
tasmın
Features
EmailSocialBlogShowing up on GoogleProduct BuilderBrand voiceIntelligence All features →
How it works Pricing

Features

EmailSocialBlogShowing up on GoogleProduct BuilderBrand voiceIntelligence All features → How it works Pricing

Legal

Data Processing Agreement

Last updated: 3 August 2026

About this document. This Data Processing Agreement (“DPA”) applies when you use Tasmin to process the personal data of your own customers or contacts (for example, your email subscribers). It sets out how Tasmin, as your processor, handles that data on your instructions, and forms part of our Terms of Service. For personal data where Tasmin is the controller (your own account data), see our Privacy Policy. If you need a counter-signed copy for your records, email privacy@tasmin.ai.

1. Parties & roles

This DPA is between you (the merchant using Tasmin — the “Customer”, acting as the data controller) and Tasmin Teoranta, a company registered in Ireland under number 821803, registered office 55 Parnell Street, Waterford, X91 X278, Ireland (“Tasmin”, acting as the data processor).

It applies to Tasmin’s processing of personal data for which the Customer is the controller (“Customer Personal Data”) — principally the personal data of the Customer’s own customers, subscribers and contacts that Tasmin processes to provide the service. Terms such as “controller”, “processor”, “personal data”, “processing”, “data subject” and “personal data breach” have the meanings given in the EU General Data Protection Regulation (Regulation (EU) 2016/679, the “GDPR”).

2. Processing on documented instructions

Tasmin will process Customer Personal Data only on the Customer’s documented instructions — which include this DPA, the Terms, and the Customer’s use and configuration of the service (for example, the audiences, content and schedules the Customer sets up) — and as required to provide and secure the service. Tasmin will not process Customer Personal Data for its own purposes. If Tasmin is required by EU or member-state law to process the data otherwise, it will inform the Customer first, unless that law prohibits it. If Tasmin believes an instruction infringes data-protection law, it will tell the Customer.

The Customer’s responsibilities. The Customer is responsible for the accuracy and legality of the data it provides, and for having a valid lawful basis and any required consent for the personal data it brings into, collects through, or sends using Tasmin.

3. Subject matter & details of processing

The subject matter, duration, nature and purpose of the processing, the types of personal data, and the categories of data subjects are set out in Annex I.

4. Confidentiality

Tasmin will ensure that the people authorised to process Customer Personal Data are bound by confidentiality obligations and access the data only as needed to perform their role.

5. Security

Taking into account the state of the art, the costs of implementation, and the nature, scope, context and purposes of processing, Tasmin implements appropriate technical and organisational measures to ensure a level of security appropriate to the risk, as described in Annex II. Tasmin may update these measures over time, provided the level of protection is not reduced.

6. Sub-processors

The Customer gives Tasmin general authorisation to engage sub-processors to help provide the service. Tasmin will: (a) impose data-protection obligations on each sub-processor that are substantially the same as those in this DPA; and (b) remain responsible for each sub-processor’s performance. The current sub-processors are listed in Annex III. Tasmin will give the Customer notice of any intended addition or replacement of a sub-processor (by updating the list and/or by email) with a reasonable opportunity to object on reasonable data-protection grounds; if the Customer objects and the parties cannot resolve it, the Customer may stop using the affected feature or terminate.

7. Assistance with data-subject requests

Taking into account the nature of the processing, Tasmin will assist the Customer by appropriate technical and organisational measures, so far as possible, to respond to requests from data subjects exercising their rights (access, rectification, erasure, restriction, portability and objection). If Tasmin receives such a request directly relating to Customer Personal Data, it will not respond itself except on the Customer’s instruction, and will refer the request to the Customer (the controller) without undue delay. The service also provides self-service tools — for example, one-click unsubscribe on emails, suppression and deletion of subscribers, and handling of Shopify’s data-request and redaction webhooks — that help the Customer meet these obligations.

8. Assistance with security, breach & impact assessments

Taking into account the nature of the processing and the information available to it, Tasmin will assist the Customer in ensuring compliance with its obligations on security of processing, personal-data-breach notification, data-protection impact assessments, and prior consultation (Articles 32–36 GDPR).

9. Personal data breach notification

Tasmin will notify the Customer without undue delay after becoming aware of a personal data breach affecting Customer Personal Data, and will provide the information reasonably available to help the Customer meet its own notification obligations. Notification of a breach is not an acknowledgement of fault or liability.

10. Deletion or return on termination

On termination of the service, and at the Customer’s choice, Tasmin will delete or return Customer Personal Data, and delete existing copies, unless EU or member-state law requires continued storage. In practice, Customer Personal Data is deleted or de-identified following account closure and on receipt of Shopify’s store-deletion request, after a short grace window, as described in the Privacy Policy (Section 8). The Customer can also export data from within the service before termination.

11. Audits & information

Tasmin will make available to the Customer information reasonably necessary to demonstrate compliance with Article 28 GDPR, and will allow for and contribute to audits, including inspections, conducted by the Customer or an auditor it mandates. To protect the security and confidentiality of other customers, audits are subject to reasonable notice, frequency, confidentiality and scope limits, and may be satisfied by Tasmin providing relevant documentation or third-party reports where available.

12. International transfers

Several sub-processors are located in, or transfer Customer Personal Data to, the United States or other countries outside the EEA (see Annex III — the live email transport Resend is US-incorporated, and AI, hosting, storage and operational-tooling providers are also outside the EEA). Every such transfer runs on an approved safeguard, and Annex III states the safeguard for each provider individually.

For the US providers Tasmin engages, that safeguard is the EU-US Data Privacy Framework — each provider's certification was checked as active on the official Data Privacy Framework list, and an Article 28 data-processing agreement is executed or accepted with each of them. Several also carry the European Commission's Standard Contractual Clauses in their data-processing agreement as a fallback. Where a provider processes within the EEA (for example Sentry's Frankfurt ingest, or Resend's EU sending region) that is stated in Annex III as well. Cloudinary — legacy image storage only, retained solely so pre-migration images can be erased — is additionally covered by the Commission's adequacy decision for Israel. DataForSEO receives no personal data, so no transfer mechanism is required for it.

Data Privacy Framework certifications can lapse. Tasmin re-verifies each provider's certification on the official list periodically and before relying on it; if a provider ceases to be certified, Tasmin will move that transfer onto Standard Contractual Clauses with any additional measures required, and update this Annex. You can ask us for the current safeguard for any specific provider at privacy@tasmin.ai.

13. Liability & precedence

This DPA forms part of, and is subject to, the Terms of Service, including the limitation-of-liability provisions in those Terms. If there is a conflict between this DPA and the Terms regarding the processing of Customer Personal Data, this DPA prevails to the extent of that conflict.

14. Governing law

This DPA is governed by the laws of Ireland and is subject to the jurisdiction provisions of the Terms of Service.


Annex I — Details of the processing

  • Subject matter: Tasmin’s provision of AI marketing-automation services to the Customer, including email marketing.
  • Duration: for the term of the Terms of Service, until deletion or return of the data under Section 10.
  • Nature & purpose: storing, organising, segmenting, sending and managing marketing and transactional communications, and related analytics and suppression, on the Customer’s instructions.
  • Categories of data subjects: the Customer’s customers, subscribers, prospects and contacts; visitors to the Customer’s store who sign up to its list.
  • Types of personal data: contact details (email address; first/last name where provided); marketing-consent status and source; engagement and delivery events (opens, clicks, bounces, complaints, unsubscribes); and limited commerce attributes used for segmentation (such as order counts, last-order date, abandoned-checkout and back-in-stock signals). Tasmin does not require, and the Customer should not submit, special categories of personal data.
  • Frequency: continuous, for the duration of the service.

Annex II — Technical & organisational security measures

Tasmin’s measures include, as implemented in the service:

  • Encryption in transit — TLS on all external data transfers (traffic to and from merchants, sub-processors and third-party APIs, and inbound webhooks). Internal service-to-service traffic (application ↔ database and cache) runs on an isolated, non-public private network rather than the public internet.
  • Encryption of secrets at rest — connected-account OAuth access tokens are encrypted at rest using AES-256-GCM, with key material held separately from the database.
  • Tenant isolation — data is scoped per merchant (tenant), with a structural cross-tenant access guard.
  • Authentication & access control — merchant sign-in is via Shopify OAuth (Tasmin stores no merchant passwords); administrative access is restricted and protected by multi-factor authentication.
  • Consent & deliverability safeguards — enforced double opt-in for direct sign-ups (addresses are withheld in a separate pending store until confirmed, with a 7-day link expiry); filtering of role/system addresses; MX-record validation on collection; suppression of hard bounces and complaints (fed by the email provider’s feedback notifications); reconciliation of Shopify marketing-consent in both directions; RFC 8058 one-click unsubscribe on outbound mail; automatic sending suspension on adverse reputation signals; and a send-disabled-by-default safeguard.
  • Data-subject & deletion workflows — handling of Shopify’s customers/data_request, customers/redact and shop/redact webhooks; subscriber suppression/deletion; and account-data export.
  • Hosting & operations — use of reputable cloud providers; logging and monitoring; and best-effort deletion of stored images on tenant erasure.

These measures are those implemented in the service. Tasmin may update them over time, provided the level of protection is not reduced (Section 5).

Annex III — Sub-processors

The sub-processors below process, host or transmit Customer Personal Data (or, for operational tooling, technical/usage data tied to the store) to help provide the service. Each row states the safeguard relied on for transfers outside the EEA. Every certification named was checked as active on the official Data Privacy Framework list, and an Article 28 data-processing agreement is executed or accepted with each provider listed (verified 23 July 2026; re-verified periodically — see Section 12).

Email delivery

  • Resend (Resend, Inc.) — live primary email transport. Sends the marketing and transactional emails the Customer creates; receives recipient email address, first name, and rendered message content, and delivery/bounce/complaint events. US-incorporated; sending is configured to an EU region (eu-west-1). Transfer mechanism: EU-US Data Privacy Framework (certification checked active), with Standard Contractual Clauses incorporated in Resend's data-processing agreement as a fallback. Article 28 DPA executed.

Hosting, storage & AI

  • Railway Corp. — application, database and cache hosting; stores Customer Personal Data at rest (the application database) and the job queue. Operator-stated EU region (EU-West); runs on Google Cloud infrastructure. US-incorporated. Transfer mechanism: EU-US Data Privacy Framework (certification checked active), with Standard Contractual Clauses in the data-processing agreement as a fallback. Article 28 DPA executed.
  • Cloudflare, Inc. — website hosting, content delivery and security, and R2 object storage for images (product / social / email imagery). US-incorporated, global edge network. Transfer mechanism: EU-US Data Privacy Framework (certification checked active). Article 28 DPA on file.
  • Cloudinary — legacy image assets only, retained solely to allow erasure of pre-migration images (no new writes). Israel / US. Transfer mechanism: the European Commission's adequacy decision for Israel, and additionally the EU-US Data Privacy Framework (certification checked active). Article 28 DPA on file.
  • Anthropic, PBC (Claude API) — AI content generation from the merchant inputs the Customer provides (brand voice, product and store data). Not intended to receive the Customer's end-customers' contact details — the service is built to send store / content inputs and aggregates (see Privacy Policy, “AI processing”). Tasmin's account is on Anthropic's Commercial Terms of Service, which incorporate Anthropic's data-processing agreement and provide that inputs and outputs are not used to train Anthropic's models. US. Transfer mechanism: EU-US Data Privacy Framework (certification checked active), with Standard Contractual Clauses (Module 2, controller-to-processor) incorporated in that agreement as a fallback.

Operational tooling (technical/usage data tied to the store, not customers' contact details)

  • Slack (Slack Technologies / Salesforce) — operator alerting. Receives merchant / store identifiers, credit amounts and error diagnostics; customer email addresses are masked before an alert is sent. US. Transfer mechanism: EU-US Data Privacy Framework (certification checked active, under Salesforce's certification). Article 28 DPA on file.
  • PostHog, Inc. — product analytics. Receives store- and usage-level product events keyed to the store rather than to any individual person (the identifier transmitted is a store reference, tenant:<id>): install, activation and subscription milestones, connection milestones, and per-generation metadata (feature label, AI model name, token counts). Store-level properties sent are shop domain, shop name, plan and account status. No end-customer contact details, and no prompt or generated content. Server-side only — there is no browser SDK, so no cookies are set and no visitor is tracked. EU-hosted (Frankfurt region). US-incorporated provider. Enabled in production 28 July 2026. Transfer mechanism: EU-US Data Privacy Framework (certification checked active). Article 28 DPA on file.
  • Voyage AI (a MongoDB, Inc. company) — help-search embeddings. Receives Tasmin's own help-article text and the merchant's typed help / assistant search queries. US; publishes a DPA at voyageai.com/dpa. Training opt-out exercised 13 July 2026 (ToS §3(iii); forward-only, irreversible) — Voyage does not train on or retain submitted content after processing. Transfer mechanism: EU-US Data Privacy Framework (certification checked active, under MongoDB's certification, which names Voyage AI Innovations, Inc.). Article 28 DPA on file.
  • Sentry (Functional Software, Inc.) — application error monitoring. Receives error diagnostics (stack traces, request / environment context) with a PII scrubber applied before transmission (email masking + named-PII redaction); configured for error monitoring only (no session replay, no performance tracing). EU-hosted (Frankfurt region). US-incorporated provider. Backend and client-side error monitoring both enabled in production 15 July 2026. Transfer mechanism: processing is EU-resident (Frankfurt ingest); for corporate access by the US entity, the EU-US Data Privacy Framework (certification checked active), with Standard Contractual Clauses also offered. Article 28 DPA on file.
  • DataForSEO — keyword research. Receives search keywords, locale and competitor domain names only — no personal data, so no transfer mechanism is required. US.
  • GitHub (GitHub / Microsoft) — documentation tooling; processes Tasmin's own help-content markdown only — no Customer Personal Data. US. Listed for completeness.

The connected platforms the Customer authorises — Shopify, Google, Meta and Pinterest — receive only what is needed to perform the actions the Customer authorises on the Customer's own accounts, and act under their own terms; Shopify is also the source from which the Customer's data enters the service, governed by the Customer's own agreement with Shopify rather than by this Annex.

Contact

Questions about this DPA or to request a signed copy: privacy@tasmin.ai, or write to Tasmin Teoranta, 55 Parnell Street, Waterford, X91 X278, Ireland.

← Back to Tasmin

tasmın Tasmin — your shop’s marketing, drafted in your voice and waiting for your yes.
Features How it works Pricing Privacy Terms

© 2026 Tasmin · Made for Shopify merchants · Privacy Policy · Terms · Refunds & Cancellation

Tasmin Teoranta · Registered in Ireland No. 821803 · 55 Parnell Street, Waterford, X91 X278, Ireland

Coming soon

Be first through the door.

Tasmin is almost ready. Join the waitlist and we’ll email you the moment you can start — with 100 free credits waiting when you do.

No spam — one email when we open. Unsubscribe anytime.

You’re on the list.

Thanks — we’ll be in touch the moment Tasmin opens. Keep an eye on your inbox.