Data Processing Agreement (DPA)
Last updated: 24 September 2026
This agreement supplements RecoKit's Terms of Use and Privacy Policy. By subscribing to or installing the service for a store, the Merchant accepts this agreement.
1. Parties and roles
The Merchant is the controller for processing carried out for its store visitors and customers. EENOD, the publisher of RecoKit, acts as processor when processing data to provide the service. EENOD remains controller for data required to manage the RecoKit account, billing and security.
2. Scope and term
Processing takes place while the service is used for Shopify, PrestaShop or another enabled integration, and covers only data needed for catalog synchronization, recommendations, sales attribution and service statistics.
3. Data processed
- catalog data: product identifiers, titles, descriptions, categories, prices, stock, images and attributes;
- recommendation signals: session identifier and viewed products;
- orders: order identifier, products, quantities, dates and amounts needed for attribution and quotas;
- technical and security data required to operate the service.
RecoKit does not require customer names, addresses, phone numbers or email addresses to display recommendations. The Merchant must not send unnecessary personal data in free-text fields.
4. Purposes and restrictions
EENOD uses the data only to provide, secure, measure and improve the service requested by the Merchant. Store data is isolated between merchants. It is not sold, used for independent advertising, or used to train a global model without a separate instruction and agreement.
5. Merchant instructions
The Merchant determines the purposes and permitted data categories. EENOD processes data on documented instructions, reports known security incidents and provides reasonable assistance with access, correction and deletion requests.
6. Sub-processors and security
Sub-processors may include OVH and Google Cloud for hosting, Polar for billing and Google Gemini for catalog semantic analysis. AI requests are limited to information required for that analysis; directly identifying customer data is not requested for this function. RecoKit uses TLS in transit, access controls and encryption of integration tokens.
7. Deletion and retention
On uninstall or Merchant request, EENOD disables the integration and starts deletion of the store data under its deletion procedure. Backup copies follow the applicable backup lifecycle. Legal retention obligations may apply. Deletion confirmation can be requested at contact@recokit.fr.
8. Data subject requests
The Merchant remains the primary contact for its customers and visitors. EENOD provides reasonable assistance where the relevant data is hosted by RecoKit.
9. Contact
EENOD, 124 rue de l'Obeau, 59310 Aix-en-Pévèle, France · contact@recokit.fr.