Data Processing Agreement
Last updated: September 17, 2026
This Agreement applies when you connect a business platform to LifeOS and we process personal data on your behalf. It forms part of our Terms of Service and should be read alongside our Privacy Policy.
1. Scope and Roles
This Agreement applies where Venturis 13 Global Holdings LLC ("LifeOS", "we", "us") processes personal data on behalf of a customer ("you") in providing the LifeOS service — in particular data obtained from a business platform you connect, such as Shopify.
For that data you are the controller and we are your processor. For data about you and your own staff — your account, your billing, your use of the product — we are the controller, and our Privacy Policy governs.
2. Our Obligations
We will:
- Process personal data only on your documented instructions. Your instructions are this Agreement, the Terms of Service, and your use of the product — the questions you ask the assistant and the features you enable. If we believe an instruction breaks applicable data protection law, we will tell you.
- Process it only for the purposes set out in Annex 1, and for no purpose of our own. We will not use your customers' personal data to train AI models, to build profiles, or to market to your customers.
- Ensure that staff with access are bound by confidentiality.
- Implement the technical and organizational measures in Annex 2.
- Engage sub-processors only under Section 4.
- Assist you, so far as we are able and taking account of the nature of the processing, in responding to data subject requests and in meeting your obligations on security, breach notification, and impact assessments.
- Notify you without undue delay, and in any event within 72 hours, of confirming a personal data breach affecting your data, with what we know and what we are doing.
- Delete or return personal data on termination, per Section 6.
- Make available the information needed to demonstrate compliance with this Agreement, and allow for and contribute to audits under Section 7.
3. Your Obligations
You warrant that you have a lawful basis for the personal data you instruct us to process, that you have given your customers any notice their law requires, and that your instructions comply with applicable data protection law.
4. Sub-processors
You give general authorization for the sub-processors listed in Annex 3. We will give at least 30 days' notice before adding or replacing one, by email to your account owner and on this page. If you reasonably object on data protection grounds within that period we will work with you in good faith; if we cannot resolve it, you may terminate the affected part of the service without penalty.
Every sub-processor is bound by obligations no less protective than these, and we remain fully liable to you for their performance.
5. International Transfers
Where personal data is transferred outside its country of origin, we rely on an adequacy decision or on Standard Contractual Clauses or an equivalent lawful transfer mechanism, and apply supplementary measures where required.
6. Retention and Deletion
We retain personal data only as long as needed for the purposes in Annex 1, within the periods published in our Privacy Policy, which are enforced automatically.
We hold no standing records of your customers. Data from your connected platform is read when needed to answer a request and is not copied into a customer database. Disconnecting the platform or uninstalling the app revokes our access immediately; we delete the stored connection, including access tokens, within 48 hours. On termination of your account we delete remaining personal data within 30 days, except where law requires us to keep it.
7. Audit
On reasonable written notice, no more than once a year unless required by a supervisory authority or following a breach, we will provide the information reasonably needed to verify our compliance. Where documentation is not enough, we will cooperate with an audit by you or an independent auditor bound by confidentiality, at your cost and without disrupting our other customers.
Annex 1 — Details of Processing
Subject matter
Provision of the LifeOS service, including its AI assistant and shipping automation.
Duration
For as long as the connection is active, plus the retention periods in the Privacy Policy.
Nature and purpose
Reading business records from your connected platform to (a) answer your questions about your business, and (b) rate, prepare, and book shipments that you approve.
Categories of data subject
Your customers; your staff who use LifeOS.
Categories of personal data
Name, email address, telephone number, shipping and billing address; order and transaction records; fulfillment and delivery information.
Special category data
None requested or required. Do not enter special category data into the assistant.
Annex 2 — Technical and Organizational Measures
- Encryption. In transit, TLS on every connection. Credentials encrypted at rest and held in a dedicated secrets vault, never in source control. Database backups encrypted, with the decryption key held off the server.
- Data minimization. No customer database exists. Records are read live, used to answer the request, and discarded.
- Access control. Production access restricted to named staff, by key, with no password authentication. Staff accounts authenticate through federated sign-in; we store no staff passwords.
- Logging. Every access to protected customer data is logged per operation, with results redacted from the log, and retained for 12 months.
- Separation. Test and production data are separated at the tooling level; test environments cannot reach production data.
- Retention. Automated expiry of conversations, recordings, and logs.
- Incident response. A written security incident response policy, reviewed annually and after any significant incident, with defined severities, containment steps, and notification deadlines.
- Resilience. Nightly encrypted backups with a documented restore procedure.
Annex 3 — Sub-processors
- DigitalOcean — hosting and database. All data, at rest.
- Anthropic — AI assistant responses. Records relevant to the question asked.
- OpenAI — AI assistant responses and transcription. Records relevant to the question asked.
- Freightcom — shipment rating and booking. Delivery address and contact details.
- Brevo — transactional email. Recipient email address.
- Twilio — voice, messaging, and video features. Phone number, where used.
- Stripe— payment processing for your billing. Your billing data, not your customers'.
Contact
Questions about this Agreement, or requests to exercise any right under it, can be sent to admin@venturis13.com.