Auftragsverarbeitungsvertrag (AVV) für die Fragfix-App für Shopify

zwischen dem Händler, der die App „Fragfix: KI-Kundenchat“ in seinem Shopify-Shop nutzt (nachfolgend „Verantwortlicher“), und Markus Künning, Einzelunternehmer, Zoppoter Straße 1, 27576 Bremerhaven, Deutschland (nachfolgend „Auftragsverarbeiter“ oder „Fragfix“) über die in den Nutzungsbedingungen der App (frag-fix.de/shop-app/terms) vereinbarte Leistung.

1. Gegenstand und Dauer

Gegenstand ist die Verarbeitung personenbezogener Daten der Besucher des Onlineshops des Verantwortlichen durch den Auftragsverarbeiter beim Betrieb des Chat-Assistenten im Shop. Der Vertrag gilt für die Laufzeit der Nutzungsbedingungen und endet mit der Löschung der Daten nach Ziffer 5.

2. Art und Zweck der Verarbeitung

(1) Der Auftragsverarbeiter nimmt Chat-Nachrichten der Shop-Besucher entgegen, beantwortet sie automatisiert mit einem KI-Modell und speichert sie für die Dauer nach Ziffer 5. Zweck ist die automatisierte Beantwortung von Kundenfragen im Shop sowie die Bereitstellung der Statistik für den Verantwortlichen (Anzahl der Gespräche, häufigste Fragen, Bewertungen der Antworten).

(2) Für jede Antwort ruft der Auftragsverarbeiter öffentlich verfügbare Produkt-, Preis-, Verfügbarkeits- und Richtliniendaten des Shops über die von Shopify bereitgestellte Schnittstelle (Storefront API) ab und durchsucht die vom Verantwortlichen hochgeladenen Dokumente (Vektorsuche mit Embeddings). Bei diesem Abruf übermittelt der Auftragsverarbeiter die IP-Adresse des Besuchers und das im Shop gewählte Land an Shopify. Shopify schreibt dies für Abrufe im Auftrag von Besuchern vor, um Missbrauch und automatisierte Zugriffe zu erkennen; das Land sorgt für die im Markt des Besuchers gültigen Preise und Verfügbarkeiten. Die IP-Adresse stammt selbst von Shopify (sie wird Fragfix mit jeder Chat-Anfrage über den App Proxy übermittelt) und wird von Fragfix dafür nicht gespeichert. Die öffentlichen Richtlinien des Shops speichert Fragfix bis zu einer Stunde zwischen.

(3) Datenfluss zur Google Gemini API (siehe Ziffer 6): Bei jeder Chat-Anfrage werden an Google übermittelt: der Text der aktuellen Nachricht, die letzten bis zu 8 Nachrichten des Gesprächs (Klartext), die als relevant ermittelten Ausschnitte aus den hochgeladenen Dokumenten, die abgerufenen Shop-Daten nach Absatz 2 sowie die Einstellungen des Assistenten (z. B. Name, Tonalität, Zusatzhinweise). Beim Hochladen eines Dokuments wird dessen Text in Ausschnitten zur Erzeugung von Embeddings an Google übermittelt. Nicht an Google übermittelt werden IP-Adresse, Sitzungs-ID, Cookies oder sonstige technische Kennungen der Besucher. Fragfix nutzt die Gemini API ausschließlich im kostenpflichtigen Modell („paid tier“); nach den zum Stand dieses Vertrags öffentlich einsehbaren Google-Bedingungen werden Ein- und Ausgaben dort nicht zum Training der Google-Modelle verwendet. Unabhängig davon speichert Google Anfragen, mitgesendeten Kontext und Antworten bis zu 55 Tage, um Verstöße gegen seine Nutzungsrichtlinien zu erkennen (ai.google.dev/gemini-api/docs/usage-policies). Maßgeblich sind die jeweils aktuellen Bedingungen von Google (ai.google.dev/gemini-api/docs/billing); ändert Google diese Praxis, gilt die neue Regelung, ohne dass es einer Anpassung dieses Vertrags bedarf.

(4) Embeddings sind eine für Menschen nicht lesbare, mathematische Darstellung von Textabschnitten. Enthält ein Abschnitt personenbezogene Daten, gilt auch das Embedding als deren Verarbeitung; eine Rückrechnung auf den Ursprungstext ist praktisch nicht vorgesehen, technisch aber nicht in jedem Fall ausgeschlossen. Embeddings der Dokumente bleiben bis zur Löschung des Dokuments gespeichert, Embeddings der Chat-Anfragen nur während der Anfrage.

3. Kategorien betroffener Personen und Daten

(1) Betroffene Personen sind die Besucher des Onlineshops, die den Chat nutzen, sowie Personen, deren Daten der Verantwortliche in hochgeladenen Dokumenten verarbeiten lässt (z. B. Ansprechpartner); für Letztere stellt der Verantwortliche sicher, dass er zur Verarbeitung berechtigt ist.

(2) Verarbeitete Daten:

(3) Nicht verarbeitet werden: Kundenkonten, Namen oder E-Mail-Adressen aus Shopify, Bestell- und Zahlungsdaten. Die Kennung eines angemeldeten Shop-Kunden, die Shopify technisch mitsendet (logged_in_customer_id), wird verworfen und weder gespeichert noch weitergegeben. Das Chat-Widget fragt keine Kontaktdaten ab.

4. Pflichten des Auftragsverarbeiters

5. Speicherdauer, Löschung und Backups

(1) Chatverläufe und Bewertungen werden automatisiert nach 30 Tagen gelöscht (täglicher Lösch-Job). Die Frist entspricht dem Zeitraum der Statistik für den Verantwortlichen.

(2) Nach der Deinstallation wird der Assistent sofort gesperrt. Installiert der Verantwortliche die App innerhalb von 48 Stunden erneut, bleibt alles erhalten. Andernfalls fordert Shopify den Auftragsverarbeiter nach 48 Stunden zur Löschung auf (shop/redact); der Auftragsverarbeiter löscht dann unverzüglich sämtliche Daten des Shops einschließlich Dokumenten, Embeddings, Einstellungen, Chatverläufen und Bewertungen.

(3) Zum Nachweis der Bearbeitung speichert der Auftragsverarbeiter ein Protokoll der Datenschutz-Anfragen von Shopify (Art der Anfrage, Shop-Adresse, Zeitpunkte, Ergebnis) ohne Inhalte und ohne Daten der Besucher für drei Jahre.

(4) Gelöschte Daten können noch bis zu 14 Tage in Sicherungskopien enthalten sein. Backups dienen ausschließlich der Wiederherstellung nach einem Ausfall oder Datenverlust, unterliegen denselben Maßnahmen wie die Produktivdaten und werden nach Ablauf der Frist automatisiert überschrieben bzw. gelöscht.

6. Unterauftragsverarbeiter

(1) Der Verantwortliche stimmt dem Einsatz folgender Unterauftragsverarbeiter zu:

(2) Shopify ist kein Unterauftragsverarbeiter von Fragfix. Die Anfragen der Besucher erreichen Fragfix über die Shopify-Plattform (App Proxy), die der Verantwortliche auf Grundlage seines eigenen Vertrags mit Shopify nutzt. Dasselbe gilt für den Abruf der Shop-Daten nach Ziffer 2 Absatz 2 einschließlich der dabei übermittelten IP-Adresse und des Landes: Shopify verarbeitet sie als Anbieter der Shop-Plattform des Verantwortlichen.

(3) Über einen neuen Unterauftragsverarbeiter informiert der Auftragsverarbeiter mindestens 14 Tage vor dessen Einsatz per E-Mail an die E-Mail-Adresse des Shops. Der Verantwortliche kann innerhalb dieser Frist aus wichtigem Grund widersprechen oder die App deinstallieren; erfolgt kein Widerspruch, gilt die Änderung als genehmigt.

7. Rechte und Pflichten des Verantwortlichen

(1) Der Verantwortliche bleibt für die Rechtmäßigkeit der Verarbeitung (Art. 6 DSGVO) und für die Information der Besucher (Art. 13 DSGVO) verantwortlich, einschließlich des Zwischenspeichers im Browser (Ziffer 3). Er nimmt den Einsatz des Chat-Assistenten in seine Datenschutzerklärung auf; einen Textbaustein dafür stellt Fragfix unter frag-fix.de/shop-app/privacy bereit.

(2) Der Verantwortliche lädt keine Dokumente mit besonderen Kategorien personenbezogener Daten (Art. 9 DSGVO) hoch und fordert Besucher nicht auf, solche Daten im Chat anzugeben.

8. Kontrollrechte

Der Verantwortliche kann sich in angemessenem Umfang von der Einhaltung dieses Vertrags überzeugen, insbesondere durch schriftliche Selbstauskünfte zu den Maßnahmen nach Anlage 1, Einsicht in verfügbare Nachweise (z. B. Konfigurations- oder Protokollauszüge) in zumutbarem Umfang sowie eine eigene Prüfung vor Ort oder aus der Ferne durch ihn oder einen zur Verschwiegenheit verpflichteten Dritten nach angemessener Vorankündigung (in der Regel mindestens zwei Wochen) und unter Rücksicht auf den Betrieb anderer Kunden. Für einen über das übliche Maß hinausgehenden Aufwand einer Vor-Ort-Prüfung kann der Auftragsverarbeiter eine angemessene Erstattung verlangen.

9. Haftung

(1) Für Ansprüche zwischen den Parteien aus diesem Vertrag gilt § 7 der Nutzungsbedingungen der App entsprechend, soweit gesetzlich zulässig.

(2) Unberührt bleibt die gesetzliche Haftung gegenüber betroffenen Personen nach Art. 82 DSGVO: Betroffene können Verantwortlichen und Auftragsverarbeiter unmittelbar in Anspruch nehmen; der Auftragsverarbeiter haftet nur, soweit er gegen die ihm speziell auferlegten Pflichten der DSGVO verstoßen oder rechtmäßige Weisungen missachtet hat (Art. 82 Abs. 2 DSGVO). Hat eine Partei vollen Schadensersatz geleistet, obwohl sie nur für einen Teil verantwortlich war, kann sie den Anteil der anderen zurückfordern (Art. 82 Abs. 5 DSGVO).

Anlage 1: Technische und organisatorische Maßnahmen (TOMs)

Stand bei Vertragsschluss. Der Auftragsverarbeiter darf Maßnahmen durch gleichwertige oder wirksamere ersetzen, solange das Schutzniveau nicht sinkt; einer förmlichen Vertragsänderung bedarf es dafür nicht.

Data Processing Agreement (DPA) for the Fragfix App for Shopify

This is an English translation. In case of any discrepancy, the German version shall prevail.

between the merchant using the app "Fragfix: KI-Kundenchat" in its Shopify store ("Controller") and Markus Künning, sole proprietor, Zoppoter Straße 1, 27576 Bremerhaven, Germany ("Processor" or "Fragfix") regarding the service agreed in the Terms of Use of the App (frag-fix.de/shop-app/terms).

1. Subject matter and duration

The subject matter is the processing of personal data of visitors to the Controller's online store by the Processor when operating the chat assistant in the store. This agreement applies for the term of the Terms of Use and ends with the deletion of the data under Section 5.

2. Nature and purpose of processing

(1) The Processor receives chat messages from store visitors, answers them automatically using an AI model and stores them for the period set out in Section 5. The purpose is to answer customer questions in the store automatically and to provide statistics to the Controller (number of conversations, most frequent questions, ratings of answers).

(2) For each answer, the Processor retrieves publicly available product, price, availability and policy data of the store via the interface provided by Shopify (Storefront API) and searches the documents uploaded by the Controller (vector search using embeddings). When retrieving this data, the Processor transmits the visitor's IP address and the country selected in the store to Shopify. Shopify requires this for requests made on behalf of visitors in order to detect abuse and automated access; the country ensures the prices and availability valid in the visitor's market. The IP address itself originates from Shopify (it is transmitted to Fragfix with every chat request via the App Proxy) and is not stored by Fragfix for this purpose. Fragfix caches the store's public policies for up to one hour.

(3) Data flow to the Google Gemini API (see Section 6): With each chat request, the following is transmitted to Google: the text of the current message, up to the last 8 messages of the conversation (plain text), the relevant excerpts from the uploaded documents, the store data retrieved under paragraph 2, and the assistant's settings (e.g. name, tone, additional notes). When a document is uploaded, its text is transmitted to Google in sections to create embeddings. IP address, session ID, cookies and other technical identifiers of visitors are not transmitted to Google. Fragfix uses the Gemini API exclusively on the paid tier; according to Google's terms publicly available at the date of this agreement, inputs and outputs are not used there to train Google's models. Irrespective of this, Google retains requests, provided context and answers for up to 55 days to detect violations of its usage policies (ai.google.dev/gemini-api/docs/usage-policies). Google's current terms are authoritative (ai.google.dev/gemini-api/docs/billing); if Google changes this practice, the new rule applies without this agreement needing to be amended.

(4) Embeddings are a mathematical representation of text sections that humans cannot read. If a section contains personal data, the embedding is also considered processing of that data; reconstructing the original text is not intended in practice but cannot be technically ruled out in every case. Embeddings of documents are stored until the document is deleted; embeddings of chat requests only for the duration of the request.

3. Categories of data subjects and data

(1) Data subjects are visitors to the online store who use the chat, and persons whose data the Controller has processed in uploaded documents (e.g. contact persons); for the latter, the Controller ensures that it is entitled to have the data processed.

(2) Data processed:

(3) Not processed: customer accounts, names or email addresses from Shopify, order and payment data. The identifier of a logged-in store customer that Shopify technically sends along (logged_in_customer_id) is discarded and neither stored nor passed on. The chat widget does not ask for contact details.

4. Obligations of the Processor

5. Storage period, deletion and backups

(1) Conversations and ratings are deleted automatically after 30 days (daily deletion job). This period matches the statistics period provided to the Controller.

(2) After uninstallation, the assistant is locked immediately. If the Controller reinstalls the App within 48 hours, everything is retained. Otherwise, Shopify requests the Processor to delete the data after 48 hours (shop/redact); the Processor then promptly deletes all data of the store, including documents, embeddings, settings, conversations and ratings.

(3) As proof of processing, the Processor keeps a log of data protection requests from Shopify (type of request, store address, times, result) without content and without visitor data for three years.

(4) Deleted data may remain in backups for up to 14 days. Backups serve only to restore data after an outage or data loss, are subject to the same measures as production data and are automatically overwritten or deleted after this period.

6. Sub-processors

(1) The Controller consents to the use of the following sub-processors:

(2) Shopify is not a sub-processor of Fragfix. Visitor requests reach Fragfix via the Shopify platform (App Proxy), which the Controller uses on the basis of its own contract with Shopify. The same applies to retrieving store data under Section 2(2), including the IP address and country transmitted in the process: Shopify processes them as the provider of the Controller's store platform.

(3) The Processor informs the Controller of any new sub-processor at least 14 days before its use by email to the store's email address. The Controller may object for good cause within this period or uninstall the App; if no objection is made, the change is deemed approved.

7. Rights and obligations of the Controller

(1) The Controller remains responsible for the lawfulness of processing (Art. 6 GDPR) and for informing visitors (Art. 13 GDPR), including about the browser storage (Section 3). It includes the use of the chat assistant in its privacy policy; Fragfix provides a template text for this at frag-fix.de/shop-app/privacy.

(2) The Controller does not upload documents containing special categories of personal data (Art. 9 GDPR) and does not ask visitors to provide such data in the chat.

8. Audit rights

The Controller may verify compliance with this agreement to a reasonable extent, in particular through written self-disclosures on the measures in Annex 1, inspection of available evidence (e.g. configuration or log excerpts) to a reasonable extent, and its own on-site or remote audit by itself or a third party bound to confidentiality, with reasonable prior notice (usually at least two weeks) and taking into account the operation of other customers. The Processor may request reasonable reimbursement for effort of an on-site audit beyond the usual extent.

9. Liability

(1) Claims between the parties under this agreement are governed by § 7 of the Terms of Use of the App accordingly, to the extent permitted by law.

(2) Statutory liability towards data subjects under Art. 82 GDPR remains unaffected: data subjects may claim directly against the Controller and the Processor; the Processor is only liable where it has not complied with obligations of the GDPR specifically directed to processors or has acted outside or contrary to lawful instructions (Art. 82(2) GDPR). If one party has paid full compensation although only partly responsible, it may claim back the other party's share (Art. 82(5) GDPR).

Annex 1: Technical and organizational measures (TOMs)

Status at the time the agreement is concluded. The Processor may replace measures with equivalent or more effective ones as long as the level of protection does not decrease; no formal amendment of this agreement is required for this.