Legal
Data Processing Agreement
This crawlable page mirrors Lutiq’s Data Processing Agreement. The product SPA also serves /dpa for the branded layout.
1. Preamble
This Data Processing Addendum ("DPA") is entered into between Lutiq LLC, a company located at 2261 Market Street, STE 88210, San Francisco, CA 94114, United States ("Lutiq"), and the Customer identified in the Lutiq Terms of Service or an applicable order form ("Customer" or "Brand Partner"). This DPA forms part of, and is incorporated into, the Terms of Service between the parties (the "Agreement"). In the event of a conflict between this DPA and the Agreement with respect to the processing of end-user personal information, this DPA controls.
2. Definitions
Capitalized terms not defined here have the meanings given in the Agreement or in the California Consumer Privacy Act, as amended by the California Privacy Rights Act (collectively, the "CCPA").
- "Personal Information" means information that identifies, relates to, describes, is reasonably capable of being associated with, or could reasonably be linked, directly or indirectly, with a particular Consumer or household, as defined in Cal. Civ. Code §1798.140(v)
- "Sensitive Personal Information" has the meaning given in Cal. Civ. Code §1798.140(ae)
- "Service Provider" has the meaning given in Cal. Civ. Code §1798.140(ag)
- "Business" has the meaning given in Cal. Civ. Code §1798.140(d)
- "Consumer" has the meaning given in Cal. Civ. Code §1798.140(i) and, where a comparable state privacy law applies, the analogous term under that law
- "Customer End-User PI" means Personal Information about Customer's visitors or customers that Lutiq processes on Customer's behalf under the Agreement
- "Experiment Data" means data collected via the Lutiq Pixel about visitors' interactions with Lutiq-served landing pages, together with the customer and order data the Customer authorizes Lutiq to access from its e-commerce platform (such as Shopify) and/or the Lutiq Pixel
- "Permitted Data" means the subset of Customer End-User PI that Customer authorizes Lutiq to use for Lutiq's own business purposes under the license in Section 5A — namely landing-page interaction and engagement data, conversion and purchase outcomes, and merchant-provided customer and order data — from the merchant's e-commerce platform (such as Shopify) and/or the Lutiq Pixel — in the hashed and minimized form Lutiq stores it
- "Security Incident" means a confirmed breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Customer End-User PI
3. Roles of the Parties
The parties acknowledge and agree that, with respect to Customer End-User PI processed to deliver the Services (generating and serving landing-page variants and producing Customer's own performance and attribution reports): (a) Customer is the Business (and, where applicable, the equivalent "controller" under comparable state laws); and (b) Lutiq is the Service Provider (and, where applicable, the equivalent "processor" under comparable state laws), acting on Customer's documented instructions.
Separately, with respect to Permitted Data that Customer licenses to Lutiq under Section 5A for Lutiq's own purpose of training and improving Lutiq's optimization and attribution models, Lutiq acts as a Business (controller) in its own right and not as Customer's Service Provider. The parties acknowledge that this making-available of Permitted Data by Customer to Lutiq for Lutiq's own business purpose may constitute a "sale" or "sharing" of Personal Information under the CCPA and comparable laws, that Consumers have the right to opt out, and that the parties allocate the resulting obligations in Sections 5A and 5B.
United States only. The Services are currently offered in the United States only and are not directed to or offered to individuals located in the European Economic Area, the United Kingdom, or Switzerland. The EU and UK General Data Protection Regulation do not govern the Services, and this DPA does not grant GDPR or UK-GDPR data-subject rights. Lutiq routes traffic that it identifies as originating outside the United States away from the Lutiq experiment — such visitors are not served a Lutiq variant, and Lutiq does not collect or retain their Personal Information — and Customer acknowledges that this is how such traffic is handled. Customer also agrees to configure its own advertising and storefront consistent with this United-States-only scope. Lutiq may suspend or restrict the Services, or exclude data, to enforce this restriction.
4. Processing Instructions
Customer instructs Lutiq to process Customer End-User PI only as necessary to provide the Services described in the Agreement, including generating landing-page variants, serving variants at the edge, measuring engagement and conversion, and producing performance and attribution reports for Customer. Customer may issue additional reasonable instructions consistent with the Agreement through written notice to [email protected]. Lutiq's use of Permitted Data to train and improve its own models is governed by the separate license in Section 5A and is not service-provider processing under this Section.
5. Restrictions on Lutiq (Service-Provider Processing)
With respect to Customer End-User PI that Lutiq processes as a Service Provider to deliver the Services (i.e., all Customer End-User PI other than the use of Permitted Data licensed under Section 5A), and as required by Cal. Civ. Code §1798.140(ag), Lutiq will not:
- Retain, use, or disclose Customer End-User PI for any purpose other than the specific purpose of performing the Services for Customer, including retention for a commercial purpose other than the business purpose specified in the Agreement
- Retain, use, or disclose Customer End-User PI outside the direct business relationship between Customer and Lutiq
- "Sell" or "share" Customer End-User PI, as those terms are defined under the CCPA
- Combine Customer End-User PI received from Customer with Personal Information received from or on behalf of another person, or collected from Lutiq's own interaction with a Consumer, except to the extent expressly permitted under Cal. Civ. Code §1798.140(ag)(1) for service-provider purposes (such as providing services to different Customers using common infrastructure where no Consumer-level cross-linking occurs). For clarity, this restriction does not limit Lutiq's combining of Permitted Data — for example, joining a merchant-provided hashed customer identifier with that visitor's interaction data on a Lutiq-served page — for attribution and for training Lutiq's models under the license in Section 5A, which is expressly permitted
Lutiq certifies that it understands the restrictions in this Section 5 and will comply with them. These restrictions govern Lutiq's service-provider processing only; they do not restrict Lutiq's use of Permitted Data as a Business under the license in Section 5A.
Aggregated and de-identified data derived from Customer End-User PI — including aggregated, de-identified performance data, the aggregated performance priors used to bootstrap optimization across the platform, and trained model parameters — is not Customer End-User PI for the purposes of this DPA, provided Lutiq (a) takes reasonable measures to ensure such data cannot be associated with a specific Consumer, household, or Customer; (b) publicly commits to maintain and use the data in de-identified form; and (c) contractually obligates any recipient to the same.
5A. Customer Data License for Model Training
Customer grants Lutiq a non-exclusive, worldwide, royalty-free license to use Permitted Data as a Business (controller) in its own right to develop, train, evaluate, and improve Lutiq's optimization and attribution models and the Services, including learning across Lutiq's customer base. Knowing what a Consumer purchases after clicking a Lutiq-served landing page is core training signal for these models. Customer represents and warrants that it has provided all notices and obtained or made available all consents, authorizations, and opt-out mechanisms required under applicable law for Customer to make Permitted Data available to Lutiq for this purpose, including any disclosure of a "sale" or "sharing" and any "Do Not Sell or Share My Personal Information" control required on Customer's storefront.
Lutiq's exercise of this license is subject to the opt-out pass-through in Section 5B. Lutiq does not, through this license, receive the right to disclose any Consumer's individual, identifiable Personal Information, or Customer's raw customer records, to another Lutiq customer or any third party. Lutiq may, however, provide Customer with identifiers or linkage that connect a visitor to Customer's own records within Customer's own context — for example, associating a Lutiq visitor identifier on Customer's Lutiq-served pages with Customer's own customer or order identifier — and Lutiq does not provide identifiers that link a person across different Brand Partners. The benefit of model training flows to other customers only through Lutiq's trained model parameters and aggregate statistical patterns. The reciprocal benefit to Customer is that Customer's own experiments draw on models improved by the wider Lutiq customer base. Lutiq does not send shopper or merchant Personal Information to the third-party LLM inference providers it uses to generate page content, and it does not use Permitted Data to train third-party foundation models; it trains its own first-party models on Permitted Data.
5B. Opt-Out Pass-Through
Lutiq will honor a Consumer's opt-out of the sale or sharing of Personal Information with respect to the Section 5A license, including Lutiq's use of Permitted Data for cross-brand model training. Lutiq recognizes the Global Privacy Control (GPC) signal as a valid opt-out and honors it automatically; accepts opt-out requests at [email protected] and at lutiq.com/privacy-request; and, on Shopify storefronts, gates on the consent flags published through Shopify's Customer Privacy API. When a Consumer has opted out, Lutiq excludes that Consumer's Personal Information from use under the Section 5A license, including from cross-brand model training. Customer acknowledges that Lutiq's ability to receive storefront opt-out signals depends on Customer correctly configuring Shopify's Customer Privacy API and surfacing the required "Do Not Sell or Share My Personal Information" control on Customer's storefront.
6. Security Measures
Lutiq will implement and maintain reasonable administrative, technical, and organizational measures designed to protect Customer End-User PI, including:
- Encryption of Customer End-User PI in transit (TLS 1.2+) and at rest
- Pseudonymization of direct identifiers — email and phone are stored only as one-way SHA-256 hashes, IP addresses are salted-hashed, and addresses are reduced to coarse geo (country, province or state, and city)
- Role-based access controls and least-privilege access for Lutiq personnel
- Automated scrubbing of Personal Information from operational logs and error reports
- Regular vulnerability scanning and periodic penetration testing of the Services
- An incident response program with documented roles, escalation paths, and post-incident review
- A roadmap toward SOC 2 Type II attestation, with interim controls documented on request
Consent Signals and Opt-Out Propagation
Where the Lutiq Pixel is installed inside a Shopify merchant's storefront, it subscribes to Shopify's Customer Privacy API and gates event collection on the Consumer's consent flags as published by Shopify (analytics processing, sale of data, marketing processing). On Lutiq-served landing pages outside the Shopify storefront (e.g., go.brand.com), Lutiq honors the Global Privacy Control (GPC) signal as a request to opt out of the sale or sharing of Personal Information.
When the applicable consent signal indicates an opt-out, Lutiq excludes the Consumer's Personal Information from use under the Section 5A license, including any cross-brand model-training use. Customer (acting as the Business under the CCPA) acknowledges that Lutiq's gating of events on Customer's storefront depends on Customer correctly configuring Shopify's Customer Privacy API and surfacing the required consent controls (including a "Do Not Sell or Share My Personal Information" link or equivalent) on Customer's storefront.
Customer may forward a verified Consumer rights request (access, deletion, correction, opt-out) to [email protected]. Lutiq will act on a verified request within thirty (30) days, subject to the verification and exception provisions of the CCPA.
7. Sub-processors
Lutiq engages sub-processors to deliver the Services. With respect to Customer's end-consumer Personal Information processed under this Addendum, Lutiq acts as a Service Provider and the sub-processors disclosed in Tier A in §C.2 of the Privacy Policy at lutiq.com/privacy#part-c are Lutiq's sub-processors of that processing.
Separately, Lutiq engages vendors to process Customer's own Personal Information (e.g., billing, account, and support data about Customer's authorized users). With respect to that processing, Lutiq acts as the Business and the vendors disclosed in Tier B in §C.3 of the Privacy Policy at lutiq.com/privacy#part-c are Lutiq's sub-processors. This Addendum does not govern Tier B processing — that processing is governed by the Terms of Service and the Privacy Policy at lutiq.com/privacy. The third-party LLM inference providers Lutiq uses to generate page content are not sub-processors of Customer End-User PI, because Lutiq does not send shopper or merchant Personal Information to them. Shopify is Customer's own platform and is not a Lutiq sub-processor.
Lutiq maintains the Tier A sub-processor list in Part C of the Privacy Policy at lutiq.com/privacy#part-c and notifies subscribers to the [email protected] list of additions to or removals from that list. Lutiq does not commit to a fixed advance-notice period, or to an objection-and-termination right, for sub-processor changes; if Customer has concerns about a particular sub-processor, Customer may contact [email protected].
Lutiq remains responsible for each Tier A sub-processor's compliance with this DPA and will impose contractual obligations on each such sub-processor that are at least as protective as those set forth here.
8. Consumer Rights Assistance
Lutiq will, taking into account the nature of the Services, provide reasonable assistance to Customer in responding to verified Consumer requests under the CCPA and comparable state laws — including requests to know, delete, correct, or opt out of sale or sharing — within the statutory timeframes. Customer is responsible for verifying the identity of the requesting Consumer and deciding whether the request must be honored under applicable law. A verified Consumer deletion request, and a Shopify customers/redact request, are handled within 30 days.
9. Breach Notification
Lutiq will notify Customer without undue delay, and in any event no later than 72 hours, after becoming aware of a Security Incident involving Customer End-User PI. Notification will include, to the extent then known, the nature of the incident, the categories and approximate volume of records affected, the likely consequences, and the measures taken or proposed to address the incident and mitigate possible adverse effects. Notifications will be sent to the primary account contact on file.
10. Data Return and Deletion
Upon termination of the Agreement, Lutiq will delete Customer End-User PI within 30 days of a written request from Customer, except (a) for Customer End-User PI Lutiq is required to retain by law; and (b) for aggregated, de-identified data and trained model parameters as described in Section 5. Merchant-provided customer and order data is retained for 24 months, or until Customer disconnects the integration or requests deletion, whichever is earlier. Certification of deletion will be provided on request.
11. Audits
Where Lutiq maintains current third-party attestations (such as SOC 2 Type II), making those attestations available will satisfy Lutiq's audit obligations under this DPA, and Customer agrees to rely on them in the first instance. If Customer has a reasonable, documented basis to believe Lutiq is not complying with this DPA, Customer may request one audit per twelve-month period, on at least 30 days' prior written notice, conducted during Lutiq's normal business hours, limited in scope to Lutiq's processing of that Customer's End-User PI, of reasonable duration, and subject to reasonable confidentiality protections. Customer bears its own costs and reimburses Lutiq for the reasonable time and expense Lutiq incurs in connection with the audit, and the parties will agree on scope and timing in advance to minimize disruption to Lutiq's operations.
11.1 Government Access Requests
If Lutiq receives a subpoena, court order, or other legally binding request for Customer End-User PI from a governmental authority, Lutiq will, to the extent legally permitted, notify Customer promptly and give Customer a reasonable opportunity to seek a protective order or other remedy.
12. Contact
Data-processing questions and formal notices under this DPA may be sent to [email protected]. Sub-processor notice subscriptions are managed at [email protected].