Data Processing Agreement · version 1.0 · September 21, 2026

Data Processing Agreement.

This DPA forms part of the agreement between NextIntent, Inc. and the business that installs or subscribes to the NextIntent service. It applies whenever NextIntent processes personal data on that business's behalf. Installing the NextIntent app or creating a NextIntent account accepts it.

1. Roles

The Customer is the controller of personal data about visitors to its websites and stores. NextIntent is the processor and acts only on the Customer's documented instructions: the service's features as the Customer configures them, this DPA, and the Privacy Policy.

2. Scope of processing

Subjects: visitors to the Customer's sites and stores. Data: a random browser identifier; page, timing, scroll, cursor, touch and click measurements; one-way hashes of submitted form values and discount codes; cart counts, totals and product handles; for stores that share orders, the order total, currency, order number, whether a discount applied, and a one-way hash of the customer reference. Excluded by design: names, email addresses, phone numbers, postal addresses, payment details, the text of form fields, the text of chat messages. Purposes: detecting the moment a visitor needs help, delivering one message from the Customer's own facts or opening the Customer's chat, measuring the outcome against a held-out group, and reporting to the Customer. Duration: the term of the agreement plus the deletion period in section 8.

3. Instructions and limits

NextIntent processes personal data only for the purposes in section 2: never for its own advertising, never to build profiles across Customers, and never to sell or share it. Identity resolution is off unless the Customer enables it, and then runs only for visitors whose consent, as recorded by the Customer's consent tools, permits it. NextIntent informs the Customer if it believes an instruction infringes data protection law.

4. Confidentiality and staff

NextIntent staff with access to personal data are bound by confidentiality. Access is limited to those who need it to operate or support the service, and is logged.

5. Security

NextIntent maintains technical and organizational measures appropriate to the risk: encryption in transit (TLS) and at rest; credentials stored as one-way hashes or encrypted; separation of production and test environments; least-privilege access; an audit log of authenticated API calls; monitoring; and an incident response process. A summary of measures is available on request.

6. Subprocessors

The Customer authorizes these subprocessors: Railway (hosting, databases; US), Cloudflare (network, edge, storage; US), Anthropic (model inference over behavioral snapshots that contain no name, email, phone or address; US), Shopify (platform, where applicable), and Clerk (Customer sign-in). NextIntent gives at least 30 days' notice of additions on the Privacy Policy page. The Customer may object in writing and, if the objection cannot be resolved, terminate the affected service. NextIntent remains responsible for its subprocessors.

7. Data subject requests

NextIntent assists the Customer in responding to requests to access, correct, delete or restrict personal data. Requests relayed through platform mechanisms (for Shopify: the customer data request, customer redact and shop redact webhooks) are handled automatically; affected records are erased within 30 days and the Customer can confirm the result on request.

8. Retention and deletion

Live session state expires within minutes of the last activity. Behavioral and order records are retained for up to 13 months, or the shorter period the Customer sets. When the Customer uninstalls the app or closes the account, outbound messages stop immediately and all personal data for the Customer's sites is deleted within 30 days except where law requires retention. Backups age out within a further 30 days.

9. Incidents

NextIntent notifies the Customer without undue delay, and within 72 hours of becoming aware, of a personal data breach affecting the Customer's data, with the information reasonably available, and cooperates with the Customer's response.

10. Audits

On reasonable written request, at most once a year unless required by a supervisory authority or following an incident, NextIntent provides the information necessary to demonstrate compliance with this DPA and allows an audit by the Customer or an independent auditor bound by confidentiality, at the Customer's cost, with reasonable notice and during business hours.

11. International transfers

Processing takes place in the United States. For personal data from the EEA, the UK or Switzerland, the parties incorporate the European Commission's Standard Contractual Clauses (module two, controller to processor) and the UK Addendum, with NextIntent as data importer; the annexes are completed by sections 2, 5 and 6 of this DPA.

12. General

This DPA prevails over conflicting terms of the agreement regarding personal data. Liability is governed by the agreement. Each party bears its own costs of compliance. This DPA is governed by the law of the agreement.

See also: Privacy Policy · What the script measures