Last updated: 26/09/2026

GetCart Data Processing Agreement (DPA)

Effective from: 26/09/2026

This DPA is part of the Terms and governs GetCart's processing of personal data on behalf of the merchant, under LGPD art. 39. By installing GetCart and accepting the Terms, the merchant signs this DPA with GetCart.

Partes

  1. Processor: GetCart, the legal entity controlling the product (the controller of the means).
  2. Controller: the legal entity that owns the Shopify, Nuvemshop or Tray store where GetCart is installed.

1. Subject

This DPA defines how the Processor processes personal data on behalf of the Controller to deliver the service described in the Terms: send messages, negotiate via the agent, generate the coupon, build the URL and charge the fee.

2. Controller instructions

The Processor processes data only following the Controller's instructions expressed in the Terms, the Privacy Policy and the configuration the Controller set in the panel. If a Controller instruction infringes the LGPD, the Processor notifies immediately.

Processing beyond those instructions — for example, model training — happens only with separate consent from the Controller.

3. Purpose and nature of processing

Purpose: recover abandoned carts via WhatsApp. Nature: reading cart data, sending the message, negotiating, generating the unique coupon, attributing the paid order to GetCart, and billing.

4. Data categories and subjects

Data: name, phone, cart items, cart amount, last visit date, content of messages exchanged with the store. Subjects: end-shoppers of the Controller's store.

6. Security measures

Encryption in transit (TLS 1.2+) and at rest (AES-256). Role-based access control (RBAC) with logging. Tenant isolation (each store sees only its own data). Encrypted backups and periodic restore tests.

A summarized security report is available on request to dpo@getcart.ai.

7. Sub-processors

The Processor may hire sub-processors for auxiliary services (Meta for WhatsApp, the store provider, the payment gateway, cloud infrastructure). The current list is at getcart.ai/legal/sub-processors and is updated at least 30 days before any change.

8. Data subject rights

The Processor helps the Controller respond to art. 18 LGPD requests within 5 business days of receiving them.

9. Security incidents

In case of an incident that creates risk or harm to data subjects, the Processor notifies the Controller within 24 hours and ANPD within 2 business days (LGPD art. 48), with information about what happened, which data was affected and what was done to mitigate.

10. International transfers

Data may be processed on servers outside Brazil when the Controller chooses a different region in /billing/payment-method, under the same guarantees of this DPA and per LGPD art. 33–36.

11. Term and termination

This DPA is in force while the Controller uses GetCart. When it ends, the Processor deletes or returns the personal data processed within 30 days, except what the law requires to keep longer.

Back to top