Partes
- Processor: GetCart, the legal entity controlling the product (the controller of the means).
- Controller: the legal entity that owns the Shopify, Nuvemshop or Tray store where GetCart is installed.
1. Subject
This DPA defines how the Processor processes personal data on behalf of the Controller to deliver the service described in the Terms: send messages, negotiate via the agent, generate the coupon, build the URL and charge the fee.
2. Controller instructions
The Processor processes data only following the Controller's instructions expressed in the Terms, the Privacy Policy and the configuration the Controller set in the panel. If a Controller instruction infringes the LGPD, the Processor notifies immediately.
Processing beyond those instructions — for example, model training — happens only with separate consent from the Controller.
3. Purpose and nature of processing
Purpose: recover abandoned carts via WhatsApp. Nature: reading cart data, sending the message, negotiating, generating the unique coupon, attributing the paid order to GetCart, and billing.
4. Data categories and subjects
Data: name, phone, cart items, cart amount, last visit date, content of messages exchanged with the store. Subjects: end-shoppers of the Controller's store.
5. Legal basis
Processing is done under the Controller's legitimate interest (LGPD art. 7, IX) for the first message sent via an approved template, and on the data subject's consent (LGPD art. 7, I) for the conversation opened with the agent and for any negotiated discount.
6. Security measures
Encryption in transit (TLS 1.2+) and at rest (AES-256). Role-based access control (RBAC) with logging. Tenant isolation (each store sees only its own data). Encrypted backups and periodic restore tests.
A summarized security report is available on request to dpo@getcart.ai.
7. Sub-processors
The Processor may hire sub-processors for auxiliary services (Meta for WhatsApp, the store provider, the payment gateway, cloud infrastructure). The current list is at getcart.ai/legal/sub-processors and is updated at least 30 days before any change.
8. Data subject rights
The Processor helps the Controller respond to art. 18 LGPD requests within 5 business days of receiving them.
9. Security incidents
In case of an incident that creates risk or harm to data subjects, the Processor notifies the Controller within 24 hours and ANPD within 2 business days (LGPD art. 48), with information about what happened, which data was affected and what was done to mitigate.
10. International transfers
Data may be processed on servers outside Brazil when the Controller chooses a different region in /billing/payment-method, under the same guarantees of this DPA and per LGPD art. 33–36.
11. Term and termination
This DPA is in force while the Controller uses GetCart. When it ends, the Processor deletes or returns the personal data processed within 30 days, except what the law requires to keep longer.