Ryea AI Receptionist
Merchant Data Processing Addendum
1. Parties and scope
This Addendum applies between Arure LLC (“Processor”) and the merchant that installs Ryea AI Receptionist on its Shopify store (“Merchant”), for personal data the App processes on the Merchant’s behalf. Installing or using the App accepts it.
2. Roles
The Merchant is the controller. Arure is the processor and acts only on the Merchant’s documented instructions, which are the App’s settings and use.
3. Nature and purpose of processing
Answering the Merchant’s calls with an AI receptionist; booking, changing and cancelling appointments; taking messages; transferring calls; showing these to the Merchant; and adding callers to the Merchant’s Shopify customers. Duration: while the App is installed, then deletion as in section 11.
4. Categories of data subjects and data
Callers and Shopify customers: phone number, name, email, call audio (processed live), transcripts and summaries, appointments and messages. Merchant staff: Admin session email. No special categories are requested; callers may volunteer them (for example health details when booking a clinic), and the Merchant decides whether the App suits its business.
5. Merchant instructions and responsibilities
The Merchant ensures it has a lawful basis for the processing and gives callers any notice its law requires, including that calls are answered by AI and transcribed, and any call-recording consent.
6. Confidentiality and security
Personnel with access are bound by confidentiality. Measures include Shopify-authenticated admin access, encryption in transit (HTTPS) and of access tokens and signing secrets at rest, signature-verified webhooks, least-privilege scopes, and nightly backups kept 14 days.
7. Subprocessors
- DigitalOcean (hosting, United States)
- Twilio (phone numbers and calls)
- Google Cloud / Firebase and Google Gemini (storage; speech and language AI)
- OpenAI and Deepgram (speech and language AI for some features)
- Vercel (Ryea web services)
- Shopify (platform, billing)
We will update this list before adding a subprocessor; the Merchant may object by uninstalling.
8. International transfers
Processing is primarily in the United States. Where required, transfers rely on standard contractual clauses or another valid mechanism.
9. Assistance with data subject rights
Shopify’s customer data and erasure requests are fulfilled automatically and shown on the App’s Privacy page. For other requests, write to privacy@arure.tech.
10. Breach notification
Arure will notify the Merchant without undue delay, and within 72 hours where feasible, after becoming aware of a personal data breach affecting Merchant data.
11. Retention and deletion
On uninstall the receptionist is paused. On Shopify’s shop/redact (about 48 hours later) the App’s data for the store is deleted, the Ryea receptionist is closed and its number released. Backups expire within 14 days.
12. Audits
Arure will provide information reasonably necessary to show compliance with this Addendum, on written request no more than once a year.
13. Liability and precedence
Liability follows the App’s terms. For personal data processing this Addendum prevails over conflicting terms.