Privacy Policy for Notia Advisor: AI Chat & FAQ

Effective date: September 7, 2026

Last updated: September 7, 2026

This Privacy Policy explains how personal data is processed when the Shopify application Notia Advisor: AI Chat & FAQ (the “App”) is used. The App provides merchants with an AI-powered chat, knowledge base and FAQ, conversation handoff to human staff, and related reporting.

This Privacy Policy applies to the App. It does not cover the general processing of personal data on notia.com or other products provided by NOTIA is, s.r.o.

1. Who we are and our role

The App is operated by NOTIA is, s.r.o., Company ID 62917731, with its registered office at Londýnská 730/59, 120 00 Prague 2 – Vinohrady, Czech Republic, registered in the Commercial Register maintained by the Municipal Court in Prague under file number C 35797 (“Notia”, “we”, “us”, or “our”).

For personal data relating to visitors and customers of an online store, the merchant operating that store (the “Merchant”) generally determines the purposes and means of processing. The Merchant is the data controller, and Notia acts as its data processor. Questions and requests concerning a customer’s data should therefore usually be directed to the Merchant whose store the customer used. Notia will provide the Merchant with the assistance required to respond to such requests.

Notia acts as an independent data controller for the limited personal data that we process to manage our contractual relationship with the Merchant, administer billing, secure the App, prevent abuse, and comply with our own legal obligations.

2. What the App does

The App may:

3. Personal data we process

3.1 Online-store visitors and customers

A user can technically enter any text into the chat. Please do not provide information that is unnecessary for answering the question, particularly passwords, full payment card details, health information, or other sensitive personal data.

3.2 Merchants and Shopify admin users

4. Purposes and legal bases

PurposeNotia’s roleLegal basis
Operating the chat and FAQ, interacting with the cart, handing a conversation to staff, and providing analytics to the MerchantProcessorThe Merchant determines the applicable legal basis as controller; Notia acts on the Merchant’s documented instructions.
Managing the installation, account, plan, and provision of the AppControllerPerformance of a contract or our legitimate interest in properly providing and administering the service.
Security, abuse prevention, troubleshooting, and legal claimsControllerThe legitimate interests of Notia and the Merchant in maintaining a secure and reliable service.
Accounting, tax, and other statutory obligationsControllerCompliance with a legal obligation.
Marketing communications sent by the Merchant to a customerProcessorA separate, freely given consent provided to the Merchant. Marketing consent is not required to hand a question over to staff.

Providing a chat message is voluntary, but the App cannot answer without the message content. Contact details are required only when a customer who is not signed in wants to receive a later response from the Merchant’s staff. Data required for installation and account administration is necessary for the Merchant to use the App.

5. Artificial intelligence

Conversation text, relevant knowledge-base and store content, and the results of App tools are sent through Anthropic’s commercial API to generate a response, suggest content, classify a topic, or perform a content review requested by the Merchant. We intentionally do not send the name or email address collected during human handoff to the AI model. If a customer enters those details directly into a chat message, however, they become part of the submitted content.

Content submitted through Anthropic’s commercial API is not used to train its general models by default. According to Anthropic’s current terms, standard API inputs and outputs are deleted within 30 days, subject to exceptions for safety, policy enforcement, legal obligations, or separately agreed terms.

AI-generated answers may be inaccurate or incomplete. The App does not make decisions that, by themselves, produce legal or similarly significant effects for a customer. Where appropriate, the customer can request contact with the Merchant’s human staff.

6. Recipients and service providers

Personal data may be disclosed, to the extent necessary, to the following categories of recipients:

We do not sell personal data or use it for our own targeted advertising.

7. International data transfers

Operation of the App can involve processing outside the European Economic Area. Anthropic states that commercial-service data may be processed in multiple regions and is stored in the United States. Its Data Processing Addendum incorporates the European Commission’s Standard Contractual Clauses. Shopify uses global infrastructure and the international-transfer mechanisms described in its Data Processing Addendum.

Where the GDPR applies to a particular transfer, an appropriate legal mechanism is used, such as an adequacy decision or Standard Contractual Clauses, together with supplementary technical and organisational measures where appropriate. Information about the mechanism applicable to a specific transfer can be requested using the contact details below.

8. Retention

9. Browser storage and analytics

The App widget uses sessionStorage for the conversation identifier and security token, to preserve chat and display state during a visit, and to limit duplicate events. This data normally expires when the relevant browser session or tab ends. localStorage may remember that a user dismissed a chat prompt so that it is not repeatedly displayed; the record remains until browser data is cleared or the App’s configuration changes.

The App uses a Shopify Web Pixel classified as analytics to measure assisted conversions. In regions where consent is required for analytics tracking, Shopify runs this pixel in accordance with the customer’s choices in the store’s privacy controls. The Merchant is responsible for configuring consent tools and providing the notices required on its store.

10. Security

We use technical and organisational measures appropriate to the risks of processing. These include encrypted transmission over HTTPS, verification of Shopify requests, signed time-limited conversation tokens, separation of data between stores, rate limiting, access controls, backups, and ongoing maintenance. No method of transmission or storage can guarantee absolute security.

11. Individual rights

Subject to applicable law, individuals may have the right to request:

If you used the App on an online store, please first contact the operator of that store and provide enough information to locate the relevant record, such as the store address, approximate conversation time, and the email address used for human handoff. The Merchant can submit the request through Shopify’s tools; the App supports Shopify’s mandatory customer data access and erasure requests.

Where Notia acts as an independent controller, rights can be exercised by contacting notia@notia.com. We may take reasonable steps to verify the requester’s identity before fulfilling a request.

Individuals also have the right to lodge a complaint with a supervisory authority, in particular the Czech Office for Personal Data Protection, Pplk. Sochora 27, 170 00 Prague 7, Czech Republic, or with the competent authority in the country of their habitual residence or place of work.

12. Contact details

NOTIA is, s.r.o.
Londýnská 730/59
120 00 Prague 2 – Vinohrady
Czech Republic
Company ID: 62917731
Email: notia@notia.com
Telephone: +420 226 251 380

13. Key service-provider notices

14. Changes to this Privacy Policy

We may update this Privacy Policy, particularly when the App’s features, service providers, or legal requirements change. The current version will always be published on this page with its latest update date. If a change is material, we will notify Merchants by reasonable means through the App, Shopify, or the contact details available to us.