Effective date: September 7, 2026
Last updated: September 7, 2026
This Privacy Policy explains how personal data is processed when the Shopify application Notia Advisor: AI Chat & FAQ (the “App”) is used. The App provides merchants with an AI-powered chat, knowledge base and FAQ, conversation handoff to human staff, and related reporting.
This Privacy Policy applies to the App. It does not cover the general processing of personal data on notia.com or other products provided by NOTIA is, s.r.o.
1. Who we are and our role
The App is operated by NOTIA is, s.r.o., Company ID 62917731, with its registered office at Londýnská 730/59, 120 00 Prague 2 – Vinohrady, Czech Republic, registered in the Commercial Register maintained by the Municipal Court in Prague under file number C 35797 (“Notia”, “we”, “us”, or “our”).
For personal data relating to visitors and customers of an online store, the merchant operating that store (the “Merchant”) generally determines the purposes and means of processing. The Merchant is the data controller, and Notia acts as its data processor. Questions and requests concerning a customer’s data should therefore usually be directed to the Merchant whose store the customer used. Notia will provide the Merchant with the assistance required to respond to such requests.
Notia acts as an independent data controller for the limited personal data that we process to manage our contractual relationship with the Merchant, administer billing, secure the App, prevent abuse, and comply with our own legal obligations.
2. What the App does
The App may:
- display an AI-powered chat and FAQ on the Merchant’s online store;
- answer questions using the Merchant’s store content, product catalogue, and knowledge base;
- interact with the shopping cart and link to products or customer accounts;
- hand a conversation over to the Merchant’s staff;
- measure use of the chat and its relationship to checkout starts and completions; and
- provide the Merchant with operational, quality, and aggregate analytics.
3. Personal data we process
3.1 Online-store visitors and customers
- Conversation content: customer messages, replies from the AI assistant and Merchant staff, system messages, communication times, and technical data required to continue an existing conversation.
- Feedback: ratings of individual answers and overall conversation satisfaction.
- Shopping context: cart identifier, the product or page from which the chat was opened, and information about actions performed through the chat, such as product searches or cart updates.
- Usage events: opening the chat, moving from an FAQ to the chat, using a suggested question, and clicking a product link.
- Checkout data: information that a checkout was started or completed, a pseudonymous checkout token, order identifier, total amount, and currency. The App does not read order line items, delivery addresses, or payment details. This information is used for aggregate analytics and to attribute an assisted conversion to a chat conversation.
- Technical and security data: IP address, store domain, conversation identifier, signed security token, and related technical records. The IP address is used for rate limiting, blocking abuse, and protecting the service.
- Approximate location based on IP address: country, region, city, and internet service provider. This location is approximate, is used only as context for the Merchant’s staff, and is not used for automated decision-making. This feature is disabled by default; the processing takes place only if the Merchant deliberately enables it in the App’s settings.
- Contact details for human handoff: name and email address if the customer provides them or is already signed in to a customer account. The name and email address are stored in the customer record in Shopify. Notia’s database normally stores only a reference to that Shopify record, rather than the name and email address themselves. The details may pass briefly through the App and its notification infrastructure so that the request can be delivered to the Merchant’s staff.
A user can technically enter any text into the chat. Please do not provide information that is unnecessary for answering the question, particularly passwords, full payment card details, health information, or other sensitive personal data.
3.2 Merchants and Shopify admin users
- store domain and Shopify identifiers, App installation, and granted permissions;
- name, email address, language, role, and other user details supplied by Shopify as part of authentication and session management;
- App settings, custom instructions and rules, widget text, links, and selected content;
- product, page, store-policy, file, and knowledge-base content that the Merchant authorises the App to access;
- plan, billing, usage, purchased-credit, and operational-limit information; and
- support communications and technical records relating to operation of the App.
4. Purposes and legal bases
| Purpose | Notia’s role | Legal basis |
|---|---|---|
| Operating the chat and FAQ, interacting with the cart, handing a conversation to staff, and providing analytics to the Merchant | Processor | The Merchant determines the applicable legal basis as controller; Notia acts on the Merchant’s documented instructions. |
| Managing the installation, account, plan, and provision of the App | Controller | Performance of a contract or our legitimate interest in properly providing and administering the service. |
| Security, abuse prevention, troubleshooting, and legal claims | Controller | The legitimate interests of Notia and the Merchant in maintaining a secure and reliable service. |
| Accounting, tax, and other statutory obligations | Controller | Compliance with a legal obligation. |
| Marketing communications sent by the Merchant to a customer | Processor | A separate, freely given consent provided to the Merchant. Marketing consent is not required to hand a question over to staff. |
Providing a chat message is voluntary, but the App cannot answer without the message content. Contact details are required only when a customer who is not signed in wants to receive a later response from the Merchant’s staff. Data required for installation and account administration is necessary for the Merchant to use the App.
5. Artificial intelligence
Conversation text, relevant knowledge-base and store content, and the results of App tools are sent through Anthropic’s commercial API to generate a response, suggest content, classify a topic, or perform a content review requested by the Merchant. We intentionally do not send the name or email address collected during human handoff to the AI model. If a customer enters those details directly into a chat message, however, they become part of the submitted content.
Content submitted through Anthropic’s commercial API is not used to train its general models by default. According to Anthropic’s current terms, standard API inputs and outputs are deleted within 30 days, subject to exceptions for safety, policy enforcement, legal obligations, or separately agreed terms.
AI-generated answers may be inaccurate or incomplete. The App does not make decisions that, by themselves, produce legal or similarly significant effects for a customer. Where appropriate, the customer can request contact with the Merchant’s human staff.
6. Recipients and service providers
Personal data may be disclosed, to the extent necessary, to the following categories of recipients:
- The Merchant and its authorised staff – to operate the chat, support customers, and use App reporting.
- Shopify – to operate the ecommerce platform, customer records, authentication, files, billing, Shopify Flow, and consent-aware Web Pixels. Shopify processing is governed by its terms, Data Processing Addendum, and privacy notices.
- Anthropic, PBC – the AI model provider. Anthropic processes the text and context described in section 5 through its commercial API.
- ipwho.is – a service used to derive an approximate location from an IP address when the Merchant has this feature enabled. The service receives the IP address and returns approximate location and internet service provider information.
- Notia’s internal notification infrastructure – for plans with the relevant feature, it processes the store and conversation identifiers, a message excerpt, and, for human handoff, the customer’s name and email address so that the Merchant’s staff can be notified. Depending on the configured delivery channel, the notification may also be processed by an email or communication service selected for the relevant store.
- Authorised Notia staff and contractors – only when access is necessary for support, security, or maintenance and subject to confidentiality obligations.
- Public authorities and professional advisers – where required by law or necessary to establish, exercise, or defend legal claims.
We do not sell personal data or use it for our own targeted advertising.
7. International data transfers
Operation of the App can involve processing outside the European Economic Area. Anthropic states that commercial-service data may be processed in multiple regions and is stored in the United States. Its Data Processing Addendum incorporates the European Commission’s Standard Contractual Clauses. Shopify uses global infrastructure and the international-transfer mechanisms described in its Data Processing Addendum.
Where the GDPR applies to a particular transfer, an appropriate legal mechanism is used, such as an adequacy decision or Standard Contractual Clauses, together with supplementary technical and organisational measures where appropriate. Information about the mechanism applicable to a specific transfer can be requested using the contact details below.
8. Retention
- Conversations, IP addresses, feedback, and related analytics events are retained while the Merchant has the App installed, unless deleted earlier on the Merchant’s instructions or following a valid customer request.
- Data relating to a specific customer and linked to a Shopify customer record is deleted after we receive a valid Shopify erasure request. An anonymous conversation can only be located using available technical details and information supplied by the requester.
- Store data, settings, conversations, and analytics are removed from the active database when the App is uninstalled. Shopify’s subsequent mandatory store-erasure request provides an additional check.
- Billing and credit records may be retained after uninstallation for as long as necessary to settle payments, restore purchased credits, protect legal claims, and comply with statutory obligations.
- Limited copies in backups may remain until the relevant backup is rotated in the ordinary course. Backups are not used for routine operations, and recorded deletion requests are reapplied following a restoration.
- Data processed through the Anthropic API is subject to the retention terms described in section 5.
9. Browser storage and analytics
The App widget uses sessionStorage for the conversation identifier and security token, to preserve chat and display state during a visit, and to limit duplicate events. This data normally expires when the relevant browser session or tab ends. localStorage may remember that a user dismissed a chat prompt so that it is not repeatedly displayed; the record remains until browser data is cleared or the App’s configuration changes.
The App uses a Shopify Web Pixel classified as analytics to measure assisted conversions. In regions where consent is required for analytics tracking, Shopify runs this pixel in accordance with the customer’s choices in the store’s privacy controls. The Merchant is responsible for configuring consent tools and providing the notices required on its store.
10. Security
We use technical and organisational measures appropriate to the risks of processing. These include encrypted transmission over HTTPS, verification of Shopify requests, signed time-limited conversation tokens, separation of data between stores, rate limiting, access controls, backups, and ongoing maintenance. No method of transmission or storage can guarantee absolute security.
11. Individual rights
Subject to applicable law, individuals may have the right to request:
- access to and a copy of their personal data;
- correction of inaccurate or completion of incomplete data;
- deletion of personal data;
- restriction of processing;
- data portability;
- to object to processing based on legitimate interests; and
- to withdraw consent at any time, without affecting the lawfulness of processing carried out before withdrawal.
If you used the App on an online store, please first contact the operator of that store and provide enough information to locate the relevant record, such as the store address, approximate conversation time, and the email address used for human handoff. The Merchant can submit the request through Shopify’s tools; the App supports Shopify’s mandatory customer data access and erasure requests.
Where Notia acts as an independent controller, rights can be exercised by contacting notia@notia.com. We may take reasonable steps to verify the requester’s identity before fulfilling a request.
Individuals also have the right to lodge a complaint with a supervisory authority, in particular the Czech Office for Personal Data Protection, Pplk. Sochora 27, 170 00 Prague 7, Czech Republic, or with the competent authority in the country of their habitual residence or place of work.
12. Contact details
NOTIA is, s.r.o.
Londýnská 730/59
120 00 Prague 2 – Vinohrady
Czech Republic
Company ID: 62917731
Email: notia@notia.com
Telephone: +420 226 251 380
13. Key service-provider notices
14. Changes to this Privacy Policy
We may update this Privacy Policy, particularly when the App’s features, service providers, or legal requirements change. The current version will always be published on this page with its latest update date. If a change is material, we will notify Merchants by reasonable means through the App, Shopify, or the contact details available to us.