Legal
Data processing addendum
ScrollEngine's data processing addendum sets out how we process personal data for merchants as their processor: on their instructions, with named sub-processors and set security measures. Draft for counsel review; not in effect.
On this page
⟦LEGAL⟧ Working draft for counsel review. Not in effect. This text was prepared for counsel under gate G5 (00 §2.2), from the product truth record. It will be replaced by the signed text before it is published. Store networks will be able to request a countersigned copy.
Open points for counsel and engineering: the notice period for new sub-processors; breach-notice timing beyond "without undue delay"; the transfer mechanism per provider; the audit clause; encryption at rest and in transit (engineering confirms before any sentence about it is added); the AI training sentence in section 13, which is published only if it holds for every provider path (FD-11).
1. Scope
This addendum forms part of the agreement between you, the merchant ("you"), and Scrollengine Labs Private Limited (as of Sep 2026) ("ScrollEngine", "we" or "us") for the ScrollEngine service (the "Service"). It applies whenever we process personal data on your behalf in providing the Service ("Customer Personal Data"). If it conflicts with our terms of service, this addendum wins for the processing of Customer Personal Data.
2. Definitions
"Data protection laws" means the laws that apply to the processing, which can include the EU General Data Protection Regulation, the UK GDPR, the Swiss Federal Act on Data Protection and US state privacy laws. "Controller", "processor", "data subject", "personal data breach" and "processing" have the meanings those laws give them.
3. Roles and instructions
You are the controller of Customer Personal Data, and we are your processor. We process it only on your documented instructions: our terms of service, the settings and workflows you configure in the Service, and this addendum. If we believe an instruction breaks data protection laws, we'll tell you.
4. Details of the processing
- Subject matter and duration: providing the Service for as long as you use it, and any period afterwards set out in section 11.
- Nature and purpose: offering delivery and pickup slots, sending orders to the right location, planning routes, running the driver app, tracking deliveries, sending customer updates, running your workflows, reporting, and support.
- Data subjects: your customers, your drivers, and your team members who use the Service.
- Personal data: names and contact details; delivery addresses and map coordinates; order details, including delivery and pickup times; messages sent to customers and drivers; drivers' location while they work a route; proof-of-delivery photos, signatures and notes; cash-on-delivery records; ratings.
- Special categories: none are needed to run the Service, and you agree not to put them into it.
5. Our people
We give access to Customer Personal Data only to people who need it to provide or support the Service, and they are bound by confidentiality.
6. Security
We protect Customer Personal Data with the technical and organizational measures in Annex A, and we keep them appropriate to the risk. Our trust center lists what's in place today and what isn't yet.
7. Sub-processors
You authorize us to use the sub-processors listed on our sub-processors page. We bind each one by a written agreement with data protection obligations no less protective than this addendum, and we remain responsible for their work. Before a new sub-processor starts processing Customer Personal Data, we update the list and notify account owners, giving you a reasonable period to object on reasonable data protection grounds.
8. Helping with data subject requests
We help you respond to requests from people exercising their rights, through the Service's tools and, for Shopify customer data, through Shopify's mandatory privacy requests for customer data and deletion. If a request reaches us directly, we pass it to you.
9. Personal data breaches
We notify you without undue delay after becoming aware of a personal data breach affecting Customer Personal Data, and give you the information you reasonably need to meet your own obligations. Security contact: support@scrollengine.com (as of Oct 2026).
10. Assessments
We give you reasonable help with data protection impact assessments and consultations with supervisory authorities that relate to the Service.
11. Deletion or return
When the Service ends, we delete Customer Personal Data, or return it if you ask before deletion, unless the law requires us to keep it. We confirm deletion on request.
12. Information and audits
We make available the information reasonably needed to show that we meet this addendum, including our security documentation on request, and we cooperate with reasonable audits on reasonable notice.
13. AI features
AI features process Customer Personal Data only when you turn them on. When a user asks Ask Engine Early access a question, or a workflow runs an AI step Early access, the question and the records needed to answer it are sent to the model provider. With the platform default, that provider, OpenRouter (as of Oct 2026), is our sub-processor. When you bring your own model key, the provider processes the data under your own agreement with them. AI features read only what your account and each user's permissions allow, and they can't change an order, a route or a message.
We don't use Customer Personal Data to train third-party models.
14. International transfers
Where Customer Personal Data is transferred to a country without an adequacy decision, we rely on the European Commission's Standard Contractual Clauses, the UK addendum to them, or another lawful transfer mechanism.
15. Liability
Each party's liability under this addendum is subject to the limits in our terms of service, except where data protection laws don't allow those limits.
Annex A: security measures
- Custom roles with granular permissions, scoped by location and zone.
- Separate access to the dashboard, the driver app and store tools.
- AI features read-only, scoped to account and user permissions, with a daily cap.
- Event-driven processing on durable queues, with independent services.
- Readiness checks, graceful restarts and circuit breakers.
- Full delivery history on every order and route, workflow execution logs and driver activity logs.
- Outbound webhooks signed so that receivers can verify them.
- Shopify's mandatory privacy webhooks for customer data requests and deletion.
Annex B: sub-processors
The current list is on our sub-processors page.
Contact
Questions about this addendum: support@scrollengine.com (as of Oct 2026), or contact us.
Changes to this document.
· v0.1
Working draft prepared for counsel review (gate G5). Not in effect.
Questions about this document? Contact us