Skip to main content

Sub-processors list

The companies that process data for Olvio, what data each one handles, and why Shopify and Anthropic aren't on the list.

Sub-processors list

Olvio is published by Topicimes. For the data about your shoppers' interactions with Olvio (conversations, question logs, widget events and order attributions), Topicimes acts as your data processor under article 28 of the GDPR. For your account data (store identifiers, plan, settings and encrypted API key) and the service's operational logs, Topicimes is the data controller. To run the service, Topicimes uses two sub-processors: Cloudflare and Intercom. This article explains what each one does and what data it handles.

The binding list is in section 12 of Olvio's Privacy Policy, which is part of Olvio's Terms of Service.

Cloudflare, Inc.

  • Role — hosts the Olvio app and stores its data.

  • Cloudflare services — including Workers (application hosting), D1 (database), Vectorize (vector index), KV (edge cache), rate limiting, Workers AI (embeddings, used to search your catalog and store content, and to group shopper questions) and AI Gateway (routing of requests to Anthropic).

  • Data processed — the data Olvio keeps for your store, including: store identifiers and the access token Shopify issues, your Shopify authentication sessions, your encrypted Anthropic API key, your plan and billing status, your widget settings, your AI Setup content, your knowledge files and web pages, your product catalog, your store's pages, blog articles and policies, shopper interaction data (conversations, question logs, unanswered questions, widget events and order attributions), and the service's operational logs. Shopper messages and the requests Olvio sends to Anthropic with your API key are also handled by Cloudflare.

  • Data location — the database is in the European Union (Western Europe region). The vector index, the cache, embeddings and the Olvio app itself run on Cloudflare's global network, which isn't restricted to the European Union. See Where is my data hosted?

Intercom R&D Unlimited Company

  • Role — support messaging built into the Olvio admin.

  • How it's used — the Intercom messenger loads in the Olvio admin, so you can chat with Olvio support without leaving the app.

  • Data processed — including the messages you exchange with support, the technical information your browser sends to Intercom (such as your IP address), and the details Olvio passes when the messenger loads: your store's .myshopify.com domain (used as your identifier and name), the date your store was added to Olvio, your current plan and your admin language. The messenger is also updated when you move between Olvio admin pages, so Intercom knows which page you're on. Olvio doesn't send your shopper conversations or catalog data to Intercom.

See Contact us and support hours for the ways to reach support.

Shopify and Anthropic aren't Topicimes sub-processors

Shopify and Anthropic also handle data when you use Olvio, but they aren't sub-processors of Topicimes, because you have your own agreement with each of them.

  • Shopify — the platform your store runs on. You have a direct agreement with Shopify for your store, and you give Olvio access when you install the app. The scopes Olvio requests give it read-only access to your store data: read_products, read_orders, read_themes, read_locales and read_metaobjects. Your Olvio subscription is billed through Shopify.

  • Anthropic — the company behind Claude. Olvio calls Anthropic with your own API key, so Anthropic is your sub-processor, under your own agreement with Anthropic. Anthropic's terms, including its Commercial Terms of Service, govern how it processes, keeps and transfers what Olvio sends with your key, for example shopper questions and the context used to answer them. Before you connect your API key, review how Anthropic handles this data. See What uses your Anthropic API key, and what doesn't.

Olvio's read-only console

Topicimes staff can view your store's Olvio data through an internal, read-only console. It shows the same dashboards, conversation lists, transcripts (with the linked order, where there is one) and Customer question map as your Olvio admin, plus account and operational information such as your plan, install date, attributed revenue and technical health. The console is used only for support, incident diagnosis and service quality control. Access is limited to people Topicimes authorizes, protected by single sign-on, and every access is logged.

Safeguards

  • Each sub-processor is bound by a data processing agreement offering protections equivalent to those of the GDPR, including, where required, the European Commission's Standard Contractual Clauses of June 4, 2021.

  • Olvio's data processing terms are part of its Terms of Service, through the Privacy Policy. A standalone data processing agreement (DPA) is available on request at [email protected].

Changes to this list

The sub-processor list is part of the Privacy Policy. When the policy changes, its Last updated date changes too. For any material change affecting merchant data, Olvio will notify active merchants in the Olvio admin before the change takes effect.

Questions or concerns

To ask about a sub-processor or to exercise your data protection rights, contact Olvio's Data Protection Officer at [email protected].

You can also uninstall Olvio. About 48 hours later, Shopify asks Olvio to delete your store's data, and Olvio permanently deletes it from its database and vector index. This deletion doesn't cover everything, for example your support conversations in Intercom: to have them deleted, email [email protected]. See What happens to my data when I uninstall Olvio.

Did this answer your question?