Europe SMS Marketing Terms of Service
Effective date: 17 September 2026
Last updated: 18 September 2026
1. About these Terms
These Terms of Service (the "Terms") govern access to and use of the Europe SMS Marketing website, Shopify application, integrations, SMS campaign tools, SMS automations, reporting and related services (together, the "Service").
The Service is provided by Genius Nutrition SRL, trading as OBSEDIA ("Europe SMS Marketing", "OBSEDIA", "we", "us" or "our"):
- VAT number: RO35355847
- Registered business address: Tamasi nr. 20, Buftea, Ilfov, Romania
- General contact: support@obsedia.ai
- Privacy contact: privacy@obsedia.ai
"Merchant", "you" or "your" means the business that installs, purchases or uses the Service. "Authorised User" means a person whom the Merchant permits to use the Service. "Recipient" means a person whose telephone number is processed for an SMS.
By installing the application, approving a subscription or usage charge, creating an account, or using the Service, you enter into a binding agreement with us and accept these Terms, the Privacy Policy and the Data Processing Terms in Schedule 1.
If you accept these Terms for a company or other organisation, you represent that you have authority to bind it.
2. Business service and eligibility
The Service is intended only for merchants and professionals acting for business purposes. It is not offered for personal or household use.
To use the Service, you must:
- be at least 18 years old;
- have legal capacity to enter into this agreement;
- be authorised to administer the relevant Shopify store;
- provide accurate business and account information;
- maintain an active Shopify account compatible with the Service; and
- comply with these Terms and applicable law.
The Service is designed for SMS delivery to supported European destinations. Availability, sender requirements, network coverage and price can vary by country, network, message category and merchant. A destination, sender type or feature is supported only when we confirm it in the Service or in writing.
3. The Service
Depending on the plan, configuration, approvals and technical availability, Europe SMS Marketing may provide:
- synchronisation of eligible Shopify customer contacts and SMS consent status;
- selection of an available Shopify customer segment;
- preparation, preview, cost estimation and sending of an immediate SMS campaign;
- marketing automations for welcome, cart recovery, checkout recovery, win-back and post-purchase or cross-sell messages;
- transactional automations for order, payment, shipment, delivery and cash-on-delivery events;
- merchant controls for enablement, budgets, frequency, suppression and emergency disablement;
- SMS provider submission and delivery-status processing;
- campaign, delivery, cost, automation and deterministic attribution reporting; and
- privacy-request, redaction, uninstall and retention processing.
Some features may be unavailable until Shopify access, protected-customer-data approval, sender registration, SMS-provider readiness, billing approval or another dependency is complete. An unavailable feature is not part of the Service supplied to you merely because it is described in documentation or appears as disabled in the application.
Europe SMS Marketing is an independent application. It is not produced, endorsed or warranted by Shopify or by a mobile network operator.
4. Licence and access
Subject to these Terms and payment of applicable charges, we grant the Merchant a limited, non-exclusive, non-transferable and revocable right to access and use the Service during the subscription for its internal business purposes.
The Merchant may permit Authorised Users to access the Service. The Merchant is responsible for:
- deciding who is authorised;
- assigning appropriate Shopify permissions;
- protecting credentials and devices under its control;
- removing access promptly when it is no longer required; and
- actions taken through its account by Authorised Users acting within their apparent authority.
You must notify support@obsedia.ai promptly if you suspect unauthorised access, credential compromise or misuse of the Service.
5. Shopify connection
The Service depends on an authorised Shopify installation. You authorise Europe SMS Marketing to access the minimum Shopify data and events required for the enabled functionality and approved access scopes.
The current core integration uses customer-read access for contact identity and SMS consent. Additional enabled automations may require expressly approved order, checkout, fulfilment, delivery or storefront access. Europe SMS Marketing will not treat a feature as available unless the required access and evidence are present.
Shopify is a separate service governed by the agreement between the Merchant and Shopify. We are not responsible for Shopify's availability, changes, acts or omissions. If Shopify suspends the store, withdraws an API, removes an approval, changes a webhook or billing contract, or prevents access to required data, the affected Europe SMS Marketing function may become unavailable.
You must not use the Service to bypass Shopify permissions, protected-customer-data restrictions, billing controls, platform rules or customer privacy choices.
6. Merchant responsibilities for privacy and electronic communications
The Merchant determines the purpose, audience, content and timing of its messages and is responsible for their lawfulness.
Before using personal data or sending an SMS, the Merchant must:
- provide all privacy and electronic-marketing notices required by applicable law;
- establish and document a valid legal basis for processing;
- obtain prior consent where required for the relevant message category and destination;
- keep reliable evidence of consent, including its scope, source, wording and time;
- ensure that the recipient information is accurate and lawfully obtained;
- identify the Merchant or the relevant sender clearly;
- provide a simple and effective opt-out method where required;
- honour withdrawal, objection, suppression and deletion requests without undue delay;
- configure audiences, automations, budgets and sender names accurately;
- review the final message and estimated segment count before authorising a send; and
- comply with all applicable privacy, electronic-communications, consumer-protection, advertising and sector-specific laws.
Possession of a telephone number, an earlier purchase, installation of Europe SMS Marketing, acceptance of general website terms or a general marketing preference does not by itself establish permission for every SMS.
The Merchant must not upload or use purchased, rented, scraped or brokered telephone lists unless it can demonstrate a lawful basis and every permission required for the proposed use. Europe SMS Marketing may reject such use regardless of the Merchant's assessment.
If a Recipient contacts us about a Merchant's message, we may refer the request to the Merchant and share the minimum information needed for the Merchant to respond. We may independently block processing where continuing it would violate law, these Terms, an effective opt-out or a platform requirement.
7. Marketing and transactional messages
The Merchant must classify each message accurately.
Marketing messages include promotions, recommendations, win-back messages, cross-selling, cart recovery, checkout recovery and any transactional message containing promotional material. All applicable legal conditions must be met before sending.
The subscribed audience uses the store’s SMS subscription status. The optional All contacts audience can include people who are not subscribed; selecting that audience does not establish consent or another lawful basis. Merchants must obtain any permission required for the message and destination and must honour withdrawals and objections.
Shopify-recorded withdrawals are excluded until a valid later re-subscription is verified. Recorded in-app STOP/unsubscribe and redaction restrictions remain enforced and are not overridden by ordinary customer synchronization.
Including an unsubscribe link in a message is a merchant-controlled option. Omitting that link does not remove applicable opt-out obligations or override an existing withdrawal.
Transactional messages must be limited to the specific order or service event that justifies them. Order, payment, shipment, delivery or cash-on-delivery wording must not contain promotional content unless the message satisfies all requirements for marketing.
Messages containing promotional content must be treated by the merchant as marketing, even when sent through an order-related automation. The merchant is responsible for the purpose and lawfulness of its final text. Automation controls do not constitute a legal assessment of merchant-written content.
Recipients may opt out using the method stated in the message or another legally effective method. The Merchant must not disable, bypass or reverse a suppression record without new legally sufficient permission.
8. Sending safeguards
Europe SMS Marketing uses safeguards intended to reduce accidental, duplicate, unlawful or uncontrolled sending. Depending on the feature, these can include:
- tenant and recipient binding;
- audience-specific SMS subscription and transactional-purpose checks;
- opt-out and suppression checks;
- cancellation and refund checks;
- audience and event deduplication;
- an automation frequency limit;
- campaign and automation budgets;
- merchant and service kill switches;
- segment estimation and message-length limits;
- provider and billing readiness checks; and
- treatment of an ambiguous provider result as unknown without automatic resend.
These safeguards support the Merchant but do not replace its legal review or responsibility. The Merchant must independently confirm that each campaign, audience and automation is appropriate.
We may set or reduce reasonable limits on recipients, campaigns, segments, cost, throughput, sender names or destinations to protect recipients, merchants, networks and the Service.
9. Message content and prohibited use
You must not use the Service to:
- send spam, unlawful marketing or messages without required permission;
- conceal or misrepresent the identity of the Merchant or sender;
- impersonate another person or use an unauthorised sender name;
- send false, deceptive, fraudulent, defamatory, threatening, harassing or unlawful content;
- facilitate phishing, malware, credential theft, fraud or unauthorised surveillance;
- infringe intellectual-property, privacy, publicity or other rights;
- discriminate unlawfully or target a person based on unlawfully processed sensitive data;
- send content or promote products prohibited by law, Shopify, the SMS provider, a telecommunications operator or an applicable industry code;
- send emergency, life-safety or time-critical communications for which delayed or failed delivery could cause harm;
- include passwords, full payment-card data, government identifiers, medical records or other unnecessary sensitive data in an SMS;
- interfere with, probe, overload, reverse engineer or gain unauthorised access to the Service, except to the extent a restriction is prohibited by law;
- circumvent a limit, safeguard, billing mechanism, consent check, suppression control or provider restriction;
- resell or provide the Service to third parties unless we authorise this in writing; or
- use the Service outside supported European destinations without our written approval.
We may investigate suspected misuse and suspend the affected campaign, automation, sender, user or account while the investigation is conducted.
10. Sender names, networks and delivery
Sender names are subject to approval by the SMS provider, networks and destination rules. Approval may require documents, fees, lead time or changes. Approval does not guarantee delivery or continuing availability.
SMS delivery depends on systems outside our control, including Shopify, the SMS provider, aggregators, mobile networks, recipient devices and destination-specific filtering. A message may be delayed, filtered, rejected, delivered out of order or not delivered.
An acceptance response means that the provider accepted the submission for processing. It is not proof of delivery, consent, legal compliance or recipient engagement. A delivery report reflects information supplied by the provider or network and may be delayed, incomplete or corrected later.
Europe SMS Marketing does not guarantee a delivery time, delivery rate, conversion, revenue, return on investment or other campaign outcome.
11. SMS encoding and billable segments
SMS charges apply per billable message part. The number of parts depends on the final message, including personalisation, links and character encoding. The composer provides an estimate; campaign review calculates the quote for the selected audience. Rate changes do not retroactively increase a confirmed quote.
Characters outside the applicable GSM character set can cause Unicode encoding and reduce the number of characters available in each segment. Long messages and certain characters can therefore create multiple billable segments.
An estimate can change before confirmation if the message or audience changes. A billable message part is not necessarily the same as the number of messages displayed on a recipient’s device.
The Merchant is responsible for reviewing the final text and estimate before confirming a campaign. Europe SMS Marketing may enforce a segment cap and reject a message that exceeds it rather than truncate the message.
12. Fees, subscriptions and usage billing
The standard Europe SMS Marketing subscription is USD 29 per 30-day Shopify billing cycle, with a 14-day trial where eligible. SMS credit is purchased separately in EUR through Shopify-approved one-time purchases. Subscription payments do not add SMS credit. Available credit packs are EUR 25, EUR 50, EUR 100, EUR 250 and EUR 500. Current destination rates are displayed in the app.
Shopify-verified development stores receive free subscription access and test credit purchases. Real test SMS are subject to the stated development allowance.
The Service reserves SMS credit before sending. The quoted charge is captured when provider acceptance is confirmed; delivery is reported separately. Uncertain submissions are held for reconciliation and are not automatically resent.
Low-balance suggestions do not authorise an automatic purchase. Each top-up requires approval in Shopify.
Provider-accepted submissions may be chargeable even if final delivery later fails. Price estimates exclude VAT unless the interface expressly states otherwise. Provider prices, destination bands, taxes and network fees may change prospectively, subject to the confirmed-quote protection in Section 11.
The Merchant authorises the recurring subscription and separate one-time credit purchases approved through Shopify. We do not create a new charge outside the limits and pricing authorised through the applicable billing flow.
The Merchant must maintain valid Shopify billing arrangements. Failure, cancellation or expiration of the relevant subscription can make sending unavailable.
13. Billing disputes and refunds
Review charges promptly and contact support@obsedia.ai with the store domain, billing period and disputed item if you believe a charge is incorrect.
We will investigate a properly documented dispute and correct duplicate charges, calculation errors or charges resulting directly from our confirmed technical error.
Except where mandatory law or the applicable Shopify billing terms require otherwise:
- consumed usage and provider-accepted SMS submissions are non-refundable;
- fees for a started subscription period are non-refundable and are not prorated merely because the Merchant cancels before the period ends;
- cancellation stops future renewal according to the Shopify billing flow but does not erase charges already incurred; and
- credits, promotional balances or trials have no cash value and may expire under the terms disclosed when issued.
This Section does not limit remedies available for our material breach or for charges that were not authorised.
Use your available SMS credit before uninstalling. Unused available credit is forfeited when you uninstall Europe SMS Marketing and is not restored by reinstalling. Unresolved reservations and provider or billing outcomes remain subject to reconciliation. This does not limit correction of billing errors, refunds required by law, or any separate refund expressly promised under these Terms when we terminate the Service.
14. Merchant content
The Merchant retains its rights in message content, trademarks, sender names, lists and other materials it submits to the Service ("Merchant Content").
The Merchant grants us a limited, non-exclusive right to host, encrypt, reproduce, transmit and otherwise process Merchant Content only to provide, secure and support the Service, comply with law and enforce this agreement.
The Merchant represents that it has all rights and permissions needed for the Merchant Content and its intended use. We do not acquire ownership of Merchant Content and do not use Recipient data or message content for our own advertising.
15. Our intellectual property
Europe SMS Marketing, its software, interface, documentation, trade names, designs and underlying technology are owned by us or our licensors and are protected by applicable intellectual-property law.
Except for the limited right in Section 4, no right or licence is granted. You must not copy, modify, distribute, sell, lease or create a competing derivative of the Service, except where applicable law expressly permits the activity despite this restriction.
Feedback may be used to improve the Service without payment or restriction, provided that we do not identify the person or Merchant who supplied it without permission.
16. Confidentiality
Each party may receive non-public information that a reasonable business would understand to be confidential. The receiving party must:
- use confidential information only for this agreement;
- protect it using at least reasonable care;
- disclose it only to personnel and providers who need it and are subject to confidentiality duties; and
- return or delete it when no longer needed, subject to legal retention requirements.
Confidential information does not include information that the receiving party can demonstrate was lawfully known without restriction, becomes public without breach, is received lawfully from another source without duty, or is independently developed.
A legally required disclosure is permitted if the receiving party gives advance notice where lawful and reasonably assists the disclosing party in seeking protection.
17. Data protection
Our Privacy Policy describes the processing for which we act as controller.
When we process Merchant Personal Data on the Merchant's behalf, Schedule 1 applies and forms part of these Terms. If Schedule 1 conflicts with another part of these Terms on the processing of Merchant Personal Data, Schedule 1 prevails.
The Merchant must not instruct us to process personal data unlawfully. We may suspend an instruction and notify the Merchant if we reasonably believe it infringes applicable data-protection law.
Data processing agreement
Our Data Processing Terms are included in Schedule 1 of these Terms and apply when we process personal data on the Merchant’s behalf. If you require a separately signed copy, contact support@obsedia.ai.
18. Security and incidents
We maintain technical and organisational safeguards appropriate to the nature and risk of the Service, including authenticated Shopify access, tenant separation, encryption of protected data, authenticated webhook processing, access restrictions, data minimisation and restricted logging.
The Merchant is responsible for security within its Shopify organisation, user accounts, devices and systems, and for promptly revoking access that is no longer required.
We will notify the Merchant without undue delay after becoming aware of a personal-data breach affecting Merchant Personal Data. Information may be provided in stages as the investigation progresses. We will provide information reasonably needed for the Merchant to meet its legal obligations. Notification is not an admission of fault or liability.
19. Service availability and changes
We provide the Service with reasonable care and skill. We may perform maintenance, release updates and modify functions to improve safety, compliance, reliability or compatibility.
We may change or discontinue a feature if reasonably necessary because of law, security, abuse, Shopify changes, provider changes, destination restrictions or technical obsolescence. Where a change materially reduces paid core functionality, we will provide reasonable notice when practicable.
Unless a separate written service-level agreement applies, the Service is provided without a guaranteed uptime or response time. Planned and emergency maintenance, third-party outages and circumstances beyond our reasonable control may affect availability.
20. Suspension
We may suspend all or part of the Service immediately where reasonably necessary to:
- prevent unlawful, fraudulent or abusive activity;
- honour a Recipient's rights or stop unauthorised messaging;
- respond to a security threat or compromised account;
- comply with law, a binding authority request, Shopify requirements, provider rules or network restrictions;
- prevent uncontrolled cost or protect a budget limit;
- address overdue undisputed charges after reasonable notice; or
- contain a material breach of these Terms.
Where lawful and practicable, we will inform the Merchant of the reason and the steps required to restore access. Suspension does not authorise us to charge for SMS that was not submitted or otherwise chargeable under Section 12.
21. Term and termination
These Terms begin when the Merchant first accepts them and continue until the agreement is terminated.
The Merchant may terminate by uninstalling Europe SMS Marketing. Uninstalling the app cancels its Shopify subscription. Charges already incurred or approved may remain payable.
The unused-credit rule and its exceptions in Section 13 apply: use available SMS credit before uninstalling, as it is forfeited on uninstall and is not restored by reinstalling. Unresolved reservations and provider or billing outcomes remain subject to reconciliation.
Either party may terminate for a material breach that is not cured within 14 days after written notice. No cure period is required for a breach that cannot be cured, unlawful messaging, serious security abuse, fraud or conduct creating material risk to recipients, networks or the Service.
We may terminate the Service for convenience with at least 30 days' notice. If we terminate a prepaid subscription for convenience, we will refund the unused prepaid portion for the period after termination, excluding usage already consumed.
Upon termination:
- the licence and account access end;
- pending campaigns and automations stop;
- amounts lawfully incurred remain payable;
- Merchant Personal Data is deleted or returned as stated in Schedule 1; and
- provisions intended by their nature to survive remain effective, including confidentiality, accrued payment obligations, intellectual property, liability and dispute provisions.
22. Warranties and disclaimers
Each party warrants that it has authority to enter into this agreement.
We warrant that we will provide the Service with reasonable care and skill and will not knowingly introduce malicious code.
The Merchant acknowledges that SMS delivery and Shopify data depend on third-party systems. To the extent permitted by law, we do not warrant uninterrupted operation, delivery of every SMS, availability of every destination or feature, or any particular commercial result.
Europe SMS Marketing provides operational controls and information. It does not provide legal advice and does not determine whether the Merchant's specific campaign is lawful. The Merchant is responsible for obtaining professional advice appropriate to its business, recipients and destinations.
No provision excludes a warranty or remedy that cannot legally be excluded.
23. Liability
Neither party is liable to the other for indirect or consequential loss, or for loss of profit, revenue, goodwill or anticipated savings, except to the extent such loss is payable to a third party under an obligation covered by Section 24.
Subject to the exclusions below, each party's aggregate liability arising out of or relating to the Service during any 12-month period will not exceed the total fees paid or payable by the Merchant for the Service during the 12 months preceding the first event giving rise to liability.
The exclusions and cap in this Section do not apply to:
- fraud or fraudulent misrepresentation;
- wilful misconduct or gross negligence where it cannot be limited;
- death or personal injury caused by negligence where it cannot be limited;
- the Merchant's obligation to pay properly due charges;
- infringement or misappropriation of the other party's intellectual property;
- breach of confidentiality caused intentionally or through gross negligence; or
- liability that applicable law does not permit a party to exclude or limit.
Data-protection liability between the parties is allocated according to each party's responsibility for the event and remains subject to rights and remedies that cannot be restricted by contract.
24. Third-party claims
The Merchant will defend and indemnify us against a third-party claim, regulatory demand, fine, damage and reasonable external cost to the extent caused by:
- an unlawful Recipient list, campaign, instruction or Merchant Content;
- failure to obtain or evidence legally required consent;
- failure to honour an opt-out or privacy request after it has been communicated to the Merchant;
- infringement by Merchant Content; or
- the Merchant's material breach of Sections 6, 7 or 9.
This obligation does not apply to the extent the claim was caused by our breach, negligence, unlawful processing or unauthorised modification of the Merchant's instruction.
The indemnified party must provide prompt notice, reasonable cooperation and control of the defence to the indemnifying party. No settlement may admit fault by, impose a non-monetary duty on, or restrict the rights of the indemnified party without its written approval.
25. Changes to these Terms
We may update these Terms to reflect changes in law, security, Shopify requirements, provider contracts, pricing or the Service.
We will give at least 30 days' notice of a material change through the Service or the Merchant's registered contact details, unless an earlier change is necessary to address law, security, fraud or an urgent third-party requirement.
A pricing change applies only prospectively after the disclosed effective date and any approval required through Shopify. If the Merchant does not accept another material change, it may terminate before the change takes effect.
26. Notices
Notices to Europe SMS Marketing must be sent to support@obsedia.ai. Privacy notices and requests must be sent to privacy@obsedia.ai.
We may send operational or legal notices to the email associated with the Merchant's Shopify account or display them in the Service. The Merchant must keep its contact details current.
Email notice is deemed received on the next business day after sending unless the sender receives a delivery-failure notice.
27. Governing law and disputes
These Terms are governed by the laws of Romania and directly applicable European Union law, without regard to conflict-of-law rules.
The parties will first attempt in good faith to resolve a dispute through written notice and direct discussion for at least 30 days. This does not prevent either party from seeking urgent injunctive relief, enforcing undisputed payment obligations, or exercising a right that cannot be restricted.
Subject to mandatory jurisdiction rules, the competent courts in Romania with jurisdiction over the registered office of Genius Nutrition SRL have exclusive jurisdiction over disputes arising from these Terms.
Nothing in this Section prevents an individual from submitting a complaint to a competent data-protection authority or exercising a non-waivable statutory right.
28. General terms
These Terms, the Privacy Policy, the Data Processing Terms and any accepted Shopify billing approval form the entire agreement concerning the Service and replace earlier discussions about the same subject.
If documents conflict, the following order applies: mandatory law; applicable international-transfer terms; Schedule 1 for personal-data processing; the accepted billing approval for price and limits; these Terms; and the Privacy Policy.
The Merchant may not assign this agreement without our written consent, except with a transfer of substantially all its relevant business where the assignee agrees in writing to these Terms. We may assign the agreement as part of a merger, reorganisation or sale of the relevant business, provided the assignment does not reduce data-protection safeguards or accrued rights.
Neither party is liable for delay caused by events beyond its reasonable control, excluding payment obligations and obligations to protect personal data. The affected party must take reasonable steps to reduce the impact.
Failure to enforce a provision is not a waiver. If a provision is unenforceable, it will be modified only to the minimum extent necessary, and the remaining provisions continue in effect.
Headings are for convenience and do not affect interpretation. The English version governs if a translation differs, except where mandatory law requires otherwise.
29. Contact
Genius Nutrition SRL, trading as OBSEDIA
Tamasi nr. 20
Buftea, Ilfov
Romania
VAT: RO35355847
General contact: support@obsedia.ai
Privacy contact: privacy@obsedia.ai
Schedule 1 — Data Processing Terms
For a separately signed copy, see Data processing agreement.
1. Scope and roles
These Data Processing Terms apply when Europe SMS Marketing processes personal data on behalf of the Merchant in connection with the Service ("Merchant Personal Data").
The Merchant is the controller and Genius Nutrition SRL is the processor, except where applicable law determines another role based on the facts. Each party is responsible for complying with the obligations applicable to its role.
These Data Processing Terms satisfy the requirement for a binding controller-processor agreement under applicable European data-protection law.
2. Processing details
Subject matter
Providing Shopify-connected SMS audience, campaign, automation, delivery, reporting, billing-support and privacy-compliance functions.
Duration
For the term of the Service and the limited deletion, return, security, legal-retention and audit period following termination.
Nature and purpose
Collection from Shopify and the Merchant; validation; organisation; encryption; storage; audience eligibility; message composition; automated event processing; transmission to the SMS provider; delivery-status processing; opt-out and suppression; campaign measurement; billing reconciliation; security; troubleshooting; privacy-request fulfilment; deletion and anonymisation.
Categories of data subjects
- Merchant customers and prospective customers;
- SMS Recipients;
- persons associated with carts, checkouts, orders, fulfilments, refunds or delivery events;
- Merchant personnel and Authorised Users; and
- persons submitting privacy or support requests.
Types of personal data
- identifiers, including Shopify customer ID, store ID, telephone number and optional first name;
- consent status, source, date, opt-out and suppression information;
- Shopify segment membership and audience eligibility;
- cart, checkout, order, payment, fulfilment, delivery, cancellation and refund evidence;
- limited transaction amount and currency evidence used for deterministic attribution;
- SMS sender, content, encoding, segment count, status, timestamps, provider reference and delivery report;
- cash-on-delivery response and related security evidence;
- IP address, authentication, device, request and security metadata; and
- hashed or encrypted identifiers, audit events and retention timestamps.
Order numbers, order totals and currencies may be used to personalise order and payment confirmation messages, as well as for attribution where applicable. We also process cart and checkout recovery URLs, shipment tracking URLs where available, cash-on-delivery responses, unsubscribe actions and the associated security records.
Encrypted Shopify webhook payloads may contain additional fields received from Shopify; their limited processing and retention are described in the Privacy Policy.
Special-category data is not intended to be processed under the Service.
3. Merchant instructions
The Merchant instructs us to process Merchant Personal Data only to:
- provide and secure the Service;
- perform the settings and actions selected by the Merchant and its Authorised Users;
- comply with these Terms; and
- comply with applicable law.
These Terms, the Merchant's use of the Service and documented support instructions constitute the Merchant's instructions. An additional instruction must be submitted in writing and may be subject to reasonable fees if it falls outside the Service.
We will notify the Merchant if, in our reasonable opinion, an instruction infringes applicable data-protection law, unless the law prohibits notification. We may suspend the affected processing while the parties resolve the issue.
4. Merchant obligations
The Merchant warrants that:
- it has authority to provide Merchant Personal Data and instructions;
- its processing and instructions comply with applicable law;
- it has provided required notices and established a valid legal basis;
- it has obtained valid consent for marketing SMS where required;
- it will not instruct us to process unnecessary sensitive data; and
- it will use the Service in a way that permits both parties to comply with data-subject rights and regulatory duties.
The Merchant is responsible for the accuracy, quality and lawfulness of Merchant Personal Data and for decisions concerning message purpose, audience, content and timing.
5. Processor obligations
We will:
- process Merchant Personal Data only on documented instructions, unless law requires other processing;
- ensure that authorised personnel are bound by confidentiality;
- implement and maintain the security measures in Section 11;
- engage subprocessors only under Section 6;
- assist the Merchant, taking account of the nature of processing, with data-subject requests;
- assist with security, breach notification, impact assessments and regulator consultations where reasonably required;
- delete or return Merchant Personal Data under Section 9;
- make information reasonably necessary to demonstrate compliance available to the Merchant; and
- notify the Merchant of a legally binding request for Merchant Personal Data unless prohibited by law.
If law requires processing beyond the Merchant's instructions, we will inform the Merchant before processing unless that law prohibits the information.
6. Subprocessors
The Merchant grants general authorisation for us to use subprocessors needed to provide the Service.
Public information about subprocessors used for the core Service is summarised below:
| Subprocessor | Function | Data involved |
|---|---|---|
| Railway Corporation | Application hosting, background processing infrastructure, PostgreSQL database hosting and configured backup storage | Store, customer, consent, message, delivery, usage and security data |
| SMS delivery providers | SMS transmission and delivery reports | Recipient number, sender name, message content, message reference and delivery information |
Railway Corporation is located at 548 Market St PMB 68956, San Francisco, California 94104, United States. Its privacy contact is privacy@railway.com. Our production application services and primary PostgreSQL database are currently hosted in Amsterdam, Netherlands. This does not establish the location of every backup, support activity or other provider operation. See Railway Privacy and Railway subprocessors.
SMS delivery providers are described publicly by category. Confidentiality obligations do not restrict legally required disclosures or the exercise of data-protection rights.
Shopify provides the Merchant's commerce platform, source data, authentication and billing channel under its separate agreement with the Merchant. It is not appointed by us as a subprocessor of Merchant Personal Data merely because Europe SMS Marketing connects to it.
We will impose written data-protection obligations on a subprocessor that are materially consistent with these Data Processing Terms for the services it performs. We remain responsible for the subprocessor's performance to the extent required by applicable law.
We will provide reasonable advance notice through the Service or the Merchant's registered contact details before adding or replacing a core subprocessor. The Merchant may object on reasonable data-protection grounds before the change takes effect. The parties will work in good faith on a commercially reasonable solution. If no solution is reasonably available, either party may terminate the affected Service without penalty for the unused prepaid period.
7. International transfers
We will not transfer Merchant Personal Data to a restricted third country unless the transfer is permitted by applicable law.
Where a transfer requires contractual safeguards, the relevant parties must enter into the applicable transfer terms and complete the required annexes before that transfer. The relevant mechanism depends on the provider relationship and processing operation. This provision does not itself establish that a particular transfer agreement or certification applies to every provider relationship. Applicable binding transfer terms prevail over conflicting provisions of this agreement.
We will provide reasonable information about the transfer mechanism and supplementary measures upon request, subject to confidentiality and security restrictions.
8. Data-subject requests and Shopify compliance requests
Taking account of the nature of processing, we will provide reasonable technical and organisational assistance for access, correction, deletion, restriction, portability, objection and opt-out requests.
Where a request is submitted directly to us and concerns Merchant-controlled data, we will forward it to the Merchant or ask the requester to contact the Merchant, unless applicable law requires us to respond directly.
The Service processes Shopify's mandatory customer-data request, customer-redaction and shop-redaction events. The Merchant remains responsible for coordinating the complete response across its own systems and other providers.
9. Return and deletion
At the end of the services relating to processing, we will, at the Merchant’s choice, return or delete Merchant Personal Data and delete existing copies, unless Union or Member State law requires retention. Any retained data remains protected and restricted to the required purpose.
Operational deletion follows the periods in the Privacy Policy. On uninstall, active sessions and tenant customer data used for messaging are purged, while minimal records may remain temporarily to prevent replay, complete billing reconciliation, meet legal duties or establish and defend claims.
Data remaining in a protected backup is isolated from ordinary use and deleted through the applicable backup cycle. Any legally retained data is restricted to the required purpose.
10. Security incidents
We will notify the Merchant without undue delay after becoming aware of a personal-data breach affecting Merchant Personal Data. Information may be provided in stages as the investigation progresses.
The notice will include, to the extent available:
- the nature of the breach;
- affected data and data-subject categories;
- likely consequences;
- measures taken or proposed;
- information reasonably needed for the Merchant's assessment; and
- a contact for follow-up.
We will take reasonable steps to contain, investigate and remediate the incident and will cooperate with the Merchant's legally required notifications.
11. Technical and organisational measures
Europe SMS Marketing maintains measures appropriate to the risk, including:
- HTTPS for public connections and encrypted private networking between application services and the database;
- Shopify-managed authentication and tenant-bound application sessions;
- least-privilege Shopify scopes and fail-closed handling of missing access;
- AES-256-GCM authenticated encryption for stored telephone numbers, optional first names, campaign content and webhook payloads;
- tenant-bound HMAC-based telephone lookup values;
- encryption-key versioning and protected secret storage;
- tenant isolation in data access and database relationships;
- authenticated Shopify webhook processing;
- authenticated provider requests and delivery-report processing;
- idempotency, deduplication and replay protection;
- access controls and confidentiality duties;
- production and development separation;
- data minimisation and automated retention processing;
- redacted logs that exclude message bodies, telephone numbers, credentials and raw webhook bodies;
- spending, frequency, suppression and kill-switch controls; and
- security monitoring, incident handling and recovery procedures.
We may update these measures to address evolving risks, provided the overall protection is not materially reduced.
12. Audits and compliance information
On reasonable written request, no more than once in a 12-month period unless a breach or regulator requires otherwise, we will provide documentation reasonably necessary to demonstrate compliance with these Data Processing Terms.
If that information is insufficient, the Merchant may request an audit by an independent qualified auditor bound by confidentiality. The audit must:
- take place on reasonable notice during normal business hours;
- avoid access to another merchant's data, secrets or security-sensitive systems;
- minimise disruption;
- follow reasonable security requirements; and
- be paid for by the Merchant unless the audit identifies a material breach by us.
Audit rights do not require disclosure that would weaken security, violate another person's rights or breach a legal duty.
13. Government requests
We will review government requests for Merchant Personal Data and disclose only data we are legally required to disclose. Where lawful, we will notify the Merchant before disclosure and will reasonably challenge a request that is unlawful, overbroad or inconsistent with applicable transfer safeguards.
14. Liability and termination
Liability arising from these Data Processing Terms is governed by Section 23 of the Terms, subject to rights and liabilities that cannot legally be limited.
These Data Processing Terms terminate when we have deleted or returned all Merchant Personal Data, except data lawfully retained under Section 9.