Data Processing Addendum

Last updated: 24 August 2026.

Roles and scope

This Data Processing Addendum ("DPA") describes how Rezolve Ai, operated by Rezolve Ai Limited, 21 Sackville Street, London W1S 3DN, England, processes personal data on behalf of its customers under UK GDPR and EU GDPR.

  • For the catalog, content, and analytics data you bring into Rezolve Ai (including storefront analytics events, where you switch that on), you are the controller and Rezolve Ai is the processor.
  • For your Rezolve Ai account itself (login email, settings, billing metadata), Rezolve Ai is the controller, as described in the Privacy Policy.

Subject matter, duration, nature and purpose

Processing covers product catalog enrichment, AI search optimization, feed generation, content publishing, and related analytics, for the duration of your subscription. Categories of data subjects: your staff and team members, and (where you enable storefront features) visitors and customers of your store. Categories of data: product and content data, staff contact details, and pseudonymized shopper interaction events (hashed IP, hashed visit identifiers, and, where you enable A/B testing, a pseudonymized visitor identifier and which version of your copy that visitor was shown). Rezolve Ai does not receive shopper names, email addresses, phone numbers or postal addresses, and rejects events that carry them.

Retention of identifiers. Pseudonymized visitor and visit identifiers are erased 35 days after the event they belong to, and the underlying events are deleted after 90 days. The aggregate day-level counts built from them survive, because they no longer relate to an identifiable person.

A/B testing and cookies on your storefront

If you switch on A/B testing, Rezolve Ai software running on your storefront stores two first-party cookies on your shoppers' devices: a random identifier so a returning shopper sees the same version of your copy, and a record of which version that is. This is the only Rezolve Ai feature that stores a cookie on a shopper's device, and nothing is stored until you have both switched it on and started a test that is actually live. Full detail, including names and lifetimes, is in our Cookie Policy.

Consent is yours to obtain. These are cookies on your domain, set to your shoppers, so you are the controller and the lawful basis is your responsibility. Rezolve Ai will not store or report anything without a consent signal from your own mechanism, and it asks for two permissions separately: preferences before storing which version a shopper should see, and analytics before reporting what they then did. It reads those signals from Shopify's Customer Privacy API or the WordPress Consent API. Where no such mechanism is present, Rezolve Ai treats the answer as no and the feature does nothing. That is a technical safeguard, not a substitute for your own consent notice: you still need to describe these cookies in your own cookie policy and collect consent for them.

What reaches Rezolve Ai. A pseudonymized visitor identifier, which version was shown, and whether that visitor reached checkout. On WordPress the identifier is hashed on your own server, with a secret unique to your store, before it is sent, so the same shopper visiting two stores produces two unrelated values. The payload carries no cookie value, no IP address, no user agent, no order record and no customer record, and Rezolve Ai stores none of them. Where a request reaches us from a browser rather than from your server, any network-level address is handled as described in the Privacy Policy, which is to say hashed rather than stored.

Withdrawal and erasure. Switching the feature off stops the split immediately and, on WordPress, removes the configuration from your site on the next scheduled run. Identifiers age out on the schedule above. To have a specific shopper's data erased sooner, or to exercise any other data subject right on their behalf, write to DPM@rezolve.com.

Aggregate benchmarking

Experiments can run controlled tests: a portion of your products is held back as a control group so the difference between the changed and unchanged groups can be measured. When one of those tests completes, Rezolve Ai keeps two numbers from it, and pools them with the equivalent numbers from other customers to work out what a given type of content change typically achieves.

What is pooled. Exactly two figures per completed test: the measured effect on a logarithmic scale, and its statistical margin of error. Each is labelled with the content type it relates to, for example "product description". Nothing else is included. In particular the pool contains no product data, no page addresses, no traffic or order counts, no revenue, no shopper data, and nothing identifying you or your store. A figure in the pool cannot be traced back to the customer it came from, and no customer can read the pool.

What it is used for. Two things only: the order in which Rezolve Ai suggests what to work on next, and the width of the uncertainty range shown beside a forecast. Pooling is what lets a new customer get a sensible ranking before they have run any tests of their own.

What it is never used for. A monetary forecast is never derived from another customer's results. Rezolve Ai shows a revenue figure only where your own completed tests stand behind the effect being applied and your own measured revenue per visit supplies the value. This is enforced in the product, not only as a policy: where that condition is not met, the revenue column is empty rather than estimated. No individual customer can dominate the pool either, because the weight any single result carries is capped.

Status of this data. We consider the pooled figures to be anonymous statistical data rather than personal data, and aggregated commercial data rather than your confidential business information. We are setting out our position here rather than leaving it unstated, so that you can disagree with it.

Opting out. You can withhold a project's results from the pool at any time in the product, under Settings, then Data & Privacy. For an instruction covering your whole account, write to DPM@rezolve.com. Opting out stops your results being shared with anyone else. It does not remove your access to the pooled figures, and it does not reduce what Rezolve Ai does for you: benchmarking costs a contributor nothing, so making it reciprocal would turn a privacy choice into a penalty. Results already pooled are excluded from the next nightly rebuild.

Sub-processors

We use the following sub-processors. We will give notice on this page before adding or replacing a sub-processor that handles customer personal data.

Sub-processorPurposeLocation
Vercel Inc.Application hosting and edge networkUnited States (us-east)
Supabase Inc.Managed PostgreSQL database, authentication, and file storageUnited States
Inngest, Inc.Background job orchestration (14-day event payload retention)United States
OpenAI, Anthropic, GoogleLarge language model inference for content generation. Not used for model training per their enterprise termsUnited States
Resend, Inc.Transactional email deliveryUnited States
Authoritas (Analytics SEO Ltd)AI search visibility and research dataUnited Kingdom
Langfuse (self-hosted)LLM observability on our own infrastructure at an Authoritas-internal domain. Receives prompts and completions for debuggingEuropean Union
Oxylabs (Teso LT, UAB)Proxy network for fetching publicly available storefront pagesLithuania
Cloudflare, Inc.Turnstile bot protection on public formsUnited States (global network)
Amazon Web ServicesObject storage for uploaded feed files and CDN log analysisConfigurable per deployment (US by default)

International transfers

Our primary hosting (Vercel, Supabase) is located in the United States, so personal data processed by Rezolve Ai is transferred to and stored in the US. For transfers out of the UK and EEA we rely on the EU Standard Contractual Clauses and the UK International Data Transfer Addendum with each sub-processor, and, where the sub-processor is certified, the EU-US Data Privacy Framework. We do not currently offer EU-region data residency.

Security measures

  • Encryption in transit (TLS) everywhere and encryption at rest in our database and storage.
  • Store access tokens encrypted at application level with AES-256-GCM.
  • API keys stored as salted hashes; plaintext shown once at creation.
  • Row-level security scoping every tenant's data in the database.
  • IP addresses stored only as salted hashes across all analytics features.
  • Role-based access control for team members within a project.

Deletion and return of data

You can export your data at any time (Settings, then Data & Privacy) and delete individual projects or your entire account in the product. Account deletion permanently removes your data from our systems, including uploaded files and generated content, per the retention table in the Privacy Policy. For Shopify installations, the mandatory shop/redact webhook additionally erases all shop-scoped data within 48 hours of uninstall.

Assistance and notification

We assist you with data subject requests that reach us instead of you, notify you without undue delay after becoming aware of a personal data breach affecting your data, and make available the information reasonably necessary to demonstrate compliance with this DPA.

Countersigned copy

If your procurement process requires a countersigned DPA incorporating the Standard Contractual Clauses, contact DPM@rezolve.com.