Skip to content
ChannelHawk AI
ChannelHawk Insights One view of the business, and a clear next move ChannelHawk Support Answers from your own approved knowledge ChannelHawk Platform The shared data, permission and AI layer
Multi-channel brands Shopify, Amazon, wholesale — one picture Business owners Know what to do Monday Agencies & consultants Stop rebuilding the same report
Integrations Pricing Security
Book a demo
Menu
Products ChannelHawk Insights One view of the business, and a clear next move ChannelHawk Support Answers from your own approved knowledge ChannelHawk Platform The shared data, permission and AI layer
Solutions Multi-channel brands Shopify, Amazon, wholesale — one picture Business owners Know what to do Monday Agencies & consultants Stop rebuilding the same report
Integrations Pricing Security Book a demo
Legal

Data Processing Agreement

This DPA describes how ChannelHawk AI processes personal data on your behalf and the safeguards we have in place.

Effective May 2026

1. Parties and roles

This Data Processing Agreement ("DPA") is entered into between the client organization subscribing to the ChannelHawk AI platform ("Controller") and ChannelHawk AI, LLC, 8430 Charter Club Circle, Suite 6, Fort Myers, FL 33919, United States ("Processor").

For the purposes of GDPR and equivalent data protection legislation, the Controller determines the purposes and means of processing personal data, while ChannelHawk processes personal data solely on the Controller's documented instructions as described in this DPA.

2. Subject matter and scope

ChannelHawk processes data originating from the Controller's connected commerce platforms (Shopify, Amazon SP-API, QuickBooks Online) for the purpose of providing analytics, reporting, and AI-generated business insights through the ChannelHawk platform.

The duration of processing corresponds to the active subscription period, after which data is deleted in accordance with Section 9.

3. Data minimization by design

ChannelHawk has implemented privacy-by-design principles at the ingestion layer. Our sync pipelines are explicitly configured to minimize the personal data collected:

  • Fields requested and stored: postal/zip code, city, state/province, country — for geographic analytics only.
  • Fields intentionally excluded: customer names, email addresses, phone numbers, and full street addresses are never requested from platform APIs and are never written to ChannelHawk databases.
  • All geographic fields are encrypted at rest (AES-256-CBC) with HMAC-SHA256 blind indexes. They are never used in plaintext SQL GROUP BY operations.

This architecture ensures that ChannelHawk does not function as a repository of consumer PII — it operates exclusively on anonymized, aggregated metrics.

4. Security measures

ChannelHawk implements the following technical and organizational measures to protect personal data:

  • Encryption at rest: AES-256-CBC field-level encryption for all personal data fields via the joepages/laravel-field-encryption package
  • Encryption in transit: TLS 1.2 or higher for all data in transit between clients, application servers, and databases
  • Tenant isolation: Each client operates in a fully isolated PostgreSQL database. There are no shared tables or cross-tenant queries
  • Access controls: Role-based access control (RBAC) with the principle of least privilege enforced across all internal tooling
  • Access logging: All privileged access to production systems and tenant data is logged and retained for audit purposes
  • Infrastructure: Hosted with established cloud infrastructure providers, with Cloudflare DDoS protection and WAF in front of all public endpoints

5. Sub-processors

ChannelHawk engages the following sub-processors to deliver the Service. The Controller hereby provides general authorization for the use of these sub-processors. ChannelHawk will provide at least 30 days' notice before adding new sub-processors.

Sub-processorPurposeLocation
Anthropic (Claude)AI report and insight generation — anonymized, aggregated metrics onlyUSA
OpenAI (GPT-4o)AI fallback processing — anonymized, aggregated metrics onlyUSA
CloudflareDNS, CDN and DDoS mitigationGlobal
ResendTransactional email deliveryUSA

AI providers — data isolation note: Only aggregated, anonymized metrics are transmitted to AI sub-processors (e.g., "total revenue this month by region"). No individual order records, customer identifiers, or other personal data are included in AI prompts. This applies to AI that runs on ChannelHawk’s keys or the Customer’s own API keys. Where the Customer connects its own Claude or ChatGPT account — through our desktop app or the Claude and ChatGPT connectors — that provider’s terms for the Customer’s account apply instead, including its training settings.

6. Data subject rights

The Controller is the primary party responsible for responding to data subject requests (access, correction, deletion, portability, objection). ChannelHawk will assist the Controller in fulfilling data subject rights requests:

  • ChannelHawk will respond to Controller requests for assistance within 72 hours of receipt
  • Technical assistance includes data exports, targeted deletions, and correction of stored records as requested

7. Data breach notification

In the event of a personal data breach affecting Controller data, ChannelHawk will notify the Controller within 72 hours of becoming aware of the breach. The notification will include:

  • A description of the nature of the breach and the categories of data affected
  • Likely consequences and the measures taken or proposed to address the breach
  • Contact details for the ChannelHawk data protection point of contact

8. Controller instructions

ChannelHawk processes personal data only on documented instructions from the Controller, as set out in the subscription agreement and these Terms. If ChannelHawk believes an instruction infringes applicable data protection law, it will inform the Controller promptly.

ChannelHawk personnel with access to Controller data are bound by appropriate confidentiality obligations.

9. Data retention and deletion

  • During the subscription: Data is retained for the duration of the active subscription as required to provide the Service.
  • Upon termination: All Controller tenant data (database, backups, cached data) is permanently deleted within 30 days of contract termination.
  • Deletion certificate: Available upon written request after confirmation of deletion.

10. International transfers and GDPR

ChannelHawk's infrastructure is located in the United States. For Controllers in the European Union or United Kingdom, personal data transfers to the US are governed by the European Commission's Standard Contractual Clauses (SCCs), which are incorporated into and form part of this DPA. A copy of the executed SCCs is available upon written request to hello@channelhawk.ai.

ChannelHawk's processing activities are designed to comply with GDPR Article 28 (processor obligations) and the UK GDPR equivalent.

11. Audits

The Controller may, on reasonable written notice (not less than 30 days) and no more than once per calendar year, conduct an audit of ChannelHawk's data processing activities or request documentation evidencing compliance with this DPA. Audits shall be conducted during business hours in a manner that does not unreasonably disrupt ChannelHawk's operations.

12. Changes to this DPA

ChannelHawk may update this DPA to reflect changes in law, regulation, or processing activities. Material changes will be communicated to the Controller with at least 30 days' notice.

13. Contact

Data protection and DPA inquiries:
hello@channelhawk.ai
ChannelHawk AI, LLC · 8430 Charter Club Circle, Suite 6 · Fort Myers, FL 33919 · United States

ChannelHawk AI

Your business data, turned into answers and action.

hello@channelhawk.ai

Products

  • Insights
  • Support
  • Platform
  • Pricing

Solutions

  • Ecommerce
  • Business owners
  • Agencies

Company

  • Contact
  • Security
  • Sign in

Resources

  • Integrations
  • Book a demo
© 2026 ChannelHawk AI. All rights reserved. Privacy · Terms · DPA · llms.txt · Sitemap