Data Processing Addendum
Last updated: September 23, 2026
This draft is intended to become Mirynna's merchant and business-customer data processing addendum. It must still be completed with governing law, international-transfer terms, and launch subprocessors before it becomes effective.
1. Roles
To the extent Mirynna processes personal data on behalf of a business customer in providing the service, the customer acts as controller/business and Mirynna acts as processor/service provider, except where applicable law assigns a different role for a specific processing activity.
2. Processing instructions
Mirynna will process personal data only to provide the contracted service, follow documented customer instructions, maintain security and reliability, comply with law, and perform other processing disclosed in the applicable agreement and Privacy Policy.
3. Confidentiality and access
Mirynna will limit personnel access to personal data to authorized individuals who require access for their role and who are subject to appropriate confidentiality obligations.
4. Security
Mirynna will maintain reasonable technical and organizational safeguards appropriate to the nature of the service and the data processed. Current product controls are summarized on the Security page.
5. Subprocessors
Mirynna may use subprocessors to provide cloud infrastructure, authentication, AI inference, and transactional communications. The current pre-launch list is published at Subprocessors. A production change-notice process will be established before this DPA becomes effective.
6. Data subject requests
Taking into account the nature of the processing, Mirynna will provide reasonable assistance to customers with applicable access, correction, deletion, restriction, portability, and objection requests when Mirynna has the relevant data and the request is legally required.
7. Deletion and return
At termination or on valid instruction, Mirynna will delete or return personal data as required by the applicable agreement and production retention schedule, except where retention is required by law or necessary for security, dispute resolution, or other permitted purposes.
8. Security incidents
Mirynna will maintain an incident-response process and notify affected customers of qualifying personal-data incidents as required by applicable law and contractual obligations.
9. International transfers
Before public commercial launch, this section will identify the transfer mechanism used where personal data is transferred across borders and a transfer mechanism is legally required.
10. Shopify merchant data
For Shopify-connected merchants, Mirynna will process protected customer data only for merchant-facing features, only within approved access, and only for the purposes disclosed to the merchant. Mirynna will not sell protected customer data or use it for unrelated advertising.
11. Processor contact details
- Processor business name: Mirynna
- Processor address:
[MAILING ADDRESS] - Privacy/DPA contact: privacy@mirynna.com
- General support: support@mirynna.com
- Company phone: +1 (702) 789-7604
- Governing law and transfer mechanism:
[TO BE FINALIZED]