1. Roles
You (the Customer) operate a WordPress site with contact forms and decide why and how submissions are filtered. You are the controller of the personal data in those submissions.
StoreFixKit provides the TW Form Guard relay and processes submission data only to return a spam/ham verdict to your site. StoreFixKit is your processor. For license, billing and support data, StoreFixKit is an independent controller and this DPA does not apply.
2. What is processed
| Item | Detail |
|---|---|
| Subject matter | Classification of contact-form submissions as spam or genuine. |
| Duration | The duration of the request: content is held in memory and discarded when the verdict is returned. The DPA lasts as long as the Premium license. |
| Nature and purpose | Automated evaluation of submission text by a language model to support your spam-filtering decision. The verdict is advisory; in Dry-run mode it is only logged, in Block mode the plugin on your site acts on it and you can release any blocked submission. |
| Data subjects | People who submit a form on your site. |
| Categories of data | Name, email address and message text as entered in the form, for submissions your traps and rules could not decide. No IP address, no other fields. |
| Special categories | Not intended. Contact-form messages may incidentally contain anything a visitor types; you agree not to route forms designed to collect health, biometric, criminal or children's data through the AI judge. |
3. Instructions
Your documented instructions are: the plugin settings you choose (AI judge on or off, mode, trusted domains, rules), these terms, and the fixed behaviour described in the documentation. We process submission data only to return a verdict and to count usage against your quota. We do not read, analyse, sell or reuse submission content, and we do not use it to train models ourselves. We will tell you if we believe an instruction breaks data-protection law.
4. Confidentiality and security
- All traffic between your site, the relay and the model provider uses TLS. Requests from your site are signed with a per-license secret and protected against replay.
- The relay holds submission content in memory only. Persistent records contain license id, timestamps, verdicts, latency, token counts and rate-limit counters, never content.
- The model provider's credentials exist only on the relay server, never in the plugin. The relay forwards only the fixed instruction and the submission; it returns only the verdict.
- Access to the relay server is limited to StoreFixKit staff under a duty of confidentiality, over authenticated SSH, with a firewall exposing only web ports.
- Abuse controls: per-license and per-address limits, burst suspension, and a daily spending fuse that returns "unavailable" instead of failing closed.
5. Sub-processors
You authorise the sub-processors below for the purposes shown. We will publish any addition on the privacy policy and email active Premium customers at least 14 days before a new sub-processor receives submission content; you may object by cancelling within that period for a pro-rated refund.
| Sub-processor | Role | Location |
|---|---|---|
| Hangzhou DeepSeek Artificial Intelligence Co., Ltd. | Language model that returns the spam/ham answer for the formatted submission text | China |
| RackNerd LLC | Hosting of the relay server on which the processing runs | United States |
Stripe and Google (Gmail SMTP) handle license and billing data for which StoreFixKit is controller; they never receive submission content.
Disclosure about the model provider. We have not found a published statement from DeepSeek that API inputs are excluded from model training, and we do not hold Standard Contractual Clauses or an equivalent transfer instrument with DeepSeek. We are confirming both points with the provider. Until they are resolved, you should treat the AI judge as a transfer without supplementary contractual safeguards and decide accordingly; the traps and rules layers involve no processing by us at all.
6. International transfers
Submission content is processed in the United States (relay) and China (model provider). Where you are subject to the GDPR, UK GDPR or Swiss FADP, you are responsible for the transfer assessment for your own site, and we will provide the information in this DPA and the privacy policy to support it. We will add appropriate transfer instruments when the provider makes them available and update this DPA.
7. Assistance and data-subject requests
Because no submission content is retained on our side, there is nothing for us to return, correct or erase for a data-subject request; use the WordPress privacy tools on your site, which the plugin supports. If a request or a supervisory authority nonetheless reaches us about your site, we forward it to you within 5 business days and help as reasonably needed. We will notify you of a personal-data breach affecting the relay without undue delay and within 72 hours of becoming aware, with the information we have at the time.
8. Records and audit
On request, no more than once a year, we provide a written description of the relay's data flow, retention and security measures sufficient to demonstrate compliance with this DPA. On-site audits are not offered for a service at this price; if a law or authority requires one, we will agree a scope and reasonable cost with you.
9. Deletion at end of service
When your license ends, there is no submission content to delete on our side. License, activation and usage records are kept for 24 months for accounting and abuse investigation and then deleted, unless the law requires longer retention. You can delete your own plugin log at any time on your site, and uninstalling the plugin removes it.
10. Liability and precedence
The liability cap in section 8 of the Terms of Service applies to this DPA. If this DPA conflicts with the Terms on a data-protection matter, this DPA prevails. Where the law of your country requires specific processor clauses (for example Article 28 GDPR), those requirements are incorporated to the extent they are not already covered here.
中文摘要(数据处理协议)
本摘要供快速理解,法律效力以上方英文全文为准。
- 角色:你是网站运营者,是表单访客个人数据的控制者;StoreFixKit 只在你开启 AI 判定时代你处理数据,是处理者。license、账单、支持数据由 StoreFixKit 自行作为控制者管理,不在本协议范围。
- 处理内容:只有陷阱和规则拿不准的提交会被发送:发件人姓名、邮箱、留言正文(≤1,500 字符)。不发访客 IP,不发其他字段。中转只在内存中处理,返回结论后即丢弃;落盘记录只有 license 编号、时间、结论、耗时、token 数和限速计数。
- 处理目的:仅用于返回 spam/ham 结论并计入你的月度额度。我们不阅读、不分析、不出售、不复用提交内容,也不用它训练模型。
- 安全:全程 TLS;请求按 license 密钥签名并防重放;模型供应商的密钥只在中转服务器上,插件里没有;中转只返回结论一个词,不透传模型原文。
- 子处理者:Hangzhou DeepSeek Artificial Intelligence Co., Ltd.(DeepSeek,中国杭州,提供模型判定);RackNerd LLC(美国,服务器托管)。新增会接触提交内容的子处理者前,至少提前 14 天邮件通知付费客户,可在此期间取消并按比例退款。
- 待确认事项:我们尚未找到 DeepSeek 公开声明"API 输入不用于模型训练",也未与其签署标准合同条款等跨境传输文件,正在向供应商确认。确认前,请把 AI 判定视为没有额外合同保障的跨境传输,自行决定是否开启;陷阱和规则两层完全不经过我们。
- 跨境:数据在美国(中转)和中国(模型供应商)处理。适用 GDPR 等法规的客户需自行完成传输评估,我们提供本协议和隐私政策作为依据。
- 协助:我们不留存提交内容,因此访客的查询、更正、删除请求请用你站点上的 WordPress 隐私工具处理(插件已接入)。如有请求或监管机构找到我们,5 个工作日内转交给你。发生影响中转的数据泄露,知悉后 72 小时内通知你。
- 结束服务:license 到期后,我们这边没有提交内容需要删除;license、激活和用量记录保留 24 个月后删除。你站点上的日志随时可删,卸载插件即清空。
- 责任:适用服务条款第 8 条的责任上限(12 个月已付费用)。数据保护事项以本协议为准。