Flyweight: Using an AI Chatbot for Shopify in Compliance with GDPR & AI Act
Complete guide to using Flyweight AI Chatbot for Shopify in compliance with GDPR and AI Act. Includes privacy policy template and compliance checklist.
Order Processing Agreement, labeling obligation, privacy policy, GDPR, AI Act - what? 🤯🤯

The checklist and privacy policy template below assume you run a Shopify store and want to add a GDPR-compliant AI chatbot. Want the full picture of what our Shopify chatbot can do? Head to the main guide. This article does not constitute legal advice or acknowledgment of a legal obligation.
Terminology
-
General Data Protection Regulation (GDPR)
The GDPR is the core privacy law in Europe. It sets the rules for how companies handle personal data, like collecting only what’s actually needed and storing it securely. It also gives people rights over their data, including access, correction, and deletion. For chatbots, that means no broad or unnecessary data collection, and clear communication about how data is used. -
Artificial Intelligence Act (AI Act)
The AI Act is a proposed EU law that sets rules for artificial intelligence. The goal is safer, fairer use of AI systems like chatbots. It groups AI systems by risk level, from low to high. Each category comes with its own requirements, like making it clear that users are interacting with AI and preventing discriminatory outcomes. Chatbots handling sensitive use cases may fall into higher-risk categories and face stricter requirements. -
Data Processing Agreement (DPA)
A Data Processing Agreement is a contract between the company using the chatbot and the provider operating it. It defines that the provider processes user data only on the company’s instructions and in line with data protection rules. If you use an external chatbot provider, a DPA is typically needed to document GDPR-compliant processing. -
Privacy Policy
A privacy policy explains what data is collected, why it’s collected, and how long it’s stored. It should also explain user rights, like the right to request deletion or access stored data. For chatbot use, this information should be easy to understand and easy to find. -
Labeling Obligation
Under GDPR principles and especially the planned AI Act, users should be able to tell they’re interacting with AI, not a human. That’s the labeling obligation. The goal is transparency and fewer misunderstandings.
Roles and Responsibilities
Roles matter because they define who is responsible for what.
Processor
The chatbot provider is usually the processor. That means the provider processes data on behalf of the store operator and based on their instructions. The provider handles the technical setup and operation of the chatbot, but does not decide why the data is being processed. Their job is to follow the controller’s requirements and implement technical and organizational measures to protect personal data. In short, the chatbot provider is contractually bound to process data only as instructed, not for its own independent purposes.
Controller
This is the part that often feels a bit counterintuitive: the store operator is the controller. As the controller, the store decides why and how data is processed, for example, what the chatbot collects and whether it’s used for support, lead generation, or something else. The controller is responsible for making sure data collection and processing meet privacy requirements and that user rights are respected. In practice, that means the store operator defines how the chatbot is used and is responsible for the privacy compliance around that use. It sounds bigger than it is. Usually, it starts with being clear in the privacy policy.
Practical Example
Let’s say the Shopify store "GarlicPress24" wants to use an AI chatbot for lead generation. A customer asks about garlic press specs, and the AI gives expert guidance. During that flow, the chatbot collects the customer’s contact details, like name and email, and forwards them to the expert.
The store has to decide how this should work. Should the lead be collected through AI? Or should the chatbot simply show a message like, “Contact our experts at Email X”? The Shopify store is the controller because it decides what happens and makes sure customers are properly informed in the privacy policy. The AI chatbot provider handles the technical setup and processes the data according to the store’s instructions, which makes the provider the processor.
How to Use an AI Chatbot in Compliance with Data Protection Requirements: A Checklist
If you want to run a chatbot in line with GDPR and the AI Act, the roles above define the responsibilities.
-
Collect Only Necessary Data
The chatbot should collect only the data that’s actually needed. This is mainly a provider responsibility. At Flyweight, we aim to process only the minimum personal data required. For example, if a customer asks about an order status, we only process postal codes and order numbers, not extra address details or broader order data. Personal data is also handled separately from the AI. -
Be Transparent
Users should understand what data the chatbot collects and what it’s used for. The privacy policy is the right place to explain this clearly, especially for Shopify store operators. Since the store is the controller, the policy should be updated so customers are properly informed. A template is included below to help with that. -
Put a Data Processing Agreement (DPA) in Place
If the chatbot comes from an external provider, there should be a contract that covers GDPR-compliant data processing. Check whether the provider offers a DPA, often as part of the standard agreement. -
Review Security and Data Protection Regularly
The AI Act also points toward regular reviews of AI-related risks, so the chatbot setup stays compliant over time. This is usually handled by the chatbot provider. We keep this guide updated and share relevant changes. -
Label the Chatbot Clearly
Even if explicit labeling is not yet a hard legal requirement in every case, being transparent is still the right move. Users should know they’re talking to AI. Our AI chatbot includes a default footer that says: “AI powered by Flyweight,” and we recommend keeping it. If you want to be extra careful, you can also mention AI in the welcome message or the chatbot name.
⭐️ Privacy Policy Template
As we’ve seen, Shopify stores acting as controllers are mainly responsible for clearly explaining how data is processed.
And the best place for that? Your privacy policy.
💡 If we were the shop operator using the Flyweight AI Chatbot, we’d add the following section to the privacy policy (without acknowledging a legal obligation or providing legal advice):
👇👇👇👇👇👇👇👇👇👇
Use of the Chatbot with Forms
We offer you an AI-based chatbot from Flyweight GmbH, Jungbuschstraße 28, 68159 Mannheim, Germany (https://flyweight.io/legal-notice / https://flyweight.io/privacy-statement) on our website to answer your questions. When using the chatbot, your queries are combined using the database created from the website information read from our own website and a large language model to provide you with answers to your query. The chatbot is instructed not to ask for personal data. Good to know: If separate forms appear as a result of your inquiries, in which you may then have to provide personal data based on your inquiry, the information you provide there will be processed separately and accordingly will not be sent to AI.
Processed Data Categories: The data categories result from your inquiries when you enter personal data within your question.
-
For example, if you ask: “Where is my order?”, a form will appear in which you can enter your order number and your zip code.
-
If, for example, you would like to find out more about a product and receive appropriate advice, a form will appear in which you can enter the relevant information (e.g. name, telephone, e-mail, etc.).
Purpose of Processing: Processing the information you provide to create responses to your requests using the chatbot.
-
Example: For example, if you ask: “Where is my order?” and enter your order number and zip code in the form, this information is used to make a direct request to the store system (Shopify) so that the delivery information can be sent and you can be informed about the status of the order.
-
Example: If you would like advice on a product, your request (with the data you provide in the form and the entire chat history) will be forwarded to the store operator so that they can contact you.
Data Source: We collect this data directly from you.
Legal Basis: We process data to fulfill contractual or pre-contractual obligations in accordance with Article 6, paragraph 1, point (b) of the General Data Protection Regulation (GDPR).
Data Retention: Data is stored until your inquiry is resolved or for the contract’s duration and beyond until legal retention periods (6 to 10 years) have passed.
Location of Recipients: EU and non-EU.
Guarantees for Transfers to Third Countries: EU Standard Contractual Clauses (SCC), Adequacy Decision
👆👆👆👆👆👆👆👆👆👆
Install the privacy-compliant chatbot for European Shopify stores ✌️














