Controller
shopware AG takes the protection of personal data seriously and operates the Agentic Commerce Alliance and the Agentic Commerce Maturity Index (ACMI).
Controller responsible for data processing
shopware AGEbbinghoff 10
48624 Schöppingen
Germany
Telephone: +49 (0) 2555 92885-0
Email: info@shopware.com
Data Protection Officer
Sascha KremerSpecialist Lawyer for IT Law (Fachanwalt für IT-Recht)
c/o KREMER RECHTSANWÄLTE
Brückenstraße 21
50667 Cologne
Germany
Data we process
Website delivery and security
When you access ACMI, the systems used to deliver and protect the website may process connection and usage data such as your IP address, requested URL, date and time, referrer, browser, device information, and technical error data. This is necessary to deliver the service, maintain availability, and detect misuse or security incidents.
Anonymous visitor cookie
ACMI uses one essential, first-party visitor cookie named __Host-acmi_visitorin production. It contains a random credential that lets the service associate assessments with your browser and restore the assessments available on that device. The raw credential remains in your browser; only a cryptographic hash is stored in the database. The cookie is HttpOnly, Secure, SameSite=Lax, and expires after one year.
Assessment and result data
When you use ACMI, we store an assessment identifier, assessment status and timestamps, your selected answers, the content version used, and the calculated overall and pillar results. You can complete the assessment and view your result without providing your name or email address.
Optional export and profile data
If you choose to take your result away, we process your email address and may process optional information you submit, such as company name, role, country, vertical, company size, commerce platform, sales channels, revenue band, ACA membership status, and a short description of what your company sells. We also record the chosen delivery method and whether you consented to follow-up contact, including the time of that consent.
Product events
ACMI records server-side product events to understand whether the assessment works as intended—for example, that an assessment was started, an answer was saved, or a result was completed. These events use anonymous or assessment-scoped identifiers. Raw email addresses, company names, and free-text profile fields are excluded. After an export, some events may use a keyed, pseudonymous identifier derived from the email address; the email itself is not sent as an analytics identifier.
Messages you send us
If you contact us by email, we process your contact details, the contents of your message, and related correspondence so that we can answer your request.
Purposes and legal bases
- Providing ACMI and its recovery features: Art. 6(1)(b) GDPR where processing is necessary to provide the service you request, and Art. 6(1)(f) GDPR for our legitimate interest in operating a reliable, secure assessment.
- Essential visitor cookie: § 25(2) no. 2 TDDDG because it is strictly necessary to provide the assessment and device-based recovery requested by you.
- Security, diagnostics, and pseudonymous product measurement: Art. 6(1)(f) GDPR, based on our legitimate interests in protecting the service, resolving faults, and understanding whether the assessment flow functions effectively.
- Optional follow-up: Art. 6(1)(a) GDPR where you give consent. You may withdraw that consent at any time with effect for the future.
- Responding to inquiries: Art. 6(1)(b) GDPR for pre-contractual or service-related requests, or Art. 6(1)(f) GDPR for our legitimate interest in responding to other inquiries.
- Legal obligations and claims: Art. 6(1)(c) GDPR where retention or disclosure is required by law, and Art. 6(1)(f) GDPR where necessary to establish, exercise, or defend legal claims.
Recipients and transfers
Personal data is available only to the teams and service providers that need it for the purposes described above. These may include providers for website hosting, databases, infrastructure, monitoring, security, and professional advice. Processors act under data processing agreements in accordance with Art. 28 GDPR.
Amplitude product analytics
If the optional server-side analytics forwarder is enabled, pseudonymous product events may be sent to Amplitude, Inc., 201 Third Street, Suite 200, San Francisco, CA 94103, USA, using its EU endpoint. ACMI does not load the Amplitude browser SDK and does not set Amplitude cookies. Transfers outside the EU/EEA are protected using an adequacy decision where available, including the EU–US Data Privacy Framework, or the European Commission's Standard Contractual Clauses and supplementary safeguards as required.
Storage and deletion
We retain personal data only for as long as it is needed for the purpose for which it was collected, to preserve the result and recovery functions you request, or to meet legal retention and documentation duties. The anonymous visitor cookie expires after one year. Technical logs are kept only for the period required for security and operations. Contact and optional profile data is deleted when it is no longer required for the request, consented follow-up, or applicable legal obligations. Data may be retained longer where necessary for the establishment, exercise, or defence of legal claims.
Your rights
Subject to the conditions of the GDPR, you have the right to:
- request access to your personal data under Art. 15 GDPR;
- request rectification of inaccurate data under Art. 16 GDPR;
- request erasure under Art. 17 GDPR;
- request restriction of processing under Art. 18 GDPR;
- receive data you provided in a portable format under Art. 20 GDPR;
- object to processing based on legitimate interests under Art. 21 GDPR; and
- withdraw consent at any time with effect for the future.
Right to object
Where processing is based on Art. 6(1)(f) GDPR, you may object at any time on grounds relating to your particular situation. If personal data is processed for direct marketing, you may object at any time without giving reasons.
Right to complain
You also have the right to lodge a complaint with a data protection supervisory authority. The supervisory authority responsible for shopware AG is:
Landesbeauftragte für Datenschutz und Informationsfreiheit Nordrhein-WestfalenKavalleriestraße 2–4
40213 Düsseldorf
Germany
Data security
We use appropriate technical and organisational measures designed to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure, or access. Measures include encrypted transport, restricted access, pseudonymisation where appropriate, security monitoring, and procedures for handling incidents.
Questions and updates
For questions about this policy or to exercise your rights, contactinfo@shopware.com. General questions about the Alliance or ACMI can be sent toinfo@agentic-commerce.org.
We may update this policy when the service, legal requirements, or our processing activities change. The effective date above identifies the version currently published.
Organizational and controller details are based on the Agentic Commerce Alliance'ssource privacy policy.