Privacy Policy

Effective date: September 1, 2026

Prisma Ltd. (“SoMerch,” “we,” “us,” or “our”) respects your privacy and is committed to protecting personal data.

This Privacy Policy explains how we collect, use, disclose, store, and protect information when you use:

  • the SoMerch website at somerch.co and its related pages;
  • the SoMerch platform and applications;
  • forms, quote-request and support services;
  • the SoMerch ChatGPT App;
  • the SoMerch Model Context Protocol (“MCP”) server and interactive components;
  • the SoMerch integration for monday.com;
  • other integrations, tools, and services operated by SoMerch; and
  • our corporate merchandise, production, warehousing, fulfilment, and delivery services.

The SoMerch website, platform, applications, and services are intended primarily for business users and are operated in a business-to-business context.

1. Who We Are

SoMerch is owned and operated by:

Prisma Ltd.
A company registered in the Republic of Bulgaria

Registered office:
23A Dimitar Konstantinov Street
Pleven, Bulgaria

Principal operational office and correspondence address:
32 Vranya Street
Banishora, 1233 Sofia
Bulgaria

Privacy and support contact: [email protected]

For the purposes of applicable data protection laws, including Regulation (EU) 2016/679, the General Data Protection Regulation (“GDPR”), Prisma Ltd. is the controller of the personal data described in this Privacy Policy, unless otherwise stated.

2. Scope of This Privacy Policy

This Privacy Policy applies when you:

  • visit or interact with the SoMerch website;
  • create or use a SoMerch platform account;
  • use a SoMerch mobile, desktop, or web application;
  • contact us or request information;
  • request a quote, proposal, sample, or product recommendation;
  • submit a corporate merchandise project;
  • place or manage an order;
  • use our warehousing, fulfilment, or delivery services;
  • use the SoMerch ChatGPT App or another authorized SoMerch integration;
  • interact with the SoMerch MCP server or an interactive SoMerch component;
  • connect or use the SoMerch integration for monday.com;
  • configure or execute a monday.com workflow that uses SoMerch;
  • receive products as part of an order placed by your employer or another business customer;
  • subscribe to marketing communications; or
  • otherwise communicate or do business with us.

This Privacy Policy does not govern the independent processing activities of third-party platforms, websites, or services, including OpenAI, ChatGPT, and monday.com. Those providers process information under their own terms and privacy policies.

3. Categories of Data We Collect

The information we collect depends on how you interact with SoMerch.

3.1 Business and contact information

We may collect:

  • first and last name;
  • company name;
  • job title or professional role;
  • business email address;
  • business telephone number;
  • country and preferred language;
  • business address;
  • billing address;
  • VAT or tax identification details;
  • information about your relationship with the company you represent; and
  • communication preferences.

3.2 Inquiry, quote, and project information

When you contact us or request a quote, we may collect:

  • project type and use case;
  • required products or product categories;
  • estimated quantities;
  • budget or budget range;
  • preferred styles, colors, and materials;
  • sustainability preferences;
  • destination countries;
  • requested production or delivery deadline;
  • branding and printing requirements;
  • packaging, warehousing, and fulfilment requirements;
  • project notes and instructions;
  • information about how you heard about SoMerch;
  • selected products or project plans; and
  • other information you voluntarily provide about the project.

3.3 Files and brand assets

Where relevant to your request or order, we may collect files such as:

  • company logos;
  • brand guidelines;
  • artwork;
  • images;
  • product references;
  • spreadsheets;
  • recipient or address files;
  • mockups;
  • print-ready files; and
  • other project documentation.

You should provide only files that you are authorized to use and share.

3.4 Platform and account data

If you use the SoMerch platform, applications, or integrations, we may collect:

  • account name and business contact details;
  • account role and permissions;
  • company or workspace association;
  • login and authentication records;
  • platform preferences;
  • product selections;
  • projects, quotes, orders, and stock records;
  • approval and activity records;
  • warehouse and fulfilment instructions;
  • support communications;
  • integration configuration information; and
  • application configuration information.

We do not ask users to provide passwords, authentication codes, or API credentials through the SoMerch ChatGPT App or through monday.com workflow fields.

3.5 Order, billing, and transaction data

Where you proceed with an order or paid service, we may process:

  • quote and order details;
  • purchase orders;
  • billing and invoicing information;
  • VAT information;
  • payment status;
  • transaction references;
  • credit notes and refund records;
  • order approvals;
  • production records;
  • warehouse records;
  • shipment records; and
  • communications relating to the order.

SoMerch does not intentionally collect complete payment-card details through the ChatGPT App. Where payment services are offered, card information may be processed directly by an authorized payment provider under its own privacy and security terms.

3.6 Recipient and delivery information

Where a confirmed project requires delivery to employees, customers, offices, event locations, or other recipients, we may process:

  • recipient name;
  • company or department;
  • delivery address;
  • business or delivery telephone number;
  • email address where required for delivery notifications;
  • clothing size or product variant;
  • selected gift or product;
  • shipment tracking information;
  • delivery status; and
  • information required to resolve returns, failed deliveries, or delivery claims.

Recipient names and home delivery addresses are not required for general product search or initial project planning through the ChatGPT App. They may be collected later through the SoMerch platform, an authorized integration such as monday.com, or another secure process when required for a confirmed fulfilment project.

If you provide personal data about another person, you are responsible for ensuring that you have an appropriate legal basis and authority to provide that information to us.

3.7 Technical and usage data

When you use our website, platform, applications, or integrations, we or our service providers may process limited technical information such as:

  • IP address;
  • browser and device type;
  • operating system;
  • language and regional settings;
  • pages or application areas visited;
  • referring source;
  • session and interaction information;
  • date and approximate time of access;
  • cookie and consent preferences;
  • application version;
  • tool, workflow, or feature used;
  • response status;
  • performance and error information;
  • workflow execution or subscription identifiers;
  • security and abuse-prevention signals; and
  • pseudonymous technical identifiers where required for operation or security.

We do not use this technical information to create sensitive profiles about users.

3.8 Marketing information

Where permitted by law, we may process:

  • marketing subscription status;
  • communication history;
  • campaign engagement;
  • event participation;
  • areas of professional interest; and
  • unsubscribe or objection records.

4. How We Collect Information

We may collect information:

4.1 Directly from you

For example, when you:

  • complete a website form;
  • contact us by email, telephone, chat, or another channel;
  • create or use a SoMerch account;
  • request a quote or product recommendation;
  • upload a file;
  • submit or approve a project;
  • place or manage an order;
  • use the SoMerch ChatGPT App;
  • connect the SoMerch integration to monday.com;
  • configure or use a workflow involving SoMerch;
  • submit a quote request through an integration;
  • contact support; or
  • subscribe to marketing communications.

4.2 From your employer or another business customer

A company may provide information about its employees, contractors, customers, event participants, or other recipients when using our production, warehousing, kitting, fulfilment, or delivery services.

4.3 Through ChatGPT, monday.com, or another authorized integration

When you use the SoMerch ChatGPT App, ChatGPT may transmit task-specific information to the SoMerch MCP tools in order to perform the action you requested.

SoMerch receives only the information transmitted to the relevant tool or interactive component. We do not request, retrieve, reconstruct, or intentionally collect your complete ChatGPT conversation history.

When you use the SoMerch integration for monday.com, monday.com may transmit information selected by you or configured in a workflow to SoMerch in order to perform the requested workflow action. This may include recipient information, selected orders and products, quantities, sizes, workflow values, and technical integration metadata.

SoMerch does not independently access or copy the full contents of your monday.com account or boards. The integration is designed to process the information required for the workflow features that you configure and use.

4.4 Automatically

Certain technical information may be collected automatically through:

  • essential cookies;
  • analytics technologies;
  • security tools;
  • server logs;
  • application logs; and
  • similar technologies necessary to operate and protect our services.

4.5 From service providers and business partners

We may receive information from providers assisting with:

  • platform hosting;
  • CRM and customer communication;
  • production;
  • warehousing;
  • shipping and delivery;
  • payment and invoicing;
  • analytics;
  • security; and
  • support.

5. SoMerch Integrations: ChatGPT, MCP, and monday.com

5.1 How the ChatGPT App works

The SoMerch ChatGPT App allows users to perform actions such as:

  • searching the SoMerch product catalog;
  • retrieving product details;
  • comparing corporate merchandise products;
  • creating preliminary onboarding, event, gifting, or other merchandise plans;
  • assessing a project against quantities, budget, destination countries, preferences, and deadlines;
  • viewing interactive project-plan components; and
  • submitting a quote request to SoMerch after explicit confirmation.

The App communicates with SoMerch through a remote MCP server operated for SoMerch.

5.2 Information processed for product search and planning

Depending on your request, the App may process:

  • search terms;
  • product categories;
  • product or collection preferences;
  • quantity;
  • estimated budget;
  • destination countries;
  • requested deadline;
  • use case;
  • preferred or excluded categories;
  • preferred colors or styles;
  • sustainability preferences;
  • whether apparel should be included or excluded; and
  • limited project notes that you choose to provide.

This information is used to provide product results or prepare a preliminary merchandise plan.

5.3 Quote requests

Searching products or generating a plan does not automatically create a quote request, order, contract, or payment obligation.

A quote request is submitted only when you:

  • select a project option;
  • provide the required business contact information;
  • review the information that will be submitted;
  • consent to being contacted; and
  • explicitly confirm the submission.

A quote request may include:

  • selected plan and products;
  • quantities;
  • project budget;
  • destination countries;
  • requested deadline;
  • company name;
  • contact name;
  • business email address;
  • optional business telephone number;
  • project notes;
  • submission and consent status; and
  • a quote-request reference.

Submitting a quote request does not place an order, reserve stock, guarantee pricing, guarantee delivery, or process a payment. A member of the SoMerch team may contact you to verify the requirements and prepare a formal proposal.

5.4 Information we do not intentionally collect through the ChatGPT App

The SoMerch ChatGPT App is not designed to request or collect:

  • complete ChatGPT conversation history;
  • ChatGPT or OpenAI passwords;
  • API keys;
  • authentication tokens;
  • multi-factor authentication or one-time codes;
  • complete payment-card details;
  • government identification numbers;
  • health information;
  • biometric information;
  • information about racial or ethnic origin;
  • political opinions;
  • religious or philosophical beliefs;
  • trade-union membership;
  • genetic information;
  • information about a person’s sex life or sexual orientation;
  • criminal-conviction information;
  • precise GPS coordinates;
  • employee home addresses during initial product planning; or
  • other information that is not necessary for the requested SoMerch function.

Please do not include such information in free-text fields, project notes, uploaded files, or integration fields unless it is strictly necessary for the requested service and you are authorized to provide it.

5.5 Data returned to ChatGPT

To present the requested result, the SoMerch MCP server may return information to ChatGPT such as:

  • product names and descriptions;
  • product images and links;
  • product identifiers;
  • prices or preliminary price estimates;
  • minimum quantities;
  • product attributes;
  • branding methods;
  • lead-time information;
  • project-plan options;
  • cost assumptions;
  • feasibility indicators;
  • warnings and limitations;
  • quote-request status; and
  • a user-facing quote-request reference.

We aim to return only information relevant to the action requested. We do not intentionally return internal logs, access tokens, private database records, internal account identifiers, or unnecessary diagnostic information.

5.6 How the monday.com integration works

The SoMerch integration for monday.com allows authorized business users to connect a SoMerch account to monday.com and use SoMerch functionality within monday.com workflows.

Depending on the workflow configured by the user, the integration may allow users to:

  • select an existing SoMerch order;
  • select products contained in that order;
  • specify product quantities and available sizes or variants;
  • provide recipient and delivery information from monday.com board fields;
  • create a shipment in SoMerch;
  • return shipment identifiers and shipment status information to monday.com;
  • receive workflow events when a SoMerch shipment status changes; and
  • use shipment tracking information in subsequent monday.com workflow actions.

The integration processes data only when an authorized user connects SoMerch to monday.com or configures or executes a workflow that uses a SoMerch integration feature.

5.7 Information processed through the monday.com integration

Depending on the workflow configured by the user, monday.com may transmit information to SoMerch such as:

  • recipient name;
  • business or delivery email address;
  • delivery address;
  • city;
  • postal code;
  • country;
  • business or delivery telephone number;
  • selected SoMerch order;
  • selected products;
  • product quantities;
  • clothing sizes or product variants;
  • shipment identifiers;
  • shipment status information;
  • tracking information;
  • workflow execution identifiers;
  • webhook or workflow-subscription identifiers;
  • monday.com account, user, or workspace identifiers where technically required to operate or secure the integration; and
  • other board or workflow values that the user explicitly maps to a SoMerch workflow field.

SoMerch uses this information only as necessary to provide the requested workflow, fulfil the relevant shipment or order, synchronize shipment information, maintain workflow subscriptions, prevent duplicate execution, provide support, maintain security, and comply with applicable contractual and legal obligations.

Users configuring a monday.com workflow are responsible for ensuring that they are authorized to transmit the selected board data and recipient information to SoMerch.

5.8 Information returned to monday.com

Where necessary to complete a workflow, SoMerch may return information to monday.com such as:

  • SoMerch order identifiers;
  • available order products;
  • available product sizes or variants;
  • shipment identifiers;
  • shipment status;
  • tracking URLs or tracking information;
  • success or validation status;
  • limited error information necessary to explain a failed workflow action; and
  • other information necessary to complete the workflow configured by the user.

We aim to return only the information required for the relevant workflow. We do not intentionally expose internal logs, authentication secrets, private database records unrelated to the workflow, or unnecessary personal data to monday.com.

5.9 Authentication and credentials for monday.com

The SoMerch monday.com integration uses authorization mechanisms designed to allow users to connect their SoMerch account without entering SoMerch passwords directly into workflow fields.

monday.com may manage SoMerch OAuth credentials through its credential-management functionality. SoMerch processes OAuth access or refresh tokens only as necessary to authenticate authorized integration requests and provide the requested SoMerch functionality.

Authentication tokens are treated as confidential security information. We do not intentionally expose them to other users, include them in workflow output fields, or store them in plaintext application logs.

Technical requests received from monday.com may also include signed authentication information or technical identifiers used to verify that a request originated from the authorized monday.com application.

5.10 monday.com workflow subscriptions, disconnection, and deletion

Some SoMerch monday.com workflow features use webhook subscriptions. When a user activates such a workflow, SoMerch may store limited subscription information necessary to send relevant events back to monday.com. This may include:

  • a monday.com webhook URL;
  • a webhook or subscription identifier;
  • the associated SoMerch organization;
  • an optional order filter;
  • technical creation or update timestamps; and
  • other limited metadata required to operate the subscription.

When the workflow is deactivated or removed, SoMerch is designed to remove the corresponding active webhook subscription.

When the SoMerch monday.com integration is deauthorized, disconnected, or uninstalled, monday-derived integration data and metadata that are not otherwise required to provide a separately requested SoMerch service, fulfil an existing shipment or order, comply with law, resolve a dispute, prevent fraud, or satisfy another lawful retention requirement will be deleted within 10 days.

Information that has become part of a legitimate SoMerch customer project, confirmed order, shipment, delivery, invoice, accounting record, support matter, or other independently authorized business transaction may continue to be retained under the applicable retention periods described in this Privacy Policy.

SoMerch does not sell monday.com user data or use monday.com integration data for behavioral advertising or cross-service advertising profiles.

6. Why We Use Personal Data

We may use personal data to:

  • provide and operate the SoMerch website, platform, applications, and integrations;
  • operate the SoMerch integration for monday.com;
  • execute user-configured monday.com workflows;
  • create shipments from authorized workflow instructions;
  • maintain and process webhook subscriptions;
  • synchronize shipment status and tracking information with authorized integrations;
  • respond to inquiries;
  • search and present relevant products;
  • create preliminary merchandise plans;
  • compare products, budgets, and known project constraints;
  • provide product and project recommendations;
  • generate and display interactive project options;
  • prepare and send quotes and proposals;
  • process explicitly confirmed quote requests;
  • communicate with business contacts;
  • manage customer and supplier relationships;
  • create and administer accounts and permissions;
  • process and fulfil orders;
  • produce, customize, package, store, and ship products;
  • deliver products to authorized recipients;
  • manage inventory and warehousing;
  • process invoices, payments, refunds, and accounting records;
  • provide support;
  • maintain service reliability;
  • detect, investigate, and prevent fraud, abuse, and security incidents;
  • prevent duplicate or unauthorized submissions and workflow executions;
  • troubleshoot technical problems;
  • improve our catalog, platform, applications, and services;
  • understand website and platform usage;
  • send marketing communications where permitted;
  • establish, exercise, or defend legal claims;
  • comply with contractual, legal, tax, accounting, and regulatory obligations; and
  • protect the rights, property, and safety of SoMerch, its customers, users, and partners.

Information submitted for product search, preliminary project planning, or execution of a monday.com workflow is not used to send marketing communications unless you have separately subscribed, requested further contact, or another lawful basis applies.

7. Legal Bases for Processing

Where the GDPR applies, we rely on one or more of the following legal bases.

7.1 Steps before entering into a contract

We process information when you:

  • request information;
  • search for relevant products;
  • ask for a project plan;
  • request pricing;
  • submit a quote request;
  • request samples; or
  • ask us to prepare a proposal.

7.2 Performance of a contract

We process information where necessary to:

  • provide contracted services;
  • manage an account;
  • operate an authorized integration used to provide contracted services;
  • produce and fulfil an order;
  • manage stock;
  • deliver products;
  • provide support; or
  • perform other contractual obligations.

7.3 Legitimate interests

We may process information where necessary for legitimate business interests, including:

  • operating and improving our services and integrations;
  • managing B2B relationships;
  • responding to business communications;
  • protecting our systems;
  • preventing fraud, abuse, and duplicate workflow execution;
  • maintaining service reliability;
  • keeping limited operational records;
  • developing our products and services;
  • conducting appropriate B2B marketing; and
  • establishing or defending legal claims.

When relying on legitimate interests, we consider whether those interests are overridden by the rights and freedoms of the affected person.

7.4 Consent

We rely on consent where required, including for:

  • non-essential cookies;
  • certain analytics technologies;
  • certain marketing communications; and
  • other processing for which consent is the appropriate legal basis.

You may withdraw consent at any time. Withdrawal does not affect processing carried out before the withdrawal.

7.5 Legal obligations

We may process and retain information where required to comply with:

  • accounting requirements;
  • tax requirements;
  • regulatory obligations;
  • court orders;
  • legally valid requests; or
  • other applicable laws.

8. AI-Assisted Recommendations and Automated Processing

The SoMerch ChatGPT App may use software-assisted or AI-assisted functionality to help identify products and organize preliminary merchandise plans.

These results may depend on:

  • the information supplied by the user;
  • available product data;
  • price information;
  • quantity requirements;
  • known production timelines;
  • product tags and collections; and
  • other project criteria.

Product recommendations and project plans are preliminary and may contain assumptions or incomplete information. They are reviewed and confirmed separately where the user proceeds with a formal quote.

SoMerch does not use the ChatGPT App to make solely automated decisions that produce legal or similarly significant effects concerning individuals.

SoMerch does not use business contact details, quote-request details, uploaded brand files, monday.com workflow data, or delivery-recipient information to train its own general-purpose AI models.

We may use aggregated or appropriately de-identified information to understand which features are useful and to improve the SoMerch catalog, platform, integrations, and services.

OpenAI independently determines how information is processed within ChatGPT under OpenAI’s own terms, privacy policy, product settings, and user controls.

9. Logging, Security Monitoring, and App Analytics

We may maintain limited technical and operational logs to:

  • deliver MCP tool responses;
  • execute and troubleshoot integration workflows;
  • detect errors;
  • measure reliability and performance;
  • prevent abuse;
  • investigate security events;
  • enforce rate limits;
  • prevent duplicate quote submissions; and
  • prevent duplicate workflow actions or shipment creation.

These records may include:

  • the tool, workflow, or function used;
  • approximate date and time;
  • success or failure status;
  • request duration;
  • error category;
  • workflow execution identifiers;
  • webhook or subscription identifiers;
  • limited technical identifiers;
  • IP or network security information; and
  • abuse-prevention signals.

Our systems are intended not to store complete ChatGPT conversations, raw chat histories, or the complete contents of monday.com boards in SoMerch application logs.

We do not intentionally store OAuth access tokens, refresh tokens, passwords, API keys, or other authentication secrets in plaintext application logs.

We do not use ChatGPT App or monday.com integration activity for behavioral advertising, cross-service advertising profiles, or the sale of personal data.

The ChatGPT App and monday.com integration components do not use advertising cookies. If we introduce additional non-essential analytics within these components, we will update this Privacy Policy and implement any consent controls required by law.

10. Cookies and Website Analytics

The SoMerch website may use cookies and similar technologies for:

  • essential website functionality;
  • remembering user preferences;
  • security;
  • analytics;
  • performance measurement; and
  • marketing where permitted.

These technologies may process information such as:

  • IP-related information;
  • browser and device information;
  • pages visited;
  • approximate session duration;
  • traffic source;
  • cookie identifiers; and
  • general interaction data.

We may use providers such as Google Analytics to understand website usage and improve performance.

Where required by law, we request consent before using non-essential cookies. You may manage your preferences through our cookie controls or browser settings.

Disabling essential cookies may affect website or platform functionality.

Information collected through non-essential analytics cookies is retained according to the applicable cookie settings and provider configuration and generally for no longer than 14 months, unless a shorter period is configured or a longer period is legally required.

11. Marketing Communications

Where permitted by applicable law, we may send business users information about:

  • SoMerch services;
  • product launches;
  • platform features;
  • relevant content;
  • events;
  • offers; and
  • company updates.

You may opt out at any time by:

  • using the unsubscribe link in the communication, where available; or
  • contacting [email protected].

Submitting a quote request, connecting the monday.com integration, or executing a workflow does not automatically subscribe you to marketing communications.

We may retain limited information on a suppression list to ensure that we continue to respect an unsubscribe or objection request.

12. How We Share Personal Data

We do not sell personal data.

We may share personal data only where necessary with the following categories of recipients.

12.1 OpenAI

When you use the SoMerch ChatGPT App, information passes through ChatGPT in order to transmit tool requests and display SoMerch results.

OpenAI processes information independently under its own terms and privacy policy.

12.2 monday.com

When you connect or use the SoMerch integration for monday.com, information may pass between monday.com and SoMerch in order to authenticate the integration, configure and execute workflows, retrieve available SoMerch orders or products, create shipments, and synchronize shipment status or tracking information.

Depending on the workflow configured by the user, information transmitted through monday.com may include business contact details, recipient delivery information, product selections, quantities, sizes, shipment identifiers, shipment status, tracking information, and limited technical workflow metadata.

monday.com is an independent third-party platform and processes information under its own terms, privacy policy, product settings, and contractual arrangements with its users.

12.3 Hosting, infrastructure, and database providers

These providers support the operation, security, storage, and availability of our website, platform, applications, MCP server, integrations, and related services.

12.4 Communication, CRM, and support providers

We may use providers to:

  • manage inquiries;
  • record quote requests;
  • send transactional communications;
  • provide customer support; and
  • manage business relationships.

12.5 Analytics and security providers

These providers may assist with:

  • website analytics;
  • consent management;
  • error monitoring;
  • infrastructure security;
  • fraud prevention; and
  • service-performance monitoring.

12.6 Production and supply partners

Where required to provide a project, we may share limited project information with:

  • product suppliers;
  • printing and decoration partners;
  • packaging providers;
  • quality-control providers; and
  • other authorized production partners.

We share only the information needed for the relevant task.

12.7 Warehouse, fulfilment, and delivery providers

Where required to fulfil or deliver an order, we may share recipient and shipment information with:

  • warehouse providers;
  • fulfilment providers;
  • postal operators;
  • couriers;
  • freight providers;
  • customs agents; and
  • other logistics partners.

12.8 Payment, invoicing, and accounting providers

Where applicable, these providers may process information necessary to administer:

  • invoices;
  • payments;
  • refunds;
  • credit notes;
  • accounting; and
  • financial compliance.

12.9 Professional advisers and authorities

We may disclose information to:

  • legal advisers;
  • accountants;
  • auditors;
  • insurers;
  • courts;
  • regulators;
  • law-enforcement authorities; and
  • other public bodies where legally required.

12.10 Corporate transactions

If SoMerch or Prisma Ltd. is involved in a merger, restructuring, acquisition, financing, or transfer of business assets, relevant information may be disclosed subject to appropriate confidentiality and data-protection safeguards.

Service providers acting on our behalf are required, where applicable, to process personal data under contractual, confidentiality, security, and data-protection obligations.

13. International Data Transfers

Some service providers or recipients may process personal data outside Bulgaria or the European Economic Area.

Where personal data is transferred to a country that does not benefit from an adequacy decision, we use appropriate safeguards where required, which may include:

  • Standard Contractual Clauses approved by the European Commission;
  • contractual and technical safeguards;
  • supplementary security measures; or
  • another lawful transfer mechanism.

You may contact [email protected] for further information about the safeguards applicable to a particular transfer.

14. How Long We Keep Information

We retain personal data only for as long as necessary for the purposes described in this Privacy Policy, including legal, contractual, accounting, security, and dispute-resolution requirements.

Our general retention periods are as follows.

14.1 Product searches

Product-search requests are not retained as a permanent personal profile.

Limited technical records relating to search execution may be retained for up to 90 days for reliability, security, and abuse prevention.

14.2 Temporary merchandise plans

Where a merchandise plan must be stored to support an interactive view or subsequent quote request, it may be retained for up to 30 days from creation.

A plan may be deleted earlier if it expires, is no longer required, or deletion is requested and no legal reason requires continued retention.

14.3 Unsuccessful or incomplete quote submissions

Incomplete or failed quote-submission records may be retained for up to 30 days to diagnose errors and prevent duplicate submissions.

14.4 Inquiries and quote requests

General inquiries and quote requests that do not become an active customer relationship may be retained for up to 6 months after the last meaningful communication.

They may be retained longer where reasonably necessary to:

  • follow up on a requested project;
  • resolve a complaint;
  • prevent abuse;
  • establish or defend a legal claim; or
  • comply with legal obligations.

14.5 Customer projects and orders

Information relating to active customers, projects, quotes, approvals, orders, deliveries, and support may be retained for the duration of the business relationship and afterward for the applicable limitation and legal-retention periods.

Invoice, accounting, tax, and transaction records may be retained for up to 10 years where required by applicable law.

14.6 Delivery-recipient information

Recipient and delivery information is retained only for as long as necessary to:

  • complete delivery;
  • manage tracking;
  • process returns;
  • investigate failed delivery;
  • resolve claims; and
  • meet contractual or legal obligations.

Unless a longer period is required for a claim, contract, or legal obligation, delivery-recipient information is generally deleted or anonymized within 24 months after completion of the relevant delivery program.

14.7 Uploaded project and brand files

Files connected with an inquiry that does not become an active project may be retained for up to 6 months.

Files used for an active project or order may be retained for the duration of the customer relationship and for as long as reasonably necessary to support repeat production, resolve disputes, or comply with contractual and legal obligations.

Customers may request earlier deletion where continued retention is not required.

14.8 Support communications

Support records may be retained for up to 12 months after the issue is resolved, unless they relate to an active order, legal claim, security incident, or other matter requiring longer retention.

14.9 Security and operational logs

Application, MCP, integration, security, and error logs are generally retained for up to 90 days.

Relevant records may be retained longer when required to investigate a security incident, prevent fraud, prevent duplicate or unauthorized execution, or establish or defend a legal claim.

14.10 Marketing data

Marketing information is retained until you unsubscribe, object, withdraw consent, or the information is no longer required for the relevant marketing purpose.

We may retain a minimal suppression record after an opt-out to ensure that we do not send further marketing communications.

14.11 Backups

Deleted data may remain in restricted backup systems for up to 90 additional days before being overwritten, unless a longer period is required for security, disaster recovery, or legal reasons.

14.12 monday.com integration data

Active monday.com workflow subscription information is retained only while necessary to operate the relevant integration or workflow.

When a workflow subscription is deactivated or removed, SoMerch is designed to delete or deactivate the corresponding active subscription information.

When the SoMerch monday.com integration is deauthorized, disconnected, or uninstalled, monday-derived integration data and metadata that are not otherwise required for an independently authorized SoMerch service, confirmed order or shipment, legal obligation, fraud-prevention purpose, security investigation, dispute, or other lawful retention purpose will be deleted within 10 days.

Operational information that has become part of a confirmed SoMerch order, shipment, delivery, invoice, or other independently authorized transaction is subject instead to the applicable project, order, delivery-recipient, accounting, or legal-retention periods described above.

At the end of the applicable period, information is deleted, anonymized, or securely restricted unless continued retention is legally required.

15. Data Security

We apply reasonable technical and organizational measures designed to protect personal data against:

  • unauthorized access;
  • accidental or unlawful destruction;
  • loss;
  • alteration;
  • disclosure;
  • misuse; and
  • other unauthorized processing.

Measures may include:

  • access controls;
  • role-based permissions;
  • secure authentication;
  • OAuth-based authorization for supported integrations;
  • verification of signed integration requests;
  • encryption in transit;
  • appropriate encryption at rest;
  • logging and monitoring;
  • backup and recovery procedures;
  • data minimization;
  • provider due diligence;
  • staff confidentiality obligations;
  • incident-response procedures; and
  • regular maintenance and security updates.

No internet transmission or storage system is completely secure. We therefore cannot guarantee absolute security.

If you become aware of a suspected security issue involving SoMerch, contact [email protected] without sending passwords, access tokens, or other authentication secrets.

16. Your Rights

Where the GDPR applies, you may have the right to:

  • receive information about how your data is processed;
  • request access to personal data we hold about you;
  • request correction of inaccurate or incomplete information;
  • request deletion of personal data;
  • request restriction of processing;
  • object to processing based on legitimate interests;
  • object to direct marketing at any time;
  • request data portability where applicable;
  • withdraw consent where processing is based on consent;
  • request information about applicable international-transfer safeguards; and
  • lodge a complaint with a competent data-protection authority.

In Bulgaria, the competent supervisory authority is the Commission for Personal Data Protection.

These rights may be subject to legal conditions, exemptions, and limitations.

To exercise a right, contact [email protected]. We may need to verify your identity and relationship with the relevant company or project before completing the request.

17. App and Integration Controls and Deletion Requests

17.1 ChatGPT App controls

When using the SoMerch ChatGPT App, you may:

  • stop product planning at any time;
  • decline to submit a quote request;
  • review the information before submission;
  • correct your contact details before submission;
  • avoid including optional information;
  • request deletion of a temporary merchandise plan;
  • request deletion of a quote request where no legal basis requires continued retention;
  • object to marketing communications; and
  • stop using or remove the App through the controls available in ChatGPT.

Removing or disconnecting the App from ChatGPT does not automatically delete a quote request or other information already submitted to SoMerch.

17.2 monday.com integration controls

When using the SoMerch integration for monday.com, you may:

  • choose whether to connect a SoMerch account;
  • choose which SoMerch workflows to configure and activate;
  • choose which monday.com board values are mapped to SoMerch workflow fields;
  • deactivate or delete individual workflows;
  • disconnect or deauthorize the SoMerch account connection through the available integration controls; and
  • uninstall or remove the SoMerch monday.com integration using the controls provided by monday.com.

Deactivating a webhook-based workflow is designed to remove the corresponding active SoMerch subscription.

Disconnecting or uninstalling the monday.com integration does not automatically delete information that has already become part of a confirmed SoMerch order, shipment, delivery, invoice, support matter, or other independently authorized transaction.

monday-derived integration data and metadata that are no longer required and are not subject to another lawful retention basis will be handled in accordance with the retention provisions in Section 14.12.

17.3 Deletion requests

To request deletion, contact [email protected] and, where available, include the relevant:

  • temporary plan ID;
  • quote-request reference;
  • shipment or order reference;
  • company name;
  • business email address; or
  • other information needed to locate the record.

Do not send passwords, authentication codes, access tokens, refresh tokens, or API keys when making a request.

18. Children

The SoMerch website, platform, applications, and services are intended for business use and are not directed to children.

We do not knowingly collect personal data directly from children through the SoMerch ChatGPT App, monday.com integration, or our business services.

If you believe that a child has provided personal data to us without appropriate authorization, contact [email protected].

19. Third-Party Platforms, Websites, and Services

Our services may contain links to or integrate with third-party websites, products, delivery providers, payment providers, or other platforms.

The SoMerch ChatGPT App operates within ChatGPT, a service provided by OpenAI. Your ChatGPT account, conversation history, ChatGPT settings, and OpenAI’s independent use of information are governed by OpenAI’s own terms and privacy policy.

The SoMerch monday.com integration operates in connection with monday.com. Your monday.com account, boards, workspaces, permissions, product settings, and monday.com’s independent processing of information are governed by monday.com’s own terms, privacy policy, and contractual arrangements with its users.

SoMerch is not responsible for the privacy practices of third parties acting as independent controllers. We encourage you to review their privacy information before providing personal data or enabling an integration.

20. Changes to This Privacy Policy

We may update this Privacy Policy to reflect:

  • changes to our services;
  • new applications or integrations;
  • changes to our data practices;
  • legal or regulatory developments;
  • security requirements; or
  • changes to the providers we use.

The updated version will be published on this page with a revised effective date.

Where a change materially affects how we use personal data, we will provide additional notice where required by law.

21. Contact Us

For questions about this Privacy Policy, the SoMerch ChatGPT App, the SoMerch monday.com integration, or the way we process personal data, or to exercise your data-protection rights, contact:

Prisma Ltd.

Registered office:
23A Dimitar Konstantinov Street
Pleven, Bulgaria

Principal operational office and correspondence address:
32 Vranya Street
Banishora, 1233 Sofia
Bulgaria

Email: [email protected]