Privacy Policy
GPSR Suite — last updated: 7 August 2026
1. Controller
Onur Cirakoglu — HEADON Kreativagentur, Am Vogelsberg 8, 97922 Lauda-Königshofen, Germany.
Email: hallo@headon.pro — Web: https://headon.pro
No Data Protection Officer has been appointed; the thresholds of Art. 37 GDPR / § 38 BDSG are not met.
2. Scope
GPSR Suite is a Shopify app that helps merchants manage the product information required by EU product safety regulation (EU) 2023/988 — manufacturer details, the EU responsible person, and safety information. This policy describes what the app processes.
It does not describe the data processing of the store the app is installed in. The merchant alone is responsible for customer data processing in their store.
3. Roles
- Towards the merchant (the store owner installing the app) we act as controller for account administration and billing.
- For the store content the app processes on the merchant's instruction — in particular product and manufacturer details — we act as a processor under Art. 28 GDPR. The merchant is the controller.
- A Data Processing Agreement (DPA) is available on request at hallo@headon.pro.
4. Data the app processes
| Data | Purpose | Legal basis | Location |
|---|---|---|---|
| Shop domain (example.myshopify.com) | Associating settings, quotas and billing with the store | Art. 6(1)(b) GDPR (contract) | Hetzner, Germany |
| Shopify access/session tokens (offline and online), expiry, granted scopes | Authenticating against the Shopify Admin API; the app cannot function without them | Art. 6(1)(b) GDPR | Hetzner, Germany |
| Staff account details supplied by Shopify with the session (ID, name, email, role) | Delivered by Shopify with the session; not analysed, not shared | Art. 6(1)(b) GDPR | Hetzner, Germany |
| Last used store language (de/en) | Rendering the app in the correct language without cookies | Art. 6(1)(f) GDPR (usable interface) | Hetzner, Germany |
| Product metadata: product ID, title, vendor, and the GPSR fields (manufacturer name/address/email, EU responsible person name/address/email, safety information) | Completeness overview, editing, bulk apply | Art. 28 GDPR on the merchant's instruction | Primarily in Shopify metafields; intermediate state and counters at Hetzner, Germany |
| Manufacturer profiles per vendor (the same GPSR fields, stored per supplier name) | Pre-filling new products of the same vendor | Art. 28 GDPR | Hetzner, Germany |
| Store scan result (counts complete/partial/missing/total, timestamps) | Dashboard status without re-counting every visit | Art. 28 GDPR | Hetzner, Germany |
| List of newly created, still incomplete products (ID, title, creation date) | Dashboard notice banner | Art. 28 GDPR | Hetzner, Germany |
| AI quota counter (shop, month YYYY-MM, extractions used) | Enforcing the monthly allowance included in the plan | Art. 6(1)(b) GDPR | Hetzner, Germany |
| Last plan Shopify confirmed for the shop (free/pro/business, timestamp) | Showing the correct plan while the lookup at Shopify temporarily fails | Art. 6(1)(b) GDPR | Hetzner, Germany |
| Supplier documents uploaded by the merchant (PDF/text) | One-off AI extraction of manufacturer details; see section 6 | Art. 28 GDPR | not stored persistently |
| Technical server logs (IP address, timestamp, path, status code) | Operational security and troubleshooting | Art. 6(1)(f) GDPR | Hetzner, Germany |
Personal data note: manufacturer details and EU responsible person details may constitute personal data where a natural person is involved (e.g. a sole trader acting as responsible person). They are processed solely for the purpose the merchant defines — and are by design intended for publication on the product page.
5. Data the app does not process
- No end-customer data. The app does not request customer data and has no access to orders, carts, checkouts or customer profiles. The only scope requested is write_products.
- No payment data. Billing runs entirely through Shopify; we never see card or bank details.
- No cookies, no tracking. The app sets no analytics or marketing cookies, embeds no ad networks and builds no user profiles. The language preference is stored server-side per shop precisely so that no cookie is needed.
- The theme block on the product page is plain Liquid markup. It loads no script, calls none of our servers and processes no data about your storefront visitors.
6. AI extraction from supplier documents
When explicitly triggered by the merchant, the app reads an uploaded document (PDF or text) and suggests manufacturer details from it.
- Recipient: Anthropic PBC, 548 Market St, PMB 90375, San Francisco, CA 94104, USA — acting as a processor via the Anthropic API.
- What is transmitted: the content of the document the merchant selected, plus the instruction to identify the GPSR-relevant fields in it. No store, customer or order data is sent.
- No training: content submitted through the Anthropic API is contractually not used by Anthropic to train models.
- Third-country transfer: processing takes place in the USA on the basis of the EU Standard Contractual Clauses together with the Anthropic DPA.
- Retention: we do not store the document persistently; it is held in memory for the duration of the request and then discarded. Anthropic states it retains API inputs and outputs only briefly for abuse monitoring.
- Review requirement: the result is a suggestion. No value is written to a metafield without the merchant explicitly confirming it.
- Opt-out: the feature is optional. If it is not used, nothing is transmitted to Anthropic. Without a configured API key it is disabled.
Further information: https://www.anthropic.com/legal/privacy and https://trust.anthropic.com
7. Hosting and other recipients
| Recipient | Purpose | Location |
|---|---|---|
| Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen | App server hosting and database | Germany (EU) |
| Shopify International Ltd., Dublin, Ireland | Platform, authentication, billing, metafield storage | EU/Canada; Shopify is itself controller for the platform |
| Anthropic PBC | only when AI extraction is used, see section 6 | USA |
No other disclosure takes place, in particular none for advertising purposes.
8. Retention
| Data | Retention |
|---|---|
| Session and access tokens | Until uninstall, then deleted without undue delay and at the latest within 48 hours (app/uninstalled webhook) |
| Manufacturer profiles, scan results, pending-product list, language preference, last confirmed plan | Until uninstall, then deleted within 48 hours at the latest |
| AI quota counter | Until the end of the month after next, at most until uninstall |
| Uploaded supplier documents | Not stored persistently; held in memory for the duration of the request only |
| GPSR values in Shopify metafields | Remain in the merchant's store — the app does not delete them on uninstall. The merchant keeps them and can remove them at any time. |
| Server logs | Written to size-limited rotating files and therefore continuously overwritten; typically only a few days remain available |
| Data covered by a shop/redact webhook | Fully deleted within 30 days of receipt |
9. Deletion and Shopify's mandatory webhooks
The app implements the privacy webhooks Shopify requires of public apps:
- customers/data_request — an end customer's access request. The app stores no end-customer data; we acknowledge receipt and report that no data is held.
- customers/redact — an end customer's erasure request. No end-customer data exists, so there is nothing to erase.
- shop/redact — sent by Shopify 48 hours after uninstall. All data stored for that shop (sessions, manufacturer profiles, scan results, pending products, quota counters, language preference, last confirmed plan) is deleted. The same deletion already runs when the app/uninstalled webhook arrives, i.e. immediately on uninstall.
Independently of this you may request deletion informally at any time at hallo@headon.pro.
10. Your rights
You have the right of access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20) and objection (Art. 21 GDPR). Contact hallo@headon.pro; we respond within one month.
You also have the right to lodge a complaint with a supervisory authority, in our case the State Commissioner for Data Protection and Freedom of Information of Baden-Württemberg (LfDI), Lautenschlagerstraße 20, 70173 Stuttgart, Germany.
11. Security
All traffic is TLS-encrypted. Database access is restricted to the application server and not publicly reachable. Only the controller has access to the production environment.
12. Changes
We update this policy when the app or the legal situation changes. Material changes are announced in the app at least 30 days in advance. The version published on this page with the date shown above is authoritative.