GPSR Suite

Privacy Policy

GPSR Suite — last updated: 7 August 2026

1. Controller

Onur Cirakoglu — HEADON Kreativagentur, Am Vogelsberg 8, 97922 Lauda-Königshofen, Germany.

Email: hallo@headon.pro — Web: https://headon.pro

No Data Protection Officer has been appointed; the thresholds of Art. 37 GDPR / § 38 BDSG are not met.

2. Scope

GPSR Suite is a Shopify app that helps merchants manage the product information required by EU product safety regulation (EU) 2023/988 — manufacturer details, the EU responsible person, and safety information. This policy describes what the app processes.

It does not describe the data processing of the store the app is installed in. The merchant alone is responsible for customer data processing in their store.

3. Roles

  • Towards the merchant (the store owner installing the app) we act as controller for account administration and billing.
  • For the store content the app processes on the merchant's instruction — in particular product and manufacturer details — we act as a processor under Art. 28 GDPR. The merchant is the controller.
  • A Data Processing Agreement (DPA) is available on request at hallo@headon.pro.

4. Data the app processes

DataPurposeLegal basisLocation
Shop domain (example.myshopify.com)Associating settings, quotas and billing with the storeArt. 6(1)(b) GDPR (contract)Hetzner, Germany
Shopify access/session tokens (offline and online), expiry, granted scopesAuthenticating against the Shopify Admin API; the app cannot function without themArt. 6(1)(b) GDPRHetzner, Germany
Staff account details supplied by Shopify with the session (ID, name, email, role)Delivered by Shopify with the session; not analysed, not sharedArt. 6(1)(b) GDPRHetzner, Germany
Last used store language (de/en)Rendering the app in the correct language without cookiesArt. 6(1)(f) GDPR (usable interface)Hetzner, Germany
Product metadata: product ID, title, vendor, and the GPSR fields (manufacturer name/address/email, EU responsible person name/address/email, safety information)Completeness overview, editing, bulk applyArt. 28 GDPR on the merchant's instructionPrimarily in Shopify metafields; intermediate state and counters at Hetzner, Germany
Manufacturer profiles per vendor (the same GPSR fields, stored per supplier name)Pre-filling new products of the same vendorArt. 28 GDPRHetzner, Germany
Store scan result (counts complete/partial/missing/total, timestamps)Dashboard status without re-counting every visitArt. 28 GDPRHetzner, Germany
List of newly created, still incomplete products (ID, title, creation date)Dashboard notice bannerArt. 28 GDPRHetzner, Germany
AI quota counter (shop, month YYYY-MM, extractions used)Enforcing the monthly allowance included in the planArt. 6(1)(b) GDPRHetzner, Germany
Last plan Shopify confirmed for the shop (free/pro/business, timestamp)Showing the correct plan while the lookup at Shopify temporarily failsArt. 6(1)(b) GDPRHetzner, Germany
Supplier documents uploaded by the merchant (PDF/text)One-off AI extraction of manufacturer details; see section 6Art. 28 GDPRnot stored persistently
Technical server logs (IP address, timestamp, path, status code)Operational security and troubleshootingArt. 6(1)(f) GDPRHetzner, Germany

Personal data note: manufacturer details and EU responsible person details may constitute personal data where a natural person is involved (e.g. a sole trader acting as responsible person). They are processed solely for the purpose the merchant defines — and are by design intended for publication on the product page.

5. Data the app does not process

  • No end-customer data. The app does not request customer data and has no access to orders, carts, checkouts or customer profiles. The only scope requested is write_products.
  • No payment data. Billing runs entirely through Shopify; we never see card or bank details.
  • No cookies, no tracking. The app sets no analytics or marketing cookies, embeds no ad networks and builds no user profiles. The language preference is stored server-side per shop precisely so that no cookie is needed.
  • The theme block on the product page is plain Liquid markup. It loads no script, calls none of our servers and processes no data about your storefront visitors.

6. AI extraction from supplier documents

When explicitly triggered by the merchant, the app reads an uploaded document (PDF or text) and suggests manufacturer details from it.

  • Recipient: Anthropic PBC, 548 Market St, PMB 90375, San Francisco, CA 94104, USA — acting as a processor via the Anthropic API.
  • What is transmitted: the content of the document the merchant selected, plus the instruction to identify the GPSR-relevant fields in it. No store, customer or order data is sent.
  • No training: content submitted through the Anthropic API is contractually not used by Anthropic to train models.
  • Third-country transfer: processing takes place in the USA on the basis of the EU Standard Contractual Clauses together with the Anthropic DPA.
  • Retention: we do not store the document persistently; it is held in memory for the duration of the request and then discarded. Anthropic states it retains API inputs and outputs only briefly for abuse monitoring.
  • Review requirement: the result is a suggestion. No value is written to a metafield without the merchant explicitly confirming it.
  • Opt-out: the feature is optional. If it is not used, nothing is transmitted to Anthropic. Without a configured API key it is disabled.

Further information: https://www.anthropic.com/legal/privacy and https://trust.anthropic.com

7. Hosting and other recipients

RecipientPurposeLocation
Hetzner Online GmbH, Industriestr. 25, 91710 GunzenhausenApp server hosting and databaseGermany (EU)
Shopify International Ltd., Dublin, IrelandPlatform, authentication, billing, metafield storageEU/Canada; Shopify is itself controller for the platform
Anthropic PBConly when AI extraction is used, see section 6USA

No other disclosure takes place, in particular none for advertising purposes.

8. Retention

DataRetention
Session and access tokensUntil uninstall, then deleted without undue delay and at the latest within 48 hours (app/uninstalled webhook)
Manufacturer profiles, scan results, pending-product list, language preference, last confirmed planUntil uninstall, then deleted within 48 hours at the latest
AI quota counterUntil the end of the month after next, at most until uninstall
Uploaded supplier documentsNot stored persistently; held in memory for the duration of the request only
GPSR values in Shopify metafieldsRemain in the merchant's store — the app does not delete them on uninstall. The merchant keeps them and can remove them at any time.
Server logsWritten to size-limited rotating files and therefore continuously overwritten; typically only a few days remain available
Data covered by a shop/redact webhookFully deleted within 30 days of receipt

9. Deletion and Shopify's mandatory webhooks

The app implements the privacy webhooks Shopify requires of public apps:

  • customers/data_request — an end customer's access request. The app stores no end-customer data; we acknowledge receipt and report that no data is held.
  • customers/redact — an end customer's erasure request. No end-customer data exists, so there is nothing to erase.
  • shop/redact — sent by Shopify 48 hours after uninstall. All data stored for that shop (sessions, manufacturer profiles, scan results, pending products, quota counters, language preference, last confirmed plan) is deleted. The same deletion already runs when the app/uninstalled webhook arrives, i.e. immediately on uninstall.

Independently of this you may request deletion informally at any time at hallo@headon.pro.

10. Your rights

You have the right of access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20) and objection (Art. 21 GDPR). Contact hallo@headon.pro; we respond within one month.

You also have the right to lodge a complaint with a supervisory authority, in our case the State Commissioner for Data Protection and Freedom of Information of Baden-Württemberg (LfDI), Lautenschlagerstraße 20, 70173 Stuttgart, Germany.

11. Security

All traffic is TLS-encrypted. Database access is restricted to the application server and not publicly reachable. Only the controller has access to the production environment.

12. Changes

We update this policy when the app or the legal situation changes. Material changes are announced in the app at least 30 days in advance. The version published on this page with the date shown above is authoritative.