Safora — Privacy Policy

Effective date: [fill at launch]

Draft. Working draft, pending Romanian / EU data protection legal review (specifically the GDPR data-flow section and the AI sub-processor disclosure).

1. Who we are

Safora is a Shopify application operated by [SRL legal name once formed] ("we", "us"). We are based in Romania and act as a data controller for the limited data described below, and as a data processor for product data we read on your instructions through the Shopify Admin API.

For questions, e-mail safora@tandor.eu.

2. What data we process

a) Data we collect when you install the app

We never receive the store owner's password, payment method, or banking information.

b) Data we read from your store

Through the Shopify Admin API, Safora reads:

Safora does not read or request customer data, order information, or payment information. The Shopify scopes Safora requests reflect this: write_products only.

c) Data we send to third-party AI providers

When you use the AI auto-fill feature, the following is sent to Anthropic, PBC:

Personal data is never sent to the AI. See Anthropic's policies at anthropic.com/legal/privacy.

d) Data we write to your store

When you save GPSR fields, Safora writes them as product metafields in your store, under the gpsr namespace. This data is yours and lives in your Shopify store — we do not maintain a separate copy.

3. Legal basis for processing (GDPR)

We do not process special-category personal data and do not engage in automated decision-making with legal effect on data subjects.

4. Sub-processors

Sub-processorPurposeLocation
ShopifyHosting our API session, billingCanada / Ireland
AnthropicAI auto-fillUnited States
Fly.ioApp backend hostingFrankfurt, EU

5. International transfers

Anthropic is based in the United States. Product title + description data sent to Anthropic is transferred under the EU Standard Contractual Clauses incorporated into our sub-processor agreement.

6. Data retention

DataRetention
Shop session recordUntil uninstall, then deleted within 48h
GPSR metafieldsStored in your Shopify store; we keep no separate copy
AI request logsUp to 30 days for debugging, then purged
Billing recordsAs required by Shopify and Romanian tax law (typically 10 years)

7. Your rights (GDPR)

You can:

To exercise these rights, e-mail safora@tandor.eu. We respond within 30 days.

8. Security

For security incidents, contact safora@tandor.eu.

9. Children's data

Safora is a B2B tool. We do not knowingly collect data from anyone under 16.

10. GDPR webhooks (Shopify mandatory)

11. Changes

We may update this Privacy Policy. Material changes will be announced with 30 days' notice.

12. Contact

[Legal entity once SRL formed]
E-mail: safora@tandor.eu
Romanian DPA: dataprotection.ro