Last updated: 1 September 2026
This Data Processing Agreement (DPA) forms part of the Terms of Service and sets out how Angaba processes personal data on your behalf under Art. 28 GDPR. It applies whenever you upload supplier documents or use the app on your shop. No signature is required — installing the app accepts it.
For personal data contained in your product data and in the supplier documents you upload (typically business contact data of supplier staff and signatories), you are the controller and we are the processor. For app account data (shop, plan, audit log) we are the controller — see the privacy policy.
Processing is limited to operating Angaba: reading and writing product and disclosure data through Shopify's APIs, storing and analyzing uploaded documents to extract product-safety data, and maintaining the audit log. The app's documented functionality is your complete instruction set; we process nothing beyond it.
Access to production data is restricted to the operator, secured with MFA. Data is encrypted in transit (TLS) and at rest (AWS-managed encryption). Documents are stored in a private bucket namespaced per shop.
You authorize the sub-processors listed at https://angaba.gigliotti.software/subprocessors/. We will update that page at least 14 days before adding or replacing one; continued use after the notice period constitutes approval. If you object, your remedy is to uninstall the app.
We assist you with data-subject requests and notify you without undue delay of any personal-data breach affecting your data.
On uninstall, sessions are deleted immediately; documents and app records within 30 days; shop-redaction requests from Shopify are honored on receipt. Disclosure data written to your shop remains under your control in your shop.
We provide the information reasonably necessary to demonstrate compliance with this DPA on written request.