← Angaba

Privacy Policy

Last updated: 1 September 2026

Angaba manages product-safety disclosure data for Shopify merchants. This policy explains what data the app and this site process, why, and where. It is written to be read.

Controller

Santo Gigliotti, trading as Gigliotti Software
Via Vergiò 27
6932 Lugano
Switzerland
E-Mail: hello@gigliotti.software

Roles: who is responsible for what

a) Your shop's product data — you are the controller

To write disclosures, Angaba reads and writes, through Shopify's APIs, your product data: titles, categories, variants (SKU, barcode), metafields and the disclosure metaobjects it manages. This is business data about products; it normally contains no personal data of your customers. Angaba does not read customer or order data at all — its Shopify permissions don't include them.

b) Supplier documents you upload — you are the controller, we process

Documents you upload for extraction (declarations of conformity, manuals, test reports) may contain personal data of your suppliers' staff — names of signatories, business contact details. We process them solely to extract product-safety data on your instruction (Art. 28 GDPR; see the DPA). Documents are stored while the app is installed — extraction provenance links depend on them — and deleted 30 days after uninstall.

c) App account data — we are the controller

Shop domain, plan, credit counters, extraction-job records and the append-only audit log (which admin user approved which write, when). Legal basis: contract performance (Art. 6(1)(b) GDPR). Audit entries exist precisely to give you an accountable record of every published disclosure.

AI extraction

When you start an extraction job, the uploaded documents are sent to Anthropic (Claude API) for analysis. We use API terms under which inputs and outputs are not used to train models. Extraction runs only when you explicitly upload documents — there is no background processing of your shop.

This website

This site is static, sets no cookies, and runs no analytics scripts. It is served via Amazon CloudFront; CloudFront processes your IP address in standard access logs for delivery and abuse prevention (legitimate interest, Art. 6(1)(f) GDPR); we keep those logs briefly for operational purposes.

Where data lives

App data and uploaded documents: AWS eu-central-1 (Frankfurt). AI extraction: Anthropic API (see sub-processors for transfer safeguards). Disclosure data itself is written into your own Shopify shop and follows Shopify's storage.

Your rights

Access, rectification, erasure, restriction, portability, objection (Art. 15–21 GDPR) — write to hello@gigliotti.software. If you are a merchant's customer, please contact the merchant (the controller for their shop data). You may lodge a complaint with a supervisory authority.

Retention

Uninstalling the app deletes sessions immediately; app records and uploaded documents are deleted no later than 30 days after uninstall, or immediately on a shop-redaction request from Shopify. Disclosure data written to your shop is yours and stays there.