Skip to main content
SDDR Spain

1. Controller and contact

SDDR Spain is operated by Genius Nutrition S.R.L., Business Logistic Center, Strada Tamasi nr. 20, Hala 6A, Buftea, Ilfov, 070000, Romania, Uniunea Europeana. Nr. reg. com: J23/4568/2015; VAT RO35355847.

For privacy questions or to exercise your rights, email privacy@obsedia.ai.

2. Data we process

  • Store domain and identifier, language, currency, and configuration status.
  • Shopify OAuth credentials and sessions required to operate the app. If Shopify provides them for a session, they can include the admin user's identifier, name, email, language, and role.
  • Identifiers, titles, SKUs, and barcodes for selected products and their variants.
  • Deposit amounts, pack units, activation status, and merchant confirmations.
  • Order and line identifiers, date, financial status, fulfillment status, cancellation, refunded quantities, and SDDR quantities and amounts required for reports and exports.

The app does not store buyer names, email addresses, phone numbers, postal addresses, or payment details.

3. Source, purpose, and basis

We receive data from the merchant and Shopify. We use it to authenticate the store, apply configured rules, maintain the subscription, protect the service, reconcile the lifecycle of SDDR lines—including refunds and cancellations—generate reports, and meet legal obligations. Processing is necessary to provide the requested service, comply with obligations, and protect legitimate security and abuse-prevention interests.

4. Providers and transfers

Shopify provides the platform, authentication, billing, and APIs. Railway provides application hosting and PostgreSQL. These providers process data under their own applicable terms and data-protection mechanisms. Current hosting may involve processing outside the European Economic Area. We do not sell data or use it for advertising.

5. Retention and deletion

We keep data while the app is installed and for the period strictly necessary to provide the service, resolve issues, and meet obligations. After uninstall, we delete access sessions. Shopify redaction requests remove the affected data; a newer installation is preserved while earlier order data is removed. Minimal hashed exclusion identifiers and deletion dates are retained solely to prevent deleted data from being imported again by delayed webhooks or reconciliation. Customer access and redaction requests are processed through Shopify compliance webhooks.

6. Security

We use HTTPS, Shopify authentication, webhook HMAC verification, limited permissions, per-store isolation, input validation, dependency scanning, and restricted production access. No system is completely infallible; incidents will be notified as required by applicable obligations.

7. Rights and complaints

Subject to applicable law, you may request access, correction, deletion, restriction, objection, or portability. You may also complain to the competent data-protection authority. To make a request, use the privacy email and identify the relevant Shopify store.