Mora Boost ApS · Legal

Privacy Policy

Last updated: 11 August 2026 · Effective immediately upon installation of Aveus AI

This Privacy Policy explains how Mora Boost ApS ("we", "us", "our") collects, uses, and protects personal data in connection with the Shopify application Aveus AI (the "Service"). It is provided in compliance with the General Data Protection Regulation (GDPR, Regulation EU 2016/679), Art. 13, and the EU Data Act (Regulation EU 2023/2854).

1. Data Controller

Legal nameMora Boost ApS
CVR number46 17 19 77
Registered addressRantzausgade 11, 2. 6., 2200 København N, Denmark
JurisdictionEuropean Union (Denmark — EU Member State)
Contact emailprivacy@aveus.ai
Supervisory authorityDatatilsynet (Danish Data Protection Agency) — datatilsynet.dk

2. What Data We Collect and Why

Aveus AI is a B2B RegTech platform serving Shopify merchants. We collect the minimum data necessary to provide compliance auditing services (GDPR Art. 5.1.c — data minimisation). We do not collect, store, or process Personally Identifiable Information (PII) from your end customers (consumers).

DataPurposeLegal Basis (GDPR Art. 6)
Shopify store domain (shop_domain)Tenant identification, RLS isolation, audit scopingArt. 6.1.b — Contract performance
Shopify Offline Access Token (encrypted AES-256-GCM)Authenticate API calls to your Shopify Admin GraphQL API to scan scripts and pixelsArt. 6.1.b — Contract performance
Script and pixel metadata (name, src URL, provider domain)EU AI Act compliance classification and risk scoringArt. 6.1.b — Contract performance
Compliance audit results (risk level, violations, legal justification)Stored in your compliance ledger as evidence of due diligenceArt. 6.1.b — Contract / Art. 6.1.f — Legitimate interests
GDPR request queue entries (shop_domain, customer_id from Shopify webhook, status)Processing Shopify-mandated privacy webhook events (customers/redact, customers/data_request, shop/redact)Art. 6.1.c — Legal obligation
Compliance ledger entries (operation, before/after snapshot, timestamp)Immutable record-keeping required under EU AI Act Art. 12Art. 6.1.c — Legal obligation
Audit log entries (action, timestamp, performed_by)Security and operational traceability of actions taken on your storeArt. 6.1.f — Legitimate interests
AI cost telemetry (store domain, AI route, model, token counts, estimated cost, and the identifier of the few items that consumed the most tokens — a theme file path such as assets/custom.js)Controlling our AI spend, detecting abuse and denial-of-wallet attacks, and diagnosing cost anomalies. We store counters and item identifiers only — never product descriptions, customer data, or any content submitted to the model.Art. 6.1.f — Legitimate interests

3. Our Role Under GDPR

With respect to your end consumers' data, Mora Boost ApS acts as a Data Processorunder GDPR Art. 28. We process GDPR webhook requests on your behalf as instructed by Shopify's mandatory webhook system. You remain the Data Controller for your customers.

With respect to your merchant data (store domain, access tokens, audit records), Mora Boost ApS acts as an independent Data Controller.

4. Data Retention

Each category below is deleted automatically once its retention period expires. Periods are upper limits, not minimums: we do not keep data beyond the purpose that justifies it (GDPR Art. 5.1.e — storage limitation).

Data CategoryRetention PeriodBasis
AI inventory (script audit results)Until app uninstallation or explicit deletion requestArt. 6.1.b — Contract
Compliance ledger (immutable audit trail)1095 days (3 years) from the entry date, then automatically deletedEU AI Act automated log-keeping (6-month floor) extended to the Danish 3-year limitation period for contractual claims — Art. 17.3.e GDPR (defence of legal claims)
Audit logs (security and operational events)730 daysArt. 6.1.f — Legitimate interest (security monitoring)
AI cost telemetry (route, model, token counts, estimated cost)365 daysArt. 6.1.f — Legitimate interest (cost control, abuse prevention)
GDPR request queue (data_portability_requests)90 days after completion (Art. 12 GDPR — 30-day processing window + buffer)Art. 6.1.c — Legal obligation
Operational error events (pseudonymised, hashed tenant)90 daysArt. 6.1.f — Legitimate interest
AI spend ledger (degraded-mode budget counters)90 daysArt. 6.1.f — Legitimate interest
Scan performance telemetry (one row per scan run: duration and result counters)90 daysArt. 6.1.f — Legitimate interest (service reliability)
Synthetic media flags, detected vendorsUntil app uninstallation or explicit deletion requestArt. 6.1.b — Contract
Compliance certificatesUntil a verified erasure request. Certificates deliberately survive uninstallation so that an already-issued QR code keeps resolving on our public /verify page.Art. 6.1.b — Contract / Art. 6.1.f — Legitimate interests
Operational notifications and storefront scan history90 days (these are not removed on uninstallation — only by a verified erasure request or by this retention period)Art. 6.1.f — Legitimate interests
Shopify access token (encrypted)Until app uninstallation or token revocationArt. 6.1.b — Contract

5. Data Recipients and International Transfers

Your data is processed by the following sub-processors:

Sub-processorPurposeLocation
Supabase Inc. (supabase.com)PostgreSQL database hosting (encrypted at rest)EU — AWS eu-central-1 (Frankfurt)
Vercel Inc. (vercel.com)Application hosting and serverless runtimeEU — Frankfurt (fra1). Edge routing and rate limiting execute at the Vercel edge location nearest the visitor.
Google Cloud EMEA Limited (Ireland) — Vertex AIAI classification of store scripts, pixels, theme code, product copy and public vendor documentationEU — Vertex AI "eu" multi-region (ML processing stays in the EU)
Upstash, Inc.Redis: rate limiting, AI spend budget and webhook idempotency (store domain, hashed IP — no end-customer data)EU region
Google Ireland Limited (Google Workspace / Gmail)Operational error alerting to our engineering mailbox (error message, stack trace, request path)EU/US — Google DPA and SCCs

AI classification runs on Google Cloud Vertex AI, pinned to the EU multi-region endpoint and restricted to generally available models, so that the ML processing of the content submitted for analysis takes place within the European Union. We authenticate with short-lived credentials issued through Workload Identity Federation — no long-lived Google Cloud service-account keyexists in our runtime. Processing is governed by the Google Cloud Data Processing Addendum (GDPR Art. 28). We do not send your end customers' personal data to the model: what is analysed is store code, configuration, product copy and publicly available vendor documentation.

Google Cloud EMEA Limited may rely on Google LLC (USA) and other Google affiliates as its own sub-processors for limited support, engineering access and abuse monitoring. Likewise, Supabase, Vercel and Upstash are US-incorporated companies whose EU infrastructure may be supported by personnel outside the EEA. Any such residual access is covered by the Standard Contractual Clausespursuant to GDPR Art. 46.2.c, incorporated into each provider's Data Processing Addendum. No personal data is transferred outside the EEA without these safeguards.

6. Your Rights as a Data Subject

Under GDPR Chapter III, you have the following rights regarding your merchant data:

  • Right of access (Art. 15)Request a copy of the data we hold about your Shopify store.
  • Right to rectification (Art. 16)Request correction of inaccurate data.
  • Right to erasure (Art. 17)Request deletion of your data. A verified erasure request purges your AI inventory, compliance ledger, audit logs, sessions, detected vendors, synthetic media flags, certificates, AI cost telemetry, spend counters, scan performance telemetry, operational notifications, storefront scan history and pseudonymised error records. Uninstalling the app automatically purges your AI inventory, synthetic media flags, detected vendors and session data; the remaining categories are removed by a verified erasure request or when their retention period expires.
  • Right to data portability (Art. 20)Request your compliance data in machine-readable format.
  • Right to restrict processing (Art. 18)Request that we limit how we use your data in certain circumstances.
  • Right to object (Art. 21)Object to processing based on legitimate interests.

To exercise any of these rights, contact us at privacy@aveus.ai. We will respond within 30 days (GDPR Art. 12).

7. Right to Lodge a Complaint

You have the right to lodge a complaint with the competent supervisory authority:

AuthorityDatatilsynet (Danish Data Protection Agency)
Websitedatatilsynet.dk
AddressCarl Jacobsens Vej 35, 2500 Valby, Denmark
Phone+45 33 19 32 00

8. Security Measures

We implement technical and organisational measures to protect your data including: AES-256-GCM encryption of access tokens at rest, Row Level Security (RLS) for tenant isolation, HMAC signature verification of all Shopify webhooks, TLS 1.3 in transit, immutable audit ledger, and regular security reviews against OWASP Top 10.

9. Changes to This Policy

We may update this Privacy Policy. We will notify you by updating the "Last updated" date at the top of this page. Continued use of the Service after changes constitutes acceptance. Material changes will be communicated via the Shopify admin notification system.