Mora Boost ApS · Legal
Privacy Policy
Last updated: 11 August 2026 · Effective immediately upon installation of Aveus AI
This Privacy Policy explains how Mora Boost ApS ("we", "us", "our") collects, uses, and protects personal data in connection with the Shopify application Aveus AI (the "Service"). It is provided in compliance with the General Data Protection Regulation (GDPR, Regulation EU 2016/679), Art. 13, and the EU Data Act (Regulation EU 2023/2854).
1. Data Controller
| Legal name | Mora Boost ApS |
| CVR number | 46 17 19 77 |
| Registered address | Rantzausgade 11, 2. 6., 2200 København N, Denmark |
| Jurisdiction | European Union (Denmark — EU Member State) |
| Contact email | privacy@aveus.ai |
| Supervisory authority | Datatilsynet (Danish Data Protection Agency) — datatilsynet.dk |
2. What Data We Collect and Why
Aveus AI is a B2B RegTech platform serving Shopify merchants. We collect the minimum data necessary to provide compliance auditing services (GDPR Art. 5.1.c — data minimisation). We do not collect, store, or process Personally Identifiable Information (PII) from your end customers (consumers).
| Data | Purpose | Legal Basis (GDPR Art. 6) |
|---|---|---|
| Shopify store domain (shop_domain) | Tenant identification, RLS isolation, audit scoping | Art. 6.1.b — Contract performance |
| Shopify Offline Access Token (encrypted AES-256-GCM) | Authenticate API calls to your Shopify Admin GraphQL API to scan scripts and pixels | Art. 6.1.b — Contract performance |
| Script and pixel metadata (name, src URL, provider domain) | EU AI Act compliance classification and risk scoring | Art. 6.1.b — Contract performance |
| Compliance audit results (risk level, violations, legal justification) | Stored in your compliance ledger as evidence of due diligence | Art. 6.1.b — Contract / Art. 6.1.f — Legitimate interests |
| GDPR request queue entries (shop_domain, customer_id from Shopify webhook, status) | Processing Shopify-mandated privacy webhook events (customers/redact, customers/data_request, shop/redact) | Art. 6.1.c — Legal obligation |
| Compliance ledger entries (operation, before/after snapshot, timestamp) | Immutable record-keeping required under EU AI Act Art. 12 | Art. 6.1.c — Legal obligation |
| Audit log entries (action, timestamp, performed_by) | Security and operational traceability of actions taken on your store | Art. 6.1.f — Legitimate interests |
| AI cost telemetry (store domain, AI route, model, token counts, estimated cost, and the identifier of the few items that consumed the most tokens — a theme file path such as assets/custom.js) | Controlling our AI spend, detecting abuse and denial-of-wallet attacks, and diagnosing cost anomalies. We store counters and item identifiers only — never product descriptions, customer data, or any content submitted to the model. | Art. 6.1.f — Legitimate interests |
3. Our Role Under GDPR
With respect to your end consumers' data, Mora Boost ApS acts as a Data Processorunder GDPR Art. 28. We process GDPR webhook requests on your behalf as instructed by Shopify's mandatory webhook system. You remain the Data Controller for your customers.
With respect to your merchant data (store domain, access tokens, audit records), Mora Boost ApS acts as an independent Data Controller.
4. Data Retention
Each category below is deleted automatically once its retention period expires. Periods are upper limits, not minimums: we do not keep data beyond the purpose that justifies it (GDPR Art. 5.1.e — storage limitation).
| Data Category | Retention Period | Basis |
|---|---|---|
| AI inventory (script audit results) | Until app uninstallation or explicit deletion request | Art. 6.1.b — Contract |
| Compliance ledger (immutable audit trail) | 1095 days (3 years) from the entry date, then automatically deleted | EU AI Act automated log-keeping (6-month floor) extended to the Danish 3-year limitation period for contractual claims — Art. 17.3.e GDPR (defence of legal claims) |
| Audit logs (security and operational events) | 730 days | Art. 6.1.f — Legitimate interest (security monitoring) |
| AI cost telemetry (route, model, token counts, estimated cost) | 365 days | Art. 6.1.f — Legitimate interest (cost control, abuse prevention) |
| GDPR request queue (data_portability_requests) | 90 days after completion (Art. 12 GDPR — 30-day processing window + buffer) | Art. 6.1.c — Legal obligation |
| Operational error events (pseudonymised, hashed tenant) | 90 days | Art. 6.1.f — Legitimate interest |
| AI spend ledger (degraded-mode budget counters) | 90 days | Art. 6.1.f — Legitimate interest |
| Scan performance telemetry (one row per scan run: duration and result counters) | 90 days | Art. 6.1.f — Legitimate interest (service reliability) |
| Synthetic media flags, detected vendors | Until app uninstallation or explicit deletion request | Art. 6.1.b — Contract |
| Compliance certificates | Until a verified erasure request. Certificates deliberately survive uninstallation so that an already-issued QR code keeps resolving on our public /verify page. | Art. 6.1.b — Contract / Art. 6.1.f — Legitimate interests |
| Operational notifications and storefront scan history | 90 days (these are not removed on uninstallation — only by a verified erasure request or by this retention period) | Art. 6.1.f — Legitimate interests |
| Shopify access token (encrypted) | Until app uninstallation or token revocation | Art. 6.1.b — Contract |
5. Data Recipients and International Transfers
Your data is processed by the following sub-processors:
| Sub-processor | Purpose | Location |
|---|---|---|
| Supabase Inc. (supabase.com) | PostgreSQL database hosting (encrypted at rest) | EU — AWS eu-central-1 (Frankfurt) |
| Vercel Inc. (vercel.com) | Application hosting and serverless runtime | EU — Frankfurt (fra1). Edge routing and rate limiting execute at the Vercel edge location nearest the visitor. |
| Google Cloud EMEA Limited (Ireland) — Vertex AI | AI classification of store scripts, pixels, theme code, product copy and public vendor documentation | EU — Vertex AI "eu" multi-region (ML processing stays in the EU) |
| Upstash, Inc. | Redis: rate limiting, AI spend budget and webhook idempotency (store domain, hashed IP — no end-customer data) | EU region |
| Google Ireland Limited (Google Workspace / Gmail) | Operational error alerting to our engineering mailbox (error message, stack trace, request path) | EU/US — Google DPA and SCCs |
AI classification runs on Google Cloud Vertex AI, pinned to the EU multi-region endpoint and restricted to generally available models, so that the ML processing of the content submitted for analysis takes place within the European Union. We authenticate with short-lived credentials issued through Workload Identity Federation — no long-lived Google Cloud service-account keyexists in our runtime. Processing is governed by the Google Cloud Data Processing Addendum (GDPR Art. 28). We do not send your end customers' personal data to the model: what is analysed is store code, configuration, product copy and publicly available vendor documentation.
Google Cloud EMEA Limited may rely on Google LLC (USA) and other Google affiliates as its own sub-processors for limited support, engineering access and abuse monitoring. Likewise, Supabase, Vercel and Upstash are US-incorporated companies whose EU infrastructure may be supported by personnel outside the EEA. Any such residual access is covered by the Standard Contractual Clausespursuant to GDPR Art. 46.2.c, incorporated into each provider's Data Processing Addendum. No personal data is transferred outside the EEA without these safeguards.
6. Your Rights as a Data Subject
Under GDPR Chapter III, you have the following rights regarding your merchant data:
- Right of access (Art. 15) — Request a copy of the data we hold about your Shopify store.
- Right to rectification (Art. 16) — Request correction of inaccurate data.
- Right to erasure (Art. 17) — Request deletion of your data. A verified erasure request purges your AI inventory, compliance ledger, audit logs, sessions, detected vendors, synthetic media flags, certificates, AI cost telemetry, spend counters, scan performance telemetry, operational notifications, storefront scan history and pseudonymised error records. Uninstalling the app automatically purges your AI inventory, synthetic media flags, detected vendors and session data; the remaining categories are removed by a verified erasure request or when their retention period expires.
- Right to data portability (Art. 20) — Request your compliance data in machine-readable format.
- Right to restrict processing (Art. 18) — Request that we limit how we use your data in certain circumstances.
- Right to object (Art. 21) — Object to processing based on legitimate interests.
To exercise any of these rights, contact us at privacy@aveus.ai. We will respond within 30 days (GDPR Art. 12).
7. Right to Lodge a Complaint
You have the right to lodge a complaint with the competent supervisory authority:
| Authority | Datatilsynet (Danish Data Protection Agency) |
| Website | datatilsynet.dk |
| Address | Carl Jacobsens Vej 35, 2500 Valby, Denmark |
| Phone | +45 33 19 32 00 |
8. Security Measures
We implement technical and organisational measures to protect your data including: AES-256-GCM encryption of access tokens at rest, Row Level Security (RLS) for tenant isolation, HMAC signature verification of all Shopify webhooks, TLS 1.3 in transit, immutable audit ledger, and regular security reviews against OWASP Top 10.
9. Changes to This Policy
We may update this Privacy Policy. We will notify you by updating the "Last updated" date at the top of this page. Continued use of the Service after changes constitutes acceptance. Material changes will be communicated via the Shopify admin notification system.