GDPR Compliance

We take your privacy rights seriously

ArmoFraud is fully compliant with the General Data Protection Regulation (GDPR) and respects the privacy rights of all users in the European Economic Area (EEA) and beyond.

Your Rights Under GDPR

βœ… Right to Access

You have the right to request copies of your personal data. We will provide you with a copy of your data in a structured, commonly used, and machine-readable format.

✏️ Right to Rectification

You have the right to request correction of any inaccurate or incomplete personal data we hold about you.

πŸ—‘οΈ Right to Erasure (Right to be Forgotten)

You have the right to request deletion of your personal data. When you uninstall ArmoFraud, all your data is automatically deleted within 48 hours.

⏸️ Right to Restrict Processing

You have the right to request that we limit the way we use your personal data.

πŸ“¦ Right to Data Portability

You have the right to receive your personal data in a portable format and transfer it to another service provider.

🚫 Right to Object

You have the right to object to our processing of your personal data for specific purposes.

How We Process Your Data

Data Controller vs Data Processor

You (the merchant) are the data controller, and ArmoFraud acts as the data processor. We only process data according to your instructions and for the purposes of providing fraud detection services.

Lawful Basis for Processing

We process your data based on:

  • Contractual Necessity: To provide fraud detection services
  • Legitimate Interest: To improve our services and prevent fraud
  • Consent: Where you have provided explicit consent

GDPR Webhooks

ArmoFraud automatically handles Shopify's GDPR webhooks:

customers/data_request

We provide all customer data within 30 days of request.

customers/redact

We anonymize all customer personal data immediately upon request.

shop/redact

When you uninstall the app, all shop data is deleted within 48 hours.

Data Transfers

Our servers are located in the United States (DigitalOcean). When we transfer data from the EEA to the US, we ensure appropriate safeguards are in place, including:

  • Standard Contractual Clauses (SCCs)
  • Adequate security measures
  • Data encryption in transit and at rest

Third-Party Data Sharing

We DO NOT sell your data to third parties. We only share data with:

  • AI Service Providers: For fraud analysis (anonymized data only)
  • Cloud Infrastructure: DigitalOcean for hosting
  • Legal Requirements: When required by law

How to Exercise Your Rights

To exercise any of your GDPR rights, please contact us:

Email: privacy@armologic.com

Data Protection Officer: dpo@armologic.com

Response Time: We will respond within 30 days

Supervisory Authority

If you are not satisfied with our response, you have the right to lodge a complaint with your local data protection supervisory authority.

Last Updated: February 1, 2026
Armologic Ltd. - GDPR Compliant