Glood.AI is fully GDPR compliant with all required documentation, technical measures, and processes in place.
Glood.AI is committed to protecting the privacy and personal data of all users, including those in the European Union. We comply with the General Data Protection Regulation (GDPR) to ensure transparent, secure, and lawful processing of personal data while delivering AI-powered personalization for Shopify stores.
For GDPR-related inquiries or to exercise your data rights, please contact our Data Protection Officer at privacy@glood.ai
Harshul Jain, Founder and Data Protection Officer
Email: privacy@glood.aiOur DPO oversees all data protection activities and ensures GDPR compliance across our operations.
Our Legitimate Interest Assessment (LIA) has been conducted and documented, confirming that our processing is proportionate, necessary, and respects individuals’ rights.
Glood.AI servers are located in the United States. We implement appropriate safeguards for international data transfers to ensure your data remains protected according to GDPR standards.
Request a copy of your personal data we process. Contact privacy@glood.ai for data access requests, or submit through your merchant’s Shopify store. We handle these requests via Shopify’s customers/data_request webhook.
Request deletion of your personal data, subject to legal obligations. Deletion requests are automatically processed through Shopify’s customers/redact webhook.
We do not share any personally identifiable information (PII) with sub-processors
All data processing occurs within Glood.AI’s secure infrastructure. We maintain full control over your data and do not rely on third-party processors for handling personal information.
Our DPA incorporates the EU Standard Contractual Clauses (Module 2: Controller to Processor) ensuring lawful data transfers from the EEA to the United States.
Rapid notification to merchants with full breach details
Impact assessment including affected data categories and individuals
Mitigation measures to address and contain the breach
Cooperation with merchants for regulatory notifications
Documentation of all breach facts and remediation actions
As outlined in our DPA, merchants (as Data Controllers) are responsible for notifying supervisory authorities within 72 hours and affected individuals when required under GDPR.
We do not knowingly collect or process personal data from individuals under 16 years of age. Our services are designed for adult shoppers, and we rely on merchants to ensure age-appropriate access to their stores.
We may update our GDPR compliance measures as regulations evolve or our services change. Any significant changes will be communicated to merchants through their registered email addresses.
EU residents have the right to lodge a complaint with their local data protection supervisory authority if they believe their rights under GDPR have been violated. You can find your local authority at https://edpb.europa.eu/about-edpb/board/members_en
✅ DPA with Standard Contractual Clauses
✅ Legitimate Interest Assessment (LIA)
✅ Records of Processing Activities (RoPA)
✅ Data Protection Impact Assessment (DPIA)