TrueSignal
Vision TrueSignal Data TrueSignal Labs Contact
TrueGuard data processing agreement

Data processing agreement for merchants.

The terms on which TrueGuard processes personal data for you when you use the app: what we do, how we protect it, who our sub-processors are, how we tell you about a breach, and the transfer clauses that cover our location in India.

Last updated 4 October 2026

1. Parties and scope

This Data Processing Agreement ("DPA") is between the merchant that installs and uses TrueGuard: Product Safety Info (the "Merchant", the controller) and Ramakrishna Bodi, trading as TrueSignal Holdings, Flat# 501, 2-2-1137/3, New Nallakunta, Hyderabad, Telangana 500044, India ("TrueGuard", the processor). It applies to personal data that TrueGuard processes on the Merchant's behalf in providing the app (the "Services"), and forms part of the terms on which the Merchant uses the Services. It takes effect when the Merchant installs the app. A Merchant that needs a signed copy can request one at apps@truesignal.company.

Where this DPA does not cover data for which TrueGuard decides the purposes (the Merchant's staff accounts, support, security and spend records), TrueGuard is a controller and the privacy policy applies.

2. Processing details (Annex I)

  • Subject matter and duration: providing the Services for as long as the app is installed, plus the erasure period in section 9.
  • Nature and purpose: receiving supplier documents and label photos the Merchant uploads, extracting a draft manufacturer, EU responsible-person and safety-warning record with an AI model, storing the draft and the Merchant's edits and approvals, and writing approved values to the Merchant's own Shopify store.
  • Categories of data subjects: individuals named in the Merchant's supplier documents, such as supplier and manufacturer contacts and EU responsible-person contacts.
  • Categories of personal data: names, business postal addresses and business email addresses appearing in those documents, and the quoted text around them. TrueGuard does not request customer or order data and does not intentionally process special-category data.
  • Frequency of transfer: continuous, each time a document is uploaded or a record is generated.
  • Retention: until the Merchant's erasure request under section 9, or the store-erasure request Shopify sends about 48 hours after uninstall.

3. Instructions

TrueGuard processes personal data only on the Merchant's documented instructions: the Merchant's use of the app's features and this DPA are the complete instructions. TrueGuard will tell the Merchant if it believes an instruction infringes data protection law, and will not use the data for its own purposes, to build marketing profiles, or to train AI models.

4. Merchant responsibilities

The Merchant is responsible for having a lawful basis to upload the documents and for informing the individuals named in them where the law requires, for the accuracy of what it approves, and for the lawfulness of what it publishes on its storefront.

5. Confidentiality

TrueGuard ensures that people it authorises to process the data are bound by confidentiality. Currently that is the operator only.

6. Security (Annex II)

TrueGuard applies the following measures, appropriate to the risk:

  • All traffic between the Merchant's browser, Shopify, the app and the AI provider is encrypted in transit (HTTPS).
  • Access to the app requires Shopify's authentication; each request is checked against the Merchant's own shop and session, and stored data is keyed by shop.
  • Data minimisation: the app requests no customer or order scopes, and requests only the five product, file, inventory and metaobject scopes it needs.
  • The approval log is protected against edits and deletes in the database, so the audit trail cannot be changed through the app.
  • Credentials and API keys are held in the hosting provider's secret store, not in source code.
  • Database storage is managed by the hosting provider, which applies its own encryption at rest and physical-security controls.
  • A per-store spend limit prevents runaway AI use.
  • On a store-erasure request, all of the store's records are deleted in one transaction.
  • Data is not shared between merchants' stores; access to production systems is limited to the operator.

7. Sub-processors (Annex III)

The Merchant gives general authorisation for the sub-processors below. TrueGuard binds each by a written agreement with data protection terms no less protective than this DPA, and remains responsible for them.

  • Anthropic — AI extraction and customs-code suggestion; receives the uploaded document, and for customs the product title and manufacturer address.
  • Render — application hosting and the production database; no EU region selected.
  • Shopify — the platform the app runs on; stores the Merchant's files and records.
  • US International Trade Commission — public HTS search; receives the product title only, not personal data.

TrueGuard will notify the Merchant at least 14 days before adding or replacing a sub-processor that handles data from the Merchant's documents, by email to the address on the Shopify account and by updating this page. The Merchant may object on reasonable data protection grounds within that period; if the parties cannot agree, the Merchant may stop using the app and request erasure.

8. Assistance and breaches

  • Data subject requests: if an individual contacts TrueGuard about data it processes for the Merchant, TrueGuard will refer them to the Merchant and will help the Merchant respond, insofar as possible, within a reasonable time.
  • Breaches: TrueGuard will notify the Merchant without undue delay, and aims to do so within 48 hours, after becoming aware of a personal data breach affecting the Merchant's data, with the information it then has, and will help the Merchant meet its notification duties.
  • Other help: TrueGuard will give reasonable help with data protection impact assessments and prior consultations, taking into account the nature of the processing.

9. Deletion and return

On uninstall, and on the store-erasure request Shopify sends about 48 hours later, TrueGuard erases all records it holds for the Merchant's store. The Merchant may ask earlier at apps@truesignal.company. The Merchant's documents and the records the app wrote into the Merchant's own Shopify store remain in the Merchant's control and are not held by TrueGuard. Backups made by the hosting provider expire under its own schedule. TrueGuard keeps nothing after erasure unless the law requires it.

10. Audits and information

TrueGuard will give the Merchant the information needed to show compliance with this DPA, and allow reasonable audits (by the Merchant or an auditor it appoints under a confidentiality undertaking) on 30 days' notice, no more than once a year unless a breach or a regulator requires otherwise. Because the operator is a single person, the first step is a written questionnaire.

11. International transfers

TrueGuard is based in India, and its sub-processors process data outside the EU, EEA, UK and Switzerland. For transfers of personal data subject to the GDPR to TrueGuard, the parties incorporate by reference the Standard Contractual Clauses of Commission Implementing Decision (EU) 2021/914, Module Two (controller to processor), with the Merchant as data exporter and TrueGuard as data importer, and the following choices:

  • Clause 7 (docking clause): not included.
  • Clause 9(a): Option 2, general written authorisation, with the 14-day notice period in section 7.
  • Clause 11(a): the optional independent dispute-resolution wording is not included.
  • Clause 13: the supervisory authority is that of the Member State in which the Merchant is established (or, where Article 3(2) applies to the Merchant, of its representative or the Member State of the data subjects).
  • Clause 17: Option 1, the law of Ireland. Clause 18(b): the courts of Ireland.
  • Annex I is section 2 of this DPA, Annex II is section 6, and Annex III is section 7. The competent supervisory authority for Annex I.C follows Clause 13 as above.

UK: for transfers subject to the UK GDPR, the parties incorporate the ICO's International Data Transfer Addendum to the EU SCCs (version B1.0). Table 1 parties and Table 2 selected SCCs are as above; Table 3 appendix information is sections 2, 6 and 7; in Table 4 neither party may end the Addendum on a change of the ICO's approved addendum except as that Addendum itself allows. Switzerland: for transfers subject to the Swiss FADP, the SCCs apply with references to the GDPR read as references to the FADP and the Swiss Federal Data Protection and Information Commissioner as supervisory authority.

TrueGuard will transfer data onward to sub-processors only under the safeguards described in the privacy policy. If the SCCs conflict with this DPA, the SCCs prevail.

12. Liability, term and changes

Each party's liability under this DPA is subject to the limitations in the terms on which the Merchant uses the Services, except where the law or the SCCs do not allow it. This DPA lasts as long as TrueGuard processes data for the Merchant. TrueGuard may update this DPA to reflect changes in law or in the Services; a change that reduces the Merchant's protection takes effect only after 30 days' notice. The Merchant's use of the app after that is acceptance; the Merchant may uninstall instead.

© 2026 TrueSignal Holdings. Flat# 501, 2-2-1137/3, New Nallakunta, Hyderabad, Telangana 500044, India. Contact