Deklarium

Privacy policy

Last updated: August 2026

This is a translation for convenience. The German version is the legally binding one.

Who processes the data

Hypez LTD, 71-75 Shelton Street, Covent Garden, London WC2H 9JQ, United Kingdom. Privacy enquiries: [email protected]

What Deklarium processes

Deklarium reads images from the merchant's shop, checks their provenance data and writes the result back into metafields of that same shop. It processes:

No customer data. Deklarium does not request any permission for customer data, does not read orders and knows nothing about buyers. What the app cannot technically see, it cannot process.

Image analysis by a third party

If Deklarium finds an AI signature in an image, an image analysis can answer what the image shows. For this a downscaled copy of the image is transferred to Anthropic PBC. This happens only for images that carry an AI signature, and only while image analysis is switched on in the settings. It can be turned off at any time; the signature check then continues without any transfer at all.

Product images can show identifiable people. Anyone who wants to rule that out switches image analysis off — the app stays usable.

Processors

RecipientPurpose and dataBasis
Anthropic PBC
San Francisco, California, USA
Image analysis: answers what an image shows
downscaled copy of the image (max. 768 px wide)only for images carrying an AI signature, and only while image analysis is switched on in the settings
EU Commission standard contractual clauses
Railway Corp.
San Francisco, California, USA
Running the application
shop domain, access token, technical logscontinuously, for as long as the app is installed
EU Commission standard contractual clauses
Supabase Inc.
Database inside the EU (Frankfurt, eu-central-1)
Database for sessions and check progress
shop domain, access token, progress of checkscontinuously, for as long as the app is installed
Processing inside the EU

Legal basis and retention

Processing takes place to perform the contract with the merchant (Art. 6(1)(b) GDPR). Access tokens and check-run data are deleted when the app is uninstalled, at the latest 48 hours afterwards (Shopify's shop/redact). Findings live in metafields inside the merchant's own shop and belong to the merchant — they stay there until the merchant removes them.

One point matters here: Shopify does not delete those metafields on uninstall, and Deklarium cannot delete them afterwards either, because its access is revoked at that moment. Anyone who wants to be rid of all findings therefore removes them before uninstalling: in the app under Settings, at the bottom, “Remove all findings”. That clears the classifications on every product, the file list on the shop and the badge list that drives the label in the storefront.

Rights of data subjects

Access, rectification, erasure, restriction, data portability and objection under Art. 15 to 21 GDPR, as well as the right to lodge a complaint with a supervisory authority. Enquiries to [email protected].