Privacy Policy

Last updated: July 2026 · Effective for all merchants in the European Economic Area (EEA), UK, and worldwide

This Privacy Policy explains how Ainnur, operated by YrFlow ("Ainnur", "we", "us"), processes personal data when you connect your Shopify store, and when your customers interact with agents deployed by Ainnur on your store. It is written to comply with the EU General Data Protection Regulation (GDPR) and the UK GDPR.

1. Roles: Controller and Processor

For data about you (the merchant) — your account, billing, and login — Ainnur acts as Data Controller.

For data about your customers (orders, carts, chat messages, emails) — Ainnur acts as Data Processor, and you (the merchant) remain the Data Controller. You determine what data is collected via your Shopify store; Ainnur processes it only to operate the agents on your behalf and per your instructions.

A Data Processing Addendum (DPA), incorporated into our Terms of Service, governs our processor obligations under Article 28 GDPR, including confidentiality, sub-processor flow-down, and assistance with data subject requests.

2. Data We Collect

3. Legal Basis for Processing (Art. 6 GDPR)

Processing activityLegal basis
Operating agents on merchant's behalfPerformance of contract (Art. 6(1)(b))
Cart recovery / support replies to end-customersMerchant's legitimate interest, as instructed (Art. 6(1)(f))
Billing and subscriptionPerformance of contract (Art. 6(1)(b))
Security loggingLegitimate interest (Art. 6(1)(f))

4. Automated Decision-Making (Art. 22 GDPR)

Ainnur's agents make certain autonomous decisions affecting end-customers — e.g. authorizing a discount percentage, or placing a fraud hold on an order. These decisions:

5. AI Inference & Data Locality

AI inference (Qwen3, self-hosted via Ollama) runs on infrastructure we operate directly. Customer and store data is not transmitted to third-party foundation model providers as part of normal operation. A fallback provider may be used only if primary infrastructure is unavailable, under the same contractual data-handling standards described here.

6. Sub-Processors

Sub-processorPurposeLocation
Hetzner Online GmbHServer hostingGermany (EU)
ResendTransactional email deliveryUS (SCC-covered)
Dodo PaymentsSubscription billing, Merchant of RecordGlobal, PCI-DSS compliant
ShopifyStore data source (via merchant's own OAuth grant)Canada/Global

Where a sub-processor is located outside the EEA, transfers are covered by Standard Contractual Clauses (SCCs) or an equivalent adequacy mechanism. We maintain and update this list; material changes are notified to merchants in advance.

7. Data Retention

Store and customer data is retained while your account is active. On uninstalling Ainnur from Shopify, your account is deactivated and billing is cancelled immediately; underlying data is deleted or anonymized within 30 days unless a longer period is required by law. You may request earlier deletion at any time.

8. Data Subject Rights (Art. 12–23 GDPR)

You, and — through you — your end-customers, have the right to:

Requests can be made to the contact below. End-customer requests should first be routed through the merchant, who is the data controller for that data; we assist merchants in fulfilling these within statutory timeframes (30 days).

9. Data Breach Notification

In the event of a personal data breach, we will notify affected merchants without undue delay, and in any case within 72 hours of becoming aware, in line with Art. 33 GDPR, including nature of the breach, likely consequences, and mitigation steps taken.

10. Data Security

11. Cookies

We use a single essential session cookie for dashboard authentication. It is strictly necessary for the service to function and is not used for tracking or advertising, so no cookie consent banner is required under EU ePrivacy rules.

12. Children's Data

Ainnur is a business-to-business service. We do not knowingly process personal data of children, and our merchants are responsible for ensuring their own storefronts comply with applicable rules regarding minors.

13. Contact / EU Representative

Data protection inquiries, subject access requests, or breach reports: yogeshramesh.eee@gmail.com