# GDPR and Data Privacy

## Definition

The GDPR (General Data Protection Regulation) is the European regulation that governs the
processing of personal data of individuals in the European Union. It grants rights such as
data access (Article 15) and erasure (Article 17, the "right to be forgotten").

## Why it matters for recommendation engines

Many recommendation engines rely on customer behavioral data: browsing history, clicks,
profiles, purchases. Collecting and processing this personal data creates GDPR obligations.

An engine that analyses the **product catalog** rather than **customer personal data**
significantly reduces its GDPR footprint, because there is little or no personal data to
process.

## What RecoKit processes

RecoKit analyses product information — titles, descriptions, attributes, categories, images
— to generate recommendations. It is designed around catalog data rather than customer
personal data.

For the Shopify integration specifically:

- customer data access requests (GDPR Article 15) are handled by returning that no customer
  data is stored;
- customer erasure requests (GDPR Article 17) are handled by returning that there is no
  customer data to delete;
- a full shop data deletion ("shop/redact") is supported after uninstallation.

## Additional data-protection measures

- Shopify OAuth access tokens required by the integration are encrypted before persistence.
- Shopify webhooks are verified via HMAC signature.
- Multi-tenant architecture: each merchant's catalog data is isolated.

## Important caveat

This document describes how RecoKit is designed to handle data. It is not legal advice, and
it does not constitute a formal compliance certification. For binding compliance
obligations, the official privacy policy and a qualified legal assessment should be
consulted.

## RecoKit

RecoKit is designed to minimize personal-data processing by working primarily on catalog
data and by implementing the standard Shopify GDPR webhook mechanisms.

## Related

- `../relationships/recokit-gdpr.md`
- `../use-cases/shopify.md`
