GDPR Compliance
Last updated: July 18, 2026
1. Overview
SHIJO.AI can be used by anyone in the world, including individuals and businesses in the European Economic Area, the United Kingdom, and Switzerland. This page summarizes how we approach the EU General Data Protection Regulation (GDPR) and related laws. It supplements, and does not replace, our full Privacy Policy.
2. Who We Are
SHIRO Technologies LLC, operating SHIJO.AI, is the data controller for the personal information described in our Privacy Policy. We are based in the United States; see Section 6 of the Privacy Policy for how international transfers are handled.
3. Legal Bases for Processing
We process personal data on the bases of contract performance (to provide the Service you signed up for), legitimate interests (such as securing the Service and preventing abuse), and consent where applicable (such as certain analytics or marketing). See Section 10 of the Privacy Policy.
4. Your Rights
Under the GDPR, you have the right to access, correct, delete, or receive a portable copy of your personal data, and to object to or restrict certain processing. You also have the right to lodge a complaint with your local data protection supervisory authority.
Self-service: you can export a complete copy of your account data or permanently delete your account at any time from Dashboard → Settings → Data & Privacy — no request or waiting period required. For anything else, contact us at legal@shijo.ai.
5. Sub-Processors
We share data with a limited set of service providers, each bound by its own privacy policy and, where applicable, a data processing agreement:
- Stripe — payment processing and billing.
- Anthropic — AI model infrastructure powering platform features.
- Resend — transactional email delivery.
- Vercel — application hosting and infrastructure.
- Neon — database hosting.
- Google Analytics — aggregate website usage analytics.
6. Data Retention
We retain your account data for as long as your account is active. Upon account deletion, we remove your personal data within 30 days, except where retention is required by law or for legitimate business purposes. See Section 9 of the Privacy Policy.
7. Security Incident Notification
If we become aware of a security incident affecting your personal information that requires notification under applicable law, we will notify affected users and relevant authorities without unreasonable delay. See our Security page for more.
8. Questions
For any question about our GDPR compliance or to exercise a privacy right not covered by our self-service tools, contact us at legal@shijo.ai.