Legal & Trust
GDPR Compliance Review
A transparency-focused readiness review and gap report.
⚠️ Requires legal review before production release.
This document is a GDPR readiness review written for transparency. It is not legal advice.
GDPR Compliance Review (Readiness & Gaps)
Last updated: 2026-07-20
Important note
This is a readiness review based on the current implementation and infrastructure described in this repository. It highlights:
- what we can already explain clearly today
- what still needs confirmation or improvement
It does not replace legal advice.
Scope
This review covers the following personal data categories processed by Klugliv:
- account information used for authentication
- receipt images and receipt-related data (including OCR outputs and derived structured fields)
- shopping history and household memory derived from receipt data
- app usage analytics events (only when analytics are configured for a build)
Lawful basis (high-level)
Below is our current “working model” for why we process data under GDPR. Exact lawful basis selection should be confirmed by qualified legal counsel.
Provide and operate the service
We process account and receipt data to provide the core product experience (authentication, receipt processing, and derived insights).
Security and service reliability
We process operational data (for example, server logs) to keep the platform secure and reliable.
Analytics (when enabled)
We may collect analytics events when PostHog is configured for a build. Events are sent only after opt-in via the in-app consent flow.
Purpose limitation & data minimisation
We process receipt images and derived fields for the specific purpose of understanding receipts and creating your shopping history.
We do not sell personal receipt data.
Storage limitation (retention)
This is described in:
We treat “storage limitation” as a work in progress where backend providers influence the final retention behavior.
Integrity & confidentiality
We use:
- encryption at rest (for example, S3/KMS in the AWS migration slice)
- controlled access (least-privilege IAM and protected secrets)
- TLS for network transfer
We also aim to avoid placing keys in client apps.
Consent
Current state in this repository:
- PostHog may be configured per build, but analytics are opt-in in the mobile app
- First-launch consent prompt and Settings → Trust & privacy toggle control whether events are sent
- No analytics events are collected until the user opts in on that device
Remaining gap to confirm with counsel: whether this opt-in flow meets requirements in every jurisdiction where Klugliv operates (for example, re-prompting rules or granular categories).
Legitimate interests
We process operational and security-related data to detect and respond to problems.
Where you rely on legitimate interests, counsel should confirm balancing tests and documentation.
Cross-border transfers
Our OCR pipeline may transfer receipt images to third parties for processing.
In the AWS migration slice, AWS functions may call Google Cloud Vision for OCR. This can involve international transfers depending on provider processing and routing.
Gap to confirm: the exact transfer mechanisms used (for example, contractual safeguards) and the specific processing locations for your configurations.
Processors
Key processors referenced in this repository:
- AWS services (hosting infrastructure)
- Supabase (authentication, database, and storage in the current system)
- Google Cloud Vision (OCR)
- PostHog (analytics when configured)
See:
Records of processing
We maintain engineering and operational documentation in this repository, including this GDPR readiness review and related policies.
Gap to confirm: how your official “records of processing activities” (RoPA) will be completed and kept current.
DPIA considerations
We have not created a full DPIA document in this sprint.
Recommendation: confirm whether a DPIA is required based on:
- systematic monitoring
- processing of sensitive data (if it ever occurs)
- large-scale processing of personal data
DPO considerations
We have not documented a Data Protection Officer (DPO) role in this sprint.
Gap to confirm: whether a DPO is required based on your activities.
Recommendations (next actions)
- Confirm international transfer safeguards for OCR (Google Vision) and analytics (PostHog), and document them.
- Complete RoPA and/or DPIA if counsel determines they are required.
- Align retention with provider retention behavior and document the practical schedule in the Data Retention Policy.
- Document incident response notifications and regulatory timelines.
Some recommendations may be staged for later sprints; this list is meant to be used by engineering and legal review together.