eTechflow LLC · Supplement SafetyOps
Supplement SafetyOps is software used by merchants who sell dietary supplements to receive, investigate and report product-safety complaints and adverse events. It is operated by eTechflow LLC.
This policy explains how we handle personal information in two different roles:
If you are a consumer who reported a problem to a brand, that brand controls your information and its own privacy policy governs. Our software helps that brand meet its legal obligations. Please contact the brand directly — see section 9.
Supplement SafetyOps is designed primarily for United States dietary-supplement brands and US FDA workflows. It is not presented as providing complete legal coverage for every country.
Where a consumer reports a product-safety concern, we may process:
Information reaches us either because the reporter submitted it, or because the merchant connected their Shopify store and we retrieved the order and customer record that the report relates to.
Solely so that a merchant can operate a lawful product-safety process: identify what was purchased and by whom; investigate the complaint; request missing information; assess seriousness; meet reporting obligations, including the duty to report serious adverse events within 15 business days; identify other consumers who may have received an affected lot; conduct safety or recall communication; and retain records as required by law.
We do not use this information for anything else. It is never used for marketing, advertising, remarketing, segmentation, profiling, scoring, sale, or training AI models. It is never shared with a merchant's marketing systems.
SafetyOps processes health-related information on behalf of merchant customers. Each merchant is responsible for identifying and documenting an applicable lawful basis under Article 6 GDPR and a separate special-category condition under Article 9 GDPR. Where required and no statutory condition applies, explicit consent under Article 9(2)(a) will be obtained. The public-health condition under Article 9(2)(i) will only be relied upon where processing is specifically authorised by applicable EU or Member State law and the required safeguards are satisfied.
Legal bases are not identical everywhere, and should not be presented as though they were.
| Jurisdiction | Basis relied on |
|---|---|
| United States | Compliance with FDA adverse-event reporting and recordkeeping requirements; performance of merchant contracts; and legitimate business purposes such as product-safety investigations. |
| EU / EEA | Contract, legitimate interests or applicable legal obligations under Article 6, plus an appropriate Article 9 condition for health data — normally explicit consent unless a specific statutory condition applies. |
| United Kingdom | Contract, legitimate interests or applicable legal obligations under UK GDPR, plus an Article 9 condition and, where required, a condition under Schedule 1 of the Data Protection Act 2018. |
| Other countries | The merchant must identify the applicable local legal basis before using SafetyOps to process health information there. |
We do not make automated decisions that produce legal or similarly significant effects.
We use AI to help safety staff work faster — reading an unstructured message and suggesting structured fields, and flagging text that may describe a serious event so that it is reviewed sooner. These are suggestions to a person, never decisions.
Every regulatory determination — whether an event is serious, whether it is reportable, whether a case may be closed — is made by a trained, authorised person, recorded with a written rationale, and attributed to a named individual. No AI output modifies a record or triggers any communication or external action on its own.
Before any AI provider is used, we assess whether data is used for model training, how long it is retained, where it is held, and what contractual controls apply. Identifying details are removed before text is sent for AI processing, and merchants can switch off external AI processing entirely for sensitive documents.
Product-safety records are retained for a minimum of six years from the date the report is received, because merchants are legally required to hold them — whether or not a report was ever submitted to a regulator. Merchants may configure longer periods.
Ordinary commerce data that is not part of a safety record — such as imported order history with no linked complaint — is kept only as long as needed for the app to function, and is deleted on schedule.
| Information | Retention |
|---|---|
| Mandatory adverse-event records | Six years from receipt of the report |
| Merchant account data after a deletion request | Ordinarily deleted within 30 days |
| Imported order data not linked to a case | 24 months rolling |
| All store data after the merchant uninstalls | Deleted as Shopify requires — see section 8 |
| Security and audit logs | 12–24 months, unless attached to a regulatory case |
| Encrypted backups | Deleted through the normal backup cycle, ordinarily within 90 days |
We will honour verified deletion requests unless the relevant information must be retained to comply with applicable legal, regulatory, safety, fraud-prevention, dispute-resolution or legal-claims requirements.
Records relating to dietary-supplement adverse-event reports may be retained for at least six years from the date the report is received where required by United States law. During a mandatory retention period, the information will be restricted to authorised compliance, safety and legal purposes and will not be used for unrelated purposes.
Once the applicable retention period expires, the information will be securely deleted or irreversibly anonymised, subject to reasonable backup-deletion cycles.
Where a request cannot be fully honoured, we separate ordinary copied data from regulated records, delete or return what can lawfully be removed, restrict access to and pseudonymise what must be retained, document the recordkeeping reason, and inform the merchant.
The six-year recordkeeping duty belongs to the merchant, not to us. Shopify instructs us to erase a store's data 48 hours after the app is uninstalled, and we act on that instruction.
So that no merchant loses records they are legally required to hold, a complete compliance archive is downloadable from their dashboard at any time throughout their subscription, they are warned before uninstalling wherever technically possible, and a secure export link is sent automatically when an uninstall is detected.
Depending on where you live, you may have the right to access your information, correct it, request deletion, restrict or object to processing, receive a portable copy, withdraw consent, and complain to a supervisory authority.
If you reported a problem to a brand, please contact that brand first — they control your information. If you contact us instead, we will pass your request to the relevant merchant and support them in responding.
For information we hold as a controller, contact us at etechflow0@gmail.com. We respond within 30 days, or within any shorter period required by applicable law.
Exercising a right never results in worse treatment.
We protect information with encryption in transit and at rest, encrypted backups, role-based access with least privilege, multi-factor authentication for privileged accounts, strict separation of production from test environments, access logging with alerting on unusual access, malware scanning, expiring download links with no public file URLs, and tested backup recovery.
Suspected vulnerabilities can be reported to etechflow0@gmail.com.
We describe our controls as Part 11-supporting. We do not claim to be Part 11 compliant, FDA approved, FDA certified or HIPAA certified — compliance depends on how software and a merchant's own procedures operate together.
Information is processed in the United States, on Oracle Cloud Infrastructure in Ashburn, Virginia. The database, files, backups and application remain in the US region where possible.
Where personal data is transferred internationally, we use an applicable lawful transfer mechanism, including European Commission Standard Contractual Clauses for transfers governed by EU GDPR, the UK International Data Transfer Addendum or International Data Transfer Agreement for transfers governed by UK GDPR, and an applicable adequacy decision where available. Where required, we also conduct transfer risk assessments and implement supplementary technical and organisational safeguards.
The app is not directed at children. Where a report concerns a child, the information is provided by an adult reporter and is handled with the same protections as other health information.
Our software is not an emergency service and does not provide medical advice, diagnosis or treatment. If you may be experiencing a medical emergency, contact emergency services or an appropriate healthcare professional.
We will post material changes on this page and notify merchant account owners. The version and date at the top of this page show the current revision.
We use the following service providers to operate Supplement SafetyOps. Each is assessed before engagement and bound by data protection terms.
| Provider | Purpose | Location |
|---|---|---|
| Oracle Cloud Infrastructure | Application hosting | United States |
| Oracle Cloud Infrastructure | Database hosting | United States |
| Oracle Cloud Object Storage | File and attachment storage | United States |
| Shopify Inc. | APIs, authentication, billing and merchant-store data | Canada / United States |
This list is kept current. We will update this page before engaging any new subprocessor, and merchants can subscribe to notifications of changes by contacting etechflow0@gmail.com.
For privacy enquiries, security or vulnerability reports, and support:
etechflow0@gmail.com
We have not appointed an EU or UK representative or a Data Protection Officer, as Supplement SafetyOps is not currently offered to, and does not monitor, individuals in the EU/EEA or the United Kingdom. We will reassess this before offering the app in those markets.