Legal

Privacy Policy

Last updated 2026-07-18 · We process the minimum personal data needed to operate the Service.

1. Controller

HazardLink (the “Controller”) is the data controller for personal data processed in the Service. Contact: [email protected]. You can also contact our internal Data Protection point of contact (DPO function) via the same address.

2. What we collect

  • Account data — email, organization name, role (owner/admin/editor/viewer/auditor/dgsa).
  • Authentication — JWT session cookie (hl_session), MFA TOTP secret (encrypted at rest).
  • Usage data — IP address, request timestamps, shipment IDs, document content-hashes.
  • Submitted content — UN-numbers / CAS / substance names, shipment fields, optionally uploaded SDS files (see retention).
  • Payment — handled by Stripe; we receive only a customer ID + subscription status, never card numbers.

2a. Uploaded document templates

If you upload your own document templates (DG document templates feature), those templates are stored in your organisation’s private library and are visible only to members of your organisation. HazardLink platform staff may view all uploaded templates for product development and quality-assurance purposes (for example, to understand common template patterns and improve the validation tooling). Template content is never shared with third-party organisations. If you flag a template as “universal” and it is approved by HazardLink, it becomes visible to other platform users — this sharing is always explicit (your opt-in flag + platform review) and never automatic. You can archive or supersede a template at any time; archived templates are retained in our audit trail per the retention schedule in section 5.

3. Lawful basis

  • Art. 6(1)(b) — Contract: account, billing, and core Service functions.
  • Art. 6(1)(f) — Legitimate interests: security logging, fraud prevention, audit-trail integrity (overrides balanced against user rights and clearly disclosed).
  • Art. 6(1)(c) — Legal obligation: tax records, response to lawful requests from authorities.

4. Sub-processors

We engage the following sub-processors. Each publishes a GDPR data-processing agreement (DPA), linked below; executed copies are available on request:

Supabase Postgres + Auth (EU region) (DPA →)
Anthropic Claude AI (SDS parsing + advisory) (DPA →)
Cloudflare DNS + email routing (DPA →)
Resend Transactional email (EU region) (DPA →)
Stripe Payment processing (DPA →)

5. Retention

  • Session cookies: 30 days from last activity.
  • Account data: while your subscription is active. On termination: 30-day grace period for export, then irreversible deletion.
  • Audit-trail: 7 years (regulatory recordkeeping for dangerous-goods declarations under ADR 1.10.5).
  • SDS uploads: discarded immediately after parsing unless you explicitly save the resulting shipment. The parsed structured fields are kept; the original PDF is not.
  • Backups: encrypted daily, retained 30 days rolling.

6. International transfers

Primary data hosting is being set up in the EU (region selected; not yet live — see our readiness page for current status). Sub-processors that may process data outside the EEA (Anthropic, Cloudflare, Stripe) are bound by EU Standard Contractual Clauses (SCCs) and supplementary measures (encryption in transit and at rest).

7. Your rights

Under GDPR Articles 15-22 you have the right to access, rectify, erase, restrict, port, and object to processing of your personal data. To exercise: email [email protected] with your request. We respond within 30 days (extendable to 90 days for complex requests, with notice). Account self-service erasure is available via the API endpoint POST /api/v2/erase.

8. DPIA status

A DPIA self-assessment has been drafted per Art. 35; it has not yet been reviewed by a Data Protection Officer or external counsel (see our readiness page for current status). The draft assesses the Service as low-risk processing because: (a) no special-category data per Art. 9 is processed, (b) data subjects are business contacts in commercial logistics, (c) no automated individual decisions producing legal effects per Art. 22 (the deterministic engine produces compliance suggestions for human review). A formal DPIA will be commissioned if a customer introduces high-risk processing categories.

9. Cookies

We use one essential session cookie (hl_session) and one organization-context cookie (hl_org). No analytics, no advertising, no third-party trackers. No cookie-banner is required because we use only strictly-necessary cookies (ePrivacy Directive Art. 5(3) exemption).

10. Complaints

You can lodge a complaint with the Swedish data protection authority (Integritetsskyddsmyndigheten, IMY): imy.se. We encourage contacting us first so we can attempt to resolve concerns directly.

See also Terms of Service and Readiness.