Privacy Policy
NormaTrack is committed to protecting the privacy and security of your data. This policy explains how we collect, use, disclose, and safeguard information.
Last updated: March 30, 2026
Introduction
This Privacy Policy applies to all visitors to our website, customers using the NormaTrack platform, and team members operating company accounts. It explains the lawful bases on which we process your data and how we safeguard your information.
Definitions
- Personal Data: Information identifying individual users or team members (e.g., names, business emails, account credentials).
- Business / Platform Data: Product pipelines, supplier lists, factory locations, and environmental inputs uploaded by your organization.
- Public DPP Data: The subset of Business Data that you deliberately choose to publish globally via a generated Digital Product Passport (DPP).
- Data Controller: The party determining why and how personal data is processed (You, the Customer, for Business Data).
- Data Processor: The party processing data on behalf of the controller (NormaTrack).
Data We Collect
Personal Data
- Account details: Names, business emails, roles, and hashed passwords.
- Communication data: Support tickets, feedback, and sales inquiries.
- Billing metadata: Invoicing details securely managed by our payment gateway.
Usage & Technical Data
- IP addresses, browser types, interaction timestamps, and device identifiers.
- Application error telemetry used purely for reliability monitoring.
How We Use Data & Legal Bases
We process personal and business data strictly according to the following lawful bases under Article 6 of the GDPR:
| Purpose | Data Categories | Legal Basis |
|---|---|---|
| Provide platform | Account, business data | Contract (Art. 6(1)(b)) |
| Calculate impact | Material, suppliers | Contract (Art. 6(1)(b)) |
| Generate DPPs | Product provenance | Contract (Art. 6(1)(b)) |
| Improve reliability | Usage, network logs | Legitimate int. (Art. 6(1)(f)) |
| Customer support | Support messages | Contract (Art. 6(1)(b)) |
| Tax compliance | Billing records | Legal oblig. (Art. 6(1)(c)) |
Retention
We retain data only as long as necessary for operational or legal compliance purposes.
| Data Type | Retention Period | After Account Deletion |
|---|---|---|
| Account info | Duration of account | Deleted within 30 days |
| Business data | Duration of account | Deleted within 30 days |
| Published DPPs | Until unpublished | Removed within 30 days |
| Audit logs | 10 years | Anonymized securely |
International Transfers
Your information is primarily hosted in the EU. Where transfers occur outside the EEA or UK (for example, to specific sub-processors), we ensure appropriate safeguards such as Standard Contractual Clauses (SCCs) and equivalent legal mechanisms are strictly in place.
Disclosure
- To authorized service providers (Subprocessors) acting on our behalf under strict Data Processing Agreements.
- To law enforcement or regulators solely when compelled by immediate legal obligations.
- As part of a merger or acquisition, subject to stringent confidentiality safeguards.
Security Measures
We implement technical and organizational controls to protect data confidentiality, integrity, and availability:
- Encryption: Data is encrypted in transit and at rest.
- Access Control: Role-based permissions and least-privilege principles.
- Monitoring: Centralized logging and incident detection protocols.
Your Rights
Depending on your jurisdiction, you have the right to request access, correction, permanent deletion, portability, or restriction of processing of your personal data. You may withdraw consent at any time where processing relies on it, or file a complaint with your supervisory authority.
Subprocessors
We utilize carefully vetted third-party service providers to ensure the reliability and security of our platform. For our website infrastructure, we utilize Vercel Inc. (Hosting), Cloudflare Inc. (Security), Sentry (Telemetry), and SendGrid (Emails).
For our core platform data engine infrastructure, you can review our full registry here:
Platform Data & Publication Boundaries
NormaTrack gives you absolute control over what is published to the world and what remains a closely guarded corporate secret.
- Public DPP Data: When explicitly published, fields like descriptive attributes, environmental impact scores, and public material compositions become visible.
- Strictly Internal Data: Never exposed publicly. This includes Tier 1-4 supplier identities, raw secondary emission factors, calculation metadata, draft variants, and internal notes.
Children's Privacy
NormaTrack is a B2B enterprise service not intended for children under 16. We do not knowingly collect personal data from minors.
Changes to Policy
We may update this policy to reflect operational or regulatory changes. Material updates will be communicated via in-app notices or direct email to account administrators, and the "Last Updated" date will be revised.
Contact Us
For privacy inquiries, GDPR data requests, or compliance escalations, contact our Privacy Team at privacy@normatrack.com.
Governing Law
This Privacy Policy is governed by and construed in accordance with the laws of France, without regard to conflict of law principles. Exclusive jurisdiction for the resolution of any dispute arising out of or in connection with this policy shall reside in the competent courts of Paris, France.