Privacy Policy

NormaTrack is committed to protecting the privacy and security of your data. This policy explains how we collect, use, disclose, and safeguard information.

Last updated: March 30, 2026

Introduction

This Privacy Policy applies to all visitors to our website, customers using the NormaTrack platform, and team members operating company accounts. It explains the lawful bases on which we process your data and how we safeguard your information.

Definitions

  • Personal Data: Information identifying individual users or team members (e.g., names, business emails, account credentials).
  • Business / Platform Data: Product pipelines, supplier lists, factory locations, and environmental inputs uploaded by your organization.
  • Public DPP Data: The subset of Business Data that you deliberately choose to publish globally via a generated Digital Product Passport (DPP).
  • Data Controller: The party determining why and how personal data is processed (You, the Customer, for Business Data).
  • Data Processor: The party processing data on behalf of the controller (NormaTrack).

Data We Collect

Personal Data

  • Account details: Names, business emails, roles, and hashed passwords.
  • Communication data: Support tickets, feedback, and sales inquiries.
  • Billing metadata: Invoicing details securely managed by our payment gateway.

Usage & Technical Data

  • IP addresses, browser types, interaction timestamps, and device identifiers.
  • Application error telemetry used purely for reliability monitoring.

How We Use Data & Legal Bases

We process personal and business data strictly according to the following lawful bases under Article 6 of the GDPR:

PurposeData CategoriesLegal Basis
Provide platformAccount, business dataContract (Art. 6(1)(b))
Calculate impactMaterial, suppliersContract (Art. 6(1)(b))
Generate DPPsProduct provenanceContract (Art. 6(1)(b))
Improve reliabilityUsage, network logsLegitimate int. (Art. 6(1)(f))
Customer supportSupport messagesContract (Art. 6(1)(b))
Tax complianceBilling recordsLegal oblig. (Art. 6(1)(c))

Retention

We retain data only as long as necessary for operational or legal compliance purposes.

Data TypeRetention PeriodAfter Account Deletion
Account infoDuration of accountDeleted within 30 days
Business dataDuration of accountDeleted within 30 days
Published DPPsUntil unpublishedRemoved within 30 days
Audit logs10 yearsAnonymized securely

International Transfers

Your information is primarily hosted in the EU. Where transfers occur outside the EEA or UK (for example, to specific sub-processors), we ensure appropriate safeguards such as Standard Contractual Clauses (SCCs) and equivalent legal mechanisms are strictly in place.

Disclosure

  • To authorized service providers (Subprocessors) acting on our behalf under strict Data Processing Agreements.
  • To law enforcement or regulators solely when compelled by immediate legal obligations.
  • As part of a merger or acquisition, subject to stringent confidentiality safeguards.

Security Measures

We implement technical and organizational controls to protect data confidentiality, integrity, and availability:

  • Encryption: Data is encrypted in transit and at rest.
  • Access Control: Role-based permissions and least-privilege principles.
  • Monitoring: Centralized logging and incident detection protocols.

Your Rights

Depending on your jurisdiction, you have the right to request access, correction, permanent deletion, portability, or restriction of processing of your personal data. You may withdraw consent at any time where processing relies on it, or file a complaint with your supervisory authority.

Subprocessors

We utilize carefully vetted third-party service providers to ensure the reliability and security of our platform. For our website infrastructure, we utilize Vercel Inc. (Hosting), Cloudflare Inc. (Security), Sentry (Telemetry), and SendGrid (Emails).

For our core platform data engine infrastructure, you can review our full registry here:

View the Complete Subprocessor Registry →

Platform Data & Publication Boundaries

NormaTrack gives you absolute control over what is published to the world and what remains a closely guarded corporate secret.

  • Public DPP Data: When explicitly published, fields like descriptive attributes, environmental impact scores, and public material compositions become visible.
  • Strictly Internal Data: Never exposed publicly. This includes Tier 1-4 supplier identities, raw secondary emission factors, calculation metadata, draft variants, and internal notes.

Cookies

We use cookies to deliver essential service functionality (authentication/CSRF) and remember your basic UI preferences. We may also use analytics cookies for aggregated, anonymized performance metrics.

Children's Privacy

NormaTrack is a B2B enterprise service not intended for children under 16. We do not knowingly collect personal data from minors.

Changes to Policy

We may update this policy to reflect operational or regulatory changes. Material updates will be communicated via in-app notices or direct email to account administrators, and the "Last Updated" date will be revised.

Contact Us

For privacy inquiries, GDPR data requests, or compliance escalations, contact our Privacy Team at privacy@normatrack.com.

Governing Law

This Privacy Policy is governed by and construed in accordance with the laws of France, without regard to conflict of law principles. Exclusive jurisdiction for the resolution of any dispute arising out of or in connection with this policy shall reside in the competent courts of Paris, France.