LEGAL · PRIVACY POLICY · DRAFT v0.1

Privacy Policy

DRAFT FOR LAWYER REVIEW — this document is pending final legal review and is not yet in force.

Founder-prepared draft for fixed-scope counsel review (GDPR focus) before publication. Not legal advice. Bracketed [FIELDS] are placeholders.

LAST UPDATED: [MON 20XX] · VERSION 0.1 (DRAFT)

01 — Controller.

EUDR Clear LLC, 30 N Gould St, Sheridan, WY 82801, USA (placeholder address) is the controller for personal data processed through this service. EU representative (GDPR Art. 27): to be appointed — [name, address, email]. [UK representative — to be appointed, Art. 27 UK GDPR]. Contact: [privacy email].

02 — Data we collect.

  • Account data — your email address, collected when you request a sign-in link; a display name is derived from it. No password is ever requested or stored.
  • Plot data — geolocation coordinates (points or polygons) and, where you enter them, plot names, commodity, and supplier references.
  • Screening evidence — inputs, dataset versions pinned per order, raw provider responses, and custody hashes.
  • Usage logs — request logs, timestamps, and error records.
  • Messages — contact-form messages and newsletter email addresses.

03 — Plot data can be personal data.

Plot coordinates and supplier names usually describe land, but where they relate to an identifiable natural person — for example a sole trader, smallholder, or individual landowner named as supplier — they are personal data under GDPR Art. 4(1). We treat such data as personal data throughout. We do not enrich, profile, or cross-reference plot data against other sources.

04 — When you are a supplier submitting a location.

If you received a collection link from a buyer and submitted a plot location through it, we process that submission on behalf of the buyer, for the buyer's EUDR due-diligence purpose. The notice shown at collection on the collection page itself: your location is used solely for EUDR due-diligence verification by your buyer. For that processing, the buyer is the controller for their compliance purpose and EUDR Clear acts as processor, while EUDR Clear remains sole controller for the service's own security and audit record [CONFIRM WITH COUNSEL]. Your submission is visible only to the buyer whose link you used; it is never used for marketing and never shared with other buyers. Retention is buyer-controlled: the location is deleted when the buyer deletes the collection link or the plot, and collection links that expire are purged after 90 days. To exercise rights over a submission, contact the buyer who sent you the link; for the security and audit records we control, [privacy email].

05 — Data minimisation.

We collect only what the service needs: your email address — the only account attribute the sign-in flow collects — the coordinates needed to run your screenings, and logs kept to security-relevant fields. Supplier names are optional where our intake allows it, and plot data is never used for marketing.

06 — Purposes and lawful bases.

  • Providing screening, monitoring, and evidence packs — contract (Art. 6(1)(b)).
  • Security, fraud prevention, audit log, service reliability — legitimate interests (Art. 6(1)(f)).
  • Anonymous, consent-gated analytics and newsletter — consent (Art. 6(1)(a)); withdrawable at any time.
  • Retaining screening evidence and business records — legal obligation and legal-defence interests (Arts. 6(1)(c), 6(1)(f)).

07 — Processors.

We use processors under written data-processing agreements: Resend (delivery of one-time sign-in links and monitoring digest emails; EU/US), Stripe (payments — we never receive card numbers; EU/US), Cloudflare (edge delivery and denial-of-service protection; EU/US), and our MySQL/TiDB host (application data storage) [confirm provider name and region]. Processors act on our instructions only. The upstream screening datasets — FAO Open Foris Whisp, Hansen GFC, GLAD, JRC TMF — are public geospatial datasets queried at screening time; they are not processors of personal data.

08 — International transfers.

Our primary hosting and database are in the United States [confirm region]. Transfers of personal data out of the EU/EEA and UK rely on Standard Contractual Clauses (Commission Decision 2021/914, plus the UK Addendum where applicable) or another lawful transfer mechanism such as the provider's participation in the EU–US Data Privacy Framework [confirm per provider; attach annexes]. We apply transfer-impact assessments where required.

09 — Retention.

  • Account data — for the life of the account, then 30 days for export, then deleted.
  • Screening evidence — up to 5 years, because EUDR Art. 12 requires operators to keep due-diligence records for five years (our retention supports that), and to establish, exercise, or defend legal claims (Art. 17(3)(e) GDPR and equivalent). Retention length follows the plan purchased.
  • Screenings produced by the deterministic demo engine — retained under the same horizon for reproducibility [CONFIRM WITH COUNSEL — shorter demo retention under review].
  • Usage logs — [12 months].
  • Leads, contact messages, newsletter — 24 months or until you unsubscribe.

10 — Publication of aggregated screening records.

We publish aggregated, owner-anonymous plot passports (public records addressed by a plot identity hash) and benchmark statistics. Plot passports are published only when at least 2 screenings are on record; benchmark figures are published only in buckets of at least 5 plots (k-anonymity). Published records are derived from screening outputs — verdict classes, counts, and dates — and never identify the operator, supplier, or buyer behind a screening; plot geometry is reduced to a one-way hash. If you believe a published record about a plot is inaccurate, contact [privacy email] with the plot identity hash and we will correct or withdraw the record where the error can be verified.

11 — Your rights.

You may request access, rectification, erasure, restriction, portability, and objection; you may withdraw consent for analytics or the newsletter at any time. Email [privacy email]; we respond within one month. You may lodge a complaint with your national supervisory authority, or, as applicable, with the UK Information Commissioner's Office (ICO) or the Swiss Federal Data Protection and Information Commissioner (FDPIC).

California residents: California law may apply to some personal information we process (for example, supplier locations or contacts in California). You may request access to or deletion of your personal information and will not be discriminated against for asking. Requests: [privacy email]. We do not sell personal information.

12 — Security.

Encryption in transit (TLS), reasonable technical measures, least-privilege admin access, and an append-only audit log of administrative actions. Screening records carry SHA-256 custody hashes so that later alteration is detectable.

13 — Cookies.

The site sets one strictly necessary session cookie (kimi_sid) when you sign in with an email link, and, only with your consent, loads cookieless analytics. See the Cookie Policy.

14 — Children.

The service is B2B and not offered to anyone under 18.

15 — Changes and contact.

We update this policy as the service changes; material changes are announced on this page and by email where required. EUDR Clear LLC · [privacy email].