Privacy policy
In short: we collect what is needed to run the analysis and issue an invoice. The data is held in the European Union. We do not profile and we sell nothing to anybody.
Controller
The controller is the operator of the service named on the operator page. For data-protection questions, write to prywatnosc@substantly.eu.
What data, and what for
- Account
- Company or shop name, email address, password as a cryptographic hash. Basis: performance of the contract (Art. 6(1)(b) GDPR).
- Shop and proof of ownership
- Domain, verification method, verification token and the date it was proved. Basis: performance of the contract, and our legitimate interest in nobody analysing somebody else's shop (Art. 6(1)(b) and (f) GDPR).
- Product catalogue
- Titles, descriptions and identifiers of the products you upload or send through the API. This is your commercial content; as a rule it holds no personal data, and if you put some in, we process it only to carry out the analysis. Basis: performance of the contract.
- Analysis results
- Findings, the ruleset version, the confidence level and the reports produced. Basis: performance of the contract.
- Payments
- Payment identifier, amount, country and invoicing details. We neither see nor store card details. Basis: performance of the contract and the legal obligation to keep accounting records (Art. 6(1)(b) and (c) GDPR).
- Technical logs
- IP address, the time and path of the request, the response code — for security and diagnostics. Basis: legitimate interest (Art. 6(1)(f) GDPR).
What we do not do
- We run no web or advertising analytics in the browser
- We embed no scripts, fonts or images from third-party servers
- We do not profile and we take no solely automated decisions with legal effect
- We neither sell data nor share it for marketing
Where the data is
The application, the database and the report storage run in data centres inside the European Union. The object storage configuration refuses a region outside the EU — that is not an organisational undertaking but a condition the code checks at start-up.
Record of processing activities
The full record: why we process data, which data, on what basis, and for how long we keep it.
| Purpose | Data | Legal basis | How long |
|---|---|---|---|
| Running the account and signing in | Email address, password hash, role, language, the date the address was confirmed | Performance of the contract (Art. 6(1)(b) GDPR) | For as long as the account exists; after a request to close it, a further 14 days |
| Proving that the shop is yours | The domain, the verification token, and the method and date of each check | Performance of the contract (Art. 6(1)(b) GDPR) | For as long as the account exists |
| Checking product copy for environmental claims | Product titles, descriptions and attributes, and the captured versions of that copy | Performance of the contract (Art. 6(1)(b) GDPR) | The current copy for as long as the account exists; captured versions for 24 months |
| Showing risk, collecting evidence and keeping diligence provable over time | The matched wording, the risk level, the confidence, the claims and the documents filed against them | Performance of the contract (Art. 6(1)(b) GDPR) | Claims and evidence for as long as the account exists; individual findings with the captured version they describe (24 months) |
| Taking payment and issuing accounting records | The amount, the currency, the billing details, the VAT id and the Stripe identifiers | Performance of the contract and a legal obligation (Art. 6(1)(b) and (c) GDPR) | For the period tax law prescribes, including after the account is closed |
| Diagnosing problems and keeping the service secure | A request id, the path, the status code and the time. No shop content and no keys | Legitimate interest in running and securing the service (Art. 6(1)(f) GDPR) | A short time, for diagnostics |
Who processes data for us
We use providers that process data on our instructions: hosting infrastructure in the EU, the payment provider Stripe (billing data), and the provider of the language model that weighs the context of the flagged passages. We have a processing agreement with each of them. The current list of processors and where they process is available on request at prywatnosc@substantly.eu.
This list is not complete yet. The hosting and mail providers have not been chosen, and no processing location is contractually confirmed. We will fill them in before launch — we would rather say so than write down something we have not checked.
| Provider | What for | Which data | Where it processes |
|---|---|---|---|
| Anthropic | The language model that judges whether a passage is an environmental claim | Fragments of product copy sent for classification. No personal data and no order data | not settled yet |
| Stripe | Taking payments | Billing details, the payer email address and the amount. We never see or store a card number | not settled yet |
| not settled yet | Servers, the database and file storage | Everything the service stores | not settled yet |
| not settled yet | Sending transactional email | The recipient email address and the content of the message | not settled yet |
For how long
Account, shop, catalogue and report data is kept for as long as the account exists. Captured versions of product copy are deleted after 24 months. Once an account is closed only the accounting records remain, for the period the law prescribes. Technical logs are kept for a short time, for diagnostics and security.
How we protect it
Captured product copy and evidence descriptions are encrypted in the database with a key the database itself does not hold. The dashboard requires a sign-in, API keys are stored only as hashes, and secrets never reach our logs. Backups are restored and their contents checked automatically, because a backup nobody has ever restored is not a backup.
Your rights
You have the right of access, rectification, erasure, restriction of processing, portability, and objection to processing based on legitimate interest. You may also complain to a data-protection supervisory authority — the one in the member state where you live or work. You can delete the product catalogue yourself, in your account, at any time.
You can download a copy of your data yourself, in the dashboard under “Data and privacy”. You can close your account there too: we erase it after 14 days, so until then you can change your mind.
Changes
We give notice of material changes by email before they take effect.