Privacy Policy
This policy explains what personal data the Batch'd platform processes, why, and what rights you have. It applies to the scanning app, the retailer dashboard, signup, and related pages.
1. Who is responsible
For data your organisation's staff enter while using the service (scan records, photos, recall responses, complaint records), your organisation is the data controller and Batch'd processes that data on its behalf to provide the service. For account signup data and platform operations, Batch'd (operated from Norway; contact below) acts as controller.
2. Data processed
- Account data — name, work email address, role, organisation and store assignment, language and region settings.
- Operational data — product names, barcodes, typed lot codes, photos of product packaging and printed lot codes, store and shelf locations, quantities, timestamps, and the identity of the staff member who recorded each action. These records exist to satisfy food-traceability requirements.
- Complaint records — where staff log customer complaints, those records may include contact details a customer chose to provide.
- Technical data — authentication tokens, and standard server logs kept by the hosting providers below.
Photos are of products and packaging; don't photograph people when capturing lot codes.
3. Purposes and legal bases
- Providing the service and its recall workflows — performance of contract.
- Creating and retaining traceability records — the organisation's compliance with legal obligations (e.g. FSMA 204; Regulation (EC) 178/2002 / Matloven).
- Sending operational emails (recall alerts, escalations, invitations) — legitimate interest in operating the recall chain; these are not marketing messages.
- Securing and improving the platform — legitimate interest.
4. Service providers (subprocessors)
| Provider | Purpose |
|---|---|
| Supabase | Database, authentication, file storage |
| Netlify | Hosting and serverless functions |
| Resend | Operational email delivery |
| Anthropic | AI product identification — a photo taken in the scanner's product step is processed to identify the product; it is not used by the provider to train models |
| Sentry (EU-hosted) | Error monitoring — when the app encounters a technical error, a report including browser details and the error context is sent to Sentry's EU data centre |
| Google Fonts / jsDelivr | Content delivery for fonts and libraries (your IP address is disclosed to the CDN when pages load) |
5. International transfers
Some providers process data in the United States. Where data of EU/EEA users is transferred, it is done under the providers' standard contractual clauses or an equivalent recognised mechanism.
6. Retention
- Traceability and recall records are kept for the period required by applicable food-safety law — as a rule 24 months in the US market and product shelf-life plus 6 months in Norway — or longer where the organisation configures it.
- Account data is kept while the account exists and deleted or anonymised after the organisation removes it, subject to records the organisation must retain.
7. Your rights
Under the GDPR (and similar laws), you can request access to, correction of, or deletion of your personal data, restriction of or objection to processing, and portability. For operational data, requests are handled together with your organisation, which controls those records. You can also complain to a supervisory authority — in Norway, Datatilsynet.
8. Security
Data is encrypted in transit, access is segregated per organisation with row-level security, and role-based permissions limit what each account can see and do. No system is perfectly secure; report suspected vulnerabilities to the contact below.
9. Changes
Updates to this policy will be posted here with a new effective date; material changes will be announced to organisation administrators.
10. Contact
Privacy questions and requests: ian.w.race@gmail.com.