Legal framework
Privacy policy
Draft version. This text describes the processing planned for the service. It must be validated by a lawyer before going live, and some retention periods are still to be set.
Draft documentThe service is not open to the public and this text has not yet been validated by a lawyer. Missing information is flagged as such rather than replaced with generic wording.
1. What we collect
- Identification data: the organisation's name, legal form, country, the manager's identity, and the identity and registration documents submitted at sign-up.
- Case data: documents submitted (permits, certificates, veterinary attestations, transport documents), their metadata and the results of the checks carried out on these documents.
- Proof data: for each accepted declaration, the signatory's identity, the date and time, the IP address, the user agent, the version of the accepted text and its hash.
- Exchange data: messages sent through the platform's messaging system, with their timestamp.
- Reports: the content of the report and, if one was left, the reporting party's contact address. The form accepts anonymous reports.
2. Why we collect it
- To provide the service: reviewing a registration, structuring a case file, checking documents, arranging a third-party verification, and enabling exchanges between parties.
- To build the proof record: keeping a timestamped trace of who declared what and when. This is the very purpose of the service, and this purpose justifies long retention periods.
- To fight trafficking: reviewing a report, suspending an account or a listing, and keeping the history of a decision even after the reported content has been removed.
- To meet our legal obligations, in particular for invoicing and accounting record-keeping.
3. Who has access to it
- SaqrBridge's teams responsible for reviewing registrations, case files and reports.
- The other party to the case file, for only the information required for the transaction in progress.
- The firms and laboratories entrusted with a verification, for only the documents covered by their assignment. They act in their own capacity and become responsible, as data controllers, for the data transmitted to them.
- Competent authorities, upon a legally founded request.
- No data is sold, rented or transferred for advertising purposes.
4. Transfers outside the European Union
- The service connects parties based in Europe, North America and the Gulf countries. Opening a case file therefore inherently involves transmitting data to a party established outside the European Union.
- These transfers are limited to what is necessary for the performance of the contract between the parties and for completing export and import formalities.
- The safeguards governing these transfers will be detailed when the service opens, following legal validation.
5. How long we keep it
- Account and identification data: for the duration of the relationship, then for the period required to handle any claims.
- Case files, submitted documents and the log of declarations: a long retention period, to be set following legal validation. A proof record deleted too early proves nothing, which would defeat the purpose of the service.
- Reports and the associated decisions: kept even after the reported content has been removed, so that removal does not erase the record.
6. Your rights
- You have a right of access, rectification, erasure, restriction, objection and data portability, under the conditions set out by the applicable regulation.
- The right to erasure has one limit specific to this service: an accepted declaration, its timestamp and the hash of the signed text cannot be deleted while they are needed to establish, exercise or defend a legal claim. We tell you this before you sign, not after you ask.
- The contact address for exercising these rights will be shown on the legal notice page when the service opens.
7. Security
- Data is never read directly from the browser: every read and every write goes through the server, and direct client-side access to the database is closed off.
- Sensitive actions are recorded in a write-only audit log, which stores the author, the action, the object concerned and the date.
A proof service retains data by designMost services promise to delete data quickly. This one does the opposite on one specific point, and it is worth reading before signing up: the value of a register of timestamped declarations depends entirely on how long it is kept. Once deleted, it proves nothing, neither for you nor against you. See the register of declarations.