Privacy policy
Last updated: January 2026
This policy explains how Etiq collects, uses, and protects personal data when you use etiq.company and the Etiq service. It is written to reflect the requirements of the EU General Data Protection Regulation (GDPR).
1. Data controller
The data controller is the entity identified below. For any privacy request, contact us at contact@etiq.company.
- Legal name
- etiq eurl
- Legal form
- EURL
- Registered in
- Algeria, Algiers
- Founded
- January 2026
- Contact
- contact@etiq.company
- Domain
- etiq.company
2. What we collect, why, and on what basis
| Data | Purpose | Legal basis |
|---|---|---|
| Label photos uploaded to the demo | Run the compliance audit and return findings | Consent (Art. 6.1.a) |
| Newsletter and contact-form email addresses | Send product updates and reply to enquiries | Consent (Art. 6.1.a) |
| Contact form: name, email, message | Reply to your enquiry | Legitimate interest (Art. 6.1.f) — replying to inbound contact |
| Coarse IP hash (SHA-256, no raw IP stored) | Rate-limit demo uploads to prevent abuse | Legitimate interest (Art. 6.1.f) |
| Aggregated, cookie-less traffic analytics | Measure page performance and content quality | Legitimate interest (Art. 6.1.f) |
3. How long we keep it
| Data | Retention |
|---|---|
| Label photos uploaded to the demo | Deleted after processing, at most 30 days |
| Audit results linked to a demo upload | Deleted with the source photo, at most 30 days |
| Newsletter subscriber email addresses | Until you unsubscribe, then 30 days in suppression list |
| Contact form messages | 24 months after last exchange |
| Rate-limit IP hashes | Rolling 24 hours |
4. Your GDPR rights
Under the GDPR you have the following rights, which you can exercise at any time by writing to contact@etiq.company:
- Right of access — obtain a copy of the personal data we hold about you.
- Right to rectification — ask us to correct inaccurate or incomplete data.
- Right to erasure — ask us to delete your data ("right to be forgotten").
- Right to restriction of processing — ask us to freeze processing in specific situations.
- Right to data portability — receive your data in a structured, machine-readable format.
- Right to object — object to processing based on legitimate interest, including profiling.
- Right not to be subject to a solely automated decision producing legal effects.
- Right to withdraw consent at any time, without affecting past processing.
5. Security measures
- Transport encryption (HTTPS/TLS) for every request.
- Data at rest encrypted by our hosting provider.
- Least-privilege access to production data; row-level security on every user-facing table.
- Vision API calls carry the label photo only, without account or contact metadata.
- Backups encrypted and rotated on a short retention window.
6. Subprocessors
We use OpenAI (vision analysis) and Supabase (database, storage, authentication) as subprocessors. Both are bound by data processing agreements. Label photos submitted to the demo are sent to the OpenAI API for analysis and are not used to train models.
7. International transfers
Some subprocessors are located outside the European Economic Area. Transfers are covered by Standard Contractual Clauses adopted by the European Commission.
8. Right to lodge a complaint
If you believe your rights have not been respected, you may lodge a complaint with the ANPDP — Autorité Nationale de Protection des Données à Caractère Personnel of Algeria — or the supervisory authority in your country of residence.