Privacy policy

Last updated: January 2026

This policy explains how Etiq collects, uses, and protects personal data when you use etiq.company and the Etiq service. It is written to reflect the requirements of the EU General Data Protection Regulation (GDPR).

1. Data controller

The data controller is the entity identified below. For any privacy request, contact us at contact@etiq.company.

Legal name
etiq eurl
Legal form
EURL
Registered in
Algeria, Algiers
Founded
January 2026
Contact
contact@etiq.company
Domain
etiq.company

2. What we collect, why, and on what basis

DataPurposeLegal basis
Label photos uploaded to the demoRun the compliance audit and return findingsConsent (Art. 6.1.a)
Newsletter and contact-form email addressesSend product updates and reply to enquiriesConsent (Art. 6.1.a)
Contact form: name, email, messageReply to your enquiryLegitimate interest (Art. 6.1.f) — replying to inbound contact
Coarse IP hash (SHA-256, no raw IP stored)Rate-limit demo uploads to prevent abuseLegitimate interest (Art. 6.1.f)
Aggregated, cookie-less traffic analyticsMeasure page performance and content qualityLegitimate interest (Art. 6.1.f)

3. How long we keep it

DataRetention
Label photos uploaded to the demoDeleted after processing, at most 30 days
Audit results linked to a demo uploadDeleted with the source photo, at most 30 days
Newsletter subscriber email addressesUntil you unsubscribe, then 30 days in suppression list
Contact form messages24 months after last exchange
Rate-limit IP hashesRolling 24 hours

4. Your GDPR rights

Under the GDPR you have the following rights, which you can exercise at any time by writing to contact@etiq.company:

  • Right of access — obtain a copy of the personal data we hold about you.
  • Right to rectification — ask us to correct inaccurate or incomplete data.
  • Right to erasure — ask us to delete your data ("right to be forgotten").
  • Right to restriction of processing — ask us to freeze processing in specific situations.
  • Right to data portability — receive your data in a structured, machine-readable format.
  • Right to object — object to processing based on legitimate interest, including profiling.
  • Right not to be subject to a solely automated decision producing legal effects.
  • Right to withdraw consent at any time, without affecting past processing.

5. Security measures

  • Transport encryption (HTTPS/TLS) for every request.
  • Data at rest encrypted by our hosting provider.
  • Least-privilege access to production data; row-level security on every user-facing table.
  • Vision API calls carry the label photo only, without account or contact metadata.
  • Backups encrypted and rotated on a short retention window.

6. Subprocessors

We use OpenAI (vision analysis) and Supabase (database, storage, authentication) as subprocessors. Both are bound by data processing agreements. Label photos submitted to the demo are sent to the OpenAI API for analysis and are not used to train models.

7. International transfers

Some subprocessors are located outside the European Economic Area. Transfers are covered by Standard Contractual Clauses adopted by the European Commission.

8. Right to lodge a complaint

If you believe your rights have not been respected, you may lodge a complaint with the ANPDP — Autorité Nationale de Protection des Données à Caractère Personnel of Algeria — or the supervisory authority in your country of residence.