Legal

Privacy notice

Last updated

Origentra helps businesses record where their products come from and publish Digital Product Passports. We collect as little personal data as we can and use only essential cookies. This notice sets out what we collect, why, and the rights you have.

1.Who we are

Origentra is a Digital Product Passport and product traceability service provided by EmKeTech (“EmKeTech”, “we”, “us”). This notice explains how we handle personal data in connection with the Origentra service, the public passport pages it serves and this website.

You can contact us about anything in this notice at support@emketech.com. Our registered address is available on request from the same address.

2.Our role: controller and processor

We are the controller of account data. We decide how and why the details needed to run your account are used, such as your name, email address and sign-in records.

We are a processor of customer content. Businesses use Origentra to record their products, batches, materials, suppliers, facilities, journey events, certifications and evidence. That content can include personal data, for example the name of a farm owner or a contact at a supplier. The business that records it is the controller, and we process it on that business’s behalf and under its instructions.

If your personal data appears in a business’s records or in a passport it has published, please contact that business first. We will help our customers respond to such requests.

3.Public passports

Customers can publish a Digital Product Passport: a public web page, usually reached from a QR code on a product, showing information the customer has chosen to share. The customer decides what is published and is responsible for it.

Passports are built only from fields designated as public. Evidence files, internal notes, prices, logistics references and contact details are not included. Where a customer publishes a person’s name, for example the name of a farm, that is the customer’s decision as controller.

If you view a passport, we do not ask who you are and do not use analytics or tracking. To protect the service from abuse, requests are rate limited using a short-lived keyed pseudonym of your network address; the address itself is not stored for this purpose.

4.Personal data we collect

As controller, we collect and use the following account data:

  • Identity and contact details: your name and email address.
  • Credentials: a password hash. We never store your password in readable form.
  • Sign-in and security metadata: such as sign-in times, failed sign-in attempts and session records, including the browser description (user agent) a session was started from. To limit repeated sign-in attempts we convert your network address into a keyed pseudonym held for a short period; the address itself is not stored.
  • Membership details: the organisations you belong to and your role in each.
  • Activity records: entries in your organisation’s audit log, such as who published a passport or changed a verification state, and when.
  • Two-factor authentication: if you turn it on, an encrypted authenticator secret and hashed recovery codes.
  • Preferences: such as notification preferences and your time zone.
  • Sales enquiries: if you use the enquiry form on our pricing page, your name, work email, company, the approximate number of products you would trace and your message. We use these only to reply and discuss Origentra with you.
  • Correspondence: the content of emails you send to us.

Origentra is not designed to hold special category data, and we ask customers not to record it.

5.How we use it and our lawful bases

  • To provide the service: creating and managing your account, signing you in, applying your role and preferences, and sending transactional emails such as invitations and password resets. Lawful basis: performance of a contract with you or with the business you use Origentra for, and our legitimate interest in providing the service our customers have requested.
  • To keep Origentra secure: rate limiting, preventing unauthorised access, and keeping audit and security logs. Lawful basis: our legitimate interests in protecting our service, our customers and their data.
  • To respond to you: answering enquiries about getting started, support, privacy and security. Lawful basis: our legitimate interest in responding to enquiries, or steps taken at your request before entering into a contract.
  • To meet legal obligations: for example, keeping records we are required to keep or responding to lawful requests. Lawful basis: compliance with a legal obligation.

We do not sell personal data or use it for advertising or profiling. Origentra does not make automated decisions that produce legal or similarly significant effects.

6.Cookies

Origentra uses only cookies that are strictly necessary for the service to work:

  • origentra_session: keeps you signed in. It is HttpOnly, Secure and SameSite=Lax, and expires when your session ends or times out.
  • origentra_org: remembers which of your organisations you last selected.
  • origentra_mfa: holds a sign-in open for up to ten minutes while you enter a two-factor code.

We do not use advertising, analytics or third-party tracking cookies, so we do not ask for cookie consent. Viewing a public passport does not require any cookie.

7.Sub-processors and sharing

We use the following service providers to operate Origentra. They process data only on our instructions.

  • Vercel: application hosting. Server functions run in Dublin, Ireland.
  • Supabase: database hosting, in the AWS eu-west-1 region (Ireland).
  • Postmark: delivery of transactional emails such as invitations and password resets, where email delivery is enabled.

We may also disclose personal data where required by law, to protect the rights, property or safety of EmKeTech, our customers or others, or as part of a reorganisation or sale of our business, subject to appropriate confidentiality protections. We will update this notice when our sub-processors change.

8.International transfers

Our primary hosting is in Ireland. Some of our service providers may process limited data outside the European Economic Area, for example for support or operational purposes. Where that happens, we rely on appropriate safeguards recognised under data protection law, such as an adequacy decision or the European Commission’s Standard Contractual Clauses. You can ask us for more information at support@emketech.com.

9.How long we keep data

  • Account data is kept for as long as your account exists. When an account is closed, we delete or anonymise it within a reasonable period, except where we need to keep limited information to meet legal obligations or resolve disputes.
  • Customer content, including published passports and their earlier versions, is kept for the life of the customer’s organisation in Origentra. Customers can export it, and we delete it on the customer’s request or after the customer’s agreement ends, in line with our terms.
  • Security logs are kept only for as long as they are needed to protect the service and investigate incidents.
  • Correspondence and sales enquiries are kept for as long as needed to deal with your enquiry and any follow-up, and enquiries that do not lead to an agreement are deleted within two years.

10.Security

We protect personal data with technical and organisational measures appropriate to the risk, including database-enforced tenant isolation, role-based access control, hashed passwords and session tokens, private evidence served through short-lived signed links, encrypted connections and audit logging. Read more on our security page.

11.Your rights

Under the General Data Protection Regulation you have the right, subject to certain conditions, to:

  • access the personal data we hold about you and receive a copy;
  • have inaccurate data corrected;
  • have your data erased;
  • restrict how we use your data;
  • object to processing based on our legitimate interests;
  • receive your data in a portable format; and
  • withdraw consent, where we rely on it, at any time.

To exercise any of these rights, email support@emketech.com. We may need to verify your identity before acting on a request, and we will respond within the time required by law, normally one month.

12.Complaints

If you have a concern about how we handle your personal data, please contact us first at support@emketech.com so we can try to resolve it. You also have the right to lodge a complaint with the Data Protection Commission in Ireland, or with the supervisory authority where you live or work.

13.Changes to this notice

We may update this notice from time to time. The date at the top shows when it was last changed. Where a change is significant, we will take reasonable steps to let account holders know, for example by email or a notice in the application.