Privacy Notice
1. Who is responsible
The organisation responsible for the hosted service is [LEGAL ENTITY NAME — REQUIRED], contactable at [PRIVACY CONTACT EMAIL — REQUIRED]. If a customer organisation decides why and how quality-control register data is uploaded, that customer will normally be the controller for that data and the service operator may act as its processor. The applicable service agreement must confirm these roles.
2. Scope
This notice describes the current ConcreteQC hosted demo and its offline version. ConcreteQC is intended for authorised professional users and concrete quality-control records. It is not designed for special-category personal data, children's data or employee monitoring.
3. Data processed
- Account and access data: user ID, tenant ID, role, session version, authentication credentials and a strictly necessary signed session cookie.
- Security data: a short-lived rate-limit identifier derived from the user ID and request IP address, kept for no more than 10 minutes, plus security and access audit events.
- Quality-control data: customer-supplied sample dates, plant, mix, concrete class, measurements, conformity results and related register fields. Customers must not put names or other unnecessary personal data into free-text fields.
- Audit data: user ID, tenant ID, role, action, target, result, timestamp and correlation ID. Audit records are designed to exclude passwords, session tokens and raw quality-control payloads.
- Backup and recovery data: tenant quality-control datasets, integrity digests and recovery metadata.
- Optional notification data: browser push-subscription endpoint, device-generated subscription keys, user ID and creation time when alerts are enabled.
- Technical request data: hosting, content-delivery and push providers may receive IP address, browser and request metadata needed to deliver the service.
4. Why data is used
Data is used to authenticate users, enforce tenant and role boundaries, display and update quality-control analytics, create audit evidence, export verified backups, support recovery, prevent abuse and deliver optional alerts.
The intended legal bases are performance of a service agreement, compliance with applicable legal obligations, and legitimate interests in providing and securing the service. Optional alerts are activated at the user's request and can be disabled at any time. These bases must be confirmed for the operator, country and customer relationship before production.
5. Service providers and disclosures
The hosted version is designed to use Cloudflare for hosting and storage. The dashboard serves verified local copies of its Chart.js, SheetJS and jsPDF browser libraries from the same origin and does not contact a software-library CDN at runtime. If push alerts are enabled, the user's browser and platform push provider process the device subscription and notification delivery. The weather check sends configured site coordinates to Open-Meteo; it does not intentionally send account or quality-control records.
The current application does not include advertising, behavioural analytics or the sale of personal data. Data may still be disclosed where required by law or to protect the service and its users.
6. International transfers
Provider locations and transfer routes depend on the final hosting and customer configuration. [HOSTING REGION, PROVIDER LIST AND TRANSFER SAFEGUARDS — REQUIRED] must be documented before production use.
7. Retention
- The signed session cookie expires after 12 hours.
- A failed-sign-in rate-limit identifier expires after no more than 10 minutes and is cleared after a successful sign-in.
- Push-subscription records remain until alerts are disabled, the subscription expires, or the service removes an invalid endpoint.
- Quality-control data, audit events and recovery points currently have no automatic deletion schedule in this isolated demo.
[APPROVED RETENTION AND DELETION SCHEDULE — REQUIRED] must be implemented before production publication. Backups must not be kept longer than the source data without a documented reason.
8. Security
The current design uses tenant-scoped storage keys, role checks, signed HTTP-only session cookies, request limits, append-only application audit records and integrity-checked backups. No internet service can be guaranteed completely secure. Production operation also requires an independent encrypted backup destination, access reviews and an incident-response process.
9. Your choices and rights
Depending on applicable law, individuals may have rights to information, access, correction, deletion, restriction, portability, objection and withdrawal of consent, and may complain to a competent data-protection authority. Requests should be sent to [PRIVACY CONTACT EMAIL — REQUIRED]. Identity may need to be verified before a request is fulfilled.
10. Changes and contact
This notice will be updated when the service, providers or processing purposes change. Material changes should be communicated before they take effect. Privacy questions should be sent to [PRIVACY CONTACT EMAIL — REQUIRED].
This is a product-readiness draft, not legal advice. It must be adapted to the actual operator, contracts, deployment and applicable law.