Legal
Privacy Policy
Last updated: TO BE PROVIDED · Version 1.0-draft
1. Controller
- Data controller: TO BE PROVIDED (legal entity)
- Registered address: TO BE PROVIDED
- Contact: hello@halalaccess.partners
- Data protection officer: TO BE PROVIDED (or "not required under Art. 37 GDPR")
2. Categories of personal data
We process a limited set of personal data, grouped as follows.
- Account data — email, name, role, hashed authentication credentials, session tokens. Processed to operate the sign-in and account features.
- Directory & claim data — publicly available business-contact information (company name, website, general company email, publicly listed halal manager or QA lead), plus supplier-submitted evidence and certificate documents. Names of natural persons appear only where they are already published in a professional capacity (e.g. on a certificate).
- Enquiry & correction data — the content of messages you send us, plus your contact email, IP address, and user agent used to submit the form.
- Log & security data — request logs, rate-limit counters, admin audit-log entries (who did what and when).
3. Purposes and legal bases
- Operating the directory — legitimate interest (Art. 6(1)(f) GDPR) in running a B2B halal supplier registry. Article 14 notifications are logged internally; the correction form is the primary channel to object.
- Providing accounts and claim/enquiry features — performance of contract (Art. 6(1)(b)) and, where you have opted in, consent (Art. 6(1)(a)).
- Security, fraud prevention, and rate limiting — legitimate interest (Art. 6(1)(f)).
- Legal compliance — compliance with legal obligations (Art. 6(1)(c)).
4. Retention
- Account data — for the life of the account plus TO BE PROVIDED months after closure.
- Claim and directory records — for as long as the listing remains active; historical admin audit-log entries are retained for TO BE PROVIDED months.
- Correction requests — retained as long as needed to handle the request plus TO BE PROVIDED months for evidentiary purposes.
- Server logs and rate-limit counters — up to 30 days.
5. Subprocessors
We rely on the following categories of subprocessors:
- Hosting & database: TO BE PROVIDED (name, role, region)
- AI providers (LLM & vision): TO BE PROVIDED
- Transactional email: TO BE PROVIDED
Where subprocessors are located outside the EEA, transfers are covered by the European Commission's Standard Contractual Clauses and, where applicable, supplementary technical measures. Full details: TO BE PROVIDED.
6. Your rights
Under the GDPR you have the right to access, rectification, erasure, restriction, portability, and objection, as well as the right to lodge a complaint with a supervisory authority.
- Exercise a right or object to processing: /corrections or hello@halalaccess.partners.
- Supervisory authority: TO BE PROVIDED (competent DPA for the controller).
7. Security
We use industry-standard transport encryption (HTTPS with HSTS), row-level security on all user-facing database tables, private storage for uploaded certificates with short-lived signed URLs, and separation between anonymous, authenticated, and administrator access. See our methodology for editorial guardrails.
8. Cookies
See our dedicated cookies statement.
9. Changes to this policy
We may update this policy from time to time. Material changes will be flagged on the site and, where required, communicated to registered users.