Legal
Privacy
What data PackAuth holds, why it holds it, and for how long.
What this site collects
Nothing. This marketing site is static and it tracks no one.
- No third-party script, no analytics cookie, no advertising tag.
- No external font, image or tracker. Every asset is our own.
- There is nothing here for you to opt out of.
- If you email us, we keep that thread so we can answer it.
What the service holds
The records you upload and everything the engine derives from them. Each one is bound to your tenant, and every query carries that tenant as a condition.
- Product, packaging, artwork, formula and evidence records.
- The compliance runs over them, and the findings they raised.
- The approvals and releases that followed, and their audit trail.
- Counterparty contacts, where you ask us to chase evidence.
- Each record is written against a published JSON schema.
What counterparties see
A supplier, laboratory, certifier or printer gets a scoped portal. It shows them the request, what they uploaded, and its status — and nothing else.
- They never see your product records, findings or approvals.
- They never see each other.
- We send them a message because a compliance duty requires it.
- We never send marketing to a counterparty contact.
How long we keep it
An approval has to stay answerable long after the packaging it cleared has left the shelf. So evidence snapshots and audit rows are append-only, and they outlive the run that made them.
- Kept while any approval relies on them, plus the market's own term.
- GDPR erasure requests are honoured where no approval depends on the record.
- Where one does, the record stays and we tell you which approval holds it.
- We answer an erasure request within 30 days.