1. Who controls your information
The legal entity identified in the relevant customer or pilot agreement will be the data controller for account and commercial information. A participating client may be the controller for project evidence uploaded on its behalf, with BioTrack acting as its processor.
2. Information processed
- Account identity and authorised-user information.
- Contact, organisation and project details.
- Project locations, materials, batches, installation and monitoring records.
- Uploaded photographs, reports, invoices, spreadsheets and supporting evidence.
- Review notes, decisions, audit events and file fingerprints.
- Technical, security and access records needed to operate the platform.
3. Purposes and lawful bases
Information may be used to provide the service, secure accounts, organise evidence, maintain attributable audit records, support contractual pilots and comply with legal obligations. Depending on the context, processing will rely on contract, legitimate interests, legal obligation or consent.
4. Artificial-intelligence processing
Where enabled, BioTrack may submit approved evidence to an artificial-intelligence service to extract information, identify gaps and prepare recommendations. Artificial intelligence does not independently verify claims, issue credits or make final approval decisions. See the AI and Data Use Policy.
5. Sharing and international transfers
Information may be shared with authorised client users, approved contractors, infrastructure and storage providers, artificial-intelligence providers when enabled, professional advisers and independent reviewers authorised for the project. Appropriate contractual and transfer safeguards must be established before live customer processing.
6. Retention and security
Retention periods will be defined by project purpose, customer contract, legal requirements and the need to preserve an audit trail. Files are intended to be protected by access controls, version history and digital fingerprints. No online system can guarantee absolute security.
7. Your rights
Subject to UK data-protection law, individuals may have rights of access, correction, deletion, restriction, portability and objection. They may also complain to the UK Information Commissioner’s Office. The final public notice will provide the confirmed controller’s contact details.
