This Privacy Policy explains what personal data ESGTrack collects, why, and what rights you have over it. It applies to account users of the Service. For how we handle data our customers upload about their own employees, suppliers, or other third parties as part of their ESG disclosures, see our Data Processing Agreement instead — in that relationship, our customer is the data controller and we act as processor.
To operate the Service: authenticate you, enforce access control between organizations, send transactional email (password resets, invitations, approval notifications), investigate security incidents, and provide support when you ask for it. We do not sell personal data, and we do not use your organization's disclosure content to train any model or for any purpose outside operating the Service for you, without separate written agreement.
We use a small number of third-party services to operate ESGTrack. As of this writing:
[This list must be kept accurate and current as real infrastructure decisions are finalized — including the specific hosting provider, database location/region, and any analytics or error-monitoring tools added later. An inaccurate sub-processor list is itself a compliance problem under GDPR Article 28 and similar provisions elsewhere.]
Account information is retained for as long as your account is active. Reporting-period data (disclosures, evidence, audit trail) is retained according to your subscription and is available for export throughout. Authentication audit logs (Section 1) are retained for [90 days / 1 year — to be set based on your actual security and compliance needs] and used specifically for rate-limiting and incident investigation. On account termination, Customer Data is retained for export for a limited window (see Terms of Service, Section 8) and deleted thereafter, except where we're required to retain it longer by law.
Passwords are stored using industry-standard hashing (bcrypt), never in plaintext. Data belonging to different customer organizations is isolated at the database query layer, not just hidden in the interface. Repeated failed login attempts are automatically detected and temporarily blocked, both per-account and per-network. Every login, logout, and permission-denied event is logged for audit purposes. [If and when SOC 2, ISO 27001, or a formal penetration test is completed, that should be referenced here specifically — a generic "we take security seriously" statement carries little weight in enterprise procurement without something concrete behind it.]
Depending on where you're located, you may have rights to access, correct, export, or delete your personal data, and to object to or restrict certain processing (for example, under India's Digital Personal Data Protection Act 2023, or the EU's GDPR if applicable to you). For account-level personal data, contact your organization's administrator, who can update or remove it directly, or contact us at [PRIVACY CONTACT EMAIL].
[To be completed once hosting region(s) are finalized — if your infrastructure sits in one region (e.g. India) but you serve customers in another (e.g. the EU, given CSRD support), this section needs a real transfer mechanism, such as EU Standard Contractual Clauses, not a placeholder.]
The Service uses a session cookie strictly necessary to keep you logged in, and a CSRF token to protect against cross-site request forgery. We do not use third-party advertising or tracking cookies.
We'll notify account administrators of material changes to this Policy by email or in-app notice before they take effect.
Questions about this Policy or your data: [PRIVACY CONTACT EMAIL].