ESGTrack

Privacy Policy

Last updated: 15 September 2026
This is a drafted starting point, not a finished legal document. It has not been reviewed by a qualified lawyer and must not be relied on as-is — particularly since this product is built to process regulated compliance and workforce data across multiple jurisdictions (India's DPDP Act 2023, the EU's GDPR, and others depending on your customers). Have counsel review and adapt this before it governs any real customer relationship or any real personal data.
1. What We Collect 2. How We Use It 3. Sub-Processors 4. Data Retention 5. Security 6. Your Rights 7. International Transfers 8. Cookies 9. Changes 10. Contact

This Privacy Policy explains what personal data ESGTrack collects, why, and what rights you have over it. It applies to account users of the Service. For how we handle data our customers upload about their own employees, suppliers, or other third parties as part of their ESG disclosures, see our Data Processing Agreement instead — in that relationship, our customer is the data controller and we act as processor.

1. What We Collect

  • Account information: name, work email, role, and company affiliation, provided at signup or by your administrator when your account is provisioned.
  • Authentication data: a hashed (never plaintext) password, or, if your organization uses Single Sign-On, information from your identity provider's OIDC token (name, email, and whatever your IdP is configured to share).
  • Usage and audit data: login timestamps, IP address, and browser user-agent string, kept for security purposes (see Section 5) — this is the same data used to detect and block suspicious login activity.
  • Content you create: the ESG disclosures, metrics, evidence files, and comments you or your organization enters into the Service.

2. How We Use It

To operate the Service: authenticate you, enforce access control between organizations, send transactional email (password resets, invitations, approval notifications), investigate security incidents, and provide support when you ask for it. We do not sell personal data, and we do not use your organization's disclosure content to train any model or for any purpose outside operating the Service for you, without separate written agreement.

3. Sub-Processors

We use a small number of third-party services to operate ESGTrack. As of this writing:

  • Email delivery: transactional email (verification, password reset, invitations) is sent via SMTP through our hosting provider's mail service.
  • Hosting and database: application and database hosting for the environment your account runs in.

[This list must be kept accurate and current as real infrastructure decisions are finalized — including the specific hosting provider, database location/region, and any analytics or error-monitoring tools added later. An inaccurate sub-processor list is itself a compliance problem under GDPR Article 28 and similar provisions elsewhere.]

4. Data Retention

Account information is retained for as long as your account is active. Reporting-period data (disclosures, evidence, audit trail) is retained according to your subscription and is available for export throughout. Authentication audit logs (Section 1) are retained for [90 days / 1 year — to be set based on your actual security and compliance needs] and used specifically for rate-limiting and incident investigation. On account termination, Customer Data is retained for export for a limited window (see Terms of Service, Section 8) and deleted thereafter, except where we're required to retain it longer by law.

5. Security

Passwords are stored using industry-standard hashing (bcrypt), never in plaintext. Data belonging to different customer organizations is isolated at the database query layer, not just hidden in the interface. Repeated failed login attempts are automatically detected and temporarily blocked, both per-account and per-network. Every login, logout, and permission-denied event is logged for audit purposes. [If and when SOC 2, ISO 27001, or a formal penetration test is completed, that should be referenced here specifically — a generic "we take security seriously" statement carries little weight in enterprise procurement without something concrete behind it.]

6. Your Rights

Depending on where you're located, you may have rights to access, correct, export, or delete your personal data, and to object to or restrict certain processing (for example, under India's Digital Personal Data Protection Act 2023, or the EU's GDPR if applicable to you). For account-level personal data, contact your organization's administrator, who can update or remove it directly, or contact us at [PRIVACY CONTACT EMAIL].

7. International Transfers

[To be completed once hosting region(s) are finalized — if your infrastructure sits in one region (e.g. India) but you serve customers in another (e.g. the EU, given CSRD support), this section needs a real transfer mechanism, such as EU Standard Contractual Clauses, not a placeholder.]

8. Cookies

The Service uses a session cookie strictly necessary to keep you logged in, and a CSRF token to protect against cross-site request forgery. We do not use third-party advertising or tracking cookies.

9. Changes

We'll notify account administrators of material changes to this Policy by email or in-app notice before they take effect.

10. Contact

Questions about this Policy or your data: [PRIVACY CONTACT EMAIL].

Terms of Service Privacy Policy Data Processing Agreement