Zum Inhalt springen
NDT Intact
Anmelden Einladung anfragen

Dieser Text ist ein Entwurf. Er wurde noch nicht von einem Anwalt geprüft und ist nicht in Kraft.

Dieses Dokument ist in Ihrer Sprache noch nicht verfügbar; der englische Text wird angezeigt.

Privacy notice

NDT Intact is run by [Name des Betreibers], [Postanschrift]. You can reach us at [Kontakt-E-Mail-Adresse].

Two roles

  • For the data an inspection company puts into NDT Intact (reports, files, registers, its clients' details), the company decides what happens to it and we process it on the company's behalf.
  • For account data (your name, email address and sign-in records) and for the beta waiting list, we decide, and this notice applies directly.

What we keep

  • Your account: name, email address, your password as a one-way hash, your language, and your two-factor settings.
  • Sign-in records: the time, IP address and browser of each sign-in, failed sign-in and sign-out, and of changes to your password or second factor. You and our platform administrators can see them; an organisation you work for cannot.
  • Organisation activity: an audit log of signing, reviewing, issuing, withdrawals, downloads, share links, permission changes, client acceptances and entering a workspace, with the IP address. The organisation's owners and admins can see it. It cannot be edited.
  • The waiting list: the name, email address, company, role and message you leave.
  • Content: whatever your organisation enters or uploads.

Why

To run the service and keep it secure, to keep the records that issued reports depend on, to send the emails the service needs (invitations, notifications, password resets), and to answer you.

Who else handles it

  • The providers that host the application and store its files, on our behalf.
  • Anthropic, only for organisations that have switched AI on, and only the documents and text sent for a draft.
  • Paddle.com, our merchant of record, for purchases. Paddle handles payment details under its own privacy notice; card numbers never reach us.
  • The provider that delivers the service's emails.

How long

  • Accounts are kept while they are in use. People are deactivated rather than deleted, because signatures and audit entries point at them. On request we anonymise your account; names recorded inside issued reports stay, because those reports are the organisation's business records.
  • Sign-in records and audit logs cannot be edited; how long they are kept will be stated here.
  • Content is kept for as long as the organisation's account exists.

Cookies

Only the ones the service needs: a session cookie, a security token against cross-site requests, and your choice of language. No advertising or tracking cookies.

Your rights

You may ask to see, correct, restrict or move your data, object to its use, or have it erased as described above, and you may complain to a data-protection authority. Where an organisation controls the data, we pass your request on to it.

Changes

We will publish changes to this notice here, and tell account holders by email about material ones.