Pilot Baseline
Privacy Notice
TraceDX handles workshop, vehicle, evidence, diagnostic, and account data. This notice explains the pilot data posture in plain language.
Controller and Contact
Nordic Creative Limited, company number 07580121, registered office 124 City Road, London, England, EC1V 2NX, is the controller for TraceDX.
Contact support@tracedx.io for privacy questions or to exercise a data right. Eliot Webb, Director, owns the private-pilot privacy decisions. This notice is the controller's pilot position, not a claim of independent legal review.
Data TraceDX Handles
TraceDX can process account email and authentication data; workshop and workspace details; vehicle registrations, VINs, vehicle details and photos; case complaints and notes; text, audio, image and PDF evidence; extracted observations; assessments, searches and citations; test results; reports and outcomes; feedback and support correspondence; and bounded technical, security, cost and audit metadata.
Vehicle identifiers, customer-linked histories, photos, reports and workshop notes are treated as sensitive operational data. Please avoid submitting special-category or criminal-offence data unless it is genuinely necessary and an appropriate legal condition has been confirmed.
Purposes and Lawful Bases
Contract, or steps you request before contract, covers invitations you request, account access, authentication, workspace delivery, evidence handling, AI-supported assessments, results, reports, outcomes and requested support where that processing is necessary to provide the service.
Legitimate interests cover reliable hosting, privacy-conscious observability, security and abuse investigation, backups and restore tests, provider cost/lifecycle controls, support audit, limited professional-pilot feedback and proportionate B2B invitation administration. Our interests are delivering and protecting the service; safeguards include private workspace scope, data minimisation, scrubbing, access controls, short retention and review of objections.
Legal obligation applies only where an identified law, regulator or binding order requires processing. Otherwise defensible request and complaint administration relies on legitimate interests.
Optional learning contribution requires a separate positive consent, is off by default and can be withdrawn before irreversible anonymisation. We do not call pseudonymised data anonymous.
Storage and Access
Workspace data is scoped by workspace membership. Raw evidence files are stored in private Supabase Storage paths, not public buckets.
Support access is restricted by a server-side allowlist and normally uses aggregate or bounded metadata. Deeper workspace investigation should happen only for a specific support request or documented security incident.
Application Providers
Supabase provides authentication, database and private file storage. Vercel hosts the application and records short-lived runtime/request metadata. Sentry receives scrubbed errors, stack traces, release, route and bounded device/network metadata for reliability; the SDK does not enable session replay or default PII, although the hosted project may process an IP address as limited network metadata.
OpenAPI Automotive receives a selected country and registration for UK/France vehicle lookup and returns vehicle identity data, potentially including a VIN. Resend delivers pilot enquiries and Supabase authentication emails. Zoho Mail receives support and data-rights correspondence. Google Drive holds only encrypted off-site backup archives and separate checksums.
These are twelve application flows: Supabase platform; Vercel runtime logs; Sentry observability; OpenAI Current Assessment; OpenAI conditional assessment web search; OpenAI voice transcription; OpenAI image/PDF extraction; OpenAI natural-language evidence organisation; OpenAPI Automotive registration lookup; Resend pilot enquiries; Resend authentication email; and encrypted Google Drive backup. Zoho Mail is the additional support/data-rights mailbox recipient.
OpenAI Processing
OpenAI receives compact vehicle/case/evidence/result context to generate a schema-constrained Current Assessment; case-derived search queries only when an eligible expanded reference check invokes OpenAI's hosted web search; raw audio and filename for transcription; image/PDF bytes, filename and visible identity content for extraction; and technician text or transcript segments for evidence organisation.
The application uses global OpenAI API endpoints. OpenAI's published subprocessors may process data in the UK, EEA and other countries. The OpenAI Data Processing Addendum uses Standard Contractual Clauses, including the UK Addendum where applicable. We do not claim EU-only OpenAI processing.
Current Assessment, image/PDF extraction and natural-language organisation use the Responses API without Zero Data Retention or Modified Abuse Monitoring. The documented default can include application state and abuse-monitoring logs for up to 30 days, subject to legal or harm-prevention exceptions; possible CSAM material may be retained for review. The transcription endpoint is documented without application-state or abuse-monitoring retention. We do not guarantee provider deletion exactly on day 30.
OpenAI states that API data is not used to train models unless the customer opts in. Nordic Creative Limited has not enabled model-feedback, evaluation/fine-tuning, or API input/output sharing and has approved no training opt-in.
International Transfers
Supabase's linked project and Sentry's project are hosted in the EU, and application functions are configured for Frankfurt. Other routing, support, subprocessors, email delivery, OpenAI processing, OpenAPI Automotive and Google services may involve processing outside the UK or EEA.
Where required, transfers rely on provider contracts, adequacy decisions, Standard Contractual Clauses and the UK Addendum, together with technical safeguards such as encryption, private storage, access control and data minimisation. Contact us for current provider information.
Retention
RET-1: account, workspace, vehicle, case, evidence, assessment, result, report and outcome records are kept while the pilot or later client service is active, then for six months after the later of service/account closure or last substantive workspace/case activity.
RET-2: terminal pilot/workspace invitations are kept for 90 days. RET-3A: unusable pending identity scans/lookups and their raw private objects are kept for 30 days after their terminal state or expiry. RET-3B and RET-3C: uncommitted upload manifests and assessment reservations are kept for up to 24 hours after expiry or settlement.
RET-4A: provider budget/usage, cleanup lease and support-audit records are kept for 12 months. RET-4B: semantic-health events are kept for 30 days after operational expiry. RET-5: feedback and direct pilot/support correspondence are kept for six months after the later of last substantive contact or the end of the pilot/client relationship.
RET-6: shared test templates are product reference data, reviewed after supersession and removal of restrictive references rather than treated as participant data. RET-7: encrypted backup archives and checksums are kept on a rolling 90-day basis and removed only after a newer checksum-valid restore proof exists.
Provider copies can follow provider contractual or legal periods: Vercel Pro runtime logs are available for one day, Resend email data for 30 days, and OpenAI follows the limits described above. OpenAPI Automotive does not provide an exact per-lookup deletion assurance, so the controller does not promise provider deletion at day 30.
Holds and Backups
A legal claim, binding duty, active security incident, verified restriction/export request, or active backup/restore incident may pause deletion only for the affected scope. The hold is reviewed every 30 days and overdue deletion completes within 30 days after it ends.
A verified erasure request may shorten a normal period. Older encrypted backups remain protected until their rolling expiry; if one is restored, the controller reconciles it against completed erasures so deleted data is not silently reintroduced.
Your Rights and Complaints
Depending on the processing and circumstances, you may request access, correction, erasure, restriction or portability, object to legitimate-interests processing, and withdraw an optional consent without affecting earlier lawful processing. These rights are not absolute and we will explain any lawful limitation.
Contact support@tracedx.io from your pilot account email and identify the relevant workspace, vehicle or case where possible. We may verify your identity and authority before acting.
You may complain to the UK Information Commissioner's Office or contact it for guidance.