Privacy Policy
Effective date:
This policy explains what CalibDue collects — both on this marketing website and, if your lab has an account, in the application itself — why, on what basis, how long we keep it, who we share it with, and how to request access to or deletion of it. We've written it to the standard we'd want as a visitor, using the GDPR's structure as the template, because it is the strictest common framework and CalibDue is built for labs anywhere.
1. Who we are
"CalibDue" ("we", "us", "our") operates the website at calibdue.com and the CalibDue application. For privacy questions, requests, or complaints, contact us at contact@calibdue.com — that address is the first and fastest route for any concern about how your data is handled.
2. What we collect
On this website. This site has no forms and collects
no personal data directly. Signing up for CalibDue happens in the
application at app.calibdue.com, not here; the site only
links you there. If you accept the cookie banner, we load
Google Analytics 4 with IP anonymisation enabled, which records
aggregated visit information (pages viewed, approximate location at
city level, device type, referrer); if you decline, no analytics data
is sent. Our hosting provider keeps short-term technical access logs
(IP address, user agent, timestamp) for security and
abuse-prevention.
In the application, if your lab has an account. Creating a user account stores your first name, last name, email address, a hashed password, and your assigned role (admin, technician, or viewer). Your lab's account stores the lab name, time zone, accreditation standard, and which modules are enabled. Beyond that, the application stores the operational records your lab chooses to enter to use the product — equipment and calibration records, training and competency records, EQA results, maintenance logs, and controlled documents — which may themselves name staff (for example, the technician who performed a calibration, or the assessor on a competency record). When you acknowledge a controlled document version, we record your IP address alongside the acknowledgment as part of that record's evidence trail.
3. What we do not collect
We do not run advertising trackers, social-network pixels, session replay, fingerprinting, or any third-party scripts beyond those listed in Section 5. We do not sell your data. We do not buy data about you.
4. Why we process it, and on what basis
- Email addresses collected before September 2026. Addresses given to the old "Get Early Access" form on this site are held so we can tell those people the product is now open. Basis: the consent given when the form was submitted. That form no longer exists, and you can ask us to delete your address at any time.
- Analytics. To understand how the site is used and improve it. Basis: your consent, given via the cookie banner.
- Server access logs. To secure the site and investigate abuse. Basis: our legitimate interest in keeping the site available and secure.
- Account and operational data in the application. To provide the service you or your lab administrator set up an account for. Basis: performance of the agreement between us and your lab, and — for the audit trail and access-control records — our legitimate interest in keeping that evidence accurate and attributable.
5. Third parties we share data with
We use a small, named set of infrastructure providers. Some are live today; others are the intended provider for a stage the product hasn't reached yet — we say which is which:
- Mailchimp (Intuit Inc., USA) — holds the email addresses collected by the early-access form that used to be on this site, and is the system we use to send marketing email. No new addresses are collected here. See Intuit's privacy statement.
- Google Analytics 4 (Google LLC, USA) — only loaded after explicit consent; IP addresses are anonymised before processing. Live today, consent-gated. See Google's privacy policy.
- Hostinger — our hosting provider for both this
website and the application, which is live at
app.calibdue.com. - Brevo — the transactional email provider used by the application for reminders, invitations, email verification, and password resets. Live today.
- Sentry — error tracking for the application. The SDK is integrated in the codebase; ask us for its current status if it matters to your assessment.
- AWS S3 — our intended object store for uploaded files. Not in use yet: files are written to the application server's own disk.
6. Cookies
This site sets cookies only under two specific conditions:
- Consent preference. A small entry in your browser's
localStorage(cd-consent-v1) records whether you accepted or rejected analytics, so we don't ask again on every page. This is set the moment you make a choice. - Google Analytics cookies. Set only if you choose "Accept" on the cookie banner. Used to distinguish unique visitors and sessions for aggregate analytics.
To withdraw your analytics consent later, clear the
cd-consent-v1 entry from your browser storage (and any
_ga cookies if already set) and refresh the page — the
banner will reappear and you can choose again.
7. How long we keep your data
- Email addresses collected before September 2026. Retained until you ask us to delete them, or until 12 months after we contact you and you have not engaged.
- Analytics data. Retained by Google Analytics for 14 months (the default we have configured).
- Server logs. Per our hosting provider's standard retention, typically 30 days.
- Account and operational data in the application. Retained for as long as your lab's account is active. If your lab closes its account, contact us and we will discuss deletion or export of your data — see "Your rights" below.
8. Your rights
Depending on your location, you may have the right to access, correct, or delete your personal data, to object to or restrict its processing, to withdraw consent, and to receive a copy of your data in a portable format. To exercise any of these rights, or if you are unhappy with how we've handled a request, email contact@calibdue.com — from the email address associated with your account, if you have one. We will respond within 30 days.
9. Children
CalibDue is a business product for accredited laboratories and is not intended for anyone under 16. If you believe a child has provided us with personal information, contact us and we will delete it.
10. Security
This website is delivered over HTTPS and submits nothing — it holds no form and stores no personal data of its own. For how the application itself protects account and operational data, including what security controls exist today and what is still in progress, see our security page.
11. Changes to this policy
We may update this Privacy Policy from time to time. We will update the "Effective date" at the top of the page when we do. For material changes, we will additionally email account holders, and anyone still on our mailing list, before the change takes effect.
12. Contact
Questions, requests, or complaints about this policy: contact@calibdue.com.
This policy covers the marketing website and the application as it exists today. CalibDue is live and open to self-serve signup; paid billing is not yet switched on. This policy will be updated as the product and its data processing evolve — including once billing and a finalised operating entity are in place.