CalibDue
Pricing Blog Sign in Start free trial

Privacy Policy

Effective date: 2 September 2026

This policy explains what CalibDue collects — both on this marketing website and, if your lab has an account, in the application itself — why, on what basis, how long we keep it, who we share it with, and how to request access to or deletion of it. We've written it to the standard we'd want as a visitor, using the GDPR's structure as the template, because it is the strictest common framework and CalibDue is built for labs anywhere.

1. Who we are

"CalibDue" ("we", "us", "our") operates the website at calibdue.com and the CalibDue application. For privacy questions, requests, or complaints, contact us at contact@calibdue.com — that address is the first and fastest route for any concern about how your data is handled.

2. What we collect

On this website. This site has no forms and collects no personal data directly. Signing up for CalibDue happens in the application at app.calibdue.com, not here; the site only links you there. If you accept the cookie banner, we load Google Analytics 4 with IP anonymisation enabled, which records aggregated visit information (pages viewed, approximate location at city level, device type, referrer); if you decline, no analytics data is sent. Our hosting provider keeps short-term technical access logs (IP address, user agent, timestamp) for security and abuse-prevention.

In the application, if your lab has an account. Creating a user account stores your first name, last name, email address, a hashed password, and your assigned role (admin, technician, or viewer). Your lab's account stores the lab name, time zone, accreditation standard, and which modules are enabled. Beyond that, the application stores the operational records your lab chooses to enter to use the product — equipment and calibration records, training and competency records, EQA results, maintenance logs, and controlled documents — which may themselves name staff (for example, the technician who performed a calibration, or the assessor on a competency record). When you acknowledge a controlled document version, we record your IP address alongside the acknowledgment as part of that record's evidence trail.

3. What we do not collect

We do not run advertising trackers, social-network pixels, session replay, fingerprinting, or any third-party scripts beyond those listed in Section 5. We do not sell your data. We do not buy data about you.

4. Why we process it, and on what basis

  • Email addresses collected before September 2026. Addresses given to the old "Get Early Access" form on this site are held so we can tell those people the product is now open. Basis: the consent given when the form was submitted. That form no longer exists, and you can ask us to delete your address at any time.
  • Analytics. To understand how the site is used and improve it. Basis: your consent, given via the cookie banner.
  • Server access logs. To secure the site and investigate abuse. Basis: our legitimate interest in keeping the site available and secure.
  • Account and operational data in the application. To provide the service you or your lab administrator set up an account for. Basis: performance of the agreement between us and your lab, and — for the audit trail and access-control records — our legitimate interest in keeping that evidence accurate and attributable.

5. Third parties we share data with

We use a small, named set of infrastructure providers. Some are live today; others are the intended provider for a stage the product hasn't reached yet — we say which is which:

  • Mailchimp (Intuit Inc., USA) — holds the email addresses collected by the early-access form that used to be on this site, and is the system we use to send marketing email. No new addresses are collected here. See Intuit's privacy statement.
  • Google Analytics 4 (Google LLC, USA) — only loaded after explicit consent; IP addresses are anonymised before processing. Live today, consent-gated. See Google's privacy policy.
  • Hostinger — our hosting provider for both this website and the application, which is live at app.calibdue.com.
  • Brevo — the transactional email provider used by the application for reminders, invitations, email verification, and password resets. Live today.
  • Sentry — error tracking for the application. The SDK is integrated in the codebase; ask us for its current status if it matters to your assessment.
  • AWS S3 — our intended object store for uploaded files. Not in use yet: files are written to the application server's own disk.

6. Cookies

This site sets cookies only under two specific conditions:

  • Consent preference. A small entry in your browser's localStorage (cd-consent-v1) records whether you accepted or rejected analytics, so we don't ask again on every page. This is set the moment you make a choice.
  • Google Analytics cookies. Set only if you choose "Accept" on the cookie banner. Used to distinguish unique visitors and sessions for aggregate analytics.

To withdraw your analytics consent later, clear the cd-consent-v1 entry from your browser storage (and any _ga cookies if already set) and refresh the page — the banner will reappear and you can choose again.

7. How long we keep your data

  • Email addresses collected before September 2026. Retained until you ask us to delete them, or until 12 months after we contact you and you have not engaged.
  • Analytics data. Retained by Google Analytics for 14 months (the default we have configured).
  • Server logs. Per our hosting provider's standard retention, typically 30 days.
  • Account and operational data in the application. Retained for as long as your lab's account is active. If your lab closes its account, contact us and we will discuss deletion or export of your data — see "Your rights" below.

8. Your rights

Depending on your location, you may have the right to access, correct, or delete your personal data, to object to or restrict its processing, to withdraw consent, and to receive a copy of your data in a portable format. To exercise any of these rights, or if you are unhappy with how we've handled a request, email contact@calibdue.com — from the email address associated with your account, if you have one. We will respond within 30 days.

9. Children

CalibDue is a business product for accredited laboratories and is not intended for anyone under 16. If you believe a child has provided us with personal information, contact us and we will delete it.

10. Security

This website is delivered over HTTPS and submits nothing — it holds no form and stores no personal data of its own. For how the application itself protects account and operational data, including what security controls exist today and what is still in progress, see our security page.

11. Changes to this policy

We may update this Privacy Policy from time to time. We will update the "Effective date" at the top of the page when we do. For material changes, we will additionally email account holders, and anyone still on our mailing list, before the change takes effect.

12. Contact

Questions, requests, or complaints about this policy: contact@calibdue.com.

This policy covers the marketing website and the application as it exists today. CalibDue is live and open to self-serve signup; paid billing is not yet switched on. This policy will be updated as the product and its data processing evolve — including once billing and a finalised operating entity are in place.

CalibDue

Lab equipment calibration tracking — done right.

Modules Calibration Training & Competency EQA / Proficiency Testing Preventive Maintenance Document Control
Product Features How it works Accreditation Pricing FAQ Start free trial Sign in
Blog All articles RSS feed
Legal Security Privacy Policy Terms of Service Refund Policy
© 2026 CalibDue. All rights reserved. Built for labs that can't afford to get it wrong.