Privacy policy
1. What we collect
- The plan-review demo. The plan text you paste or upload is sent to our review pipeline and discarded when the response is returned. It is not stored. If you ask for the report by email, we store your email address, the species and process you chose, the findings exactly as shown to you, and the time of the request. That is the only email capture on the site.
- Accounts. Your email address, name, organization, and the role and trained-individual designation you or your organization set. Sign-in is by emailed link; we do not store passwords.
- The file itself. Supplier and product records, HACCP plans, guarantees, certificates, test results, shipment records, and the signed verification log an importer keeps in Keelsure, and the plans and records a processor keeps in Draft.
- Usage. Page views and a small number of product events (a demo review started, a demo review completed, a report emailed) through Vercel Analytics, which does not use cookies and does not identify individual visitors. Server logs record requests for security and debugging.
2. How we use it
To provide the service, including running plan reviews, sending the emails you ask for, sweeping for expiring documents, and producing the binder. To send transactional email: sign-in links, supplier invitations, expiry notices, the demo report. To reply when you write to us. To understand which pages are read and whether the demo is used. We do not sell personal data, we do not run advertising, and we do not use your file to train any model.
3. Who sees it
- Inside the service. An importer sees only its own organization’s file. A processor’s documents in Draft are private by default and visible only to the importer who invited that processor — uploading through that invitation is what shares them. No importer sees another importer’s data, and no processor’s documents are visible to an importer that did not invite them.
- Providers we rely on. Vercel (hosting, file storage, analytics), Neon (database), Anthropic (the language model that reads plan text during a review; plan text is sent to it for that purpose and is subject to its API data terms, which do not permit training on customer content), and Google Workspace (outbound email). Each processes data only to provide its service to us.
- When required. We will disclose data where the law requires it. If a regulator asks us for your records, we will tell you unless we are legally barred from doing so.
4. How long we keep it
- Demo report requests: twelve months, then deleted.
- Account and file data: for the life of the account and, after termination, thirty days for export, then deleted. Verification records you have marked as required for a retention period under 21 CFR 123.9 are kept for that period if you ask us to.
- Server logs: ninety days.
5. Your choices
Email hello@keelsure.com to see, correct, export, or delete the personal data we hold about you, or to withdraw a demo report request. We answer within thirty days. Deleting an account deletes its file except where a retention period you set, or the law, requires otherwise.
6. Security
Data is encrypted in transit and at rest by the providers above. Access is scoped to your organization on every query. The verification log is append-only and hash-chained so that an entry cannot be altered or backdated after the fact. No system is perfectly secure; if we learn of a breach affecting your data we will tell you promptly.
7. Changes
We will post changes here and, for material changes, email account holders at least thirty days before they take effect.