Legal

Privacy Policy

This policy explains how personal data is handled when you visit or use HACCP PILOT.

Last updated: 3 October 2026

Who we are

HACCP PILOT is operated by BRAND IQ, a sole trader registered in Ireland ("we", "us" or "our").

For privacy questions or to exercise your rights, email hello@brandiq.ie.

Our role and your business

We are the controller for account administration, billing, support, service security and our limited product analytics.

For staff details, food-safety records and evidence entered by a customer, the customer business normally decides why and how the information is used. The customer is therefore normally the controller and BRAND IQ processes that information to provide HACCP PILOT. Staff should direct record-related requests to their employer first.

Data we collect

  • Account data: name, email, authentication details, role, sign-in status and assigned locations.
  • Business data: business and location details, equipment, suppliers, recipes, cleaning schedules and related settings.
  • Food-safety records: temperatures, deliveries, cooking and cooling, cleaning, corrective actions, traceability, training and other compliance records.
  • Evidence and documents: label photos, certificates, signatures, completed forms, PDFs and other files uploaded by authorised users.
  • Fitness-to-work data: SC7 answers may include health information. Access is restricted within the service. Customers and users must record only information that is necessary and lawful.
  • Billing data: subscription, plan and transaction status. Full card details are handled by Stripe and are not stored by HACCP PILOT.
  • Support and technical data: messages, device/browser information, security events and error details needed to diagnose and protect the service.
  • Optional analytics: limited milestone events, such as starting a trial or creating a first record. We do not include the contents of food-safety records.

How and why we use data

We use information to create and secure accounts, provide records and reports, process subscriptions, support users, maintain audit trails, prevent misuse, improve HACCP PILOT and comply with legal obligations.

Our legal bases under Irish and EU data-protection law include performing our contract, legitimate interests in operating and securing the service, compliance with legal obligations, and consent where required for optional analytics. Customers are responsible for identifying a valid basis for the staff, health and compliance information they enter.

Who receives data

We share information only as needed with service providers supporting HACCP PILOT, including Lovable Cloud infrastructure for application hosting, database, authentication and private file storage; Stripe for subscription payments; hosting and error-diagnostic services; and email-delivery services where applicable.

We may also disclose information when required by law, to protect legal rights or service security, or as part of a business transfer subject to appropriate safeguards. We do not sell personal data or use it for third-party advertising.

International transfers

Some service providers may process information outside Ireland or the European Economic Area. Where required, we rely on adequacy decisions, approved standard contractual clauses or another lawful transfer mechanism and require appropriate safeguards.

How long we keep data

We keep account and operational data while an account is active and for as long as reasonably required to provide the service, meet legal obligations, resolve disputes and protect legal rights. Subscription expiry places an account in read-only status for 90 days and then in Archived / Subscription Required status; compliance records are not automatically deleted.

Customers should export records according to their own legal retention obligations. When deletion is requested or an account is closed, we delete or anonymise information when no longer required, subject to legal, security, backup and dispute-retention needs.

Security

We use access controls, tenant and location restrictions, private file storage, signed file links, audit records and other technical and organisational measures designed to protect information. No online service can guarantee absolute security. Users must protect their credentials and promptly report suspected unauthorised access.

Your rights

Depending on the circumstances, you may have rights to access, correct, erase, restrict or object to processing, receive portable data, and withdraw consent without affecting earlier lawful processing. You may also complain to Ireland's Data Protection Commission at dataprotection.ie.

Email requests to hello@brandiq.ie. We may need to verify your identity. If your employer controls the relevant records, we may refer the request to that business.

Cookies and policy changes

See our Cookie Policy and use Cookie settings in the footer to manage optional analytics.

We may update this policy when the service or law changes. Material changes will be communicated where appropriate, and the updated date will appear above.