Privacy Policy
The short version
U-ELTOS is a business system used by companies that trade and move commodities. Almost everything in it is commercial data — cargoes, contracts, invoices — not personal data. The personal data we do hold is mostly the small amount needed to give someone an account and to record what they did with it.
We do not sell personal data, we do not use it for advertising, and we do not use customer content to train models.
Two different roles
As controller. For the accounts we issue — name, work email, role, sign-in records — we decide why and how the data is processed, so we are the controller.
As processor. For everything a customer puts into the system, we act on that customer’s instructions. If a contract names an individual broker, or a port agent’s email sits on a record, that is the customer’s data and the customer is the controller. Requests about it should go to them; if they reach us first we will pass them on.
What we hold, and why
- Account details
- Name, work email, organisation, role and module entitlements — so we can tell who you are and what you are allowed to see. Basis: performance of the contract with your employer.
- Authentication records
- Sign-in attempts (successful and failed), IP address, browser user-agent, session start and end, second-factor enrolment. Kept so an account takeover can be spotted and reconstructed. Basis: legitimate interest in securing the service.
- Audit log
- Who changed what, and when. This is deliberately append-only — it cannot be edited or deleted, including by us. In a commodity trading system the value of the record is precisely that nobody can quietly revise it. Basis: legitimate interest, and in most cases our customers’ own legal and regulatory obligations.
- Support correspondence
- What you send us when you ask for help. Basis: legitimate interest.
- Operational telemetry
- Error reports and performance measurements, so faults can be found. We keep these free of commercial content wherever we can.
What we do not do
- No advertising, and no advertising trackers.
- No sale or sharing of personal data with data brokers.
- No automated decision-making with a legal or similarly significant effect.
- No use of customer content to train machine-learning models.
Cookies
Only what sign-in requires. A session cookie that identifies your sitting, and a small flag recording whether you ticked “remember me”. Both are HttpOnly, so page scripts cannot read them. There are no analytics or advertising cookies, which is why this site does not ask you to accept any.
Who else sees it
Only the processors needed to run the service: our cloud hosting and database provider, our application hosting provider, and the service that sends transactional email such as password resets. Each is bound by a written agreement and may act only on our instructions. We will keep an up-to-date list available to customers on request.
We may also disclose data where the law requires it. Where we are lawfully able to tell the affected customer first, we will.
Where it is held
Data is held in the region agreed with the customer. Where personal data leaves the UK or EEA it is transferred under an approved mechanism — adequacy regulations or standard contractual clauses.
How long we keep it
- Account details: while the account exists, then up to 12 months.
- Authentication records: 24 months.
- Audit log: for the life of the customer relationship and then as long as that customer’s own retention obligations require. It is append-only, so entries are removed by expiry of the whole record, never edited out.
- Customer content: while the subscription runs, then 30 days, then deleted.
- Support correspondence: 24 months.
How it is protected
- Encrypted in transit and at rest.
- Commercial data is read and written by the server only. There is no database key in the browser.
- Access is by module entitlement, checked on every page and again in the database.
- Administrative consoles require a second factor beyond the password.
- Where our staff need to see a customer’s screen to support them, that access is read-only and every use of it is logged under the real person, not the account being viewed.
Your rights
Depending on where you live you may ask for a copy of your personal data, ask us to correct it, ask us to delete it, object to or restrict processing, or ask for it in a portable form. You may also withdraw consent where processing relies on consent.
Where we act as processor we will refer the request to the customer who controls the data, because they are the ones entitled to decide. Where we act as controller we will respond within one month.
One limit worth stating plainly: we cannot delete individual entries from the audit log. It is append-only by design, and that design is what makes it trustworthy. If that affects a request you are making, we will tell you and explain what we can do instead.
Complaints
Tell us first and we will try to put it right. You also have the right to complain to your data protection authority — in the UK, the Information Commissioner’s Office.
Contact
Privacy questions can be sent to the contact address on your order form. If you reached this page from a sign-in screen at your employer, your own IT administrator is the fastest route.