Disclaimer: This website is not an official GS1 publication and is currently in development. The content, mappings, and AI-generated responses are for testing and demonstration purposes only and should not be used for compliance decisions or official reporting. Always refer to official GS1 documentation and regulatory texts for authoritative information.

Privacy Policy

Last updated: January 2, 2026

1. Introduction

Welcome to the Intelligent Standards Architect (ISA), operated by GS1 Netherlands. We are committed to protecting your personal data and respecting your privacy. This privacy policy explains how we collect, use, and safeguard your information when you use our platform.

ISA is designed to help organizations navigate ESG regulations and GS1 standards. We process minimal personal data necessary to provide our services and comply with applicable data protection laws, including the General Data Protection Regulation (GDPR).

2. Data Controller

The data controller responsible for your personal data is:

GS1 Netherlands

Stationsplein 9K

3818 LE Amersfoort

The Netherlands

Email: [email protected]

3. Information We Collect

We collect and process the following types of information:

3.1 Account Information

When you create an account or log in via Manus OAuth, we collect:

  • Name and email address
  • User ID (generated by our authentication system)
  • Account creation date
  • Role (user or admin)

3.2 Usage Data

We automatically collect information about how you use ISA:

  • Pages viewed and features accessed
  • Search queries and filters applied
  • Analysis requests and AI interactions
  • Time spent on the platform
  • Device type and browser information

3.3 User-Generated Content

When you use ISA's features, we store:

  • Saved regulations and standards
  • Custom alerts and notifications
  • Analysis history and reports
  • Collaboration notes and comments

4. How We Use Your Information

We use your personal data for the following purposes:

4.1 Service Provision

To provide and maintain ISA's core functionality, including regulation tracking, standards mapping, AI-powered analysis, and personalized recommendations.

Legal basis: Performance of contract (GDPR Article 6(1)(b))

4.2 Communication

To send you important updates about regulations, system notifications, and responses to your inquiries.

Legal basis: Legitimate interests (GDPR Article 6(1)(f))

4.3 Improvement and Analytics

To analyze usage patterns, improve our services, and develop new features based on aggregated, anonymized data.

Legal basis: Legitimate interests (GDPR Article 6(1)(f))

4.4 Security and Compliance

To protect against fraud, ensure platform security, and comply with legal obligations.

Legal basis: Legal obligation (GDPR Article 6(1)(c)) and legitimate interests (GDPR Article 6(1)(f))

5. Data Sharing and Disclosure

We do not sell your personal data. We may share your information only in the following circumstances:

5.1 Service Providers

We work with trusted third-party service providers who assist in operating ISA:

  • Hosting: Manus (cloud infrastructure and deployment)
  • Database: TiDB Serverless (data storage)
  • Authentication: Manus OAuth (user authentication)
  • AI Services: OpenAI (content analysis and recommendations)

All service providers are contractually bound to protect your data and use it only for the purposes we specify.

5.2 Legal Requirements

We may disclose your information if required by law, court order, or governmental authority, or to protect our rights, property, or safety.

6. Data Retention

We retain your personal data only as long as necessary for the purposes outlined in this policy:

  • Account data: Retained while your account is active and for 90 days after account deletion
  • Usage logs: Retained for 12 months for security and analytics
  • Analysis history: Retained while your account is active
  • Error logs: Retained for 30 days for debugging purposes

After the retention period, we securely delete or anonymize your data.

7. Your Rights

Under GDPR, you have the following rights regarding your personal data:

Right to Access

You can request a copy of the personal data we hold about you.

Right to Rectification

You can request correction of inaccurate or incomplete data.

Right to Erasure

You can request deletion of your personal data ("right to be forgotten").

Right to Data Portability

You can request a copy of your data in a structured, machine-readable format.

Right to Object

You can object to processing based on legitimate interests.

Right to Withdraw Consent

Where processing is based on consent, you can withdraw it at any time.

To exercise any of these rights, please contact us at [email protected]. We will respond to your request within 30 days.

8. Data Security

We implement appropriate technical and organizational measures to protect your personal data:

  • Encryption of data in transit (HTTPS/TLS) and at rest
  • Secure authentication with OAuth 2.0
  • Regular security audits and vulnerability assessments
  • Access controls and role-based permissions
  • Automated backups with 7-day retention
  • Rate limiting and DDoS protection

9. International Data Transfers

Your data is primarily stored and processed within the European Economic Area (EEA). If we transfer data outside the EEA, we ensure adequate safeguards are in place, such as Standard Contractual Clauses approved by the European Commission.

10. Cookies and Tracking

ISA uses minimal cookies necessary for functionality:

  • Session cookies: To maintain your login state (essential)
  • Analytics cookies: To understand usage patterns (anonymized)

We do not use advertising or tracking cookies. You can manage cookie preferences in your browser settings.

11. Children's Privacy

ISA is not intended for individuals under 16 years of age. We do not knowingly collect personal data from children. If you believe we have inadvertently collected data from a child, please contact us immediately.

12. Changes to This Policy

We may update this privacy policy from time to time to reflect changes in our practices or legal requirements. We will notify you of significant changes by email or through a prominent notice on ISA. The "Last updated" date at the top indicates when the policy was last revised.

13. Contact Us

If you have questions about this privacy policy or how we handle your data, please contact us:

GS1 Netherlands

Email: [email protected]

Phone: +31 (0)33 450 11 00

Address: Stationsplein 9K, 3818 LE Amersfoort, The Netherlands

You also have the right to lodge a complaint with the Dutch Data Protection Authority (Autoriteit Persoonsgegevens) if you believe we have not handled your data appropriately.