Last updated 21 August 2026
This notice describes what happens to personal data when you use Authentrace. It is written to be checked against the system rather than to reassure: where we say something is not stored, that is a property of how the software is built, not a policy we intend to follow.
Authentrace operates the service. Group entities and their registrations are listed in the legal notice; that page also names our EU representative under Article 27 GDPR once designated. For anything in this notice, write to legal@authentrace.ai.
Where a producer configures a passport or an assistance programme, that producer decides what is published and to whom applications go. For those decisions the producer is the controller and Authentrace acts on their instructions.
A tap or scan sends the chip's own identifier, its read counter and a cryptographic code. We record the scan so the producer can detect counterfeiting patterns — duplicated tags, harvested codes, stock appearing in a market it was never allocated to.
| Recorded | Why | Kept |
|---|---|---|
| Tag identifier, read counter, verdict | Detecting cloned and replayed tags | For the life of the tag |
| Country of the scan, as reported by our network edge | Detecting stock diverted outside its market | With the scan record |
| Time of the scan | Ordering the above | With the scan record |
Not recorded: your name, your account (you do not need one), your precise location, or your IP address against the scan. Location is coarse by design — a country, never a place. Server request logs are kept for seven days and are configured not to store IP addresses.
Some medicines carry a link to a manufacturer's cost-assistance programme. If you apply, you may provide contact details, circumstances relevant to eligibility, and — if the programme asks for them — photographs of documents such as a prescription. In the EU this is special category data under Article 9 GDPR, and it is handled accordingly.
If you photograph a document, the image is sent to an optical character recognition service to extract its text, so you do not have to type it. That service is Mistral AI, operating in the European Union, and it was chosen for that reason. The image is transmitted for processing and is not retained by us. Extraction only ever fills in fields the programme already asked for.
You can decline this. Typing the details yourself works, and a programme that asks for a document will say what it needs.
The sponsor named on the programme — the manufacturer or the administrator they appoint. What you send goes to them, and their own privacy notice governs what they do with it. We pass it on; we do not analyse it, profile you, or use it for anything else.
If you work for a producer using Authentrace, we hold your name and work email, your role in the organisation, your organisation's records (products, passports, production batches), and an audit log of significant actions — who issued a recall, who authorised a batch, who invited an administrator. The audit log exists to answer questions after the fact and is append-only. Sign-in alerts are sent when your account is used from a new location.
| Processing | Basis (GDPR Art. 6) |
|---|---|
| Verifying a scan and recording it | Legitimate interests — detecting counterfeiting, which protects buyers and producers alike |
| Relaying an assistance application | Your explicit consent, given by submitting it (Art. 9(2)(a) for health data) |
| Running console accounts | Performance of a contract with the producer |
| Audit logging and security | Legal obligation and legitimate interests |
Service infrastructure runs in the European Union (Google Cloud, europe-west9), and application email is sent from an EU region. During the pilot, administration is carried out from Bangladesh, which is not covered by a European Commission adequacy decision. Transfers of personal data outside the EEA are made under the European Commission's Standard Contractual Clauses, with supplementary measures where required.
pending — the executed clauses and the transfer assessment are being completed as part of establishing the EU entity. Until they are, EU-facing processing is limited to the pilot described here. Ask legal@authentrace.ai for the current position before relying on it.
| Assistance applications | Not stored — passed on and discarded |
| Document photographs | Not stored — read in memory, discarded |
| Scan records | Life of the tag; they concern the object, not you |
| Server request logs | 7 days, without IP addresses |
| Console accounts | While the account exists, then removed |
| Audit log | Append-only; retained for the accountability it exists to provide |
Where the GDPR applies you may request access to your personal data, its correction or erasure, restriction of or objection to processing, and portability; and you may withdraw consent at any time. Write to legal@authentrace.ai.
An honest limitation: for a product scan we hold no identifier that links to you, so we cannot find “your” scans — there is nothing to retrieve or erase, which is the point of collecting it that way. For an assistance application, we no longer hold it; the sponsor does, and their notice tells you how to reach them.
You also have the right to complain to a supervisory authority — in the EU, the authority where you live or work.
The public verification page sets no cookies and loads no third-party scripts or trackers. The producer console stores a sign-in token in your browser so you stay signed in; it is necessary for the console to work and is not used for tracking.
Material changes will be reflected here with a new date at the top. During the pilot this notice is expected to change as entities and safeguards are registered; the pending markers show what is not settled yet.