← Authentrace

Privacy notice

Last updated 21 August 2026

This notice describes what happens to personal data when you use Authentrace. It is written to be checked against the system rather than to reassure: where we say something is not stored, that is a property of how the software is built, not a policy we intend to follow.

The short version. Scanning a product to check whether it is genuine does not require an account and does not identify you. If you apply to a patient assistance programme, your application is passed to the programme's sponsor and is not stored by us. If you use the producer console, we hold the account and business records needed to run it.

1. Who is responsible

Authentrace operates the service. Group entities and their registrations are listed in the legal notice; that page also names our EU representative under Article 27 GDPR once designated. For anything in this notice, write to legal@authentrace.ai.

Where a producer configures a passport or an assistance programme, that producer decides what is published and to whom applications go. For those decisions the producer is the controller and Authentrace acts on their instructions.

2. Scanning a product

A tap or scan sends the chip's own identifier, its read counter and a cryptographic code. We record the scan so the producer can detect counterfeiting patterns — duplicated tags, harvested codes, stock appearing in a market it was never allocated to.

RecordedWhyKept
Tag identifier, read counter, verdictDetecting cloned and replayed tagsFor the life of the tag
Country of the scan, as reported by our network edgeDetecting stock diverted outside its marketWith the scan record
Time of the scanOrdering the aboveWith the scan record

Not recorded: your name, your account (you do not need one), your precise location, or your IP address against the scan. Location is coarse by design — a country, never a place. Server request logs are kept for seven days and are configured not to store IP addresses.

3. Patient assistance programmes

Some medicines carry a link to a manufacturer's cost-assistance programme. If you apply, you may provide contact details, circumstances relevant to eligibility, and — if the programme asks for them — photographs of documents such as a prescription. In the EU this is special category data under Article 9 GDPR, and it is handled accordingly.

We do not keep your application. There is no submissions table in this system, by design. Your answers and any documents are held in memory only for as long as it takes to pass them to the programme's sponsor, then discarded. What remains with us is that an application was relayed for a given programme, and whether it succeeded — never its contents.

Reading a photographed document

If you photograph a document, the image is sent to an optical character recognition service to extract its text, so you do not have to type it. That service is Mistral AI, operating in the European Union, and it was chosen for that reason. The image is transmitted for processing and is not retained by us. Extraction only ever fills in fields the programme already asked for.

You can decline this. Typing the details yourself works, and a programme that asks for a document will say what it needs.

Who receives it

The sponsor named on the programme — the manufacturer or the administrator they appoint. What you send goes to them, and their own privacy notice governs what they do with it. We pass it on; we do not analyse it, profile you, or use it for anything else.

4. Producer console accounts

If you work for a producer using Authentrace, we hold your name and work email, your role in the organisation, your organisation's records (products, passports, production batches), and an audit log of significant actions — who issued a recall, who authorised a batch, who invited an administrator. The audit log exists to answer questions after the fact and is append-only. Sign-in alerts are sent when your account is used from a new location.

5. Legal bases

ProcessingBasis (GDPR Art. 6)
Verifying a scan and recording itLegitimate interests — detecting counterfeiting, which protects buyers and producers alike
Relaying an assistance applicationYour explicit consent, given by submitting it (Art. 9(2)(a) for health data)
Running console accountsPerformance of a contract with the producer
Audit logging and securityLegal obligation and legitimate interests

6. International transfers

Service infrastructure runs in the European Union (Google Cloud, europe-west9), and application email is sent from an EU region. During the pilot, administration is carried out from Bangladesh, which is not covered by a European Commission adequacy decision. Transfers of personal data outside the EEA are made under the European Commission's Standard Contractual Clauses, with supplementary measures where required.

pending — the executed clauses and the transfer assessment are being completed as part of establishing the EU entity. Until they are, EU-facing processing is limited to the pilot described here. Ask legal@authentrace.ai for the current position before relying on it.

7. Retention

Assistance applicationsNot stored — passed on and discarded
Document photographsNot stored — read in memory, discarded
Scan recordsLife of the tag; they concern the object, not you
Server request logs7 days, without IP addresses
Console accountsWhile the account exists, then removed
Audit logAppend-only; retained for the accountability it exists to provide

8. Your rights

Where the GDPR applies you may request access to your personal data, its correction or erasure, restriction of or objection to processing, and portability; and you may withdraw consent at any time. Write to legal@authentrace.ai.

An honest limitation: for a product scan we hold no identifier that links to you, so we cannot find “your” scans — there is nothing to retrieve or erase, which is the point of collecting it that way. For an assistance application, we no longer hold it; the sponsor does, and their notice tells you how to reach them.

You also have the right to complain to a supervisory authority — in the EU, the authority where you live or work.

9. Cookies

The public verification page sets no cookies and loads no third-party scripts or trackers. The producer console stores a sign-in token in your browser so you stay signed in; it is necessary for the console to work and is not used for tracking.

10. Changes

Material changes will be reflected here with a new date at the top. During the pilot this notice is expected to change as entities and safeguards are registered; the pending markers show what is not settled yet.