IDRUNE Origin Privacy Policy
Last updated: 3 October 2026. This Privacy Policy explains how Build Actions Ltd, trading as IDRUNE Origin ("IDRUNE Origin", "we", "us", "our"), collects, uses, shares, and protects personal data through idrune.com, the {company}.idrune.com admin dashboard, and the public product pages reached by scanning a QR code or NFC tag (together, the "Service"). We are committed to complying with the UK GDPR, the EU GDPR, and the UK Data Protection Act 2018.
1. Three Different People This Policy Covers
This policy covers three different groups, because the Service works differently for each: (a) manufacturer account users — the staff of a company using IDRUNE Origin's admin dashboard, for whom IDRUNE Origin is the "data controller"; (b) end consumers — people who scan a QR code or NFC tag on a physical product and, optionally, register their warranty or leave feedback, for whom IDRUNE Origin acts as a "data processor" on behalf of the manufacturer (the controller) — see our Data Processing Agreement for the terms of that relationship; and (c) business contacts we have written to without being asked — people at manufacturing and importing companies whose work email address was published by their employer, for whom IDRUNE Origin is the data controller. Where this policy refers to "you", the relevant section makes clear which group it addresses.
If you are reading this because you received an email from us that you did not ask for, section 4 is written for you and answers the question you most likely have, which is where we got your address.
2. What Data We Collect
From manufacturer account users: name, email address, and password (stored as a salted hash — we never see or store your plain-text password); role/permissions within your company's account; activity-log records of actions you take in the dashboard.
From end consumers, only if you choose to register a product warranty or submit feedback: email address (required); name and phone number (optional, if the manufacturer's registration form asks for them); the specific product, serial number, and purchase context you register against; consent choices (e.g. whether you agree to receive recall/safety notices or product update notices) — recorded as an append-only log, so we always have an accurate history of what you actually agreed to and when, never a single value that could be silently changed.
From business contacts we have written to without being asked: a work email address published by the employer, a job title and name where those were published alongside it, and the page and date we took them from. Nothing is inferred and nothing is bought — see section 4.
From every visitor to a public product page (registered or not): scan/visit metadata — the country and city derived from your IP address, the address itself not being stored (section 7 explains exactly what happens to it), referrer (e.g. QR scan, NFC tap, direct link, campaign link), device/browser type, and which sections of the page you viewed and for how long. We do not collect or infer age, gender, or other demographic data from a scan.
3. How and Why We Use Your Data (Lawful Basis)
Manufacturer account data — operating your dashboard account — relies on contract necessity (Art. 6(1)(b)).
Consumer registration and consent data is processed on the manufacturer's instructions, as their processor, for the purposes they have configured (e.g. warranty administration, safety-notice reach calculation) — see our Data Processing Agreement for the processor terms this relies on.
Business contact data used to introduce ourselves to a manufacturer or importer relies on legitimate interests (Art. 6(1)(f)), assessed and documented in advance, and is explained in full in section 4 — including how to stop it, which takes one click.
Scan/visit analytics — helping the manufacturer understand how their product pages are reached — relies on the manufacturer's legitimate interest as controller, balanced against minimizing what we collect (your IP address is not stored, and we infer nothing demographic). We describe this as pseudonymous rather than anonymous, because the same device is recognisable as the same device: that is what makes a visitor count a count rather than a page count.
4. If We Emailed You Without You Asking Us To
This section is for group (c) in section 1: someone at a manufacturing, importing or distributing company who received an email from us and did not sign up for anything. UK GDPR Article 14 requires us to tell you certain things when we hold data about you that you did not give us yourself. This is that notice, and it is written to be read rather than to be complied with.
Where we got your address. From a source your employer chose to make public: your company's own website, or a public register such as Companies House or a producer register published under the Open Government Licence. We did not buy a list, we did not take it from a conference or association database, and we did not guess it from a pattern. We record the exact page and the date we took it from, for every address, and we can tell you both on request.
What we hold. Your work email address; where it was published, a job title and name; and company-level information that is not about you personally — company number, registered address, industry classification. We prefer a role address (such as quality@ or info@) over a named individual's wherever one exists, because it identifies a function rather than a person.
Why we are contacting you, and our lawful basis. Our basis is legitimate interests (Article 6(1)(f)). The interest is this: from 18 February 2027 the EU battery regulation requires a digital passport for products in its scope, and the wider Ecodesign framework extends that to other product groups afterwards. Companies placing goods on the EU market generally need a per-item passport page, and many do not yet know it. We publish those pages, so we write to tell you. We have carried out and documented a balancing assessment weighing our interest against your rights, and you can ask us for a summary of it.
What we will not do. We do not profile you, score you, or build a picture of you from other sources. We do not place a tracking pixel in our emails, so we do not know whether you opened one. We do not sell or share your details with anyone for their own marketing. We send at most two emails and then stop unless you reply.
How to make it stop, and how fast. Use the unsubscribe link in any email we sent you — one button, no sign-in, no account, and nothing for you to prove. You can also reply with the word "remove", or write to [email protected]. Your address then goes on a do-not-contact list and our sending system refuses it before any further email can be created. You do not have to give a reason, and we will not ask for one.
One thing worth being straight about. If you ask us to delete your data, we delete the record of your company, the source we took the address from, and anything you replied — but we keep the address itself, with the date you objected, on the do-not-contact list. That is the only way we can be sure never to write to you again; deleting it outright would leave us with no way to recognise you. The Information Commissioner's Office recommends suppression over deletion for exactly this reason.
How long we keep the rest. If you never respond, your record is deleted twelve months after we last contacted you, and what remains is an anonymous count by industry and outcome that cannot be traced back to you. If we had a conversation, twenty-four months.
Your rights. You can object to this processing at any time, and for direct marketing that objection is absolute — there is no balancing test and no delay. You can also ask for a copy of what we hold, ask us to correct it, or ask us to erase it, as described in section 8. Write to [email protected]. If you are not satisfied with how we respond, you can complain to the Information Commissioner's Office at ico.org.uk.
5. Who We Share Data With
We do not sell personal data. We share data only with: Stripe, to process manufacturer subscription payments; Anthropic, to provide AI-assisted translation/specification suggestions on content a human always reviews before it publishes; a transactional email provider, to send account and registration-related emails; hosting and infrastructure providers, to run the Service; law enforcement or regulators where required by law; and a successor entity in the event of a merger or acquisition, subject to the protections in this policy. See our Sub-Processors page for the full current list.
6. Where Your Data Is Held
The Service's shared database is hosted in London, United Kingdom. Some sub-processors process data outside the UK/EEA under their own approved transfer mechanism (such as Standard Contractual Clauses) — see our Sub-Processors page for exactly which ones and where.
7. Data Retention
Manufacturer account data is retained for as long as the company's account is active, plus any period required for legal, tax, or accounting purposes. Consumer registration and consent data is retained for as long as the manufacturer instructs, consistent with our Data Processing Agreement, or as needed to administer an active warranty — the append-only consent log itself is never deleted or altered, only ever added to, so there is always an accurate record of what was agreed and when, even after a later change of mind.
Scan/visit analytics are retained for a bounded period and then aggregated or deleted. Your IP address is not among what is stored. At the moment of the request it is used for two things — deriving the country and city, and computing a one-way salted hash — and is then discarded. The hash is what lets us tell one visitor from another without holding anything that identifies them; it cannot be reversed to recover the address, and because the salt is ours alone it cannot be matched against the same address held by anyone else.
8. Your Rights Under GDPR
Depending on your location, you have the right to access, rectify, erase, port, object to, and restrict processing of your personal data, and to withdraw consent at any time for consent-based processing, without affecting the lawfulness of processing before withdrawal.
If you are a manufacturer account user, contact your account administrator or [email protected]. If you are an end consumer who registered a product, we do not yet have a fully automated self-service tool for exercising these rights directly — contact [email protected], or the manufacturer whose product you registered, and we will process your request, normally within 30 days as required by UK GDPR. A self-service option is planned; until it exists, this is a real, disclosed gap rather than an implied capability.
You also have the right to lodge a complaint with the UK Information Commissioner's Office (ico.org.uk) or your local data protection authority.
9. Security
We use industry-standard measures including encrypted transport (HTTPS) throughout the Service, hashed passwords and API keys, and per-company data isolation enforced in our application code on every data access. We disclose honestly, rather than imply otherwise, that we have not yet completed a formal penetration test or ISO 27001 certification; a lightweight security questionnaire describing our current posture is available on request.
10. Children's Privacy
The Service is intended for use by businesses and their staff, and by consumers of physical products generally. We do not knowingly directly target children. If we become aware we have collected personal data from a child without appropriate consent, we will delete it.
11. Changes to This Policy
We may update this Privacy Policy from time to time. If changes are material, we will notify manufacturer account users by email or via a notice on the Service at least 14 days before they take effect. The "Last updated" date at the top reflects the most recent version.
12. Contact Information
- Build Actions Ltd, trading as IDRUNE Origin (part of the IDRUNE product family)
- Company number: 13333702
- Registered office: Unit Da2 Sutherland House, 43 Sutherland Road, London, United Kingdom, E17 6BU
- Privacy inquiries: [email protected]
- Legal/terms inquiries: [email protected]
- You may also lodge a complaint with the UK Information Commissioner's Office (ico.org.uk).
