IDRUNE Origin Privacy Policy
Last updated: 26 July 2026. This Privacy Policy explains how Build Actions Ltd, trading as IDRUNE Origin ("IDRUNE Origin", "we", "us", "our"), collects, uses, shares, and protects personal data through idrune.com, the {company}.idrune.com admin dashboard, and the public product pages reached by scanning a QR code or NFC tag (together, the "Service"). We are committed to complying with the UK GDPR, the EU GDPR, and the UK Data Protection Act 2018.
1. Two Different People This Policy Covers
This policy covers two different groups, because the Service works differently for each: (a) manufacturer account users — the staff of a company using IDRUNE Origin's admin dashboard, for whom IDRUNE Origin is the "data controller"; and (b) end consumers — people who scan a QR code or NFC tag on a physical product and, optionally, register their warranty or leave feedback, for whom IDRUNE Origin acts as a "data processor" on behalf of the manufacturer (the controller) — see our Data Processing Agreement for the terms of that relationship. Where this policy refers to "you", the relevant section makes clear which group it addresses.
2. What Data We Collect
From manufacturer account users: name, email address, and password (stored as a salted hash — we never see or store your plain-text password); role/permissions within your company's account; activity-log records of actions you take in the dashboard.
From end consumers, only if you choose to register a product warranty or submit feedback: email address (required); name and phone number (optional, if the manufacturer's registration form asks for them); the specific product, serial number, and purchase context you register against; consent choices (e.g. whether you agree to receive recall/safety notices or product update notices) — recorded as an append-only log, so we always have an accurate history of what you actually agreed to and when, never a single value that could be silently changed.
From every visitor to a public product page (registered or not): scan/visit metadata — approximate geographic region derived from IP address (we do not retain full IP addresses in analytics records), referrer (e.g. QR scan, NFC tap, direct link, campaign link), device/browser type, and which sections of the page you viewed and for how long. We do not collect or infer age, gender, or other demographic data from an anonymous scan.
3. How and Why We Use Your Data (Lawful Basis)
Manufacturer account data — operating your dashboard account — relies on contract necessity (Art. 6(1)(b)).
Consumer registration and consent data is processed on the manufacturer's instructions, as their processor, for the purposes they have configured (e.g. warranty administration, safety-notice reach calculation) — see our Data Processing Agreement for the processor terms this relies on.
Anonymous scan/visit analytics — helping the manufacturer understand how their product pages are reached — relies on the manufacturer's legitimate interest as controller, balanced against minimizing what we collect (no raw IP retention, no demographic inference).
4. Who We Share Data With
We do not sell personal data. We share data only with: Stripe, to process manufacturer subscription payments; Anthropic, to provide AI-assisted translation/specification suggestions on content a human always reviews before it publishes; a transactional email provider, to send account and registration-related emails; hosting and infrastructure providers, to run the Service; law enforcement or regulators where required by law; and a successor entity in the event of a merger or acquisition, subject to the protections in this policy. See our Sub-Processors page for the full current list.
5. Where Your Data Is Held
The Service's shared database is hosted in London, United Kingdom. Some sub-processors process data outside the UK/EEA under their own approved transfer mechanism (such as Standard Contractual Clauses) — see our Sub-Processors page for exactly which ones and where.
6. Data Retention
Manufacturer account data is retained for as long as the company's account is active, plus any period required for legal, tax, or accounting purposes. Consumer registration and consent data is retained for as long as the manufacturer instructs, consistent with our Data Processing Agreement, or as needed to administer an active warranty — the append-only consent log itself is never deleted or altered, only ever added to, so there is always an accurate record of what was agreed and when, even after a later change of mind.
Anonymous scan/visit analytics are retained for a bounded period and then aggregated or deleted; raw IP addresses are never retained beyond the moment needed to derive an approximate region.
7. Your Rights Under GDPR
Depending on your location, you have the right to access, rectify, erase, port, object to, and restrict processing of your personal data, and to withdraw consent at any time for consent-based processing, without affecting the lawfulness of processing before withdrawal.
If you are a manufacturer account user, contact your account administrator or [email protected]. If you are an end consumer who registered a product, we do not yet have a fully automated self-service tool for exercising these rights directly — contact [email protected], or the manufacturer whose product you registered, and we will process your request, normally within 30 days as required by UK GDPR. A self-service option is planned; until it exists, this is a real, disclosed gap rather than an implied capability.
You also have the right to lodge a complaint with the UK Information Commissioner's Office (ico.org.uk) or your local data protection authority.
8. Security
We use industry-standard measures including encrypted transport (HTTPS) throughout the Service, hashed passwords and API keys, and per-company data isolation enforced in our application code on every data access. We disclose honestly, rather than imply otherwise, that we have not yet completed a formal penetration test or ISO 27001 certification; a lightweight security questionnaire describing our current posture is available on request.
9. Children's Privacy
The Service is intended for use by businesses and their staff, and by consumers of physical products generally. We do not knowingly directly target children. If we become aware we have collected personal data from a child without appropriate consent, we will delete it.
10. Changes to This Policy
We may update this Privacy Policy from time to time. If changes are material, we will notify manufacturer account users by email or via a notice on the Service at least 14 days before they take effect. The "Last updated" date at the top reflects the most recent version.
11. Contact Information
- Build Actions Ltd, trading as IDRUNE Origin (part of the IDRUNE product family)
- Company number: 13333702
- Registered office: Unit Da2 Sutherland House, 43 Sutherland Road, London, United Kingdom, E17 6BU
- Privacy inquiries: [email protected]
- Legal/terms inquiries: [email protected]
- You may also lodge a complaint with the UK Information Commissioner's Office (ico.org.uk).
