Yokohama

Privacy Policy

Draft placeholder — not yet reviewed or approved. Do not treat this page as accurate or binding until it has been checked against real data flows and this notice is removed.

1. Who we are

The data controller for this site is [legal entity name/address]. Placeholder — confirm the correct entity and add a registered address.

2. What we collect

Account/contact details (name, email, customer code, country); shipment and EUDR compliance document records, imported from our own systems (by CSV upload, or an SFTP/S3 source an administrator has configured); login activity, including the IP address a login came from and an approximate location derived from it; and a record of actions taken in the Portal (the audit log), for security and support purposes. Placeholder — confirm every field actually stored matches this list.

3. Why we process it (lawful basis)

Performing the account-access relationship (letting you view and download your documents), legitimate interests (keeping the Portal secure — detecting and blocking suspicious login activity, maintaining an audit trail), and legal obligation (recordkeeping tied to EUDR compliance). Placeholder — confirm a lawful basis is recorded for each activity.

4. Who we share it with

Our email delivery provider (for password resets and account notifications); IP geolocation lookup services (ipapi.co and ip-api.com), which receive the IP address a login came from in order to resolve an approximate city/country for our security records; and our hosting/infrastructure provider. Placeholder — name each processor formally and confirm a data processing agreement is in place with each.

5. International transfers

Placeholder — confirm whether any processor above stores or accesses data outside the UK/EEA, and what safeguard applies (e.g. SCCs, adequacy decision) if so.

6. How long we keep it

Placeholder — set retention periods for account data, shipment/document records (typically driven by EUDR’s own recordkeeping requirements), and login/audit logs.

7. Your rights

Under UK GDPR and EU GDPR, you have the right to access, correct, delete, restrict, or port your data, and to object to certain processing. Complaints can be made to the ICO (UK) or your local supervisory authority (EU). Placeholder — add a contact route for exercising these rights.

8. Cookies

We currently set only strictly necessary cookies — none of them are used for analytics or marketing. Your accept/reject choice from the cookie banner is stored in your browser’s local storage, not a cookie itself; you can change it at any time from the “Cookie preferences” link in the footer.
NamePurposeDuration
eudr_customer_sessionKeeps you securely signed in as a customer7 days
eudr_admin_sessionKeeps you securely signed in as an admin12 hours
eudr_admin_view_asLets an admin securely view the Portal as a customer, for support2 hours
eudr_localeRemembers your chosen languageUntil you close your browser
eudr_themeRemembers your light/dark display preference1 year
Placeholder — update this section (and ask for consent, not just note it) if analytics/marketing cookies are ever added.

9. Security

We use IP-based rate limiting and blocking on login attempts, and keep an audit trail of actions taken in the Portal. Placeholder — describe further technical/organisational measures in place, and the process for reporting a suspected data breach.

10. Contact

Placeholder — data protection contact details, and reference to Terms & Conditions.

Last updated: not yet published. Contact your account administrator with any questions.