Privacy Policy
Last updated: July 2, 2026
This policy explains what SDS.guide, operated by [Operator legal name], collects and how it is used. We collect the minimum needed to run the service: no advertising, no analytics trackers, no sale of personal data.
1. What we collect
- Account data: company name, administrator email address, and a password (stored only as a salted scrypt hash — we cannot read your password).
- Content you upload: SDS documents (PDFs) and the data extracted from them, plus optional facility-location labels you add to binder entries. Uploaded SDS documents are published to the shared public library by design. Location labels are shown on your public binder pages — do not enter confidential information in them.
- Technical data:standard server logs (IP address, request path, timestamp) used for security and abuse prevention, and hosting-provider logs per that provider's policy.
Employees viewing a binder do not need an account, and we do not collect personal data from them beyond standard server logs.
2. How we use it
- To operate accounts, binders, and the shared library.
- To secure the service (rate limiting, abuse detection).
- To contact the account email about the service when necessary.
3. Processors (third parties)
- Anthropic (Claude API):when AI extraction is enabled, uploaded SDS PDFs are sent to Anthropic's API to be parsed into the standardized view. SDS documents are product-safety documents and should not contain personal data.
- Hosting provider:the site and its data are hosted on our hosting provider's infrastructure, which processes traffic and stores data on our behalf.
We do not sell or share personal data for advertising.
4. Cookies
We use a single strictly necessary session cookie to keep company administrators signed in. There are no analytics, advertising, or third-party cookies. Details: Cookie Policy.
5. Retention and deletion
- Account data is kept while the account exists.
- Binder entries can be removed at any time from the dashboard. Documents you uploaded are deleted from the library when you remove them, unless another company's binder still references them (the shared library is designed to preserve documents in use).
- To delete your account and associated personal data, email [contact email] from the account address.
6. Security
Passwords are hashed with scrypt and unique salts; sessions use signed, HTTP-only, secure cookies; traffic is encrypted in transit (HTTPS/TLS); and access to stored data is restricted. No system is perfectly secure — report suspected vulnerabilities to [contact email].
7. Your rights
Depending on where you live (e.g. GDPR in the EU/UK, CCPA/CPRA in California), you may have rights to access, correct, export, or delete your personal data, and to lodge a complaint with a supervisory authority. Exercise these rights by emailing [contact email]. We do not discriminate for exercising them.
8. Children
The service is for workplace use and is not directed at children under 16; we do not knowingly collect their data.
9. Changes
We will post any changes on this page with a new “last updated” date and, for material changes, notify account emails.
10. Contact
Data controller: [Operator legal name] — [contact email]