Privacy Notice
This Privacy Notice explains how Tradelint handles personal data in connection with the Tradelint ICS2 goods-description compliance service, the Tradelint website, demos, customer communications and related services.
Tradelint is operated by Mohammed Gariballa, trading as Tradelint ("Tradelint", "we", "us" or "our").
Tradelint is a business-to-business service. It is not intended for personal, household or consumer use.
1. Our data-protection roles
Our role depends on the data and the context in which we process it.
Where we act as processor
We normally act as a processor when we process personal data contained in commercial invoices, shipment documents, goods descriptions, CSV outputs or related customer files submitted by or on behalf of a customer.
In that context, the customer is the controller. The customer decides what documents are submitted, why they are submitted and what personal data they contain. We process that data only to provide the service and in accordance with the customer's documented instructions, our Terms of Service, and any applicable Data Processing Agreement.
Where we act as controller
We act as controller for personal data that we collect and use for our own business purposes, including:
- website visitor information;
- demo, sales and onboarding enquiries;
- business contact details of customer personnel;
- account administration information;
- billing and commercial records;
- support communications;
- security, audit and service-operation logs;
- marketing preferences and opt-outs.
2. Personal data we process
Customer document data
Customer documents may incidentally contain personal data. This may include:
- shipper, consignee, seller, buyer, importer, exporter or notify-party names;
- business or trading addresses;
- email addresses and telephone numbers;
- names of sole traders, employees, signatories or operational contacts;
- shipment references, invoice references and related logistics information;
- product descriptions, HS-code candidates, quantities, values and other trade-document data.
Many customer documents relate only to companies, but some may identify individuals, sole traders or employees.
We do not require customers to submit special-category data, criminal-offence data or children's data. Customers must not submit such data unless they have a lawful basis to do so and have agreed appropriate safeguards with us in writing. If such data is included incidentally in customer documents, we will handle it in accordance with our security procedures, contractual obligations and applicable law.
Customer, demo and business-contact data
We may process:
- names;
- work email addresses;
- work telephone numbers;
- company names;
- job titles or roles;
- login or account details;
- demo requests and sales enquiries;
- support messages;
- notification email addresses;
- billing and subscription details;
- marketing preferences.
Website, technical and security data
We may process:
- IP addresses;
- browser and device information;
- server logs;
- authentication and access logs;
- usage events needed to operate, secure and debug the service;
- cookie data, as described in the cookies section below.
3. How we use personal data
We use personal data for the following purposes.
| Purpose | Role | Lawful basis where we are controller |
|---|---|---|
| Providing the Tradelint service to customers | Processor, or controller for account/admin data | Contract, legitimate interests |
| Processing customer invoices and shipment documents | Processor | The customer is responsible for its lawful basis |
| Generating suggested compliant goods descriptions and CSV outputs | Processor | The customer is responsible for its lawful basis |
| Sending service notifications, review notices and operational emails | Controller or processor depending on context | Contract, legitimate interests |
| Handling demos, sales enquiries and onboarding | Controller | Legitimate interests, consent where required |
| Providing customer support | Controller or processor depending on context | Contract, legitimate interests |
| Maintaining security, audit logs and fraud prevention | Controller and processor | Legitimate interests, legal obligations |
| Billing, accounting and commercial administration | Controller | Contract, legal obligations |
| Sending product updates or marketing to business contacts | Controller | Legitimate interests or consent, with an opt-out |
| Handling legal claims, compliance and dispute resolution | Controller | Legitimate interests, legal obligations |
Where we act as processor, the customer is responsible for ensuring that it has a lawful basis for submitting the relevant personal data to Tradelint and for using the resulting output.
4. How we process customer documents
We process customer documents only to provide, secure and improve the operation of the contracted service. This includes:
- receiving invoice or shipment documents;
- extracting line-item data;
- identifying goods-description issues;
- checking descriptions against relevant stop-word and compliance logic;
- generating suggested rewritten descriptions for human review;
- producing CSV or structured outputs;
- sending review and completion notifications;
- maintaining security, error, operational and audit logs;
- investigating faults, support issues or suspected misuse.
Customer document data is not sold, used for advertising, or used to train or fine-tune AI models.
5. AI and automated processing
Tradelint uses automated systems, including AI tools, to extract invoice data, identify potential goods-description issues and generate suggested compliant descriptions or related classification candidates.
These outputs are advisory only. They are intended to support human review by the customer's compliance, operations or customs team. The customer remains responsible for reviewing, approving and using any output before it is submitted to a carrier, customs system, authority or other third party.
Tradelint does not make solely automated decisions about individuals that produce legal or similarly significant effects on them.
6. Sub-processors and service providers
We use trusted service providers and sub-processors to operate the service. These providers may process personal data only for the purposes described in this notice and under contractual obligations designed to protect the data.
| Provider | Purpose | Typical location / region |
|---|---|---|
| Supabase Inc. | Database, file storage and serverless functions | EU region where configured |
| Amazon Web Services | Underlying infrastructure used by Supabase and related hosting providers | EU region where configured |
| Resend | Inbound and outbound transactional email | EU / US |
| Anthropic, PBC | AI extraction, analysis and description rewriting | EU endpoint where available / US |
| OpenAI | Embeddings, matching or other limited AI-assisted processing where enabled | US or other provider region |
| Airtable | Human review workflows and operational tracking where enabled | US |
| n8n | Workflow orchestration | EU region where configured |
| Cloudflare | DNS, security, routing and edge services | Global |
We will maintain a current sub-processor list and give customers reasonable prior notice of material changes where required by contract or Data Processing Agreement.
7. International transfers
Some providers may process personal data outside the UK or European Economic Area.
Where we transfer personal data internationally, we use appropriate safeguards where required. These may include adequacy regulations, the UK International Data Transfer Agreement, the UK Addendum to the EU Standard Contractual Clauses, the EU Standard Contractual Clauses, provider data-processing terms, and transfer-risk assessments where appropriate.
8. Retention
We keep personal data only for as long as reasonably necessary for the purposes described in this notice, unless a longer period is required by law, contract, security, audit, dispute-resolution or compliance requirements.
| Data type | Standard retention period |
|---|---|
| Original customer invoice or shipment files | 30 days from receipt, unless otherwise agreed |
| Generated CSV outputs and review results | 90 days, unless otherwise agreed |
| Demo-submitted documents | 30 days, unless otherwise agreed |
| Submission metadata and audit logs that do not contain full invoice text | Up to 7 years |
| Account, billing and customer administration records | Up to 6 years after the end of the customer relationship |
| Support communications | Up to 6 years, unless deleted earlier |
| Website and security logs | Normally up to 12 months, unless needed for investigation or security |
| Marketing preferences and suppression records | Until the person opts out or the record is no longer needed |
AI providers and other sub-processors may retain limited API, security or abuse-monitoring logs under their own data-processing terms. Where available, we configure providers to minimise retention and prevent use of customer data for model training.
9. Security
We use technical and organisational measures designed to protect personal data, including:
- encryption in transit;
- encryption at rest where supported by the relevant provider;
- access controls and least-privilege permissions;
- customer-level data separation;
- audit logging of key service events;
- secure authentication practices;
- restricted administrative access;
- webhook verification and service-integrity controls;
- supplier due diligence;
- incident-response procedures.
No system can be guaranteed to be completely secure, but we design and operate Tradelint with the aim of protecting customer documents and business data against unauthorised access, loss, misuse and disclosure.
10. Personal-data breaches
If we become aware of a personal-data breach affecting data for which we are controller, we will assess the breach and notify the Information Commissioner's Office and affected individuals where required by law.
If we become aware of a personal-data breach affecting customer document data for which we act as processor, we will notify the affected customer without undue delay and provide reasonable assistance so the customer can meet its own legal obligations.
11. Your rights
Subject to applicable law, individuals may have rights to:
- access their personal data;
- correct inaccurate personal data;
- request deletion;
- restrict processing;
- object to processing;
- request data portability;
- withdraw consent where processing is based on consent;
- complain to a supervisory authority.
To exercise your rights in relation to data for which Tradelint is controller, contact us at privacy@tradelint.co.uk.
If your request relates to personal data contained in customer documents, the relevant customer is usually the controller. In that case, we may direct you to the customer or assist the customer in responding to your request.
12. Marketing communications
We may send product updates, service information or relevant business-to-business marketing to customer contacts, demo users or people who have engaged with Tradelint.
You can opt out of marketing emails at any time by using the unsubscribe link in the email or by contacting privacy@tradelint.co.uk.
We will still send necessary service, security, account or transactional messages where required to operate the service.
13. Cookies
Our website uses essential cookies and similar technologies needed to operate and secure the site.
We do not use advertising cookies or cross-site tracking cookies.
If we add analytics, advertising or non-essential cookies in future, we will update this notice and, where required, request consent before setting those cookies.
14. Complaints and contact
For privacy questions, rights requests or complaints, contact privacy@tradelint.co.uk.
Postal address:
95 Fieldway, Dagenham, RM8 2BB
You also have the right to complain to the UK Information Commissioner's Office. The ICO's website is ico.org.uk/make-a-complaint/.
15. Changes to this notice
We may update this Privacy Notice from time to time. The "Last updated" date above shows when this version took effect.
Where we make material changes that affect customers or the way we process customer data, we will provide notice where required by contract or applicable law.