Privacy Policy
Last updated: 9 May 2026 · v3.0 · Effective immediately
1. Who We Are
YARDtwin™ is a yard management platform operated by YARDtwin Ltd ("we", "us", "our"), registered in Ireland. We provide cloud-based software for managing yard operations including dock scheduling, gate automation, trailer tracking, and analytics.
Data Controller contact: admin@yardtwin.com. You can also submit a request via our Data Subject Request Portal
2. Data We Collect
We collect the following categories of personal data:
3. How We Use Your Data
Service Delivery: Processing appointments, managing docks, tracking trailers, generating analytics, and providing all platform features you have subscribed to.
Smart Slots Recommendations: To generate booking recommendations through Smart Slots, we process operational data including booking times, carrier identity, dock assignments, configured break windows, and historical arrival patterns. This processing is performed on your tenant only and is not used for any cross-customer model training in Phase 1. Driver personal data (name, phone, photo) is never used as a Smart Slots input — the engine uses carrier identity, not driver identity. Phase 2 retraining (when introduced) is per-tenant by default; cross-tenant training would require explicit opt-in via Site Configuration and a separate DPA addendum. See the Smart Slots page for details.
Account Management: User authentication, role-based access control, subscription billing, and tenant isolation.
Security & Compliance: Maintaining audit trails for GMP compliance (21 CFR Part 11, EU Annex 11), fraud detection, and security monitoring.
Communications: Sending monthly newsletters (with explicit opt-in consent), system notifications, and service updates.
Improvement: Aggregated, anonymised analytics to improve platform performance and features.
4. Legal Bases for Processing
Contract Performance (Art. 6(1)(b) GDPR): Processing necessary to provide the YARDtwin service as agreed in your subscription.
Legitimate Interest (Art. 6(1)(f) GDPR): Security logging, fraud prevention, and platform improvement where our interest does not override your rights.
Consent (Art. 6(1)(a) GDPR): Newsletter subscriptions and marketing communications, which you can withdraw at any time.
Legal Obligation (Art. 6(1)(c) GDPR): Retention of audit data to comply with pharmaceutical regulatory requirements (GMP/GDP).
5. Data Security
Encryption in Transit: All data transmitted via TLS 1.2+ (HTTPS). TLS certificates managed by Microsoft Azure (DigiCert).
Encryption at Rest: Azure PostgreSQL Flexible Server with transparent data encryption. Azure Blob Storage encryption for documents and images. Field-level encryption (AES-256-GCM) for biometric data (driver licence images, signatures) with keys held in Azure Key Vault. Passwords hashed with bcrypt (12 rounds).
Multi-Tenant Isolation: Each customer's data is logically isolated using tenant IDs. API middleware enforces tenant boundaries on every request. Verified by an automated 25-test cross-tenant audit on every release.
Role-Based Access Control: Six distinct user roles (admin, ops_manager, gate_guard, warehouse_operator, carrier, super_admin) with route-level permissions. Single sign-on supported via Google and Microsoft.
Rate Limiting: API rate limiting on all routes; tighter limits on authentication endpoints. Helmet-style security headers on all responses.
Session Security: JWT access tokens with 1-hour expiry. Refresh tokens with 7-day expiry and rotation on use. IP-anchored session tracking.
Audit Logging: Every significant action logged with user, timestamp, IP address, and old/new values. GMP-relevant events flagged separately. Append-only at the application layer; 6-year retention.
Continuous Monitoring: Azure Application Insights with schema-drift alert (Postgres "column / relation does not exist" → triggers within 15 min). End-to-end /health/db-write probe verifies the application can write and read on every deploy.
Infrastructure: Hosted on Microsoft Azure in Sweden Central + Norway East (EEA). Containerised deployment via Azure Container Registry with staging-slot-then-swap pattern. Secrets held in Azure Key Vault and accessed via managed identity. Daily backups + 7-day point-in-time recovery on Postgres.
Software Supply Chain: Every pull request is scanned by npm audit, Trivy (container CVEs), Semgrep (SAST OWASP top-ten + Node.js + React + secrets rules), gitleaks (secret history), and OWASP ZAP (dynamic scan against staging on schedule).
6. Data Retention
Account Data: Retained for the life of the subscription plus 6 years (audit retention). Pseudonymised on Art. 17 erasure request.
Operational Data: Retained for the duration of your subscription. Exported to you on request before deletion. At end of subscription, retained or returned per the customer Data Processing Agreement.
Driver biometric data (licence photos, face images): 30 days post check-out. Auto-deleted by scheduled cleanup process.
General driver PII (name, phone, email, licence number): 90 days post check-out, configurable per site.
Audit Data: Retained for 6 years post-event to comply with pharmaceutical regulatory requirements (GMP / 21 CFR Part 11). Pseudonymised — not deleted — on subject erasure (Art. 17(3)(b) legal obligation override).
Newsletter Data: Retained until you unsubscribe. Consent records retained for 3 years after withdrawal.
Session Data: Access tokens expire after 1 hour. Refresh tokens expire after 7 days. Session rows hard-deleted on logout or erasure.
7. Data Sharing & Sub-Processors
We do not sell your personal data. We share data with the following sub-processors, each acting under a Data Processing Agreement and (where applicable) Standard Contractual Clauses:
Microsoft Azure (Sweden Central + Norway East, EEA) — cloud hosting, storage, Key Vault, Application Insights. Microsoft Online Services DPA + EU SCCs.
Stripe (Stripe Ireland, EEA) — subscription billing. Stripe processes payment data directly; we do not store credit card numbers. Stripe DPA + SCCs for any onward US transfer.
Resend (US) — transactional email (welcome, trial reminders, DSAR responses). Resend DPA + SCCs.
Google Cloud Vision (EU regions) — driver licence OCR where the customer enables licence-photo verification at gate.
Google Workspace / Microsoft Entra ID — OAuth single sign-on for users who choose to sign in with their Google or Microsoft account.
Anthropic (US) — Claude API for the in-product AI assistant and licence-OCR text parsing. Anthropic DPA + zero-retention claim + SCCs.
Customer Reference Use: We may display your company name and logo as a customer of YARDtwin in marketing materials, customer lists, case studies, and on our website. You can opt out by emailing admin@yardtwin.com — see the Terms of Service §6a.
Your Organisation: Tenant administrators can see user activity within their own organisation as part of normal platform functionality.
Legal Requirements: We may disclose data if required by law, court order, or to protect our legal rights.
8. Your Rights
Under GDPR (and Irish Data Protection Act 2018), you have the right to:
To exercise any right, submit a request via the Data Subject Request portal or email admin@yardtwin.com. We will respond within 30 days.
Internally, requests are fulfilled by our administration team via two endpoints: POST /api/v1/dsar/export/by-email produces a machine-readable JSON document of every record we hold for an email address (Art. 15 / 20); POST /api/v1/dsar/erase/by-email pseudonymises the data subject across all PII tables while preserving audit-log integrity per Art. 17(3)(b) (Art. 17).
9. Cookies
YARDtwin uses essential cookies and localStorage for session authentication (JWT tokens). The cookie consent banner offers four categories: essential (always on), functional (preferences), analytics (currently not used), and marketing (currently not used). Visitors can choose Reject non-essential / Customise / Accept all. Preferences are stored locally with a version stamp; the banner re-shows if categories change. Detailed cookie inventory is on the Cookie Policy page.
10. International Transfers
Your operational data is stored within the European Economic Area (EEA) on Microsoft Azure (Sweden Central + Norway East). Onward transfers to non-EEA sub-processors:
- Stripe: Stripe Ireland is the contracting entity (EEA). Some support functions in the US under SCCs.
- Resend: US-based. Transfers under Standard Contractual Clauses 2021.
- Anthropic: US-based. SCCs in place; Anthropic's zero-retention claim applies. Chatbot prompts intentionally exclude operational PII; the licence-OCR JSON parser does send OCR text.
- Google: EU regions for Vision OCR; Google Workspace global for OAuth identity tokens. Google Cloud DPA + EU SCCs.
A Transfer Impact Assessment is maintained for each US transfer.
11. Children's Privacy
YARDtwin is a business-to-business platform. We do not knowingly collect data from anyone under 16 years of age.
12. Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be communicated via email to account administrators and a notice within the platform. Continued use of YARDtwin after changes constitutes acceptance.
13. Contact & Supervisory Authority
Data Controller: YARDtwin Ltd · Email: admin@yardtwin.com
Supervisory Authority: Data Protection Commission (DPC), Ireland · www.dataprotection.ie