Cookie preferences

YARDtwin uses essential cookies for authentication and session management. We don’t currently set analytics or marketing cookies, but our cookie policy categorises them ahead of any future change. Read our Privacy Policy, GDPR Policy, and Cookie Policy.

Privacy Policy

Last updated: 9 May 2026 · v3.0 · Effective immediately

1. Who We Are

YARDtwin™ is a yard management platform operated by YARDtwin Ltd ("we", "us", "our"), registered in Ireland. We provide cloud-based software for managing yard operations including dock scheduling, gate automation, trailer tracking, and analytics.

Data Controller contact: admin@yardtwin.com. You can also submit a request via our Data Subject Request Portal

2. Data We Collect

We collect the following categories of personal data:

Account Data: Name, email address, phone number, position/job title, company name and address (street, city, country) — provided during account registration.
Authentication Data: Hashed passwords (bcrypt, 12 rounds), session tokens, JWT refresh tokens, login timestamps, and IP addresses. SSO identifiers from Google and Microsoft for users who sign in with those providers.
Operational Data: Appointment details, carrier information, dock assignments, trailer movements, inspection records, documents, and task assignments created through normal use of the platform.
Driver Data: Names, phone numbers, email addresses, licence numbers, licence photos and (where customer enables it) face images for biometric verification at gate. Special-category data under GDPR Art. 9 — captured under explicit consent at the gate. Retention 30 days for biometric, 90 days for general PII, configurable per site.
Audit Data: User actions, timestamps, IP addresses, and user-agent strings for compliance and security purposes. Retained 6 years post-event for GMP/Part 11 compliance.
Newsletter Data: Email address and company name when subscribing to our newsletter, along with consent timestamp and IP.
Technical Data: Browser type, device information, and access logs collected automatically for security and performance.

3. How We Use Your Data

Service Delivery: Processing appointments, managing docks, tracking trailers, generating analytics, and providing all platform features you have subscribed to.

Smart Slots Recommendations: To generate booking recommendations through Smart Slots, we process operational data including booking times, carrier identity, dock assignments, configured break windows, and historical arrival patterns. This processing is performed on your tenant only and is not used for any cross-customer model training in Phase 1. Driver personal data (name, phone, photo) is never used as a Smart Slots input — the engine uses carrier identity, not driver identity. Phase 2 retraining (when introduced) is per-tenant by default; cross-tenant training would require explicit opt-in via Site Configuration and a separate DPA addendum. See the Smart Slots page for details.

Account Management: User authentication, role-based access control, subscription billing, and tenant isolation.

Security & Compliance: Maintaining audit trails for GMP compliance (21 CFR Part 11, EU Annex 11), fraud detection, and security monitoring.

Communications: Sending monthly newsletters (with explicit opt-in consent), system notifications, and service updates.

Improvement: Aggregated, anonymised analytics to improve platform performance and features.

4. Legal Bases for Processing

Contract Performance (Art. 6(1)(b) GDPR): Processing necessary to provide the YARDtwin service as agreed in your subscription.

Legitimate Interest (Art. 6(1)(f) GDPR): Security logging, fraud prevention, and platform improvement where our interest does not override your rights.

Consent (Art. 6(1)(a) GDPR): Newsletter subscriptions and marketing communications, which you can withdraw at any time.

Legal Obligation (Art. 6(1)(c) GDPR): Retention of audit data to comply with pharmaceutical regulatory requirements (GMP/GDP).

5. Data Security

Encryption in Transit: All data transmitted via TLS 1.2+ (HTTPS). TLS certificates managed by Microsoft Azure (DigiCert).

Encryption at Rest: Azure PostgreSQL Flexible Server with transparent data encryption. Azure Blob Storage encryption for documents and images. Field-level encryption (AES-256-GCM) for biometric data (driver licence images, signatures) with keys held in Azure Key Vault. Passwords hashed with bcrypt (12 rounds).

Multi-Tenant Isolation: Each customer's data is logically isolated using tenant IDs. API middleware enforces tenant boundaries on every request. Verified by an automated 25-test cross-tenant audit on every release.

Role-Based Access Control: Six distinct user roles (admin, ops_manager, gate_guard, warehouse_operator, carrier, super_admin) with route-level permissions. Single sign-on supported via Google and Microsoft.

Rate Limiting: API rate limiting on all routes; tighter limits on authentication endpoints. Helmet-style security headers on all responses.

Session Security: JWT access tokens with 1-hour expiry. Refresh tokens with 7-day expiry and rotation on use. IP-anchored session tracking.

Audit Logging: Every significant action logged with user, timestamp, IP address, and old/new values. GMP-relevant events flagged separately. Append-only at the application layer; 6-year retention.

Continuous Monitoring: Azure Application Insights with schema-drift alert (Postgres "column / relation does not exist" → triggers within 15 min). End-to-end /health/db-write probe verifies the application can write and read on every deploy.

Infrastructure: Hosted on Microsoft Azure in Sweden Central + Norway East (EEA). Containerised deployment via Azure Container Registry with staging-slot-then-swap pattern. Secrets held in Azure Key Vault and accessed via managed identity. Daily backups + 7-day point-in-time recovery on Postgres.

Software Supply Chain: Every pull request is scanned by npm audit, Trivy (container CVEs), Semgrep (SAST OWASP top-ten + Node.js + React + secrets rules), gitleaks (secret history), and OWASP ZAP (dynamic scan against staging on schedule).

6. Data Retention

Account Data: Retained for the life of the subscription plus 6 years (audit retention). Pseudonymised on Art. 17 erasure request.

Operational Data: Retained for the duration of your subscription. Exported to you on request before deletion. At end of subscription, retained or returned per the customer Data Processing Agreement.

Driver biometric data (licence photos, face images): 30 days post check-out. Auto-deleted by scheduled cleanup process.

General driver PII (name, phone, email, licence number): 90 days post check-out, configurable per site.

Audit Data: Retained for 6 years post-event to comply with pharmaceutical regulatory requirements (GMP / 21 CFR Part 11). Pseudonymised — not deleted — on subject erasure (Art. 17(3)(b) legal obligation override).

Newsletter Data: Retained until you unsubscribe. Consent records retained for 3 years after withdrawal.

Session Data: Access tokens expire after 1 hour. Refresh tokens expire after 7 days. Session rows hard-deleted on logout or erasure.

7. Data Sharing & Sub-Processors

We do not sell your personal data. We share data with the following sub-processors, each acting under a Data Processing Agreement and (where applicable) Standard Contractual Clauses:

Microsoft Azure (Sweden Central + Norway East, EEA) — cloud hosting, storage, Key Vault, Application Insights. Microsoft Online Services DPA + EU SCCs.

Stripe (Stripe Ireland, EEA) — subscription billing. Stripe processes payment data directly; we do not store credit card numbers. Stripe DPA + SCCs for any onward US transfer.

Resend (US) — transactional email (welcome, trial reminders, DSAR responses). Resend DPA + SCCs.

Google Cloud Vision (EU regions) — driver licence OCR where the customer enables licence-photo verification at gate.

Google Workspace / Microsoft Entra ID — OAuth single sign-on for users who choose to sign in with their Google or Microsoft account.

Anthropic (US) — Claude API for the in-product AI assistant and licence-OCR text parsing. Anthropic DPA + zero-retention claim + SCCs.

Customer Reference Use: We may display your company name and logo as a customer of YARDtwin in marketing materials, customer lists, case studies, and on our website. You can opt out by emailing admin@yardtwin.com — see the Terms of Service §6a.

Your Organisation: Tenant administrators can see user activity within their own organisation as part of normal platform functionality.

Legal Requirements: We may disclose data if required by law, court order, or to protect our legal rights.

8. Your Rights

Under GDPR (and Irish Data Protection Act 2018), you have the right to:

Access your personal data (Art. 15)
Rectify inaccurate data (Art. 16)
Erase your data (Art. 17)
Restrict processing (Art. 18)
Data portability (Art. 20)
Object to processing (Art. 21)
Withdraw consent at any time
Lodge a complaint with the DPC

To exercise any right, submit a request via the Data Subject Request portal or email admin@yardtwin.com. We will respond within 30 days.

Internally, requests are fulfilled by our administration team via two endpoints: POST /api/v1/dsar/export/by-email produces a machine-readable JSON document of every record we hold for an email address (Art. 15 / 20); POST /api/v1/dsar/erase/by-email pseudonymises the data subject across all PII tables while preserving audit-log integrity per Art. 17(3)(b) (Art. 17).

9. Cookies

YARDtwin uses essential cookies and localStorage for session authentication (JWT tokens). The cookie consent banner offers four categories: essential (always on), functional (preferences), analytics (currently not used), and marketing (currently not used). Visitors can choose Reject non-essential / Customise / Accept all. Preferences are stored locally with a version stamp; the banner re-shows if categories change. Detailed cookie inventory is on the Cookie Policy page.

10. International Transfers

Your operational data is stored within the European Economic Area (EEA) on Microsoft Azure (Sweden Central + Norway East). Onward transfers to non-EEA sub-processors:

  • Stripe: Stripe Ireland is the contracting entity (EEA). Some support functions in the US under SCCs.
  • Resend: US-based. Transfers under Standard Contractual Clauses 2021.
  • Anthropic: US-based. SCCs in place; Anthropic's zero-retention claim applies. Chatbot prompts intentionally exclude operational PII; the licence-OCR JSON parser does send OCR text.
  • Google: EU regions for Vision OCR; Google Workspace global for OAuth identity tokens. Google Cloud DPA + EU SCCs.

A Transfer Impact Assessment is maintained for each US transfer.

11. Children's Privacy

YARDtwin is a business-to-business platform. We do not knowingly collect data from anyone under 16 years of age.

12. Changes to This Policy

We may update this Privacy Policy from time to time. Material changes will be communicated via email to account administrators and a notice within the platform. Continued use of YARDtwin after changes constitutes acceptance.

13. Contact & Supervisory Authority

Data Controller: YARDtwin Ltd · Email: admin@yardtwin.com

Supervisory Authority: Data Protection Commission (DPC), Ireland · www.dataprotection.ie

Hi there! Start your free trial in 2 minutes — I'll help you set everything up!