// Legal

Privacy policy

What we collect on this site, in the passports we host, and when you get in touch, then what happens to it afterwards.

Document
Privacy policy
Revision
1.0
Effective
2026-09-04
Contact
hello@specproven.com
01

Who this covers

This policy describes what [legal entity name], trading as Specproven, does with personal information in three situations: when you browse this website, when you contact us, and when you scan a product passport we host for one of our clients.

For the passports we host, our client, the company whose product you scanned, decides what the passport contains and what happens with the record of your scan. We run the service on their behalf. If you want data from a specific passport removed, contacting us is fine; we will route the request to the client that owns it.

02

This website

This site is a set of static pages. It sets no cookies, runs no advertising or analytics scripts, and loads no third-party trackers. Fonts are served from the same domain as the page.

Our hosting provider keeps standard server logs of IP address, timestamp, page requested, and browser user agent for a short period, to serve the site and to investigate abuse and faults.

03

When you contact us

If you email us or send us a spec sheet, we receive whatever you send: your name and email address, the content of your message, and any attachments. We use it to answer you, to build a sample if you have asked for one, and to keep a record of our correspondence.

We do not add you to a marketing list on the strength of an enquiry, and we do not sell or share your contact details with anyone outside the providers listed in section 06.

04

When you scan a passport

Scanning a tag opens a web page. Serving it produces the same standard server logs described in section 02: network address, timestamp, the passport requested, and browser type. We do not ask you to create an account or log in, we do not read your device location, and we do not attempt to identify you personally.

Where a client has scan reporting enabled for their engagement, we also record which passport was opened and when, so the company that owns the product can see that its units are being used. That reporting is about units, not people.

If you use an action on a passport, such as reordering a part, requesting service, or asking a question, you choose to send your contact details, and those go to the company that owns the product.

05

What we do with it

We use the information described above to:

  • Operate, secure, and troubleshoot the site and the passports we host.
  • Pass requests, and any scan reporting they have enabled, to the client whose product was scanned.
  • Answer enquiries and deliver work we have been engaged to do.
  • Produce aggregate statistics that do not identify any individual.

We do not sell personal information. We do not build advertising profiles, and we do not combine what we hold with data from other sources to identify individuals.

06

Who else sees it

Information reaches other parties in a small number of ways:

  • Our clients. Requests sent from a passport, and any scan reporting enabled for that engagement, go to the company that owns the scanned product.
  • Service providers. Hosting, email, and error-monitoring providers process data on our instructions in order to run the service.
  • Professional advisers and authorities. Where we are legally required to disclose something, or need advice on a dispute.
  • A successor. If the business is sold or reorganised, records may transfer with it, subject to this policy.
07

How long we keep it

Server logs are kept for a short operational period. Correspondence is kept for as long as the relationship is active and for a reasonable period afterwards for our records. Passport records are kept for the term of the client engagement they belong to, and are deleted or de-identified when that engagement ends, unless the client asks us to export them first.

Aggregate statistics that cannot identify a person may be kept indefinitely.

08

Security

Everything we host is served over encrypted connections. Access to client data is limited to the people who need it to do the work, and provider accounts are protected with multi-factor authentication. No system is immune to compromise, and we do not claim otherwise. If a breach affects your information, we will tell the affected parties promptly and say what we know.

09

Your choices and requests

You can ask us what information we hold about you, ask for it to be corrected, ask for it to be deleted, or object to how we use it. Write to hello@specproven.com and we will respond within 30 days.

Where the law that applies to you gives you further rights over your personal information, we will honour them; tell us what you are asking for and we will act on it or explain why we cannot. If a request concerns a passport belonging to one of our clients, we will pass it to them and tell you we have done so.

10

Where data is processed

Our providers may process data in countries other than your own. Where that happens we use providers that offer recognised safeguards for international transfers under their own contractual terms. If you need to know the specific providers and regions for an engagement, ask us and we will tell you.

11

Changes to this policy

We may update this policy. The version on this page is the current one and the effective date at the top of the page tells you when it took effect. If a change materially affects how we handle information for an active engagement, we will tell the client directly.

12

Contact

Questions about this policy, or a request about your information, go to hello@specproven.com. Our postal address is [registered address].