Data governance
How we handle your chain’s data.
This page is Tracebud’s public data-governance statement for buyers, partners, and procurement reviews. It sits beside our Privacy policy and Data & security overview.
Scope
What this covers.
Tracebud AS (Oslo, Norway) provides an EUDR-focused field app, organisation dashboard, and API. We process personal and operational data so farmers, cooperatives, and buyers can map plots, keep evidence, and prepare due diligence statements.
Ownership
Farmers and organisations own their records.
- A producer’s plots, papers, and delivery receipts belong to the producer. They keep them in their app and can carry them to another buyer.
- Member lists, lots, seals, and filings belong to the organisation that created them. Export is available; leaving Tracebud does not mean losing your data.
- Tracebud is the carrier, not the owner. We do not sell customer chain data or use it to price against you.
Consent
Sharing follows consent on the record.
Records move across organisational boundaries only with consent attached (for example a sealed shipment or an explicit grant). Farmers can review and manage sharing through the consent wallet on app.tracebud.com. Desk users request and respect those grants.
Consent wallet (farmers)Sub-processors
Who processes data for us.
Primary database, auth, API, rate-limit Redis, and Vercel Functions run in the EU: Supabase Frankfurt (eu-central-1), Railway EU West for api.tracebud.com, Upstash Redis eu-central-1, and Vercel Functions in Frankfurt (fra1). Error monitoring ingest uses Sentry Germany. Residual processors outside the EEA include Twilio (SMS OTP), Expo/Apple/Google (push and OTA), and Notion (pilot tools). Vercel’s Edge CDN remains multi-region. We do not claim that every processor is EU-only.
Active processors include Supabase (database, auth, storage), Railway (API hosting), Vercel (marketing and dashboard), Sentry (error monitoring with PII scrubbing), Expo/EAS (mobile builds and OTA), Apple APNs and Google FCM (push tokens), and Twilio Verify (phone OTP). Optional processors such as Resend (email) or Stripe (billing) are used when those features are live.
A fuller ledger is maintained internally for customer DPAs. Procurement questionnaires: hello@tracebud.com.
Retention & erasure
Keep what the law requires; shred what it allows.
Account deletion and cryptographic shredding tooling is implemented for personal fields where retention law allows. EUDR and related holds may require keeping some compliance references. Export and correction requests are honoured. Absolute “GDPR-certified” claims are reserved until counsel signs off.
Security posture
Controls we run today.
TLS in transit, provider encryption at rest, tenant isolation, role-scoped access, audit logs for compliance actions, rate limiting, and CAPTCHA on auth surfaces. Independent certification (SOC 2, ISO 27001) is on the roadmap — not a current certification claim.