← Return to Home

Privacy Policy

Last Updated: June 2026

Applicable Frameworks: Digital Personal Data Protection Act 2023 (India) & EU General Data Protection Regulation (GDPR)

Role Designation:
For account and billing data, Urbane Labs ("Zero") acts as the Data Fiduciary (under India's DPDP Act 2023) / Data Controller (under EU GDPR). For supply chain compliance documents (BOMs, MSDSs, test certificates, supplier declarations) uploaded via our platform for REACH compliance processing and DPP generation, the Customer acts as the Data Controller, and Zero acts strictly as the Data Processor. We process this compliance data solely under the Customer's documented instructions and never for our own purposes.

1. Data We Collect

Zero collects the minimum data necessary to provide REACH compliance automation and DPP infrastructure services. Data types include:

  • Identity Data: Name, Email Address, Organization Name (collected via Supabase authentication).
  • Financial Data: Billing address, Payment method details (processed and stored exclusively by Stripe; Zero does not store card numbers).
  • Technical Data: IP Address, Browser type and version, session identifiers.
  • REACH Compliance Data (Processor Role): Bills of Materials (BOMs), Material Safety Data Sheets (MSDSs), test certificates, SVHC declarations, supplier compliance questionnaires, and related compliance documents uploaded for processing. We extract text and chemical data via AI models (Gemini multimodal pipeline) solely for your REACH compliance mapping and .i6z IUCLID dossier generation. This data is never used to train foundational AI models.
  • Workflow & Audit Data: HITL review actions, manual override reasons, confidence score overrides, extraction provenance metadata (source document, page number, bounding box coordinates), and ingestion job states.

2. Audit Trails & Record Keeping

Zero maintains detailed compliance provenance logs and environmental footprint records to support your regulatory requirements. Data generated for Digital Product Passports (DPPs) and finalized ECHA SCIP notifications are retained as part of a verifiable audit trail.

For all working data (Account details, Draft BOMs, in-progress HITL reviews, ingestion queue items), you retain full rights to correction and erasure subject to applicable retention periods. Once compliance data is finalized for regulatory submission, modifying these records is subject to standard audit logging procedures.

3. Enterprise Security & Data Isolation

For highly sensitive supply chain data (e.g., Tier 2/Tier 3 supplier identities, exact BOM costs, proprietary formulation details), Zero utilizes strict tenant isolation architecture. All data is logically separated and encrypted both in transit and at rest using SOC2-compliant cloud infrastructure providers. This security architecture ensures your proprietary trade secrets are securely handled and never exposed to unauthorized third parties or cross-tenant access.

4. Cross-Border Data Transfer

We process data primarily in India and the United States (via SOC2-compliant infrastructure partners including Supabase and Vercel). By utilizing our platform, EU-based Customers consent to this processing under Standard Contractual Clauses (SCCs) ensuring GDPR-equivalent data protection. Under India's DPDP Act 2023, cross-border transfers are currently permitted unless the Central Government notifies specific country restrictions, which we will comply with promptly.

5. Grievance Redressal

In accordance with the Information Technology Act 2000, the Digital Personal Data Protection Act 2023 (Section 13), and the DPDP Rules 2025, the contact details of the Grievance Officer are provided below:

Name: Aditya R (Founder)

Designation: Grievance Officer

Email: adityaranjan@urbanelabs.xyz

Address: Bangalore, Karnataka, India

We will acknowledge all grievances within 24 hours and resolve them within 15 days of receipt, in compliance with the DPDP Rules 2025 timeline requirements.

6. Your Rights

  • Right to Access (GDPR Art. 15 / DPDP Sec. 11): Request a summary of personal data processed about you.
  • Right to Correction (GDPR Art. 16 / DPDP Sec. 12): Update inaccurate or misleading personal data.
  • Right to Erasure (GDPR Art. 17 / DPDP Sec. 12): Request deletion of personal data, subject to legal retention and regulatory record-keeping obligations.
  • Right to Data Portability (GDPR Art. 20): Request export of your compliance data in a structured, machine-readable format.
  • Right to Grievance Redressal (DPDP Sec. 13): As detailed in Section 5 above.
  • Right to Withdraw Consent: You may withdraw consent for non-essential data processing at any time via your account settings or by contacting us. Withdrawal does not affect the lawfulness of processing performed prior to withdrawal.

7. Cookies and Analytics

To maintain platform security and understand user interaction, Zero employs the following categories of cookies and similar technologies:

  • Strictly Necessary Cookies: Authentication session tokens (Supabase), CSRF protection, and ingestion job workflow state persistence. These cannot be disabled as they are essential to platform operation.
  • Analytics Cookies (Consent Required): We use analytics tools to collect non-personally identifiable information such as page views, interaction times, feature usage patterns, and referring URLs. These are only activated upon your explicit consent via our cookie banner.

We do not use marketing, advertising, or cross-site tracking cookies. You may manage your cookie preferences at any time via the cookie consent banner. Rejecting analytics cookies will not impact the functionality of the REACH compliance dashboard, HITL review desk, or DPP generation tools.

8. Data Retention

We retain your account and billing data only for as long as your account is active or as needed to provide our services and comply with legal obligations (including tax, accounting, and Indian Companies Act record-keeping requirements). Upon account termination, personal data will be securely deleted or anonymized within 90 days. REACH compliance data (uploaded BOMs, MSDSs, generated .i6z dossiers) is retained for the duration of the Customer relationship plus 90 days, after which it is securely purged, unless longer retention is required by compliance audit standards. Unengaged lead data collected via our outbound systems is automatically purged after 180 days in compliance with GDPR Article 17.

9. Third-Party Sharing and Business Transfers

We do not sell your personal data or supply chain compliance data. We share data only with strictly vetted sub-processors essential to our infrastructure: Stripe (payment processing), Supabase (database and authentication), Vercel (hosting), and Google Cloud (Gemini AI inference). Each sub-processor is bound by data processing agreements ensuring equivalent or superior data protection standards. In the event that Urbane Labs is involved in a merger, acquisition, or sale of assets, your data may be transferred as part of that transaction. We will notify you via email and/or a prominent notice on our platform of any change in ownership or uses of your personal information, and you will retain the right to delete your data prior to such transfer.

10. Age Restrictions

Zero is a B2B data infrastructure platform designed exclusively for professional use by REACH compliance consultancies and supply chain audit firms. Our services are not directed to, and we do not knowingly collect personal information from, children under the age of 18. By using the platform, you represent that you are at least 18 years old and possess the legal authority to form binding contracts on behalf of yourself or your organization.

11. AI-Specific Data Processing Disclosure

Zero uses AI models (including Google Gemini multimodal pipeline) to extract text, chemical identifiers (CAS numbers, SVHC names), concentration percentages, and structural data from uploaded documents (PDFs, scanned images, Excel files). This processing is performed solely for the purpose of generating your REACH compliance assessments and is subject to the following safeguards: (a) no uploaded document content or extracted data is sent to AI model providers for the purpose of model training; (b) all AI inference is performed via authenticated server-side pipelines—no signed URLs, storage paths, or raw file content are directly exposed in LLM prompts; (c) AI extraction outputs below 0.8 confidence are flagged for mandatory Human-in-the-Loop review and are not included in generated .i6z dossiers without explicit human approval.

Zero by Urbane Labs • Bangalore, India • Zero is a B2B REACH compliance data infrastructure provider. Final legal verification of EU regulatory submissions, including ECHA SCIP notifications and ESPR Digital Product Passports, remains the sole responsibility of the Duty Holder.