Privacy Policy

Matainable Privacy Policy

Privacy Policy

Effective Date: [INSERT DATE]

Last Updated: [INSERT DATE]

This Privacy Policy explains how Matainable Ltd ("Matainable", "we", "us", or "our") collects, uses, shares, and protects personal data when you use our platform, website, and services (collectively, the "Platform"). Matainable is a B2B SaaS platform for supply chain compliance and digital product passports serving the interiors, textiles, and fashion industries.

We are committed to protecting your privacy and processing your personal data in accordance with the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018, and, where applicable, the EU General Data Protection Regulation (EU GDPR).

1. Data Controller

The data controller responsible for your personal data is:

Matainable Ltd
Company Registration Number: 16543039
Registered Address: 3rd Floor, 86-90 Paul Street, London, England, EC2A 4NE
Privacy Contact: admin@matainable.com

EU Representative: As Matainable offers services to data subjects in the European Economic Area, we are assessing our obligation to appoint an EU representative under Article 27 of the EU GDPR. If an EU representative is appointed, their details will be published here and at matainable.com/legal. In the meantime, EU-based data subjects may direct privacy enquiries to admin@matainable.com.

Data Protection Officer: We have designated a privacy contact reachable at admin@matainable.com. We keep our obligation to appoint a Data Protection Officer under Article 37 of the UK GDPR and EU GDPR under review as the Platform scales.

2. Personal Data We Collect

2.1 Account Data

When you register for an account, we collect:

  • Full name
  • Email address
  • Company name
  • Role or job title
  • Country
  • Password (stored in hashed form only; we never store plaintext passwords)

2.2 Company and Organisation Data

Depending on your role on the Platform (Supplier or Buyer), we may collect:

  • Company name, registered address, and contact details
  • Industry classification
  • Certifications and accreditations held
  • Production facility locations and details

2.3 Material, Product, and Digital Product Passport Data

Suppliers may submit data relating to materials and products, including:

  • SKU identifiers and material descriptions
  • Certifications and sustainability credentials
  • Pricing information
  • Product images
  • Digital Product Passport (DPP) data, including material composition, compliance certifications (e.g. EUDR, CSRD, CSDDD references), carbon footprint data (PCF/LCA), and supply chain information

To the extent that any of this data identifies or relates to a natural person, it will be treated as personal data under this Policy.

2.4 Usage Data

We automatically collect information about how you interact with the Platform, including:

  • Pages viewed and features used
  • Session duration and frequency of use
  • Device type, browser type, and operating system
  • IP address (which may be truncated or anonymised for analytics purposes)

2.5 AI Chat Data

If you use our AI-powered assistant, we collect:

  • Queries and prompts you submit to the AI assistant
  • Responses generated by the AI assistant

2.6 Communication Data

We collect data generated through Platform communications, including:

  • Business-to-business messages exchanged between Buyers and Suppliers
  • Requests for quotation (RFQ) data

2.7 Payment Data

Payment processing is handled entirely by our third-party payment processor, Stripe. Matainable does not collect, store, or have access to your full payment card numbers, bank account details, or other sensitive financial information. We receive only transaction confirmations, invoice data, and limited identifiers necessary to associate payments with your account.

3. How We Collect Your Data

We collect personal data through the following means:

  • Directly from you: when you create an account, complete your company profile, upload materials or product data, use the AI assistant, send messages, or contact us.
  • Automatically: through cookies and similar technologies when you use the Platform (see Section 10 below).
  • From third parties: from our payment processor (Stripe) regarding transaction status, and potentially from publicly available sources to verify company information.

4. Lawful Bases and Purposes of Processing

We process your personal data on the following lawful bases under Article 6 of the UK GDPR and EU GDPR:

Processing ActivityLawful Basis
Creating and managing your accountContract — necessary for the performance of our contract with you (Terms of Service)
Providing Platform functionality (material listings, searches, Digital Product Passports, B2B messaging, RFQs)Contract — necessary for the performance of our contract with you
Processing payments via StripeContract — necessary for the performance of our contract with you
Sending transactional emails (account confirmations, password resets, order notifications)Contract — necessary for the performance of our contract with you
Processing AI assistant queriesContract — necessary to provide the AI assistant feature you have chosen to use
Product analytics and Platform improvementLegitimate Interest — server-side analytics using aggregated and pseudonymised data to improve the Platform and understand usage patterns (see Sections 4.1 and 11.2). No client-side cookies are used for analytics
Security monitoring and fraud preventionLegitimate Interest — to protect the Platform, our users, and our business from security threats and fraudulent activity
Compliance with legal obligations (e.g. tax, anti-money laundering, regulatory requests)Legal Obligation — necessary to comply with applicable laws
Marketing communications (where applicable)Consent — only where you have given explicit opt-in consent; you may withdraw consent at any time

4.1 Legitimate Interest Assessment

Where we rely on legitimate interest as a lawful basis, we have conducted a balancing assessment and concluded that our interests do not override your fundamental rights and freedoms. Our analytics processing uses aggregated and pseudonymised data wherever possible. You may object to processing based on legitimate interest at any time (see Section 8).

5. Digital Product Passports and Public Data

A core function of the Platform is the creation and management of Digital Product Passports (DPPs). DPP data may be made publicly accessible or shared with specific parties, subject to visibility controls configured by the Supplier who created the passport.

The Platform provides granular visibility flags that allow Suppliers to control which categories of DPP data are visible to different audiences. Suppliers are responsible for ensuring they have the necessary rights and authority to publish any data included in a Digital Product Passport, including data that may relate to third-party suppliers in their supply chain.

To the extent DPP data contains personal data relating to third parties (for example, the names or contact details of individuals at sub-suppliers), Suppliers warrant that they have obtained all necessary consents or have an appropriate lawful basis to share such data through the Platform. Matainable acts as a data processor in respect of DPP data uploaded by Suppliers.

6. AI Data Processing

Our Platform includes an AI-powered assistant that helps users with queries about materials, sustainability data, and Digital Product Passports. This feature is powered by Anthropic's Claude model.

  • Queries you submit to the AI assistant are sent to Anthropic for processing and response generation.
  • We do not use your AI queries to train or fine-tune AI models. Anthropic's commercial API terms provide that customer data is not used to train their models.
  • Anthropic may retain API request logs for up to 30 days for safety and abuse monitoring purposes, in accordance with their commercial API terms. Matainable retains AI chat logs for up to 12 months for quality assurance and error resolution purposes (see Section 9 for full retention details), after which they are deleted or anonymised.
  • AI-generated responses are provided for informational purposes only and do not constitute legal, regulatory, or compliance advice. You should independently verify any information provided by the AI assistant.

7. Data Sharing and Third-Party Processors

We share your personal data with third-party service providers who act as data processors on our behalf under appropriate data processing agreements. These include providers of infrastructure hosting, payment processing, email delivery, analytics, AI processing, file storage, and security services. Our primary database and file storage are hosted in the EU. Where sub-processors are based outside the UK or EEA, appropriate transfer safeguards (such as Standard Contractual Clauses or the EU-US Data Privacy Framework) are in place.

A complete list of our current sub-processors, including their purposes, the data they process, their locations, and the applicable transfer mechanisms, is published at matainable.com/legal/sub-processors.

We may also share personal data:

  • With other Platform users as necessary for the functioning of the service (e.g. Buyer-Supplier communications, publicly visible DPP data);
  • With professional advisors (legal, accounting, audit) who are bound by professional confidentiality obligations;
  • Where required by law, regulation, legal process, or enforceable governmental request;
  • In connection with a merger, acquisition, reorganisation, or sale of assets, in which case you will be notified of any change in data controller.

We do not sell your personal data to third parties. We do not share your personal data with third parties for their own marketing purposes.

8. International Data Transfers

Our primary database infrastructure is hosted in the EU (via Xano). However, some of our third-party processors are based in, or transfer data to, the United States or other countries outside the UK and EEA.

Where personal data is transferred outside the UK or EEA, we ensure appropriate safeguards are in place, including:

  • The EU-US Data Privacy Framework (and UK Extension), where the recipient is certified;
  • Standard Contractual Clauses (SCCs) approved by the European Commission and/or the UK Information Commissioner's Office (ICO), as applicable;
  • Adequacy decisions by the European Commission or the UK Secretary of State, where applicable.

Where required, we conduct Transfer Impact Assessments to evaluate whether the laws of the recipient country provide an adequate level of protection for personal data, and to identify any supplementary measures needed to ensure the effectiveness of the safeguards in place.

You may request a copy of the relevant safeguards or Transfer Impact Assessments by contacting us at admin@matainable.com.

9. Data Retention

We retain your personal data only for as long as necessary to fulfil the purposes for which it was collected, or as required by law. Our general retention periods are:

  • Account data: retained for the duration of your active account, plus 90 days after account closure to allow for reactivation. After that period, account data is deleted unless retention is necessary for the establishment, exercise, or defence of legal claims, compliance with legal obligations (e.g. tax records), or resolution of outstanding contractual matters, in which case the relevant data is retained only for as long as the specific purpose requires.
  • Company and material data: retained for the duration of your active account. Upon account closure, data may be retained in anonymised or aggregated form for Platform integrity purposes.
  • Digital Product Passport data: retained for the duration of the Supplier's active account, plus any additional period required by applicable product compliance regulations.
  • B2B messaging and RFQ data: retained for 24 months from creation, or the duration of the account, whichever is shorter.
  • AI chat data: query logs retained for up to 12 months for quality assurance, then deleted or anonymised.
  • Usage/analytics data: retained for up to 24 months, after which it is aggregated or deleted.
  • Payment records: retained for 7 years as required by UK tax and accounting legislation.
  • Security logs: retained for up to 12 months.

When personal data is no longer required, it is securely deleted or irreversibly anonymised.

10. Your Rights as a Data Subject

Under the UK GDPR and EU GDPR, you have the following rights in relation to your personal data:

  • Right of access (Article 15) — You may request a copy of the personal data we hold about you.
  • Right to rectification (Article 16) — You may request correction of inaccurate or incomplete personal data.
  • Right to erasure (Article 17) — You may request deletion of your personal data where there is no compelling reason for its continued processing.
  • Right to restriction of processing (Article 18) — You may request that we restrict the processing of your personal data in certain circumstances.
  • Right to data portability (Article 20) — You may request your personal data in a structured, commonly used, machine-readable format.
  • Right to object (Article 21) — You may object to processing based on legitimate interests at any time. We will cease processing unless we demonstrate compelling legitimate grounds.
  • Right to withdraw consent — Where processing is based on consent, you may withdraw that consent at any time without affecting the lawfulness of processing before withdrawal.
  • Right not to be subject to automated decision-making (Article 22) — We do not currently make decisions based solely on automated processing that produce legal or similarly significant effects on you.

To exercise any of these rights, please contact us at admin@matainable.com. We will respond within one month of receiving your request, as required by law. This period may be extended by up to two further months where requests are complex or numerous, in which case we will inform you of the reason for the delay within one month of your original request. We may request proof of identity before processing your request.

If you are unsatisfied with our response, you have the right to lodge a complaint with the UK Information Commissioner's Office (ICO) at ico.org.uk, or with your local supervisory authority if you are based in the EEA.

11. Cookies and Similar Technologies

11.1 Strictly Necessary Cookies

These cookies are essential for the Platform to function and cannot be switched off. They include:

  • Authentication tokens: JSON Web Tokens (JWT) stored in cookies to maintain your authenticated session. Without these, you would not be able to remain logged in.

Lawful basis: These are exempt from consent requirements as they are strictly necessary for the service you have requested.

11.2 Analytics

We use PostHog to collect anonymised usage analytics to understand how users interact with the Platform and to improve our service. Our analytics are processed server-side — we do not currently set any analytics cookies in your browser. The data collected includes:

  • Pages viewed and features used
  • Session information
  • Anonymised user identifiers

Lawful basis: Legitimate Interest — our server-side analytics use aggregated and pseudonymised data and do not involve cookies or client-side tracking. You may object to this processing at any time (see Section 10). If we introduce client-side analytics cookies in the future, we will obtain your consent before setting them and update this section accordingly.

11.3 Managing Cookies

You can manage or delete cookies through your browser settings. Disabling strictly necessary cookies may prevent you from using certain features of the Platform. For more information about cookies, visit allaboutcookies.org.

12. Data Security

We implement appropriate technical and organisational measures to protect your personal data against unauthorised access, alteration, disclosure, or destruction. These measures include:

  • Encryption of data in transit (TLS/HTTPS)
  • Password hashing using industry-standard algorithms
  • Access controls and role-based permissions
  • Regular security reviews
  • Use of reputable, security-certified third-party infrastructure providers

While we take reasonable measures to protect your data, no method of transmission over the internet or electronic storage is completely secure. We cannot guarantee absolute security of your personal data.

13. Controller-Processor Relationships

  • Matainable as Controller: We act as the data controller for Account Data, Usage Data, and Communication Data that we collect and process for our own purposes (account management, analytics, Platform operation).
  • Matainable as Processor: Where Suppliers upload material data, DPP data, or supply chain data that contains personal data relating to their own employees, contractors, or third-party suppliers, Matainable acts as a data processor on behalf of the Supplier. Suppliers acting as controllers are responsible for ensuring they have a lawful basis for such processing and for informing the relevant data subjects.

Where a controller-processor relationship exists, a Data Processing Agreement (DPA) applies automatically. Our standard DPA is published at matainable.com/legal/dpa and is incorporated by reference into these Terms. If you require a bespoke DPA or have questions, please contact admin@matainable.com.

14. Supply Chain Data and Third-Party Information

The Platform is designed to facilitate supply chain transparency and compliance. Users may input data that relates to third parties in their supply chain (e.g. sub-supplier names, facility locations, certification details).

Users are solely responsible for ensuring that any third-party data they upload to the Platform is shared in compliance with applicable data protection laws, including having a lawful basis for sharing such data and providing appropriate notices to the relevant individuals. Matainable does not independently verify the accuracy or lawfulness of third-party supply chain data uploaded by users.

15. Children's Data

The Platform is a business-to-business service and is not directed at individuals under the age of 18. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, please contact us at admin@matainable.com and we will take steps to delete such data.

16. Liability

Liability in connection with the Platform, including in relation to data processing, is governed by our Terms and Conditions. Nothing in this Privacy Policy limits or excludes any liability that cannot be limited or excluded under applicable data protection legislation, including your right to compensation under Article 82 of the UK GDPR or EU GDPR.

17. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. Where changes are material, we will notify you by email or by posting a prominent notice on the Platform at least 30 days before the changes take effect.

Where changes involve new processing purposes, new categories of data sharing, or a change of lawful basis that requires your consent, we will seek that consent separately and will not rely on continued use of the Platform as consent. For all other changes, your continued use of the Platform after the effective date constitutes your acknowledgement of the updated Policy.

18. Contact Us

If you have any questions about this Privacy Policy, wish to exercise your data subject rights, or have a complaint about how we handle your personal data, please contact us:

Privacy enquiries: admin@matainable.com
General enquiries: admin@matainable.com
Postal address: Matainable Ltd, 3rd Floor, 86-90 Paul Street, London, England, EC2A 4NE

We aim to respond to all privacy-related enquiries within 30 days.

This Privacy Policy is governed by the laws of England and Wales.

Sustainable Materials, Now Attainable
© 2025 Matainable. All rights reserved
Matainable Ltd. CRN: 16543039

3rd Floor, 86-90 Paul Street
London, England
United Kingdom,
EC2A 4NE