Emfara Privacy Notice
Last updated: 25 September 2026
Who we are
Emfara Inc. provides DGM One, a dangerous goods compliance service. We are a Delaware corporation with our registered office at 251 Little Falls Drive, Wilmington, New Castle County, Delaware 19808, USA. For anything about your personal data, contact privacy@emfara.com. This is also our contact point for complaints under Clause 11(a) of the EU standard contractual clauses.
Our two roles
Data in DGM One. When an organisation uses DGM One, we process the documents, photographs, training records and other data in its account on its behalf, as its processor. That organisation decides how its data is used, and its own privacy notice applies. If you have a question or request about that data, contact the organisation; if you contact us, we will pass your request to it.
Our own processing. This notice covers the limited personal data we process for our own purposes, as controller. We get it from you, or from the organisation you work for.
What we process, why and on what basis
| Data | Purpose | Legal basis (GDPR) | How long we keep it |
|---|---|---|---|
| Sign-in and security events: name, work email, organisation, sign-in events, and the IP address of each sign-in, which we store unhashed | Keeping DGM One secure and preventing account misuse (the user accounts themselves are the organisation's data, which we process as its processor) | Article 6(1)(f) (legitimate interest in security) | Up to 12 months after the event, or longer where needed to deal with a security incident |
| Security data: IP addresses, hashed wherever we use them for abuse control; bot-protection signals collected through Cloudflare Turnstile (IP address, TLS fingerprint, user agent) | Preventing abuse, fraud and attacks | Article 6(1)(f) (legitimate interest in security) | Up to 12 months, or longer where needed to deal with a security incident |
| Support and enquiries: name, contact details, what you tell us | Answering you | Article 6(1)(f) (legitimate interest in answering you); Article 6(1)(b) where you are yourself party to a contract with us | Up to 3 years after the last contact |
| Business contacts of customers and partners: name, role, business contact details | Managing our business relationships and contracts | Article 6(1)(f) (legitimate interest in managing our business relationships); Article 6(1)(b) where you are yourself party to the contract | For the relationship, then up to 6 years where the law requires |
We do not sell personal data, and we do not use it for advertising. We do not use the documents, photographs, training records or other content in customers' DGM One accounts for our own purposes or to train AI models. We do look at how the application is used, through the product analytics described below, to find faults and improve the service.
Cookies
On this website we use only cookies and similar technologies that are strictly necessary: protecting the forms against bots and abuse. These need no consent. This website sets no analytics or advertising cookies, and if we add analytics to it we will ask for your consent first and update this notice.
Inside DGM One at app.dgmone.com, a cookie keeps you signed in, and product analytics (PostHog, United States) records how the application is used, but only for people who have chosen to allow it. Session replay — screen recording — is switched off. Those are part of the service we provide to the organisation whose account you use, which decides how they are used as controller; its own privacy notice applies. We use no advertising cookies anywhere.
Who receives the data
We use service providers under written contracts for:
- hosting (Vercel);
- database (Supabase);
- storage and security (Cloudflare);
- error monitoring (Sentry);
- email (Resend);
- product analytics inside DGM One, for people who have allowed it (PostHog);
- payments and subscription billing (Stripe);
- our own email and office tools.
The full list is on our Sub-processors page.
We may also disclose data where the law requires it. We review any request from a public authority for its legality, and disclose only the minimum required.
Where the data is processed
We are based in the United States and process data there. Where our providers process data elsewhere, or where the law requires a transfer safeguard, we use the EU standard contractual clauses (with the UK Addendum and the Swiss adaptations where relevant) or an adequacy decision.
Your rights
Depending on the law that applies to you, you may ask us for access to your personal data, correction, erasure, restriction or portability, and you may object to processing based on our legitimate interests. Write to privacy@emfara.com. You may also complain to the data protection authority where you live or work.
EU Data Act information
These are the details that Articles 26 and 28 of Regulation (EU) 2023/2854 require.
Switching. A customer may ask at any time to export its data or to switch to another provider or to its own systems. The customer chooses a notice period of up to 2 months, followed by a 30-day transition period during which we keep providing DGM One and export the data. The customer then has at least 30 days to retrieve it.
What we export. We export all customer data, including the audit trail and training records:
- in JSON or CSV;
- with documents and photographs as the files kept in DGM One, described on the Data Export Formats page.
Details of the data structures and formats are on our Data Export Formats page. We make no charge for export, switching or deletion. Known restriction: no organisation wide export tool and no customer facing deletion tool exist yet. Both an export and a deletion are carried out by Emfara by hand on request, from the datasets described on that page; there is nothing a customer can run for itself.
Jurisdiction and safeguards. The ICT infrastructure used for DGM One is in the United States and is subject to US law. To protect data against unlawful access by any government, we:
- encrypt data in transit, and rely on our managed database and object storage providers to encrypt it at rest under their own key management (we hold no separate application layer encryption and we do not offer customer managed keys);
- isolate each customer's data and restrict staff access;
- review every request from a public authority, challenge it where there are reasonable grounds, notify the customer where we lawfully can and disclose only the minimum required.
Changes
We will update this notice when our processing changes and show the date of the latest version at the top.