ProductSolutionsDGeniusSecurityNetworkResourcesFree tools
Book a demoFind your DGM One providerLog in to portal

Complete dangerous goods compliance · 49 CFR · ADR · IATA · IMDG · RID · GHS

Emfara Privacy Notice

Who we are

Emfara Inc. provides DGM One, a dangerous goods compliance service. We are a Delaware corporation with our registered office at 251 Little Falls Drive, Wilmington, New Castle County, Delaware 19808, USA. For anything about your personal data, contact privacy@emfara.com. This is also our contact point for complaints under Clause 11(a) of the EU standard contractual clauses.

Our two roles

Data in DGM One. When an organisation uses DGM One, we process the documents, photographs, training records and other data in its account on its behalf, as its processor. That organisation decides how its data is used, and its own privacy notice applies. If you have a question or request about that data, contact the organisation; if you contact us, we will pass your request to it.

Our own processing. This notice covers the limited personal data we process for our own purposes, as controller. We get it from you, or from the organisation you work for.

What we process, why and on what basis

We do not sell personal data, and we do not use it for advertising. We do not use the documents, photographs, training records or other content in customers' DGM One accounts for our own purposes or to train AI models. We do look at how the application is used, through the product analytics described below, to find faults and improve the service.

Cookies

On this website we use only cookies and similar technologies that are strictly necessary: protecting the forms against bots and abuse. These need no consent. This website sets no analytics or advertising cookies, and if we add analytics to it we will ask for your consent first and update this notice.

Inside DGM One at app.dgmone.com, a cookie keeps you signed in, and product analytics (PostHog, United States) records how the application is used, but only for people who have chosen to allow it. Session replay — screen recording — is switched off. Those are part of the service we provide to the organisation whose account you use, which decides how they are used as controller; its own privacy notice applies. We use no advertising cookies anywhere.

Who receives the data

We use service providers under written contracts for:

  • hosting (Vercel);
  • database (Supabase);
  • storage and security (Cloudflare);
  • error monitoring (Sentry);
  • email (Resend);
  • product analytics inside DGM One, for people who have allowed it (PostHog);
  • payments and subscription billing (Stripe);
  • our own email and office tools.

The full list is on our Sub-processors page.

We may also disclose data where the law requires it. We review any request from a public authority for its legality, and disclose only the minimum required.

Where the data is processed

We are based in the United States and process data there. Where our providers process data elsewhere, or where the law requires a transfer safeguard, we use the EU standard contractual clauses (with the UK Addendum and the Swiss adaptations where relevant) or an adequacy decision.

Your rights

Depending on the law that applies to you, you may ask us for access to your personal data, correction, erasure, restriction or portability, and you may object to processing based on our legitimate interests. Write to privacy@emfara.com. You may also complain to the data protection authority where you live or work.

EU Data Act information

These are the details that Articles 26 and 28 of Regulation (EU) 2023/2854 require.

Switching. A customer may ask at any time to export its data or to switch to another provider or to its own systems. The customer chooses a notice period of up to 2 months, followed by a 30-day transition period during which we keep providing DGM One and export the data. The customer then has at least 30 days to retrieve it.

What we export. We export all customer data, including the audit trail and training records:

  • in JSON or CSV;
  • with documents and photographs as the files kept in DGM One, described on the Data Export Formats page.

Details of the data structures and formats are on our Data Export Formats page. We make no charge for export, switching or deletion. Known restriction: no organisation wide export tool and no customer facing deletion tool exist yet. Both an export and a deletion are carried out by Emfara by hand on request, from the datasets described on that page; there is nothing a customer can run for itself.

Jurisdiction and safeguards. The ICT infrastructure used for DGM One is in the United States and is subject to US law. To protect data against unlawful access by any government, we:

  • encrypt data in transit, and rely on our managed database and object storage providers to encrypt it at rest under their own key management (we hold no separate application layer encryption and we do not offer customer managed keys);
  • isolate each customer's data and restrict staff access;
  • review every request from a public authority, challenge it where there are reasonable grounds, notify the customer where we lawfully can and disclose only the minimum required.

Changes

We will update this notice when our processing changes and show the date of the latest version at the top.