Privacy Policy
Effective date: 1 January 2026
This Privacy Policy explains how we process your personal data when you use PackageIQ, and how you can exercise your rights. Additional details may be set out in our Terms of Service, in product-specific terms, and in any separate notice we give you at the point we collect your data. It applies to all users of package-iq.com and related services.
PackageIQ is operated by OD Fextor, a registered legal entity in Bosnia and Herzegovina ("we", "us", "our"), which is responsible for the processing described here. Our full registered address and company registration number are available on request via the contact in Section 16.
1. Scope of this policy
This policy covers the personal data we process as controller in relation to:
- visitors to package-iq.com and users of the PackageIQ service, including anonymous free scans
- people who register an account, buy tokens or generate reports
- people who write to us through the contact form, by email or through support, or who have opted in to receive news and updates from us
- our contacts at the suppliers, service providers and business partners we work with
It does not cover our own personnel or applicants for a job with us, whose data is handled under a separate internal notice, and it does not cover websites we merely link to - see Section 12. Where we give you a separate notice at the point we collect particular data, that notice governs that data. Except where mandatory local law provides otherwise, your use of the service and any dispute about privacy are also subject to our Terms of Service, including their limitations of liability.
2. What personal data do we process?
Account data
When you create an account we collect your display name, email address and a protected version of your password. We also record the language and display preferences you choose, and the record of your account activity that we need in order to give you access to what you have paid for.
Usage data
We record how the service is used: pages viewed, analyses submitted, report types selected and interactions with individual features. We use this to operate, secure and improve the service. We do not sell it, and we do not use it to build advertising profiles.
Product and packaging data
When you run an analysis you provide product descriptions, packaging specifications, market context and, optionally, a photograph of your packaging. We process this content in order to produce your report and store it so that you can retrieve the report later. It is not shared with other customers and it is not used to train the underlying models.
Payment and billing data
Purchases are handled by an external payment provider that acts as merchant of record. That provider collects your card and billing details directly and is responsible for tax and invoicing on those transactions. We do not receive or store your card number. We keep a record of each transaction - amount, currency, date, status, the products purchased and the provider's reference for it - so that we can issue receipts, answer billing questions and handle refunds.
Technical data
Our systems keep standard technical records such as your IP address, browser type and the time of each request. We use these to keep the service available and secure, to investigate faults and to detect misuse.
Data we receive from other sources
Almost everything we hold comes from you directly. A limited amount reaches us from others: our payment provider confirms the outcome, amount, currency and reference of your transaction and the country used to determine tax; our email provider tells us whether a message we sent you was delivered or bounced; our hosting and security providers supply technical records of requests made to the service. If you reached us through a partner, an event or a referral to which you gave your details, we receive the business contact details you provided there. We do not buy personal data, and we do not enrich your profile with information from data brokers, social networks or advertising networks.
3. Why do we process your data, and on what legal basis?
- To provide, operate and support the PackageIQ service, including creating and delivering the reports you request (necessary to perform our contract with you)
- To process purchases, issue receipts and handle refunds (necessary to perform our contract with you; legal obligation for tax and accounting records)
- To send service messages such as account confirmations, report notifications and important changes to the service (necessary to perform our contract with you)
- To keep the service secure and to detect, investigate and prevent fraud, abuse and misuse (our legitimate interest in protecting the service and our users)
- To analyse, test and improve our products, features and processes, including statistical evaluation (our legitimate interest in developing our business)
- To establish, exercise or defend legal claims, and to respond to authorities (our legitimate interest in protecting our rights; legal obligation)
- To comply with accounting, tax, consumer protection and other legal obligations (legal obligation)
We only send marketing messages if you have opted in. You may withdraw that consent, or object to marketing, at any time and at no cost - see Sections 8 and 9. We do not process special categories of personal data (such as health or biometric data), and you should not submit any as part of an analysis.
4. Automated processing and artificial intelligence
PackageIQ is an automated analysis service: your report is produced by artificial intelligence applied to the product and packaging information you submit, combined with our own research library. Reports are advisory. They are not always accurate or complete, and they are not legal, regulatory or engineering advice - you remain responsible for validating them before acting on them.
We do not use this processing to make decisions about you that produce legal effects or similarly significantly affect you, and we do not profile you for advertising purposes. Automated checks are applied to detect fraud and abuse; if such a check restricts your access, you may contact us to ask for the decision to be reviewed by a person.
5. Who do we share your personal data with?
Within our organisation, access is limited to the people who need it to do their work. We also use carefully selected external service providers, who act on our instructions under written data processing agreements and may not use your data for their own purposes. They fall into the following categories:
- Hosting and infrastructure providers - operate the platform and store the data associated with your account and reports
- Artificial intelligence providers - process the information you submit in order to generate the analysis, images and text in your report
- Payment providers - take payment, act as merchant of record, issue invoices and process refunds
- Communication providers - deliver the service emails and documents we send to you
- Analytics and support tools - help us monitor availability, diagnose faults and answer your enquiries
- Professional advisers and authorities - accountants, auditors, lawyers and, where we are legally required or entitled to do so, public authorities and courts
We may also disclose personal data where you have asked us to, where it is necessary to establish or defend legal claims, or in connection with a corporate transaction such as a merger, acquisition or transfer of assets - in which case the recipient remains bound by this policy until it gives you notice of any change. We do not sell your personal data.
6. Do we transfer your data abroad?
PackageIQ is offered worldwide and is operated from Bosnia and Herzegovina. Whichever country you are in, using the service involves your personal data being transferred to and processed in other countries - including the European Economic Area, the United Kingdom and the United States, where several of the providers described above are located.
Where a recipient is in a country that does not offer an equivalent level of data protection, we put appropriate safeguards in place - typically the European Commission's Standard Contractual Clauses, the UK International Data Transfer Addendum, or an equivalent mechanism recognised under the law that applies to you - together with contractual confidentiality and security commitments. You may request details of the safeguards used for a particular transfer via the contact in Section 16.
7. How long do we keep your data?
- Account data - kept while your account is active and for 90 days after it is deleted
- Analyses and reports - kept for 24 months; you may delete individual reports at any time from your account
- Payment and billing records - kept for 7 years to meet accounting and tax obligations
- Technical and security records - kept for 30 days
8. What rights do you have?
We apply the following rights to every user, wherever you live, as our baseline standard. Depending on the data protection law that applies to you, some of them may also be legally enforceable, and your country may give you further rights - see Section 10:
- Access - request a copy of the personal data we hold about you
- Rectification - correct inaccurate data
- Erasure - request deletion of your account and associated data (subject to legal retention obligations)
- Portability - receive your data in a machine-readable format
- Objection - object to processing based on legitimate interest
- Restriction - request that we limit processing while a dispute is resolved
- Withdraw consent - where processing relies on your consent (for example, marketing emails), withdraw it at any time without affecting the lawfulness of processing carried out before withdrawal
To exercise any of these rights, email us at info.packageiq@gmail.com. We will respond within 30 days. We may need to verify your identity before acting on a request.
You also have the right to lodge a complaint with your local data protection supervisory authority, or with the supervisory authority of the country where we are established, if you believe our processing of your personal data infringes applicable law.
You are not obliged to give us personal data, but we cannot open an account or provide the service without the data needed to do so. We are not currently required to appoint a Data Protection Officer; data protection queries can be directed to the contact in Section 16.
9. Your choices
You do not have to make a formal request to control most of what we do. The following are available to you at any time, free of charge:
- Your account details - update your display name, email address, password, language and display preferences directly in your account settings
- Marketing email - use the unsubscribe link in any marketing message, or tell us by email. Opting out does not stop the service messages we have to send you about your account, purchases and reports
- Your reports - delete individual analyses and reports from your account at any time. Deleting a report does not reverse the tokens spent on it - see our Terms of Service for refunds
- Your account as a whole - ask us to close your account and delete the associated data, using the contact in Section 16. A dispute over unused tokens does not delay a deletion request
- Cookies and browser storage - clear or block what we store in your browser through your browser settings. Blocking it will sign you out and reset your language and display preferences - see Section 11
10. Country-specific information
PackageIQ is available worldwide, so more than one data protection law may apply to you. The following supplements apply in addition to the rest of this policy; where a local rule conflicts with anything above, the local rule prevails for users in that country.
- European Economic Area, United Kingdom and Switzerland - we process your data under the GDPR, the UK GDPR and the Swiss FADP respectively. You may lodge a complaint with your national supervisory authority (in the UK, the Information Commissioner's Office; in Switzerland, the FDPIC). Details of our representatives, where appointed, are given in Section 16.
- California - under the CCPA/CPRA you may request the categories and specific pieces of personal information we have collected, their sources and the purposes, and request correction or deletion. The categories we collect - identifiers, customer records, commercial information, internet activity, geolocation inferred from IP address, and professional or business information - and the purposes for each are set out in Sections 2 and 3; the sources are in Section 2; and the categories of recipient are in Section 5. We do not sell your personal information and do not share it for cross-context behavioural advertising, and we have not done so in the preceding 12 months. We do not use or disclose sensitive personal information beyond the purposes permitted without a right to limit. We will not discriminate against you for exercising these rights, and you may use an authorised agent to make a request.
- Other US states - residents of states with comprehensive privacy laws (including Virginia, Colorado, Connecticut, Utah, Texas, Oregon and Montana) have rights of access, correction, deletion, portability, and opt-out of targeted advertising, sale and profiling with legal effects. We do not carry out any of those three activities. Where a state law provides an appeal from our decision on a request, you may appeal by replying to our response; if we deny the appeal you may contact your state Attorney General.
- Brazil - we process personal data under the LGPD. In addition to the rights in Section 8 you may request confirmation of processing, anonymisation or blocking of unnecessary data, information about the entities with which we have shared your data, and information about the consequences of refusing consent. You may petition the ANPD.
- Canada - we process personal information under PIPEDA and applicable provincial laws. You may withdraw consent subject to legal and contractual restrictions, and you may complain to the Office of the Privacy Commissioner of Canada.
- Australia and New Zealand - Australian users are covered by the Privacy Act and the Australian Privacy Principles, and New Zealand users by the Privacy Act 2020, including the right to be told if we cannot give you access to your data and why, and the right to complain to the Office of the Australian Information Commissioner or the New Zealand Privacy Commissioner.
- Japan, South Korea and Singapore - we process personal data in accordance with the APPI, PIPA and PDPA respectively, including the disclosure of the third-party categories to whom data is provided and the countries in which it is handled, as set out in Sections 5 and 6. Korean users may withdraw consent and request suspension of processing at any time.
- China - the service is provided from outside mainland China and your data is processed abroad, as described in Section 6. By using the service you give separate consent under the PIPL to that cross-border processing; you may withdraw it at any time, in which case we will no longer be able to provide the service.
- India - under the Digital Personal Data Protection Act you may access, correct and erase your data, nominate another person to exercise your rights in the event of death or incapacity, and raise a grievance with us using the contact in Section 16 before approaching the Data Protection Board.
- South Africa and the Gulf states - South African users are covered by POPIA, including the right to complain to the Information Regulator. Users in the UAE, Saudi Arabia and Qatar are covered by their national data protection laws, which give equivalent access, correction and deletion rights.
If your country is not listed, the rest of this policy still applies to you and we will honour the rights in Section 8 as a matter of practice. Local law may give you further rights - tell us which country you are in and we will apply them. Wherever you are, the service is intended for business users aged 18 or over - see Section 14.
11. Cookies and browser storage
We store a small amount of information in your browser to remember your display preferences, your chosen language and the fact that you are signed in. We do not use advertising or cross-site tracking cookies, we do not use session-replay or heatmap tools, and we do not embed tracking pixels in our emails. We measure availability and faults from our own server records rather than by following you around the web. Because we do not track you across sites, do not serve targeted advertising and do not sell or share personal data, there is nothing for a browser "Do Not Track" or Global Privacy Control signal to switch off; where we receive one, we treat it as confirming the position we already apply to everyone. If we introduce cookies that require consent, we will update this policy, ask for your consent first, and give you a way to change your mind - see Section 9.
12. Third-party links
The service, our reports and our emails may link to websites we do not operate - a supplier, a standards body, a regulator, or a research source cited in your report. Following such a link takes you outside PackageIQ and this policy stops applying: those sites collect and use data under their own privacy policies, which we do not control and for which we are not responsible. Please read the policy of any site you visit before giving it personal data.
13. How do we protect your data?
We apply appropriate technical and organisational measures to protect your personal data against loss, misuse, unauthorised access and unlawful processing. Passwords are never stored in a readable form, data is encrypted in transit, and access to production systems is restricted to authorised personnel and protected by multi-factor authentication. No online service can be guaranteed to be completely secure, so please keep your password confidential and tell us promptly if you suspect misuse of your account.
14. Children
PackageIQ is a business tool and is not designed for or directed at children. We do not knowingly collect personal data from anyone under 18, and an account may only be opened by someone able to enter into a binding contract. If we discover that a child has provided us with personal data, we delete it from our systems. If you believe a child has given us personal data, tell us using the contact in Section 16 and we will act on it.
15. Changes to this policy
We may update this policy to reflect changes in the service or in applicable law. Material changes will be notified by email to registered users at least 14 days before they take effect. Continued use of the service after that date constitutes acceptance of the revised policy. In the event of ambiguity, the English text of this policy prevails.
16. Contact
Questions about this policy, requests to exercise your data rights, or complaints - from any country - can be sent to us here, and we will route them to the right team:
We have not yet appointed a representative under Article 27 GDPR (EU) or Article 27 UK GDPR. We are in the process of appointing one and will publish the representative's name and address here once confirmed. Until then, users in the EEA, the UK and Switzerland can direct any query, request or complaint to the email address above, and we will handle it under the same time limits.