Privacy & consent
The Privacy & Consent page puts you in control of how Traceable processes your data. This includes AI processing consent, data exports under GDPR, cookie preferences, and email notification preferences. Navigate to Settings → Privacy & Consent to manage these settings.
AI Processing Consent
What It Means
Traceable's Document AI feature uses Anthropic Claude to analyse compliance documents you upload — for example, to extract battery chemistry data from a manufacturer's test report, identify missing fields in a Declaration of Conformity, or summarise a supplier's technical file. This involves sending the content of uploaded documents to Anthropic's API for processing.
AI processing is governed by Anthropic's data processing terms. Document content sent for AI analysis is not used to train AI models. However, because third-party processing is involved, explicit consent from your organisation is required before this feature activates.
Document AI does not activate until you give consent. Without consent, all other Traceable features work normally — only the Document AI capabilities are unavailable.
Giving Consent
Consent can be given in two ways:
- First-use modal — the first time you navigate to a Document AI feature, a consent dialogue is displayed. You must click I accept to proceed. This records your own consent.
- Settings page — navigate to Settings → Privacy & Consent and toggle AI Document Processing to the on position. Confirm in the dialogue that appears.
Consent is recorded per user. Each user grants or revokes their own AI-processing consent — it is not given or withdrawn on behalf of the whole account.
Revoking AI Consent
To revoke consent:
- Navigate to Settings → Privacy & Consent.
- Toggle AI Document Processing to the off position.
- Confirm the revocation in the dialogue.
Revocation takes effect immediately:
- Document AI features are disabled for your user (other users' consent is unaffected).
- No further documents are sent to Anthropic for processing on your behalf.
- Documents that were already processed are not retroactively deleted — the extracted data already stored in your DPPs is not affected. Only future processing is stopped.
To re-activate Document AI later, return to Settings → Privacy & Consent and toggle AI Document Processing back on.
Data Export (GDPR Article 20)
Under Article 20 of the General Data Protection Regulation (GDPR), you have the right to receive a copy of the personal and organisational data Traceable holds about you in a portable, machine-readable format.
Requesting a Data Export
- On the Privacy & Consent page, click Request data export.
- Confirm the request in the dialogue.
- Traceable assembles your export and your browser downloads the JSON archive directly. No email link is sent, and there is no waiting period.
What the Export Contains
The export is a structured JSON archive containing:
- Your company profile data (legal name, address, contact details).
- Your account metadata (creation date, plan history, last activity).
- All products and DPP data associated with your account.
- All compliance documents (as file references; binary files can be separately requested via support).
- All verifiable credentials issued or received by your account.
- Your full account audit log.
- Your team member list and invitation history.
The export does not include third-party data (e.g., other companies' DPPs that you have viewed, or supplier data that belongs to another account).
How You Receive the Export
The export downloads directly in your browser as soon as it is generated. Nothing is emailed, and there is no expiring link. If the download does not start, or is interrupted, return to the Privacy & Consent page and request the export again.
Cookie Consent
Under the ePrivacy Directive (Article 5(3)), cookies that are strictly necessary for a service the user has requested may be set without consent, while non-essential cookies require prior consent.
Traceable's Operator Portal sets only strictly necessary cookies — the session cookies required for authentication and core platform functionality. These cannot be disabled, because the platform cannot operate without them, and they do not require consent.
Traceable does not currently set performance, functional, or marketing cookies that would require prior consent, so there is no in-portal cookie preference panel to configure. A managed consent banner (CookieYes) is planned to handle granular, category-level cookie choices if and when any non-essential cookies are introduced.
Email Preferences
Email preferences let you configure which types of automated emails Traceable sends to your registered email address. Each category can be toggled independently.
| Category | Description |
|---|---|
| Product alerts | Notifications about your own DPPs — e.g., a DPP approaching its review date, a certificate expiring soon. |
| Team alerts | Notifications about team member activity — e.g., a team member has published a DPP or been added to the account. |
| Supply chain updates | Notifications about your supply chain — e.g., a supplier has responded to a data request, a verifier has completed a task. |
| Campaign notifications | Notifications about campaigns — e.g., a campaign acknowledgement received, a recall campaign with outstanding recipients. |
| Marketing | Product updates, feature announcements, and educational content from Traceable. |
To update your preferences:
- Toggle each category on or off as required.
- Click Save preferences.
Transactional emails that are required for account security — such as email verification messages, password reset emails, and two-factor authentication codes — are not subject to email preferences and cannot be disabled.