Privacy Policy
As of December 2025 · version 1.2
This policy explains which personal data we process when you visit woodguardcare.com and when you use the Woodguard platform, for what purpose, and which rights you have.
1. Controller
AutomatonSoft FZ-LLC
Unit Area 199, Alquisaidat Nakheel
Ras Al Khaimah, United Arab Emirates
Phone: +971 (56) 924 6585
Email: info@automatonsoft.com
2. EU representative and data protection officer
Representative pursuant to Art. 27 GDPR: Woodguard EU Representative, c/o Musterkanzlei Berlin (example), Beispielstraße 1, 10115 Berlin, Germany, eu-rep@automatonsoft.com
Data protection officer: datenschutz@automatonsoft.com
3. Categories of data processed
- Server log data: shortened IP address, date and time of access, page requested, referrer, volume of data transferred, browser type and operating system
- Contact and enquiry data: name, company, function, email address, phone number, country, number of suppliers, content of your message
- Contract data when using the platform: billing address, contact person, contract term, payment details
- Platform usage data: sign-in times, user account, actions recorded in the audit trail
- Content you upload: supplier, product and origin data as well as documents that may contain personal details (for example a supplier's contact person)
4. Purposes and legal bases
- Providing and securing the website – legitimate interest in stable and secure operation, Art. 6(1)(f) GDPR
- Handling demo, contact and quotation requests – pre-contractual measures, Art. 6(1)(b) GDPR
- Performing the platform contract – Art. 6(1)(b) GDPR
- Processing customer data inside the platform – on behalf of the customer under Art. 28 GDPR on the basis of a data processing agreement
- Meeting statutory retention and documentation obligations – Art. 6(1)(c) GDPR
- Newsletters or other information where requested – consent, Art. 6(1)(a) GDPR, revocable at any time
5. Processing on behalf of customers
Where you use Woodguard as a customer and thereby process personal data of third parties – for example contact persons at your suppliers – you act as controller and we act as processor. We conclude a data processing agreement under Art. 28 GDPR with every customer before processing begins. It governs instructions, confidentiality, technical and organisational measures, the use of sub-processors, assistance obligations, and deletion or return of data at the end of the contract.
6. Recipients and service providers
We disclose data only where necessary to perform the contract, where you have consented, or where a legal obligation applies. The following are currently engaged:
- Hosting and data centre: provider located in Frankfurt am Main, Germany (example) – processor
- Email and collaboration services: provider with servers in the EU (example) – processor
- Backup and archive storage: provider with servers in the EU (example) – processor
- Tax, legal and audit advisors to the extent required by law
7. Transfers to third countries
The controller is established in the United Arab Emirates. For transfers of personal data from the EU/EEA we rely on the European Commission's Standard Contractual Clauses (Implementing Decision (EU) 2021/914) together with supplementary technical measures, in particular encryption in transit and at rest and least-privilege access control. Platform data is stored in data centres located within the European Union.
8. Retention periods
- Server log data: 7 days, then deleted automatically
- Enquiries without a resulting contract: 6 months after the last contact
- Contract and invoicing data: up to 10 years after the end of the relevant financial year where required by law
- Customer data in the platform: for the duration of the contract; export on request after the contract ends, then deletion within 90 days
- Records of consent: 3 years after withdrawal
9. Cookies and browser storage
This website does not set cookies for marketing or tracking purposes and does not embed any third-party analytics. The only technically necessary item stored is your language selection (key “wg-lang” in the browser's local storage). It is never transmitted to us and can be deleted at any time in your browser settings.
Inside the platform, a technically necessary session cookie is set for authentication. It expires when you sign out, and after 12 hours at the latest.
10. Contact and demo forms
The forms on this website do not transmit your entries to a server; they open a prepared email in your own email client. Transmission therefore takes place via your own email provider. We process the details once your message reaches us, solely in order to handle your enquiry.
11. Your rights
- Access to the data stored about you (Art. 15 GDPR)
- Rectification of inaccurate data (Art. 16 GDPR)
- Erasure (Art. 17 GDPR) and restriction of processing (Art. 18 GDPR)
- Data portability in a structured, commonly used format (Art. 20 GDPR)
- Objection to processing based on legitimate interests (Art. 21 GDPR)
- Withdrawal of consent with effect for the future (Art. 7(3) GDPR)
An informal message to datenschutz@automatonsoft.com is sufficient. We respond within one month.
12. Right to lodge a complaint
You have the right to lodge a complaint with a data protection supervisory authority. The competent authority is the one at your place of residence, place of work or the place of the alleged infringement. For our EU representative this is the Berlin Commissioner for Data Protection and Freedom of Information, Alt-Moabit 59–61, 10555 Berlin (example).
13. Data security
Transmission takes place exclusively over TLS 1.2 or higher. Platform data is encrypted at rest. Access is role-based and logged. Staff are bound to confidentiality; security incidents are reported within 72 hours in accordance with Art. 33 GDPR.
14. No automated decision-making in individual cases
Woodguard produces risk assessments relating to supply chains, products and companies. No automated decision producing legal effects concerning natural persons within the meaning of Art. 22 GDPR takes place; the assessment supports decisions taken by the customer.
15. Changes to this policy
We update this policy when our processing activities or the legal framework change. The version published on this page, with the date stated above, applies.