MGTrace← Back to site

MGTrace — Privacy Policy

Last updated: 11 September 2026

This Privacy Policy explains how ERIN AUTOMATION, S.L. ("MGTrace", "we", "us") collects and uses personal data when you visit our website, create an account and use the MGTrace platform (the "Service"). It meets the transparency requirements of Articles 13–14 of the EU General Data Protection Regulation (GDPR) and Spain's LOPDGDD.

Our two roles. For the data of your own account (identity, usage, communications) we are the data controller, and this Policy governs that. For the content you create inside the Service on behalf of your organization (documents, requirements, protocols, electronic signatures and the personal data of your team contained in them), your organization is the controller and we act as a data processor on its instructions — that relationship is governed by our Data Processing Agreement (DPA), not this Policy.

1. Who we are (Controller)

  • Controller: ERIN AUTOMATION, S.L. (Sociedad Unipersonal; CIF B-25925611)
  • Registered address: Avinguda Can Serra, 3, Escalera B, 3º 3ª, 08390 Montgat (Barcelona), Spain
  • Privacy contact: privacy@mgtrace.com

2. The personal data we process

Where we are the controller, we process:

a) Account & identity data — name, email address, password (stored only as a salted hash by our authentication provider), and your organization and role within it.

b) Profile / segmentation data — the optional job role and intended use you provide at sign-up, used for product analytics and to improve onboarding.

c) Authentication & security data — cookies strictly necessary to keep you logged in (sb-…-auth-token) and to enforce inactivity time-out (mg_last_activity); if you enable a second factor, the authenticator enrolment held by our auth provider and, only if you ask for it, a record of the browsers you chose to remember (browser type, dates, expiry). Sign-ins, failed attempts and lockouts are recorded in the audit trail.

d) Usage data — records of pages you navigate within the Service (event, path, timestamp) and your approximate location (country, city, region) derived from your IP address. We do not store your raw IP address in usage analytics, and we do not use third-party advertising or tracking cookies. On the public website and in the Service we also measure visits and page performance with Vercel Web Analytics and Speed Insights — cookieless and aggregated (page, referrer, country, browser and device class, load-time metrics), with no identifier stored on your device and no raw IP address kept.

e) Electronic signature & audit data — when you sign a record or when the system logs a controlled change, we record your identity, role, the meaning of the signature, the date-time (UTC) and your IP address. This is required to meet electronic-records and audit-trail obligations (e.g. 21 CFR Part 11, EU Annex 11) and to protect the integrity of regulated records.

f) Communications — verification, invitation, password-reset and service emails, messages about your account during early access (welcome, onboarding help, requests for feedback), any messages you send us for support, and the feedback and error reports you submit from within the Service (with the version, page and browser they came from).

g) Waiting list — if you request early access from the website: your email address and, for abuse prevention only, your IP address, kept for 30 days.

We do not intentionally collect special categories of data (Article 9). The Service is designed for equipment/software commissioning & qualification data, not patient or health data, and customers are contractually required not to upload special-category data.

3. Why we use it, and our legal basis

Purpose Legal basis (GDPR Art. 6)
Create and operate your account; provide the Service Performance of a contract (6.1.b)
Authenticate you and keep sessions secure (incl. inactivity log-off) Performance of a contract / legitimate interests (6.1.b/f)
Electronic signatures, audit trail, record integrity and retention Legal obligation / legitimate interests (6.1.c/f)
Product analytics and improvement (usage, approximate location) Legitimate interests (6.1.f) — you may object (see §7)
Optional job-role / intended-use segmentation Legitimate interests / consent (6.1.f/a)
Service messages about your account during early access (welcome, onboarding help, feedback requests) — never advertising Performance of a contract / legitimate interests (6.1.b/f) — you may object at any time
Marketing or academy communications, where offered Consent (6.1.a) — opt-in, withdrawable at any time
Comply with law and respond to lawful requests Legal obligation (6.1.c)

4. Cookies

We use only strictly necessary cookies (authentication and session time-out) and one functional cookie you set yourself when you tick "Remember this browser" after a second-factor code. We do not use analytics, advertising or third-party tracking cookies; visit and performance measurement (Vercel Web Analytics and Speed Insights) is cookieless and stores nothing on your device, and no third-party fonts are loaded at run time, so no cookie-consent banner is required for current functionality. See our Cookie Policy for details. If we introduce non-essential cookies in future, we will ask for your consent first.

5. Who we share data with

We do not sell your personal data. We share it only with:

  • Service providers (processors) who host and run the Service under contract and appropriate safeguards:
    • Supabase — database, authentication and file storage (hosted in the EU — eu-west-1, Ireland);
    • Vercel — application hosting, serverless compute, IP-based geolocation headers and cookieless web analytics (visits and page performance, aggregated);
    • Resend — delivery of service emails (verification, invitations, password reset), EU region (Ireland). A current list is available in our Sub-processor List (Annex to the DPA).
  • Authorities or third parties where required by law, to protect our rights, or in connection with a corporate transaction.

6. International transfers

We host data in the European Union wherever possible. Some providers (e.g. Vercel, based in the United States) may process data outside the European Economic Area. Where that happens, we rely on the European Commission's Standard Contractual Clauses (SCCs) and, where relevant, additional safeguards. You can request a copy of the safeguards via the contact above.

7. Your rights

Subject to the GDPR, you have the right to access, rectify, erase, restrict and port your personal data, to object to processing based on legitimate interests (including product analytics), and to withdraw consent at any time without affecting prior processing. To exercise any right, contact privacy@mgtrace.com; we will respond within one month.

Note: some records (electronic signatures, audit-trail entries) cannot be erased while they are required for the integrity of regulated records or to comply with a legal obligation; we will explain any such limitation when you ask.

You may also lodge a complaint with your supervisory authority. In Spain this is the Agencia Española de Protección de Datos (AEPD) — www.aepd.es.

8. How long we keep it

Data Retention
Account & profile While your account is active; deleted or anonymized within 90 days of account closure
Usage analytics 24 months, then aggregated/anonymized
Electronic signatures & audit trail Retained for the life of the regulated record and any legally required period, even after account closure
Support communications 24 months

9. Security

We apply technical and organizational measures appropriate to the risk, including encryption in transit (HTTPS/TLS), encryption at rest, role-based access control, database row-level security isolating each organization's data, session inactivity log-off, an immutable audit trail, and least-privilege access for our own staff. No system is perfectly secure, but we work to protect your data and to detect and respond to incidents.

10. Automated decision-making

We do not make decisions producing legal or similarly significant effects about you based solely on automated processing.

11. Children

The Service is a professional B2B tool and is not directed to, or intended for, anyone under 18.

12. Changes to this Policy

We may update this Policy from time to time. We will post the new version here and update the "Last updated" date; material changes will be notified through the Service or by email.

13. Contact

Questions or requests: privacy@mgtrace.com, or by post at the registered address above.

Privacy PolicyCookie PolicyTerms & ConditionsLegal notice

ERIN AUTOMATION, S.L. (Sociedad Unipersonal) · CIF B-25925611 · Avinguda Can Serra, 3, Esc. B, 3º 3ª, 08390 Montgat (Barcelona), Spain · Registro Mercantil de Barcelona, Hoja B-647457

© 2026 MGTrace