Noedal Inc. is the controller for the public Noedal website and customer-account administration. Its address is 1207 Delaware Ave #754, Wilmington, DE 19806, USA. Contact legal@noedal.com or use our contact form for privacy questions or requests.
This notice covers visitors, account users, business contacts and people whose information is included in Noedal workflows. A privacy notice explains processing; using the site does not by itself constitute consent to optional processing.
Who is responsible
For customer documents and records processed on an organization's instructions, that organization generally determines the purpose and is the controller; Noedal acts as its processor or service provider. Direct requests about those records to that organization, or contact us so we can help route them.
Noedal Technologies OÜ (Estonia), Noedal Limited (UK), and Sellpoint Co., Ltd. (Republic of Korea) may provide contracted or regulatory-representation services. The applicable agreement identifies their role. An entity's role follows its actual responsibilities, not simply your location. A data-processing agreement is required where the relationship calls for one; this notice is not a substitute.
Information and sources
Account and business information includes names, work email addresses, phone numbers, organizations, roles, profile images, addresses and verification documents. We receive it from you, your employer or organization administrator, invited collaborators, and connected business contacts.
Workspace information includes formulas, product and facility records, labels, files, messages, comments, shared presentations, assessor qualifications, signatures, regulatory submissions and their history. Formulations are not necessarily personal data, but associated contact details and documents can be.
Safety reports may contain reporter or consumer contact details, age-related information, health symptoms, photographs and other sensitive information. Use the designated safety workflow, minimize identifying detail, and do not put unnecessary health information or identity documents into general messages or AI prompts.
Transactions include billing contacts, order amounts, tax information, payment status and provider identifiers. Payment providers handle full card credentials; Noedal receives the information needed to reconcile payments and manage authorized renewals.
Technical information includes IP addresses, browser/device information, security logs and service activity. Optional website analytics uses cookie identifiers and page visits only after permission. Requested website links and public regulatory sources may also supply information relevant to a workflow.
Purposes and legal grounds
We use information to operate accounts and workspaces, fulfill orders, prepare and track authorized regulatory work, support collaboration, respond to requests and maintain transaction records.
For EU/EEA and UK processing, the basis depends on the activity: a contract with the individual, legitimate interests in administering business relationships and protecting the service, applicable legal obligations, or consent for optional activities. We consider the impact on individuals when relying on legitimate interests. An employee's data is not automatically covered by their employer's contract as an individual contractual basis.
Optional analytics and promotional communications require consent where applicable. You can refuse or withdraw without losing unrelated core services. Essential service, billing and safety messages are separate from marketing.
Sensitive information requires an additional lawful condition, not just a general business interest. The relevant controller must establish the applicable condition for health or safety records, such as explicit consent or a specific legal/public-health obligation. Korean processing uses the applicable PIPA ground, with separate consent where required.
AI-assisted features
AI-assisted extraction, translation, label review and drafting can send selected content, artwork and associated context to the configured AI provider. Review the material before using these features and avoid unnecessary personal data. Outputs can be inaccurate and require review; they do not constitute a government decision or a qualified assessor's signature.
This notice does not grant a license to train general-purpose models on confidential customer content. Provider training, storage and regional-processing conditions must be governed by the applicable service and data-processing terms, not inferred from a model name. Contact us before uploading data that requires specific regional or sensitive-data safeguards.
You can ask for an explanation and human review of a decision affecting you. Rights concerning solely automated decisions with significant effects apply where the relevant law provides them.
International processing
The core production application is hosted in AWS's Seoul region. Noedal's personnel, affiliated service entities, global content delivery and external providers can involve processing in Korea, the United States, the EEA, the UK or other provider locations. Hosting in Seoul does not mean all processing remains in Korea.
Where EU/EEA or UK transfer restrictions apply, a transfer needs an applicable adequacy decision or other valid safeguard, such as the appropriate contractual clauses together with any required assessment and supplementary measures. A cloud certification alone is not a transfer mechanism. Contact us for information about the safeguards applicable to your service.
For Korean information, PIPA Article 28-8 applies to overseas transfers. Where notice or separate consent is required, it must identify the data, recipient and contact, country, timing/method, purpose, retention and the method and effect of refusal. This general policy is not blanket overseas-transfer consent. Please request the service-specific transfer information before enabling a workflow subject to those requirements.
Retention and deletion
Retention depends on the purpose, customer instructions, contract, applicable legal period and any legal hold. Account information is used while the relationship continues and as needed to close the account, resolve disputes or meet legal obligations.
Where Korean e-commerce recordkeeping applies, contract/withdrawal and payment/supply records are generally retained for five years, consumer complaint/dispute records for three years, and advertising records for six months. Other jurisdictions or tax obligations can require different periods.
Regulatory, safety and signed evidence can need longer retention than the subscription. Removing a product or ending a subscription does not automatically erase filed records, reviewed-label history, shared copies or authority records. Only the records needed for the continuing purpose should be retained, with access restricted as appropriate.
When retention is no longer justified, information should be deleted or irreversibly anonymized. Backup expiry and legal holds can delay final erasure. Ask us for the retention criteria and deletion arrangements applicable to a particular record. Website cookie-choice and analytics-cookie periods are described in the Cookie Policy.
Security
Noedal uses access controls, encrypted connections and protected storage to reduce risk. Organizational roles, scoped sharing, staff authorization and activity records support access management. These controls do not make every user action safe or guarantee that a breach cannot occur.
Report suspected unauthorized access promptly. We assess incidents and make notifications to affected people, customers and authorities where required by the applicable law and our contractual role.
Your rights and requests
Depending on applicable law, you may request access, correction, deletion, portability, restriction or suspension, object to processing, or withdraw consent. Rights are subject to legal exceptions. We may verify identity and authority proportionately, but do not require unnecessary sensitive documents. We will explain a refusal and available review or appeal routes.
EU/EEA and UK: responses are generally due within one month, with a permitted extension explained within that month. You may object to direct marketing and complain to your competent supervisory authority. Withdrawing consent does not make earlier lawful processing unlawful.
Korea: you may request access, correction/deletion, suspension and withdrawal of consent under PIPA, including through an authorized representative. We follow the statutory procedure and deadlines, including the ten-day access-response period where applicable. Complaints may be raised with the Personal Information Protection Commission, KISA's privacy center or the Personal Information Dispute Mediation Committee.
US: applicable state laws may provide rights to know/access, correct, delete, obtain a copy and opt out of sale, cross-context sharing, targeted advertising or specified profiling, with additional sensitive-data rights. California requests generally receive a response within 45 days, subject to a permitted extension. Authorized agents may act with appropriate verification. Where an appeal right applies, reply to our decision requesting an appeal. We do not penalize you for exercising protected rights.
Contact legal@noedal.com or our contact form. Tell us the request and the service involved; do not send passwords or full payment credentials. If an organization controls the record, we will assist it as appropriate rather than bypass its lawful instructions.
Sale, sharing and tracking choices
We do not sell personal information for money. The public website does not enable advertising or retargeting tags, and optional Google Analytics is disabled until permission is given. The site honors Global Privacy Control by keeping optional analytics off in that browser. This does not alter required security or transaction processing.
Cookie settings can be reopened from the footer. Choices apply to this website and browser, not automatically to other devices, the authenticated app or independent provider websites. Traditional Do Not Track is not a uniform consent standard; use the cookie controls or Global Privacy Control for this site.
Children and safety reports
Business accounts are intended for adults aged 18 or over. Safety reports can concern children even though the platform is not marketed to them. Such records require appropriate authority, minimization and safeguards, and may need to be retained for applicable safety obligations. A child should not create a business account. Contact us about incorrectly collected information.
Changes to this notice
We update this notice when processing changes and show the revision date. Material changes require appropriate notice; a new purpose or consent requirement is not authorized merely by publishing revised wording. Mandatory local protections take priority. Contact us to obtain a previous version or discuss the processing applicable to your agreement.

