Privacy policy — MYDG applications
Last updated: 15 July 2026 · version 1.0
Who we are
The controller of the personal data described in this policy is MYDG.SHOP SL, a company registered in Spain, VAT number ESB26607069, with its registered office at C. Jeronimo de Valencia 28, Despacho 6, 06006 Badajoz, Spain. You can contact us about anything in this policy at contact@mydg.shop.
What this policy covers
This policy covers the applications we operate at app.mydg.shop:
- MYDG2CHECK — verification of dangerous goods shipments.
- MYDG ADR/AGENT — the AI assistant for ADR/RID/ADN.
- MYDG2SAVE — the emergency intervention sheet.
Our online store at mydg.shop is a separate service, hosted by Shopify, and is covered by its own privacy policy. If you buy from the store and also use an application, both policies apply, each to its own part.
What we process, and why
Your account and access
To give you access to any application we process your email address, together with authentication records (sign-in times, the device and browser used) and, where applicable, the organisation you belong to and your access permissions. The email address is the account: without it we cannot sign you in, control who has access, or remove access when it ends.
Legal basis: performance of our contract with you, or the steps taken at your request before entering into one. Where access is granted free of charge, our legitimate interest in operating and controlling the service.
MYDG2CHECK
To verify a shipment we process what you submit: the shipment form (including consignor and consignee names, addresses, telephone numbers, air waybill number, origin, destination and the goods declared), the documents you upload (dangerous goods declaration, air waybill, safety data sheets, invoice), the photographs of the packages, the checklist answers, and the report we issue.
These documents commonly contain personal data of people who are not our customer — typically staff of the consignor and the consignee. We process that data only to carry out the verification you asked for, and we do not use it for any other purpose.
Legal basis: performance of our contract with you. Where we act on behalf of a business customer with respect to third-party data contained in their documents, we act as a processor under that customer's instructions; business customers may request a data processing agreement from us.
MYDG ADR/AGENT
We process the questions you ask, the answers given, and usage records (number of questions, date, and the cost attributed to your account). Please do not include personal data or confidential information in your questions when it is not necessary to answer them.
Legal basis: performance of our contract with you; our legitimate interest in measuring use, preventing abuse and controlling cost.
MYDG2SAVE
We process only your email address and the organisation whose access code you used, plus the record of your authorisation and its validity. We do not process your name, your rank, your telephone number, or the substances you look up. The intervention sheets are produced entirely on your device, from data packaged inside the application: your searches are not sent to us and we cannot see them, including when you are online.
Where your organisation has been given access, we may tell it how many of its members use the application and how often, as aggregate figures. We do not tell it what any individual looked up.
Legal basis: performance of our contract with your organisation, or our legitimate interest in providing and controlling access where it is granted free of charge.
Free tools on our website
The free tools published on our store — the 1.1.3.6 calculator, the substance lookup and the dry ice calculator — are answered by our applications, even though they appear on the store. To keep them free and available we allow five uses per tool per day, and to count them we record your IP address, which tool you used and the running count for the day. We do not record what you looked up: the calculation happens in your browser and the substance or quantity you entered never reaches us.
Legal basis: our legitimate interest in preventing abuse of a service we give away.
Asking us for a quote
When you write to us asking for a quote or a service, we record your name, company, email address, telephone number and VAT number, the subject, and the full text of your message, so that we can give the request a number, follow it through, and invoice it if it becomes an order. Messages sent to our addresses are captured into that record automatically.
Legal basis: the steps taken at your request before entering into a contract.
Marketing
We send commercial communications only to those who have asked for them, by ticking the relevant box, which is never ticked in advance. Signing up for an application does not sign you up for marketing. You can withdraw at any time, using the link in every message or by writing to us; withdrawing does not affect your access to the applications.
Legal basis: your consent.
Acceptance of our terms
When you accept the terms of use of an application, we record which product, which version of the text, and when, together with your IP address and browser, and — where available — your email address or the request the invitation link belongs to. We keep this so that we can show what was agreed and when. On the public demonstration of MYDG ADR/AGENT, where you do not sign in, the IP address and browser are the only data recorded.
Legal basis: our legitimate interest in evidencing the agreement and defending our legal position.
Security, obligations and improvement
We process technical records (IP address, application errors, access events) to keep the service secure and to detect abuse; and invoicing data to meet our accounting and tax obligations.
Legal basis: our legitimate interest in the security of the service; compliance with a legal obligation.
Use of artificial intelligence
Two of our applications send content to an artificial intelligence model provided by Anthropic (Claude), which acts as our processor:
- MYDG2CHECK — the documents you upload and the photographs of your shipment are sent to Anthropic to be analysed against the applicable regulations. As set out above, these documents may contain personal data of third parties.
- MYDG ADR/AGENT — your question is sent to Anthropic, together with the extracts of the regulation retrieved to answer it.
- MYDG2SAVE uses no artificial intelligence and sends nothing to Anthropic. It is a lookup performed on your own device.
Anthropic does not use content submitted through its API to train its models. This processing takes place in the United States — see International transfers below.
No decision producing legal effects, or similarly significant effects, is taken about you by automated means alone. The MYDG2CHECK report is reviewed and issued by a human operator before it reaches you. The answers of MYDG ADR/AGENT are informational: they must be checked against the official text cited before being acted on.
Who processes data for us
We use the following processors. Each is bound by a contract that limits them to processing on our instructions:
| Provider | What it does for us | Where |
|---|---|---|
| Supabase | Database, authentication and document storage | Ireland (EU) |
| Railway | Application hosting | Netherlands (EU) |
| Anthropic | Analysis of documents and AI answers (see above) | United States |
| Resend | Sending sign-in and service emails | United States |
| Shopify | Online store and purchases only — not the applications | See the store policy |
We do not sell your personal data, and we do not share it with third parties for their own advertising.
International transfers
Our application servers are in the European Union (Amsterdam), and your account data and the documents you submit are stored in the European Union (Ireland). Only two operations involve a transfer to the United States: the analysis performed by Anthropic and the sending of email by Resend. Those transfers are made under the standard contractual clauses adopted by the European Commission, together with the safeguards set out in each provider's data processing agreement. You may ask us for a copy of the safeguards in place.
How long we keep it
| Data | Retention |
|---|---|
| Account and access | While the account is active, and 12 months after the last sign-in. |
| Security and technical logs (IP, access, errors) | 12 months. |
| MYDG2SAVE — email and authorisation | While the authorisation lasts, and 6 months after it expires without renewal. |
| MYDG2CHECK — forms, documents, photographs and reports | 5 years from the issue of the report, so that we can evidence the verification carried out and meet the record-keeping obligations applicable to dangerous goods transport. |
| MYDG ADR/AGENT — questions and usage records | 24 months. |
| Free tools — IP address | 30 days. Older records are deleted automatically; they serve no purpose once the day has passed. |
| Quote requests — your message and contact details | 3 years from our last contact, if it does not become an order. If it does, the period required by tax law. |
| Acceptance of our terms | 6 years from acceptance, so that we can evidence what was agreed and defend our legal position. We keep it even after the account is deleted, under Article 17(3) GDPR. |
| Marketing consent | Until you withdraw it, plus the record of the withdrawal itself. |
| Invoicing | The period required by Spanish accounting and tax law. |
Your rights
You have the right to access your personal data, to have it corrected or erased, to restrict or object to its processing, to receive it in a portable format, and to withdraw consent at any time where processing is based on consent. Withdrawing consent does not affect processing carried out before you withdrew it.
To exercise any of these rights, write to contact@mydg.shop. We reply within one month. If you believe we have not handled your data properly, you may complain to the Spanish data protection authority, the Agencia Española de Protección de Datos (aepd.es), or to the supervisory authority of the country where you live.
Security
Access to data is separated by customer at database level, so that one customer cannot read another's data. Submitted documents are held in private storage, reachable only through authenticated requests. All traffic travels encrypted. Access by our staff is limited to those who need it to provide the service. No measure is perfect, and we do not claim otherwise.
Children
The applications are professional tools and are not intended for children. We do not knowingly collect data about them.
Changes to this policy
We may update this policy. The date and version at the top always tell you which text is in force. When a change is material, we tell you inside the application before it takes effect, and where we have your consent for something, we ask again.
Contact
MYDG.SHOP SL — VAT ESB26607069
C. Jeronimo de Valencia 28, Despacho 6, 06006 Badajoz, Spain
Privacy: contact@mydg.shop