Privacy Policy
Last updated: August 2026
This Privacy Policy explains how BadgeSeal, an individual enterprise based in Austria with its place of business at Schillergasse 45/3, 2620 Neunkirchen, Austria ("BadgeSeal", "we", "us"), collects and processes personal data. We comply with the EU General Data Protection Regulation (GDPR) and applicable Austrian data protection law.
1. Two roles: controller and processor
When an organization creates a BadgeSeal account, that organization is the data controller for the personal data of its own staff members (names, photos, contact details, role titles) that it uploads to the Service. BadgeSeal acts as a data processor for that staff data, processing it only as instructed by the organization, solely to provide the Service. For the organization's own admin accounts (the people who sign in to the dashboard) and for visitors to our public pages, BadgeSeal acts as the data controller.
2. What we collect
- Admin account data: email address, hashed password (or Google account identifier if you sign in with Google), organization name, and optional two-factor authentication settings.
- Staff data (uploaded by the organization): name, role, contact details, and an optional photo, used to generate a business card and/or badge.
- Billing data: for paid subscriptions, our payment provider collects and processes payment card details directly — BadgeSeal does not store full card numbers.
- Technical data: standard web server logs (IP address, request timestamps) generated by our hosting infrastructure, and the contents of the admin session cookie used to keep you signed in.
3. How we use it
We use this data to operate the Service: authenticating admins, generating and serving business cards and badges, verifying scanned badges, sending transactional emails (password resets, admin invitations, welcome emails), and — only if an organization chooses to use the design-import feature — analyzing an uploaded photo of an existing card or badge to suggest a matching template and color palette. We do not sell personal data or use it for advertising.
4. Sub-processors
We rely on the following service providers to operate BadgeSeal. Each processes data only as necessary to provide its service to us:
- Cloudflare, Inc. — hosting, database, and file storage for the entire application.
- Resend — delivery of transactional emails (password resets, invitations, welcome emails).
- Anthropic, PBC — analyzes an uploaded design photo when an organization explicitly uses that optional feature.
- Google LLC — used only if you choose "Sign in with Google" instead of a password.
- Microsoft Corporation — used only if you choose "Sign in with Microsoft" instead of a password.
- Our payment provider — processes subscription payments as merchant of record for paid plans.
Some of these providers may process data outside the European Economic Area. Where that is the case, they do so under appropriate safeguards such as Standard Contractual Clauses or an equivalent adequacy framework.
5. Data retention
We keep staff and account data for as long as the organization's account remains active. If an organization is deactivated, its data is retained but no longer publicly accessible, so it can be reinstated on request; permanent deletion can be requested at any time by contacting us.
6. Your rights
If GDPR applies to you, you have the right to access, correct, delete, restrict, or export your personal data, and to object to certain processing. If you are a staff member whose card or badge was created by an organization using BadgeSeal, please contact that organization first, since it controls your data; if you are an admin account holder, contact us directly at contact@badgeseal.com. You also have the right to lodge a complaint with the Austrian data protection authority (Österreichische Datenschutzbehörde) or your local supervisory authority.
7. Cookies
BadgeSeal uses a small number of strictly necessary cookies — an admin session cookie to keep you signed in, and a cookie to remember your chosen dashboard language. We do not use advertising or third-party tracking cookies.
8. Security
Passwords are hashed, never stored in plain text. Each organization's badge-signing key is encrypted at rest. Access to the admin dashboard is protected by session-based authentication with optional two-factor authentication.
9. Changes to this policy
We may update this Privacy Policy from time to time; material changes will be communicated to account owners.
10. Contact
For any privacy question or request, contact us at contact@badgeseal.com, or see our Contact page.