Privacy Policy

Effective date: 19 June 2026  ·  Version 1.1  ·  Controller: EGS Enggist and Grandjean Software SA

Contents

  1. Who We Are and Scope
  2. Controller and Processor Clarification
  3. Notice to Kitchen Staff
  4. What We Collect and Why
  5. Cookies and Local Storage
  6. Data Storage and Security
  7. Data Retention
  8. Data Sharing
  9. International Transfers
  10. Your Rights (All Jurisdictions)
  11. EEA and Swiss Residents
  12. UK Residents
  13. California Residents (CCPA/CPRA)
  14. Other US State Rights
  15. Australian Residents
  16. Canadian Residents
  17. India Residents
  18. Singapore Residents
  19. South Africa Residents
  20. New Zealand Residents
  21. Supervisory Authorities
  22. Breach Notification
  23. DPA with Customers
  24. AI-Assisted Features
  25. Children
  26. Changes to This Policy
  27. Contact

1. Who We Are and Scope

EGS Enggist and Grandjean Software SA operates Blaze Labels, a B2B kitchen food-safety label printing application for hotels and restaurants. This Privacy Policy explains how EGS processes personal data in connection with the Blaze Labels service (the "Service"), the Blaze Labels website, and related communications.

This Policy applies to: business customers (account holders, administrators); kitchen staff whose names are associated with print jobs by their employer; and visitors to blaze.calcmenu.io.


2. Controller and Processor Clarification

Privacy law distinguishes between a data controller (who determines why and how data is processed) and a data processor (who processes data on the controller's instructions).

Category of dataControllerProcessor
Staff name + print activityCustomer (the hotel or restaurant)EGS
Printer MAC address, odometer countEGSSupabase (infrastructure)
Admin email hash, device platform, quota dataEGSSupabase (infrastructure)

When EGS processes staff personal data on behalf of a Customer, EGS acts as a data processor under GDPR Article 28 and equivalent laws. Our Data Processing Agreement (DPA), available at blaze.calcmenu.io/dpa, governs that relationship and is incorporated into the Terms of Service for all business customers.

When EGS processes printer telemetry, quota data, and admin account data for its own legitimate business purposes, EGS acts as data controller.


3. Notice to Kitchen Staff

If you are a kitchen employee

Your employer (the hotel or restaurant) is the data controller for the processing of your name in Blaze Labels. Your employer has chosen to use Blaze Labels as a food-safety compliance tool.

What Blaze Labels records: Your name is associated with each label you print to provide a food-safety audit trail. This is standard practice in commercial kitchens.

Your rights: You may exercise your rights (access, correction, deletion, etc.) by contacting your employer directly. You may also contact EGS at privacy@blazeiq.io — we will coordinate with your employer to respond within the applicable legal timeframe.

Data retention: Your employer controls how long your print history is retained. EGS will delete staff print records when a customer account is closed, subject to any legal retention obligations.


4. What We Collect and Why

4.1 Data We Collect Directly

Data elementWhy we collect itLawful basis (GDPR Art. 6)
Admin account email (SHA-256 hash, first 16 hex chars)Account identificationLegitimate interest (Art. 6(1)(f))
Staff name (as entered by employer)Food-safety audit trail per print jobContract performance — processor role (Art. 6(1)(b))
Food item name per print jobFood-safety audit trailSame as staff name
Print timestampAudit trail, quota calculationLegitimate interest
Device platform (e.g., "android", "ios", "web")Bug diagnosis, compatibility analytics — not a full user-agent stringLegitimate interest
Printer Bluetooth MAC addressPrinter identification; quota enforcement per printerContract performance (Art. 6(1)(b))
Printer odometer count (cumulative labels printed)Quota tracking; fraud preventionContract performance
Label quota balanceService delivery; quota enforcementContract performance
Staff profile photo (optional, taken or selected by admin)Display on staff selection screen and print historyConsent / contract performance (Art. 6(1)(b))
Custom label background images (optional, uploaded by admin)Visual branding on printed labelsContract performance (Art. 6(1)(b))

4.2 Admin Email Hashing

The administrator email address is stored as the first 16 hexadecimal characters of its SHA-256 hash (96 bits). This is pseudonymous data: it cannot be trivially reversed but does not meet the legal standard for anonymization under GDPR Recital 26. We treat it as personal data and apply full safeguards accordingly.

4.3 What We Do Not Collect

Blaze Labels does not collect:

4.4 Camera and Photo Library

The Blaze Labels mobile app may request access to the device camera and photo library solely to let administrators capture or select staff profile photos and custom label background images. Images are uploaded to the customer's Supabase storage bucket and are not used for advertising, analytics, or any purpose other than displaying them within the customer's own Blaze Labels account.

4.5 Bluetooth Low Energy (BLE) Scanning

The Blaze Labels mobile app performs BLE scanning to discover nearby label printers. During a scan, the app receives advertisement packets from all BLE devices in range. Unknown MACs are discarded immediately in memory and are never written to storage, logged, or transmitted. Only MACs that match a printer registered in your Blaze Labels account are retained and used.


5. Cookies and Local Storage

5.1 Local Storage (App)

The Blaze Labels web and mobile application stores application state in browser localStorage (not cookies). This includes: selected printer configuration, user preferences, print history cache, and session tokens.

This storage is strictly necessary for the application to function. Under the UK Privacy and Electronic Communications Regulations (PECR) and equivalent EU ePrivacy rules, strictly necessary storage is exempt from the consent requirement. No consent banner is required for this storage.

5.2 Cookies (Website)

blaze.calcmenu.io may set essential session cookies for authentication. No third-party advertising or tracking cookies are set. If we introduce non-essential cookies in the future, we will update this Policy and implement appropriate consent mechanisms.


6. Data Storage and Security

Personal data is stored on Supabase (Supabase Inc.), hosted in the Zurich, Switzerland region (AWS eu-central-2). EGS has executed Supabase's Data Processing Agreement. Supabase is ISO 27001 certified and SOC 2 Type II compliant.

Security measures include: TLS 1.2+ encryption in transit; encryption at rest; database row-level security (RLS) policies limiting access to the owning customer; admin email hashing; and regular software dependency updates. No system is perfectly secure — we cannot guarantee absolute security against all threats.


7. Data Retention

Data categoryRetention period
Staff print records (name + food item + timestamp)Duration of customer account + 30 days after closure
Printer MAC and odometerDuration of printer registration + 30 days after deregistration
Admin email hashDuration of account + 90 days after closure
Quota transaction log7 years (accounting obligation)
Staff profile photos and custom label backgroundsDuration of customer account + 30 days after closure
Support correspondence3 years from last interaction
Security logs12 months

Where applicable law requires a longer retention period (e.g., food safety record-keeping mandates), the legal requirement governs.


Account Deletion

Admin users who signed in with Google or Apple can delete their own account directly from the Blaze Labels mobile app: Settings → Delete account. This removes the admin's access to all linked properties, deletes the associated authentication record, and revokes any linked Apple Sign-In tokens. Operational data belonging to the business (food items, print records, templates, etc.) is retained for the customer account and is not deleted by this action.

Business customers may also request closure of their entire Blaze Labels account by contacting privacy@blazeiq.io.


8. Data Sharing and Third Parties

We do not sell personal data.

RecipientPurposeBasis
Supabase (Zurich, Switzerland)Database and auth infrastructureProcessor; DPA in place
Stripe / payment processorPayment processing (billing only; no print data shared)Independent controller
Apple / Google (app distribution)App delivery; subject to their platform policiesIndependent controllers
Legal or regulatory authoritiesCompliance with court order, legal obligation, or governmental requestLegal obligation (Art. 6(1)(c))

We do not share staff print data with third parties except as instructed by the Customer (controller) or as required by law.


9. International Data Transfers

9.1 EEA Customers

Personal data from EEA customers is transferred to and stored in Switzerland (Supabase Zurich region, AWS eu-central-2). Switzerland benefits from a European Commission adequacy decision (most recently reaffirmed by Commission Implementing Decision (EU) 2024/2490), so transfers from the EEA to Switzerland do not require additional safeguards such as SCCs. For any onward transfer outside the EEA/Switzerland, we rely on the EU Standard Contractual Clauses (Commission Decision 2021/914).

9.2 UK Customers

For transfers from the UK to Switzerland, the UK has recognised Switzerland as providing adequate protection (UK Adequacy Regulations 2021), so no additional safeguards are required. For any onward transfer from Switzerland to a non-adequate country, we apply the UK International Data Transfer Agreement (IDTA) or the UK Addendum to the EU SCCs.

9.3 EU Representative Assessment

EGS is established in Switzerland (EU adequacy status). EGS does not currently have a formal Article 27 GDPR representative appointed in an EU member state because its processing activities do not meet the Article 27(2)(a) threshold (not large-scale processing of special category data; not systematic monitoring). We keep this assessment under annual review.


10. Your Rights (General — All Jurisdictions)

Depending on your location, you may have the following rights: Access, Correction, Deletion (erasure), Restriction, Portability, Object to processing, and Withdraw consent.

To exercise these rights, contact privacy@blazeiq.io. We will respond within the timeframe required by applicable law. We may verify your identity before processing a request. If you are a kitchen staff member, we will coordinate with your employer to fulfill your request.


11. EEA and Swiss Residents — GDPR and nFADP

Under GDPR and the Swiss nFADP, you may also lodge a complaint with your local data protection supervisory authority. You have the right to human review of automated decisions that significantly affect you — quota enforcement calculations are automated but disputable (see Terms of Service clause 4.4).

For Swiss residents: rights under the revised Federal Act on Data Protection (nFADP, effective 1 September 2023). Supervisory authority: FDPIC at edoeb.admin.ch.

Response time: 30 days (extendable by 60 days for complex requests, with notice).


12. UK Residents — UK GDPR and PECR

EGS processes data relating to UK individuals in accordance with UK GDPR (as retained by the Data Protection Act 2018). Your rights are substantially equivalent to those in Section 11. You may complain to the Information Commissioner's Office (ICO) at ico.org.uk. Response time: one calendar month.


13. California Residents — CCPA / CPRA

13.1 Notice at Collection

This Policy serves as our Notice at Collection. Categories of personal information collected are set out in Section 4.

13.2 Your California Rights

Under CCPA/CPRA, California residents have the right to:

13.3 Exercising California Rights

Submit requests to privacy@blazeiq.io. We will respond within 45 days (extendable by 45 days where reasonably necessary, with notice). We will verify your identity — typically by confirming control of the registered email address. For authorized agents: provide written authorization signed by the consumer, or a power of attorney, together with the agent's identity verification.


14. Other US State Privacy Rights

Residents of the following states have rights to access, correct, delete, and obtain a copy of personal data, and to appeal a denial of a privacy request:

StateLawResponse timeAppeal timeframe
ColoradoColorado Privacy Act (CPA)45 days (+ 45 day extension)45 days
ConnecticutConnecticut Data Privacy Act (CTDPA)45 days (+ 45 day extension)60 days
DelawareDelaware Personal Data Privacy Act (DPDPA)45 days (+ 45 day extension)60 days
IndianaIndiana Consumer Data Protection Act (INCDPA)45 days (+ 45 day extension)60 days
IowaIowa Consumer Data Protection Act (ICDPA)90 days (+ 45 day extension)60 days
KentuckyKentucky Consumer Data Protection Act (KCDPA)45 days (+ 45 day extension)60 days
MarylandMaryland Online Data Privacy Act (MODPA)45 days (+ 45 day extension)60 days
MinnesotaMinnesota Consumer Data Privacy Act (MCDPA)45 days (+ 45 day extension)45 days (+ 60 day extension)
MontanaMontana Consumer Data Privacy Act (MTCDPA)45 days (+ 45 day extension)60 days
NebraskaNebraska Data Privacy Act (NDPA)45 days (+ 45 day extension)60 days
New HampshireNew Hampshire Data Privacy Act (NHDPA)45 days (+ 45 day extension)60 days
New JerseyNew Jersey Data Privacy Act (NJDPA)45 days (+ 45 day extension)45 days
OregonOregon Consumer Privacy Act (OCPA)45 days (+ 45 day extension)45 days
Rhode IslandData Transparency and Privacy Protection Act (RIDTPPA)45 days (+ 45 day extension)60 days
TennesseeTennessee Information Protection Act (TIPA)45 days (+ 45 day extension)60 days
TexasTexas Data Privacy and Security Act (TDPSA)45 days (+ 45 day extension)60 days
UtahUtah Consumer Privacy Act (UCPA)45 days (+ 45 day extension)N/A
VirginiaConsumer Data Protection Act (CDPA)45 days (+ 45 day extension)60 days

To exercise these rights or appeal a denied request, contact privacy@blazeiq.io with the subject line identifying your state. If dissatisfied with our appeal response, you may complain to your state's Attorney General.


15. Australian Residents — Privacy Act and APPs

EGS handles personal information in accordance with the Australian Privacy Act 1988 and the Australian Privacy Principles (APPs). You may request access to or correction of your personal information by contacting privacy@blazeiq.io. We will respond within 30 days. We have ensured our overseas service providers are contractually bound to equivalent privacy standards.

Complaints: Office of the Australian Information Commissioner (OAIC) at oaic.gov.au.


16. Canadian Residents — PIPEDA and Quebec Law 25

16.1 Federal (PIPEDA)

EGS handles personal information of Canadian residents in accordance with PIPEDA. You have the right to access and correct your personal information. Privacy Officer: privacy@blazeiq.io. Supervisory authority: Office of the Privacy Commissioner of Canada at priv.gc.ca.

16.2 Quebec (Law 25)

Quebec residents have additional rights, including portability (structured, commonly used technological format) and de-indexation. Supervisory authority: Commission d'accès à l'information (CAI) at cai.gouv.qc.ca.

Une version française de cette politique de confidentialité est disponible sur demande. Contactez privacy@blazeiq.io.


17. India Residents — DPDP Act 2023

EGS processes personal data of India residents in accordance with the Digital Personal Data Protection Act, 2023. You have the right to: access a summary of personal data processed; correct and complete your personal data; erase your personal data; withdraw consent; and nominate a representative to exercise rights in the event of your incapacity or death.

Grievance Officer: For complaints relating to India residents' personal data, contact privacy@blazeiq.io with subject "DPDP Grievance — India." We will acknowledge within 48 hours and resolve within the statutory period.


18. Singapore Residents — PDPA

EGS complies with the Singapore Personal Data Protection Act 2012 (PDPA). You have the right to access and correct personal data held about you, and to withdraw consent to collection, use, or disclosure.

Data Protection Officer (DPO): privacy@blazeiq.io

Supervisory authority: Personal Data Protection Commission (PDPC) at pdpc.gov.sg.


19. South Africa Residents — POPIA

EGS processes personal information of South Africa residents in accordance with the Protection of Personal Information Act 4 of 2013 (POPIA).

Information Officer: privacy@blazeiq.io. EGS's Information Officer is registered with the Information Regulator.

You have the right to access personal information held about you (subject to POPIA and PAIA conditions). A PAIA Manual is available on request.

Supervisory authority: Information Regulator (South Africa) at inforegulator.org.za.


20. New Zealand Residents

EGS handles personal information of New Zealand residents in accordance with the Privacy Act 2020 and the Information Privacy Principles. Complaints: Office of the Privacy Commissioner at privacy.org.nz.


21. Supervisory Authorities

JurisdictionAuthorityWebsite
SwitzerlandFederal Data Protection and Information Commissioner (FDPIC)edoeb.admin.ch
EU / EEAYour local EU member state DPA (coordinated via EDPB)edpb.europa.eu
United KingdomInformation Commissioner's Office (ICO)ico.org.uk
AustraliaOffice of the Australian Information Commissioner (OAIC)oaic.gov.au
Canada (federal)Office of the Privacy Commissioner of Canada (OPC)priv.gc.ca
Canada — QuebecCommission d'accès à l'information (CAI)cai.gouv.qc.ca
New ZealandOffice of the Privacy Commissionerprivacy.org.nz
SingaporePersonal Data Protection Commission (PDPC)pdpc.gov.sg
South AfricaInformation Regulatorinforegulator.org.za
IndiaData Protection Board (forthcoming under DPDP Act)meity.gov.in

22. Personal Data Breach Notification

If EGS discovers a personal data breach that poses a risk to individuals, we will notify affected parties and relevant supervisory authorities in accordance with applicable law:

JurisdictionAuthority notificationIndividual notification
EU (GDPR)72 hours of awarenessWithout undue delay if high risk
Switzerland (nFADP)Without undue delayWithout undue delay if high risk
UK (UK GDPR)72 hours of awarenessWithout undue delay if high risk
Australia (NDB)As soon as practicable after assessmentAs soon as practicable
Canada (PIPEDA)Promptly, as soon as feasiblePromptly, as soon as feasible
Quebec (Law 25)72 hoursAs soon as practicable
Singapore (PDPA)3 calendar days (≥500 individuals or significant harm)Without undue delay
South Africa (POPIA)As soon as reasonably possibleAs soon as reasonably possible
India (DPDP)As prescribed by Data Protection BoardAs prescribed
New ZealandAs soon as practicableAs soon as practicable

EGS will also notify affected Customers (data controllers) without undue delay upon discovery of a breach affecting their staff personal data, to enable controllers to fulfill their own notification obligations.


23. Data Processing Agreement with Customers

Customers who process staff personal data using Blaze Labels act as data controllers. EGS acts as their data processor. Our standard Data Processing Agreement (DPA), compliant with GDPR Article 28 and applicable national implementations, is available at blaze.calcmenu.io/dpa. The DPA covers: processing purpose and duration, data subject rights handling, subprocessor management, security obligations, and breach notification.


24. AI-Assisted Features

Blaze Labels uses AI language models (via Anthropic's Claude API) for two optional, catalog-management features available to business administrators:

These features process food item and category names only — not staff names, print logs, or any other personal data covered elsewhere in this Policy. Suggested and translated text is always editable and subject to administrator review before it is used; nothing is auto-published without a human confirming it. This processing takes place under Anthropic's commercial API terms, which do not use submitted content to train AI models.

If your organisation needs more detail on our AI vendor's data handling terms for your own compliance review, contact privacy@blazeiq.io.


25. Children

The Service is not directed to persons under the age of 16, and we do not knowingly collect personal data from children under 16. If we learn that personal data of a person under 16 has been collected, we will take steps to delete it promptly. Contact: privacy@blazeiq.io.


26. Changes to This Policy

We may update this Privacy Policy from time to time. When we make material changes, we will update the effective date and provide notice via email or in-app notification at least 30 days before the changes take effect. Your continued use of the Service after the effective date constitutes acceptance. Previous versions are available on request.

27. Contact

EGS Enggist and Grandjean Software SA

Rue des Usines 17, 2000 Neuchâtel, Switzerland (CHE-112.254.588)

Privacy inquiries: privacy@blazeiq.io

For GDPR/nFADP requests, include "Privacy Request" in the subject line and indicate your jurisdiction.