Privacy

Privacy policy

Last updated: July 17, 2026

Markets in scope (this policy): United Kingdom; the EU/EEA Phase-B1 storefronts (Ireland · Malta · Netherlands · Germany · Sweden · Denmark · Finland · Norway (EEA) · Iceland (EEA) · Austria · Belgium · Luxembourg · Portugal · Croatia · Estonia); Australia; New Zealand.


1. Who we are (controller + representatives + trader identity)

Data controller. The Fred Group, Inc. ("the Company"), a corporation incorporated in Ontario, Canada, operating the NordicScan mobile application.

Registered / trading address (publicly displayed for app-store trader identification under EU Digital Services Act Art. 30 and equivalent store requirements): 795640 3rd Line EHS, Mono, ON L9V 1B5, Canada

Contact for privacy matters: privacy@nordicscan.co — the privacy / DSAR contact and the DSA-trader email. Company phone (public / store-displayed): 888-482-6017 (toll-free). Trader contact (store-displayed, DSA Art. 30): phone 888-482-6017 · email privacy@nordicscan.co.

UK Article-27 representative (UK GDPR / DPA 2018) — APPOINTED 2026-06-17 (PUBLIC). GDPRLocal Ltd. · contact Adam Brogden · contact@gdprlocal.com · 1st Floor Front Suite, 27–29 North Street, Brighton, England BN1 1EB. This is the UK-rep block for the privacy notice and app-store representative/contact field.

EU/EEA Article-27 representative (EU GDPR) — APPOINTED + EFFECTIVE 2026-06-22 (PUBLIC). Instant EU GDPR Representative Ltd · contact Adam Brogden · contact@gdprlocal.com · Office 2, 12A Lower Main Street, Lucan, Co. Dublin, K78 X5P8, Ireland. This is the Company's Art-27 representative in the Union for the EU/EEA storefronts; data subjects in the EU/EEA may contact the representative as well as the Company. Data-subject request channels (representative portals). In addition to privacy@nordicscan.co (the primary contact — see §8), data subjects may contact the representative via the GDPRLocal portals (separate EU/UK paths) — EU/EEA: https://tfgioan-639173199754229335.gdprlocal.com/eu · UK: https://tfgioan-639173199754229335.gdprlocal.com/uk. The primary contact remains privacy@nordicscan.co.

2. What this App is (and is not)

NordicScan is a consumer-research utility: you scan a food or cosmetic product and the App shows ingredient information and a "concern score" computed under our published method.

Nordic Scan provides ingredient information and a concern score under our published method, for general consumer research. It is not medical advice and not a medical device, and does not diagnose, treat, cure, or prevent any disease, or determine the safety of any product. Decide for yourself.

See the methodology page for how the score works and how to challenge a rating.

3. The personal data we process (and why) — the minimized data set

We deliberately collect little. The set below is the minimized schema of record; we do not collect a user "skin type," a user allergy/health profile, or behavioural advertising identifiers, and we do not run a third-party advertising-analytics SDK.

Data What it is Why we process it (purpose) Lawful basis (UK/EU — §§A/B)
Account identifiers Email + an internal account ID (AWS Cognito sub) Create/operate your account; authentication; support Contract (perform the service you sign up for)
Age-gate result Only a pass/fail record: {passed, threshold, storefront, policy_version, timestamp}we do not store your date of birth or precise age Confirm you meet the minimum age for your storefront (§9); statutory child-consent compliance Legal obligation / contract (age-eligibility); minimization by design
Optional gender A gender value only if you choose to provide it (skippable) To tailor product recommendations (an optional feature) — not health recommendations Consent (freely given, withdrawable; not a condition of the core service)
Product images you upload When you add a product for analysis, the packaging photos you upload — a front image, an ingredients image, and a nutrients-panel or usage-instructions image (stored in Amazon S3) Analyze the product; build + maintain our shared product database; analyze, debug, and improve our analysis Contract (the analysis you request) + legitimate interests (maintaining + improving the shared product database and the quality of our analysis)
Scan history Your scan results + history Show your scan history Contract
Scan-time location Precise location captured when you scan or add a product (when-in-use permission; optional — scanning works if you decline) Product availability — powers proximity-aware recommendations Contract / legitimate interests
Subscription / purchase data Subscription status + purchase events (via RevenueCat; the store is the merchant of record) Operate paid subscriptions; entitlement Contract
Market, trial & access data Country-level device-locale and app-storefront signals; your market of record and how it was set; trial start, expiry and status; scan-quota and entitlement status; pseudonymous trial/access analytics Apply market-specific trial and scan allowances, operate access, and measure aggregate trial conversion Contract (access and entitlements) + legitimate interests (service analytics)
Push token A device push token (Firebase Cloud Messaging) created only after you grant the OS notification permission Send transactional / user-requested notifications only — no marketing push without consent Consent (notifications) / legitimate interests (transactional), subject to ePrivacy (§B)
Diagnostics / crash data Crash + stability diagnostics (Firebase Crashlytics) Keep the App stable and secure Legitimate interests, subject to the ePrivacy SDK posture (§B)
Support correspondence What you send us by email/support Answer you; keep a support record Legitimate interests

Our shared product database (community-built). NordicScan is partly built by its users. When you successfully add a product, its front image becomes that product's catalog image and is shown to other users who scan the same barcode. Once published to the shared database, that image is product information keyed to the barcode — no longer linked to you — and it remains in the database even if you later delete your account. The ingredients / nutrients / usage images you upload are not shown to other users; we use them to analyze the product and to debug and improve our analysis.

Retention for analysis & improvement. We may keep the images you upload — whether or not the product is successfully added — for up to 7 years, to analyze, debug, and improve our analysis. See §6. You can object to this improvement use (§7).

Incidental personal data in photos. Product images are meant to capture packaging, but may incidentally include personal data (e.g., a hand or a reflection). They are product images, not health data about you (§4); please photograph only the product.

Source of data (UK/EU GDPR Art. 14). Most data comes directly from you. Some comes from third parties acting in connection with the service: the App stores / RevenueCat (subscription/purchase events), Firebase SDKs (diagnostics + push-token state), and your support correspondence. We do not buy or enrich your data from data brokers.

4. Special-category / sensitive data — the precise claim

No intentional collection of user health-condition, skin-type, allergy, diagnosis, treatment, pregnancy, skin-condition, or health-goal data. Product photos / scan history, scan-time location, and optional demographics (gender) are ordinary personal data — not special-category data under Article 9 UK/EU GDPR (nor "sensitive information" under the Australian Privacy Act / NZ Health Information Privacy Code / HIPC) — unless combined with user health inputs, which the App does not collect.

We deliberately avoid the over-broad assertion "we collect no health data." The accurate position is the bordered statement above. A product's own allergen/ingredient list is public product information, not your personal data.

AU/NZ caveat. This sensitive/health classification for Australia and New Zealand remains subject to the product data-map / HIPC test: any positive finding (a stored sensitive/health field) triggers an APP-3 consent + APP-6 collection-necessity step (AU) or an IPP/HIPC collection-limitation + consent step (NZ) before that market relies on the claim.

5. How we use AI

We use AI-assisted ingredient parsing to read labels. When we handle a data-subject request (§7), controlled AI tooling may assist our team operating only against our own systems — we never paste your personal data into a public AI chat service.

6. How long we keep it (retention)

We keep personal data only as long as needed for the purposes above, then delete or anonymize it. The governing criterion (UK/EU GDPR Art. 13(2)(a)) is: "kept for as long as necessary for the stated purpose, and for any period a legal, tax, or accountability obligation requires, then deleted or anonymized." Provider-side windows (e.g., diagnostics) are confirmed against our systems before we rely on them.

Data Retention (policy)
Account data For the life of your account; deleted on account deletion (after backup aging completes)
Product images you upload (front / ingredients / nutrients / usage) Up to 7 years, to analyze, debug, and improve our analysis — whether or not the product was successfully added
Front image of a successfully added product (shared catalog image) Retained as product-database content keyed to the barcode (de-identified — not linked to you) for as long as the product is in our catalog; persists after account deletion as product information
Scan history Until you delete the item or your account
Age-gate result Life-of-account (audit evidence of the policy decision; no birth date retained)
Subscription / purchase / tax records Retained per financial/tax obligation (RevenueCat-side event records; see DSAR retention exceptions)
Market of record + trial lifecycle fields Life of account (entitlement + access audit)
Pseudonymous trial/access analytics events 180 days
Diagnostics / crash logs (Firebase Crashlytics) 90 days
DSAR audit log 2 years (accountability)

7. Your rights + how to exercise them

Depending on your market you have rights to access, rectification (correction), erasure (deletion), restriction, objection, and data portability, and the right to withdraw consent at any time (without affecting prior processing). Exercise any right by emailing privacy@nordicscan.co — we verify your identity, then respond within the statutory deadline for your market (UK/EU: 1 month, extendable; AU/NZ: without undue delay). We follow a documented internal process for verifying your identity and routing your request to the right systems and processors.

You can also edit or delete optional data (e.g., gender) and your account in-app, and manage notification permissions in your device settings.

Erasure — what we delete, and the two exceptions. When you delete your account, we delete your account and the personal data linked to you, including your user-linked scan records, your active recall watch-list subscriptions, and the images we hold to improve our analysis. Two things we keep: (1) a front image already published to the shared product catalog, and the de-identified product-analysis data we derive and store keyed to the product barcode (our analysis archive), remain as product information no longer linked to you; and (2) records we are required to keep for legal, tax, regulatory, or accountability reasons (e.g., the request audit log, financial records, and the recall-watch archive retained under FDA/CFIA food-safety recordkeeping, typically 5–7 years). Until you delete your account, we may keep photos you uploaded for up to 7 years to improve our analysis (see §6). You may also object (UK/EU GDPR Art. 21) to our use of your uploaded images to improve our analysis.

8. International data transfers

The Company operates from Canada and uses processors in Canada and the United States. When you use the App from the UK or the EU/EEA, your personal data is transferred outside the UK/EEA to these processors. We rely on: - EU/EEA → Canada: the EU adequacy decision for Canadian commercial organisations; and/or Standard Contractual Clauses (SCCs) with a transfer-impact assessment where adequacy does not apply. - UK → Canada/US: the UK International Data Transfer Agreement (IDTA) or the UK Addendum to the EU SCCs, with a transfer risk assessment. - EU/EEA → US processors: SCCs + a transfer-impact note. - AU (APP 8) / NZ (IPP 12): cross-border disclosure handled by contract + comparable-safeguards (see §§C/D).

The current subprocessor list is §3-linked and published below.

8.1 Subprocessor list

Subprocessor Role Location Transfer mechanism
Amazon Web Services (AWS) — Cognito, S3, infrastructure Processor US SCCs / UK IDTA
Google / Firebase — Crashlytics, Cloud Messaging (FCM) Processor US SCCs / UK IDTA
RevenueCat — subscription management Processor US SCCs / UK IDTA
OpenAI — ingredient/text parsing in the rating pipeline Processor — retained on the list as a conservative default US SCCs / UK IDTA
Email (no third-party helpdesk tool) — support + privacy via privacy@nordicscan.co n/a — no separate support subprocessor n/a

The App store itself acts as merchant of record for subscription sales (it is not our subprocessor for that role).

9. Children

NordicScan is not directed at children and is a general-audience consumer-research utility. We apply an age gate at sign-up that stores only a pass/fail result (§3): - 13+ in the United Kingdom, Australia, and New Zealand; - 16+ across the EU/EEA storefronts (a deliberate conservative single value covering the strictest member-state child-consent ages).

We do not knowingly process the personal data of users below the applicable age. We apply child-protective, data-protection-by-design defaults regardless (high-privacy defaults, data minimization, no behavioural profiling, no nudge/dark patterns). If we learn we have collected data from an under-age user, we delete it.

10. Security

We protect your data with appropriate technical and organizational measures (encryption in transit, access controls, least-privilege, vendor due-diligence). No system is perfectly secure; if a breach affecting your data occurs, we follow our data-breach procedure (including any notification the law requires).

11. Cookies / on-device storage / SDKs (ePrivacy)

The App is not a website and does not use advertising cookies or advertising identifiers (no AdMob / AD_ID). Some SDKs store or access information on your device (Crashlytics, Firebase Cloud Messaging). Where the law treats that as requiring consent (EU/EEA ePrivacy, §B), we apply — and, for the EU/EEA, verify before enablement — the SDK-by-SDK posture (diagnostics auto-collection off or strictly-necessary; push token only after OS permission).

12. Changes + how to complain

We will update this policy as the App or the law changes; the effective date is below. If you have a concern, contact privacy@nordicscan.co first. You also have the right to complain to your data-protection regulator — see your market's annex (§§A–D).

Effective date: 2026-06-22 · Version: v1.0 FINAL.


Annex A — United Kingdom (UK GDPR · DPA 2018 · PECR)

  • Controller + UK representative: §1 (the UK Art-27 representative appointed via GDPRLocal).
  • Lawful bases (UK GDPR Art. 6): as mapped in §3 — contract (account, scanning, subscriptions, support records as service necessity), consent (optional gender; marketing notifications), legitimate interests (diagnostics/security, support). For legitimate interests we balance our interest against your rights; we document our legitimate-interests assessments (LIA) in our internal records of processing.
  • Your UK rights: access, rectification, erasure, restriction, objection, portability, and rights related to automated decision-making (we do not carry out solely-automated decisions with legal/similarly-significant effects). Exercise via privacy@nordicscan.co; statutory response 1 month, extendable by up to 2 months for complex requests with notice.
  • PECR (notifications/marketing): we send marketing/push only with consent; transactional messages are service messages.
  • International transfers: UK IDTA / UK Addendum (§8).
  • Complaints: you may complain to the Information Commissioner's Office (ICO)ico.org.uk — as the UK supervisory authority, though we ask that you contact us first.

Annex B — EU / EEA (EU GDPR Arts 13/14 · ePrivacy)

  • Controller + EU/EEA representative: §1. The EU/EEA Art-27 representative (Instant EU GDPR Representative Ltd, Dublin — effective 2026-06-22, §1) is your point of contact in the Union alongside privacy@nordicscan.co.
  • Legal bases (Art. 6): core rating/account = contract 6(1)(b); optional gender + tailored recommendations = consent 6(1)(a) (freely given, specific, informed, withdrawable, age-gated); diagnostics/security = legitimate interests 6(1)(f), subject to the ePrivacy gate.
  • Special-category data: none intentionally collected (§4); we do not rely on an Art. 9 condition because we do not process Art. 9 data.
  • ePrivacy (Art. 5(3)): SDK-by-SDK posture (§11) — Crashlytics auto-collection off or strictly-necessary; FCM token only after OS permission + a transactional/user-triggered need; no marketing push without consent. Before EU enablement we will run and record a fresh-install EU check proving no pre-consent diagnostics/push collection.
  • Your EU rights: access, rectification, erasure, restriction, objection, portability, withdraw consent, and the right to lodge a complaint. Automated decision-making (Art. 22): none with legal/similarly-significant effect.
  • International transfers: EU adequacy (Canada) and/or SCCs + transfer-impact note (US processors) (§8). The subprocessor list is §8.1.
  • Complaints: "You may lodge a complaint with your local EEA supervisory authority." As a non-EU controller acting through a representative, we do not assert a single lead/one-stop-shop authority. Contact the EU/EEA representative or privacy@nordicscan.co first.
  • Age: 16+ across the EU/EEA storefronts (§9).
  • Language (Germany): the German-language version of this privacy notice is provided at the German storefront.
  • VAT / consumer terms: subscription pre-contract disclosure, the 14-day withdrawal right (waivable for immediate digital-content delivery with your express consent + acknowledgement), and cancellation are surfaced at the store paywall — separate from this privacy policy.

Annex C — Australia (Privacy Act 1988 · Australian Privacy Principles)

The Company assumes APP-aligned compliance for Australian users regardless of the small-business threshold. - APP 1 (open & transparent): this policy. - APP 5 (collection notice): at or before collection we tell you what we collect and why (the in-app notice mirrors §3). - APP 8 (cross-border disclosure): your personal information is disclosed to overseas recipients (our Canadian/US infrastructure and subprocessors, §8.1). We take reasonable steps so overseas recipients handle it consistently with the APPs (contractual safeguards). - APP 12 / 13 (access + correction): request via privacy@nordicscan.co; same process as §7. - Sensitive information: we do not collect sensitive/health information about you (§4). If a future product data-map finds sensitive/health fields, an APP-3 consent / APP-6 collection-necessity step becomes a launch condition. - Notifiable Data Breaches (NDB): eligible data breaches are assessed and notified to the OAIC and affected individuals per our data-breach procedure. - Complaints: contact us first; you may complain to the Office of the Australian Information Commissioner (OAIC)oaic.gov.au.

Annex D — New Zealand (Privacy Act 2020 · Information Privacy Principles · HIPC)

NZ rides the same effort as Australia, with NZ-specific naming. - Privacy officer (Privacy Act 2020 requirement): Frederic Hausmann, privacy@nordicscan.co. - IPP 3 (collection notice): at or before collection (in-app notice mirrors §3). - IPP 12 (cross-border): where your information is sent to an overseas person, we rely on the recipient being subject to comparable safeguards (contract) or your authorization; note that an overseas processor/host acting on our behalf is not necessarily a "disclosure" under IPP 12. - IPP 6 / 7 (access + correction): request via privacy@nordicscan.co; same process as §7. - Health information: we do not collect health information about you (§4); if any health-type field were ever stored, the NZ Health Information Privacy Code (HIPC) would apply and a consent step would be required (product data-map test). - Notifiable privacy breaches: breaches meeting the "serious harm / likely serious harm" threshold are notified to the Office of the Privacy Commissioner (OPC) and affected individuals per our data-breach procedure. - Complaints: contact us first; you may complain to the Office of the Privacy Commissioner (OPC)privacy.org.nz.