Privacy Policy
1. Introduction
Alternatively, you may contact our DPO, at sridhar.ranganathan@freehand.ai
Quaking Aspen Technologies India Pvt Ltd / Quaking Aspen Inc ("we," "our," or "us") provides a Supply Chain Management SaaS platform that enables businesses to manage logistics, inventory, and compliance with global trade regulations.
California Attorney General’s Office
https://oag.ca.gov/privacy/ccpa
We are committed to protecting personal data in compliance with:
For CCPA:
- General Data Protection Regulation (GDPR) (EU 2016/679)
- California Consumer Privacy Act (CCPA) (as amended by CPRA)
- ISO/IEC 27001 (Information Security Management System)
- ISO 28000 (Supply Chain Security Management System)
- Customs and trade compliance regulations (e.g., CTPAT, AEO, ITAR, EAR, BIS, OFAC)
- Local data protection laws applicable to users' jurisdictions
- Supervisor Authority: Sridhar Ranganathan
- Contact: sridhar.ranganathan@freehand.ai
- Address: Quaking Aspen, Inc., 220 N Green Street, Chicago IL 60607, USA
This Privacy Policy explains how we collect, process, share, and protect your data when using our platform and services.
For GDPR:
2. Data Controller and Contact Information
If you believe we have violated your data protection rights, you may lodge a complaint with:
For data processing activities covered by this policy, we act as the Data Controller. If you have any questions, you can contact us:
14. Complaints & Regulatory Contact
- Quaking Aspen, Inc.
- 220 N Green Street, Chicago IL 60607, USA
- Data Protection Officer (DPO) Contact: sridhar.ranganathan@freehand.ai
If significant changes occur, we will notify you via email or in-app notifications.
3. Personal Data We Collect
We may update this Privacy Policy periodically. The latest version will always be available on our website.
We collect different types of data necessary for supply chain operations, compliance, and security.
13. Changes to This Privacy Policy
a. Customer & Business Data (User-Provided)
Our service may include links to external websites. We are not responsible for their privacy practices.
- Name, email, and job title
- Company details (e.g., name, address, tax ID)
- Billing and payment details
- User account credentials
- Communication and support inquiries
12. Third-Party Links
b. Supply Chain-Specific Data
For more details, see our [Cookie Policy].
- Supplier, vendor, and logistics partner details
- Order tracking, inventory, and shipment records
- Driver location data from the Driver App
- Freight forwarding and customs documentation
- Risk assessments for supply chain security (ISO 28000 compliance)
- Compliance data (export control checks, regulatory certificates)
We use cookies to improve functionality, analytics, and marketing. California residents can opt-out of targeted advertising via the "Do Not Sell or Share My Personal Information" link on our website.
c. Technical & Usage Data (Collected Automatically)
11. Cookies and Tracking Technologies
- IP address and device details
- Browser type and OS information
- System logs, usage metrics, and API call data
- Cookies and tracking technologies
- Under GDPR (EU & UK): We do not process the personal data of children under 16 years old without verifiable parental consent.
- Under CCPA (California): We do not sell or share data of minors under 16 years old without explicit opt-in consent.
- Under COPPA (U.S.): If we become aware that we have collected data from a child under 13 years old without parental consent, we will delete it immediately.
We do not process special category data (e.g., health, biometric data) unless explicitly required and with user consent.
Our services are not intended for children under the age of 16 (or 13, where applicable by law), and we do not knowingly collect personal data from children.
4. Purpose and Legal Basis for Processing
10. Collection of Data from Children
We process personal data based on lawful grounds under GDPR (Article 6) and CCPA’s "business purposes" definition:
To exercise these rights, contact us at [your contact email]. We respond within one month (GDPR) or 45 days (CCPA).
PurposeLegal Basis (GDPR)Legal Basis (CCPA)To provide and manage our SaaS platformContractual necessityBusiness purposeTo ensure system security and fraud preventionLegitimate interestBusiness purposeTo optimize supply chain performance and analyticsLegitimate interestBusiness purposeTo ensure regulatory and customs complianceLegal complianceLegal obligationTo provide customer support and respond to inquiriesContractual necessityBusiness purposeTo send product updates and marketing communicationsConsent (can be withdrawn)Consumer consent
- Right to Know what personal data we collect and share
- Right to Delete personal data (with exceptions)
- Right to Opt-Out of data sales (we do not sell data)
- Right to Non-Discrimination for exercising privacy rights
5. Data Sharing and Third-Party Integrations
Under CCPA:
We do not sell personal data but may share it in the following cases:
- Right to Access, Rectification, and Erasure
- Right to Restrict Processing and Data Portability
- Right to Object to Processing and Withdraw Consent
- With service providers: Cloud hosting, analytics, and customer support providers.
- With supply chain partners: Logistics providers, freight forwarders, customs agencies, and regulatory authorities.
- With third-party integrations: We connect with ERP systems (SAP, Oracle), logistics platforms (DHL, FedEx), and compliance tools (SAP GTS, Amber Road).
- For legal compliance: To comply with customs regulations (e.g., CTPAT, AEO) and trade laws (e.g., ITAR, EAR, BIS, OFAC).
- During business transfers: If we undergo a merger, acquisition, or restructuring.
Under GDPR:
All third-party processors are bound by GDPR, CCPA, ISO 27001, and contractual security measures.
As a data subject, you have the following rights:
6. International Data Transfers
9. Your Rights Under GDPR and CCPA
If we transfer data outside the European Economic Area (EEA) or California, we ensure compliance through:
- Encryption: Data in transit and at rest is encrypted.
- Access Controls: Role-based access, multi-factor authentication (MFA).
- Regular Security Audits: Continuous monitoring, penetration testing, and vulnerability assessments.
- Supply Chain Risk Management: Risk assessments, vendor security audits, and compliance verifications.
- Incident Response: Procedures in place for breach detection and notification.
- Standard Contractual Clauses (SCCs) (GDPR)
- CCPA opt-out mechanisms for data sharing
- Adequacy decisions by the European Commission
- Binding Corporate Rules (BCRs) for global data processing
We implement ISO 27001- and ISO 28000-compliant security controls, including:
7. Data Retention
8. Security Measures
We retain data only as long as necessary for its intended purpose:
When retention is no longer necessary, data is securely deleted or anonymized.
- User account data: Until account deletion.
- Supply chain records: Retained for legal and audit purposes (typically 7 years).
- Customs and trade compliance records: Retained per regulatory requirements (e.g., 5 years for ITAR compliance).
- Security logs: Retained for 12 months unless required for an investigation.
1. Introduction
Freehand Technologies India Pvt Ltd and Freehand Inc. (collectively referred to as "Freehand Technologies", "we," "our," or "us") provides an AI-powered Supply Chain Management SaaS platform that enables businesses to manage logistics, inventory, and compliance with global trade regulations.
We are committed to protecting personal data in compliance with:
- General Data Protection Regulation (GDPR) (EU 2016/679).
- Digital Personal Data Protection Act, 2023 (DPDPA 2023) — applicable to Indian data principals.
- California Consumer Privacy Act (CCPA) as amended by CPRA.
- ISO/IEC 27001:2022 (Information Security Management System).
- ISO/IEC 27701:2025 (Privacy Information Management System).
- ISO 28000 (Supply Chain Security Management System).
- ISO/IEC 42001:2023 (AI Management System) — governing responsible use of AI in our platform.
- Customs and trade compliance regulations (e.g., CTPAT, AEO, ITAR, EAR, BIS, OFAC).
- Local data protection laws applicable to users' jurisdictions.
This Privacy Policy explains how we collect, process, share, and protect your personal data when using our platform and services.
2. Data Controller and Contact Information
For data processing activities covered by this Policy, Freehand Technologies India Pvt Ltd and Freehand Inc. act as the Data Controller. If you have any questions regarding this Policy or your personal data, you may contact us:
- Data Protection Officer (DPO): Sridhar Ranganathan — dpo@freehand.ai
| Entity | Address | Contact |
|---|---|---|
| Freehand Inc. (USA) | 220 N Green Street, Chicago IL 60607, USA | dpo@freehand.ai |
| Freehand Technologies India Pvt Ltd | No. 47 & 49, VBC Solitaire Building, Bazullah Road, T. Nagar, Chennai — 600017, India | dpo@freehand.ai |
3. Personal Data We Collect
We collect different types of data necessary for supply chain operations, compliance, and security.
a. Customer and Business Data (User-Provided)
- Name, email address, and job title.
- Company details (e.g., name, address, tax ID, registration numbers).
- Billing and payment details.
- User account credentials.
- Communication and support enquiries.
b. Supply Chain-Specific Data
- Supplier, vendor, and logistics partner details.
- Order tracking, inventory, and shipment records.
- Driver location data from the Driver App.
- Freight forwarding and customs documentation.
- Risk assessments for supply chain security (ISO 28000 compliance).
- Compliance data (export control checks, regulatory certificates).
c. Technical and Usage Data (Collected Automatically)
- IP address and device details.
- Browser type and operating system information.
- System logs, usage metrics, and API call data.
- Cookies and tracking technologies.
We do not process special category data (e.g., health data, biometric data) unless explicitly required and with user consent.
4. Purpose and Legal Basis for Processing
We process personal data based on lawful grounds under GDPR (Article 6), DPDPA 2023 (Sections 4–7), and CCPA's "business purposes" definition:
| Purpose | Legal Basis (GDPR) | Legal Basis (DPDPA 2023) | Legal Basis (CCPA) |
|---|---|---|---|
| To provide and manage our SaaS platform | Contractual necessity — Art. 6(1)(b) | Contractual necessity — s.7(a) | Business purpose |
| To ensure system security and fraud prevention | Legitimate interest — Art. 6(1)(f) | Legitimate use — s.7(g) | Business purpose |
| To optimise supply chain performance and analytics | Legitimate interest — Art. 6(1)(f) | Legitimate use — s.7(g) | Business purpose |
| To ensure regulatory and customs compliance | Legal obligation — Art. 6(1)(c) | Legal obligation — s.7(b) | Legal obligation |
| To provide customer support and respond to enquiries | Contractual necessity — Art. 6(1)(b) | Contractual necessity — s.7(a) | Business purpose |
| To send product updates and marketing communications | Consent — Art. 6(1)(a) | Consent — s.6 | Consumer consent |
| To operate AI and automated decision-making systems | Legitimate interest / Contract — Art. 6(1)(b)/(f) | Legitimate use — s.7(g) | Business purpose |
5. Data Sharing and Third-Party Integrations
We do not sell personal data. We may share personal data in the following circumstances:
- With service providers: Cloud hosting (AWS), analytics, and customer support providers bound by Data Processing Agreements (DPAs).
- With supply chain partners: Logistics providers, freight forwarders, customs agencies, and regulatory authorities as required for platform operations.
- With third-party integrations: ERP systems (SAP, Oracle), logistics platforms (DHL, FedEx), and compliance tools (SAP GTS, Amber Road).
- For legal compliance: To comply with customs regulations (e.g., CTPAT, AEO) and trade laws (e.g., ITAR, EAR, BIS, OFAC).
- With AI service providers: Where we use third-party or foundation AI models (including Amazon Bedrock and the Claude model family) within our platform, such providers are bound by data protection, confidentiality, and security obligations. We do not permit AI service providers to use your personal data to train their general-purpose models without your explicit consent.
- During business transfers: If Freehand Technologies undergoes a merger, acquisition, or restructuring, data may be transferred subject to appropriate safeguards.
All third-party processors are bound by GDPR, DPDPA 2023, CCPA, ISO/IEC 27001:2022, and contractual security obligations consistent with this Policy.
6. International Data Transfers
Personal data may be transferred from India, the EEA, or California to other jurisdictions as part of our cloud operations (primarily AWS). We ensure all such transfers comply with applicable law through:
- Standard Contractual Clauses (SCCs) as approved by the European Commission (GDPR).
- Adequacy decisions by the European Commission where applicable.
- Data Processing Agreements with cross-border transfer provisions for DPDPA 2023 compliance.
- CCPA opt-out mechanisms for data sharing where applicable.
- Binding Corporate Rules (BCRs) for intra-group global data processing.
7. Data Retention
We retain personal data only as long as necessary for its intended purpose and applicable legal obligations:
| Data Category | Retention Period | Basis |
|---|---|---|
| User account data | Until account deletion | Contract / User request |
| Supply chain records | Typically 7 years | Legal and audit requirements |
| Customs and trade compliance records | Per regulatory requirements (e.g., 5 years for ITAR compliance) | Legal obligation |
| Security and system logs | 12 months (or longer if required for investigation) | Legitimate interest / Legal obligation |
| AI processing logs and model inputs | 90 days unless required for audit or legal purposes | AIMS governance |
| Marketing consent records | Until consent is withdrawn + 3 years | GDPR / DPDPA 2023 accountability |
When retention is no longer necessary, data is securely deleted or anonymised in accordance with our Data and Record Retention and Deletion Policy.
8. Security Measures
We implement ISO/IEC 27001:2022- and ISO 28000-compliant security controls across our platform and operations:
- Encryption: Data in transit (TLS 1.2+) and at rest (AES-256 via AWS KMS) is encrypted at all times.
- Access Controls: Role-based access control (RBAC) enforced via JumpCloud SSO and AWS IAM; multi-factor authentication (MFA) is mandatory for all users.
- Regular Security Audits: Continuous monitoring (AWS CloudWatch, Security Hub), penetration testing, and vulnerability assessments.
- Supply Chain Risk Management: Risk assessments, vendor security audits, and compliance verifications per ISO 28000.
- AI System Security: AI systems — including Amazon Bedrock deployments — are secured via approved guardrail configurations, prompt injection controls, and access monitoring per our AI Management System (AIMS) Policy.
- Incident Response: Documented procedures for breach detection, containment, and notification within statutory timelines (72 hours under GDPR; applicable windows under DPDPA 2023).
9. Your Rights
Under GDPR (EU / UK):
- Right of Access — obtain a copy of your personal data.
- Right to Rectification — correct inaccurate or incomplete data.
- Right to Erasure ("Right to be Forgotten") — request deletion subject to legal obligations.
- Right to Restrict Processing — limit how we use your data.
- Right to Data Portability — receive your data in a structured, machine-readable format.
- Right to Object — object to processing based on legitimate interest or direct marketing.
- Right to Withdraw Consent — where processing is based on consent, withdraw at any time.
- Right not to be subject to solely automated decisions — see Section 13f.
Under DPDPA 2023 (India):
- Right to Information — know what personal data is being processed and the basis for processing.
- Right to Correction and Erasure — correct inaccurate or complete incomplete data; request erasure.
- Right to Grievance Redressal — raise a grievance with our DPO (dpo@freehand.ai) within 48 hours of receipt.
- Right to Nominate — nominate another person to exercise rights in case of death or incapacity.
Under CCPA (California):
- Right to Know — what personal data we collect, use, disclose, and share.
- Right to Delete — request deletion of personal data (subject to exceptions).
- Right to Opt-Out — of the sale or sharing of personal data (we do not sell data).
- Right to Non-Discrimination — exercising your privacy rights will not result in discriminatory treatment.
- Right to Correct — correct inaccurate personal data we hold about you.
- Right to Limit Use of Sensitive Personal Information — where applicable.
To exercise any of these rights, please contact our DPO at dpo@freehand.ai. We respond within one calendar month (GDPR), 48 hours for acknowledgement (DPDPA 2023), or 45 days (CCPA). Response periods may be extended where legally permitted, and we will notify you accordingly.
10. Collection of Data from Children
Our platform and services are not intended for children, and we do not knowingly collect personal data from children.
- Under GDPR (EU and UK): We do not process the personal data of children under 16 years old without verifiable parental or guardian consent.
- Under DPDPA 2023 (India): We do not process personal data of children under 18 years old without verifiable parental consent, and we do not undertake tracking, behavioural monitoring, or targeted advertising directed at children.
- Under CCPA (California): We do not sell or share the data of minors under 16 years old without explicit opt-in consent.
- Under COPPA (USA): If we become aware that we have inadvertently collected data from a child under 13 years old without parental consent, we will delete it immediately.
11. Cookies and Tracking Technologies
We use cookies and similar tracking technologies to improve platform functionality, perform analytics, and support marketing activities. The types of cookies we use include essential/functional cookies, analytics cookies, and marketing cookies.
California residents may opt out of targeted advertising via the "Do Not Sell or Share My Personal Information" link on our website. For full details of the cookies we use, their purpose, retention period, and how to manage your preferences, please refer to our Cookie Policy.
12. Third-Party Links
Our platform may include links to external websites or third-party services. Freehand Technologies is not responsible for the privacy practices or content of such external sites. We recommend reviewing the privacy policy of any third-party site you visit.
13. Responsible Use of Artificial Intelligence
We use artificial intelligence (AI) and automated decision-making technologies within our platform to enhance supply chain efficiency, compliance, and security. We are committed to using AI responsibly, transparently, and in accordance with our AI Management System (AIMS) (ISO/IEC 42001:2023) and Responsible Use of AI Systems Procedure.
a. How We Use AI
- Supply Chain Optimisation: AI-driven analytics to forecast demand, optimise routing, and improve inventory management.
- Risk Assessment and Compliance: Automated screening for trade compliance (e.g., sanctions and denied-party list checks under OFAC, BIS, ITAR, EAR) and supply chain security risk scoring (ISO 28000).
- Fraud Detection and Security: AI-based anomaly detection to identify suspicious transactions, shipments, or account activity.
- Customer Support: AI-assisted tools — including Amazon Bedrock-powered chatbots and the Claude model family — to handle routine enquiries efficiently.
b. Human Oversight
Where AI-generated outputs may significantly affect a user (e.g., compliance flags, denial of service, risk classifications), we ensure meaningful human review before final decisions are made. Users may request human intervention or contest an automated decision by contacting our DPO at dpo@freehand.ai.
c. Data Used for AI Processing
AI systems process data described in Section 3. We do not use special category data (e.g., health or biometric data) to train or operate our AI models. Where feasible, we apply anonymisation or pseudonymisation techniques to minimise personal data used in AI processing, consistent with the Anonymisation and Pseudonymisation Policy.
d. Fairness, Accuracy, and Bias Mitigation
We take reasonable steps to test and monitor our AI systems for accuracy and to reduce unfair bias, particularly in risk-scoring and compliance-screening functions. AI outputs are treated as decision-support tools, not sole determinants, for compliance or security actions. Bias evaluations are documented as part of our AI model card process under the Responsible AI Development Lifecycle Procedure.
e. Third-Party and Foundation AI Models
Where we integrate third-party or foundation AI models — including Amazon Bedrock-hosted models and the Claude model family (Anthropic) — into our platform, such providers are contractually bound to data protection, confidentiality, and security obligations consistent with Section 5. We do not permit third-party AI providers to use your personal data to train their general-purpose models without your explicit consent. Amazon Bedrock guardrails are enabled for all applicable deployments to prevent harmful or non-compliant outputs.
f. Your Rights Regarding Automated Decision-Making
Under GDPR (Article 22), DPDPA 2023, and applicable law, you have the right not to be subject to a decision based solely on automated processing — including profiling — that produces legal or similarly significant effects, except where necessary for contract performance, authorised by law, or based on explicit consent. Where such automated decisions apply, you may request:
- An explanation of the logic involved in the automated decision.
- Human review of the decision by one of our qualified team members.
- The ability to contest the outcome and provide your perspective.
To exercise these rights, contact us at dpo@freehand.ai.
14. Changes to This Privacy Policy
We may update this Privacy Policy periodically to reflect changes in our practices, regulatory requirements, or platform capabilities. The latest version will always be available on our website. If significant changes occur, we will notify you via email or in-app notification at least 30 days before the changes take effect.
15. Complaints and Regulatory Contact
If you believe we have violated your data protection rights, you may raise a complaint with our DPO first. If you remain unsatisfied, you may lodge a complaint with the relevant supervisory authority:
| Jurisdiction | Supervisory Authority | Contact / Reference |
|---|---|---|
| EU / EEA (GDPR) | Relevant EU Data Protection Authority in your country of residence | edpb.europa.eu |
| India (DPDPA 2023) | Data Protection Board of India | To be notified upon formal establishment by the Government of India |
| UK (UK GDPR) | Information Commissioner's Office (ICO) | ico.org.uk |
| USA (CCPA) | California Attorney General's Office | oag.ca.gov/privacy/ccpa |
| DPO (All regions) | Sridhar Ranganathan — Data Protection Officer | dpo@freehand.ai · Freehand Inc., 220 N Green Street, Chicago IL 60607, USA |

