← Torna al sito

Privacy Policy

B2B Platform | EU GDPR and UK Data Protection | Version 1.0
Effective date: 31 August 2026

This Privacy Policy explains how Shardana UK Ltd processes personal data in connection with the Trust Run B2B marketplace, SaaS platform, website, producer and buyer accounts, orders, support services, Digital Product Passport functionality and related platform services.

1. Who We Are

The data controller is Shardana UK Ltd (“Shardana”, “Trust Run”, “we”, “us”), a company incorporated in England and Wales under Company No. 14611233, VAT No. GB436361106, with registered office at International House, 36-38 Cornhill, London EC3V 3NG, United Kingdom.

Privacy contact: privacy@trustrun.it.

Trust Run is a business-to-business platform. It is intended for producers, buyers and other persons acting in a professional or business capacity, not for consumers.

2. EU Representative

Shardana UK Ltd is established in the United Kingdom and offers the Trust Run service to business users in the European Union. For the purposes of Article 27 EU GDPR, Shardana UK Ltd has designated an EU Representative in Italy to act as a point of contact for data subjects and competent EU supervisory authorities.

EU Representative: Luca Rossi, Via Rosario 3, 36027 Rosà (VI), Italy. Email: rappresentante.ue@trustrun.it

3. Personal Data We Process

Depending on how you use Trust Run, we may process the following categories of personal data:

4. Why We Use Personal Data and Our Lawful Bases

We determine the lawful basis for each purpose before processing. We do not rely on consent merely because personal data is involved.

PurposeTypical dataLawful basis
Create, verify and administer Producer and Buyer accountsAccount, contact, business and verification dataPerformance of a contract or steps requested before entering into a contract; legitimate interests where processing relates to representatives of business customers.
Operate orders and platform transactionsAccount, order, transaction and communications dataPerformance of a contract; legitimate interests in operating the B2B marketplace and supporting transactions between business users.
Provide payment functionality and manage disputes/chargebacksTransaction, account and dispute dataPerformance of a contract; legitimate interests in payment administration, fraud prevention, dispute management and protection of the platform.
Support shipping and logistics workflowsBusiness contact, order, shipping and tracking dataPerformance of a contract; legitimate interests in facilitating fulfilment and resolving delivery issues.
Provide Digital Product Passport functionalityProducer/product data and, where applicable, identifiable business contact dataPerformance of a contract; legitimate interests in providing product information and traceability-related platform functionality.
Provide customer support and manage complaintsContact, account, order and communications dataPerformance of a contract; legitimate interests in customer service, dispute resolution and service improvement.
Protect the platform, prevent fraud and enforce rulesTechnical, security, account, payment and usage dataLegitimate interests in security, fraud prevention, abuse prevention and legal protection; legal obligation where applicable.
Comply with tax, accounting, regulatory and legal obligationsAccount, business, billing, transaction and communications dataLegal obligation; legitimate interests in establishing, exercising or defending legal claims where applicable.
Provide AI-enabled assistancePrompt, response, account/context data necessary for the featurePerformance of a contract where necessary to provide a requested feature; otherwise legitimate interests in providing and improving support functionality, subject to appropriate safeguards.
Send optional direct marketing where consent is usedContact details and marketing preferenceConsent. Consent is optional, separate from acceptance of platform terms, and may be withdrawn at any time.

5. Legitimate Interests

Where we rely on legitimate interests, those interests may include operating and securing Trust Run, facilitating B2B transactions, preventing fraud and misuse, supporting users, improving the service, maintaining business records, protecting legal rights and resolving disputes. We consider whether those interests are necessary and balanced against the rights and interests of affected individuals.

6. Payments

Trust Run uses an independent payment service provider to process platform payments and payment account onboarding. The payment provider may collect information directly from Producers and Buyers and may act as an independent controller for some processing under its own privacy terms.

Trust Run may receive transaction status, account identifiers, dispute information, chargeback information and other payment-related data necessary to operate the platform and administer its contractual and financial responsibilities. Trust Run does not need to store full payment-card credentials where these are handled directly by the payment provider.

7. Logistics

Where shipment data is shared with a carrier or logistics operator, that organisation may process personal data as an independent controller for its own transport, delivery, compliance and claims-handling purposes. Trust Run processes and shares only the information reasonably required for the platform’s logistics workflow, support and dispute handling.

8. Digital Product Passport

Trust Run may use a specialist technology provider to generate or host Digital Product Passports and QR-linked product information. Information supplied by a Producer may be transmitted to that provider to provide the requested service.

Product passport information may be publicly accessible through a QR code. Producers must not submit personal data for public display unless it is appropriate, lawful and necessary for the intended product information.

9. AI-Enabled Features

Trust Run may provide AI-enabled assistance. When a user chooses to use such a feature, the content submitted to the feature, relevant conversation context and limited technical/account information may be transmitted to an AI technology provider to generate a response.

Users should not submit special-category personal data, passwords, payment credentials, confidential third-party information or other unnecessary sensitive information into AI prompts.

AI-generated information is intended to assist users and should not be treated as an automated legal, regulatory, financial or product-safety decision. Trust Run does not intend to use AI features to make solely automated decisions producing legal or similarly significant effects on users unless users are separately informed and the applicable legal requirements are satisfied.

Any statement about whether an AI provider uses data for model training or how long that provider retains prompts must match the actual provider contract and configuration in force. Trust Run will publish or link to any additional AI-specific notice required by the implemented service.

10. Service Providers and Recipients

We may disclose personal data to recipients where necessary to operate Trust Run, comply with law or protect legitimate interests. Depending on the services enabled, these may include:

Where a supplier processes personal data on our behalf as a processor, we use contractual data-protection terms as required. Where a recipient determines its own purposes and means of processing, it may act as an independent controller.

11. International Data Transfers

Shardana UK Ltd is established in the United Kingdom. Personal data relating to EU users may therefore be processed in or transferred to the United Kingdom.

The European Commission has adopted an adequacy decision recognising that the United Kingdom provides an adequate level of protection for personal data transferred from the European Union within the scope of that decision. Trust Run may rely on that adequacy framework for relevant EU-to-UK transfers while it remains applicable.

Some technology suppliers may process data in other countries, including the United States. Where a transfer requires a transfer mechanism, Trust Run will rely on an applicable adequacy framework, recognised certification framework where legally available, Standard Contractual Clauses or another lawful safeguard, together with supplementary measures where required.

Information about applicable safeguards may be requested using the privacy contact details in this Policy.

12. Data Retention

We retain personal data only for as long as reasonably necessary for the purpose for which it was collected and to meet legal, accounting, tax, security and dispute-resolution requirements. Current operational retention targets are:

Where data is no longer required, it is deleted, anonymised or securely archived where continued retention is legally required.

13. Your Data Protection Rights

Depending on the applicable law and circumstances, individuals may have rights to request access to their personal data, rectification of inaccurate data, erasure, restriction of processing, data portability, and to object to certain processing.

Where processing is based on consent, you may withdraw that consent at any time. Withdrawal does not affect processing that was lawful before withdrawal.

Where we rely on legitimate interests, you have the right to object on grounds relating to your particular situation. You also have the right to object at any time to processing of personal data for direct marketing.

Requests may be made using the privacy contact details stated in section 1. We may need to verify identity before acting on a request.

14. Complaints

If you have concerns about how we process personal data, please contact Shardana first so that we can investigate.

You may also have the right to complain to the Information Commissioner’s Office (ICO) in the United Kingdom and, where the EU GDPR applies, to the competent supervisory authority in the European Union, including the authority in the Member State of your habitual residence, place of work or the place of the alleged infringement.

15. Security

We use technical and organisational measures designed to protect personal data against unauthorised access, accidental loss, alteration, disclosure or destruction. Access is limited according to business need and appropriate authentication, access-control, logging and service-provider safeguards are used where relevant.

No internet-based system can be guaranteed to be completely secure. Users are responsible for protecting their account credentials and for notifying Trust Run promptly of suspected unauthorised account use.

16. Cookies and Similar Technologies

Trust Run may use cookies or similar technologies that are necessary to operate sessions, authentication, security and core platform functionality. Any non-essential analytics, advertising or similar technologies will be addressed through the applicable Cookie Policy and consent mechanism where legally required.

The current Cookie Policy should be kept aligned with the technologies actually deployed on the website and platform.

17. Marketing

Where Trust Run relies on consent for electronic marketing, the marketing choice is optional, presented separately from contractual acceptance and is not pre-selected. A user may withdraw marketing consent at any time using the unsubscribe mechanism or the privacy contact details.

Where another lawful basis is relied upon for B2B communications, Trust Run will apply the relevant data protection and electronic-marketing rules and provide an appropriate right to object or opt out.

18. Changes to this Privacy Policy

We may update this Privacy Policy to reflect changes in law, technology, suppliers or the Trust Run service. The current version and effective date will be published on the platform. Where a change materially affects how we use personal data, we will bring the change to affected users’ attention before the new processing begins where required.

19. Contact

Data Controller: Shardana UK Ltd

Registered office: International House, 36-38 Cornhill, London EC3V 3NG, United Kingdom

Company No.: 14611233

VAT No.: GB436361106

Privacy contact: privacy@trustrun.it

EU Representative pursuant to Article 27 GDPR: Luca Rossi, Via Rosario 3, 36027 Rosà (VI), Italy. Email: rappresentante.ue@trustrun.it