Now live: FDA · Health Canada · EU/UK 1169 · Gulf GSO · FSANZ · Swiss LIV · India FSSAI · Eurasian TR CU 022 · East African EAS 38 · CARICOM CRS 5 · MERCOSUR / ANVISA · Japan CAA label formats · true-scale KLD dielines · multilingual ingredient intelligence

Home › Privacy Policy

Privacy Policy

Privacy Policy

Effective 14 July 2026. Data controller:

KD Alliance (a partnership firm) · Plot No. 16, G.T. Road, Part-1, Sector 29, HUDA, Panipat, Haryana 132103, India
GSTIN 06ABCFK7864M1ZR · PAN ABCFK7864M · support@labelyog.com · +91-98964-44440

Grievance Officer / privacy contact: Amit Dhingra · support@labelyog.com

What changed, and when. Earlier versions of this policy said we never stored an IP address. From 14 July 2026 we do. We would rather say that at the top than hide it in a paragraph. Section 3 explains what we keep, why, for how long, and how to have it erased.

1. Two different roles — and the difference matters

For your account data and website analytics, KD Alliance is the controller: we decide why and how they are processed. For the content you put into the Service — recipes, ingredients, suppliers, business details, artwork — we act as a processor on your behalf: you decide what goes in and why, and we process it only to run the Service for you.

2. Account data

What: name, e-mail, password (stored only as a hash — we cannot read it), company, country, and the business details you enter for printing on labels. Why: to create and secure your account, provide the Service, send transactional e-mail, and meet our tax and legal obligations. Basis: performance of our contract with you (GDPR Art. 6(1)(b)); legal obligation for tax records (Art. 6(1)(c)); and, under India’s DPDP Act 2023, processing for the specified purpose for which you gave it.

3. Website analytics — including your IP address

What we record for each page view: the page, the date and time, your IP address, the country it resolves to, your operating system, your browser, whether you are on a phone or a desktop, the site that referred you (including which search engine, where there is one), and any campaign tags in the link you followed.

Why: to understand where genuine interest in the product comes from; to tell real readers apart from the automated scanners that hit every public website continuously; and to detect and investigate abuse, fraud and attacks on the Service.

Basis: our legitimate interest in understanding, operating and protecting our own website (GDPR Art. 6(1)(f)). We have weighed that against your rights: the data is first-party, never sold, never shared with advertisers, never used to profile you, and never used to follow you to another website. You may object at any time — write to us and we will stop, and erase what we hold about you.

Retention: IP addresses are deleted after 90 days. The anonymous counts that remain — page, country, device — carry no personal data and are kept longer for trend analysis.

No cookies, no trackers. Analytics are cookieless and first-party. There is no Google Analytics, no Meta pixel, no advertising network and no cross-site tracker on this site. The only cookie we set is the strictly-necessary session cookie that keeps you signed in.

4. The content you put into the Service

Your recipes, ingredients, suppliers and artwork are yours. We process them only to compute panels, render labels and PDFs, back them up, and help you when you ask. We do not sell them. We do not share them with advertisers. We do not use them to train machine-learning models. We do not show them to other customers. Deleted content is removed from the live system; encrypted backups roll off on their own schedule. Closing your account deletes your content, except records we must keep by law (an invoice, for example).

5. Payments

Payments are processed by third-party providers. We never receive or store your full card number. We keep the invoice, amount, tax and transaction reference, because tax law requires it.

6. Who else can see your data

DigitalOcean — hosting of the application and database, in Frankfurt, Germany (EU). Our payment provider — taking payment and issuing invoices. Our own mail server (Frankfurt) — transactional e-mail. That is the whole list. No data brokers. No advertisers. No analytics vendors.

7. International transfers

Our servers are in the European Union (Frankfurt). Where personal data is transferred out of the EEA or UK, we do so under an approved mechanism such as the Standard Contractual Clauses.

8. Security

Passwords are hashed. Traffic is encrypted in transit (HTTPS). The database is not exposed to the public internet. Access is limited to those who need it. No system is perfectly secure; if a breach affects your personal data we will notify you and the relevant authority as the law requires.

9. Your rights

Wherever you live you may ask us to tell you what we hold, correct it, delete it, give you a copy in portable form, or restrict or object to processing — including the analytics in Section 3 — and to withdraw consent where we relied on it.

EU / EEA / UK (GDPR): you may also complain to your supervisory authority. India (DPDP Act 2023): raise a grievance with our Grievance Officer, Amit Dhingra, and escalate to the Data Protection Board of India. California (CCPA/CPRA): we do not sell or share personal information, and we do not discriminate against anyone who exercises their rights.

Write to support@labelyog.com. We answer within 30 days.

10. Children

The Service is for businesses. It is not directed at children and we do not knowingly collect data from anyone under 18.

11. Changes

Any change is posted here and the Effective date is updated. When a change is material — as the IP change at the top of this page was — we say so plainly, rather than letting silence imply that nothing has changed.