Bardi Fuels — Privacy Policy

Last updated: 4 June 2026

Who we are (Data Controller)

Bardi Fuels is a private market-information service — a price-reporting portal that publishes indicative prices, bids and offers, and trade recaps to a closed group of the operator's vetted professional clients. This policy explains the limited personal data we handle to run that portal.

Bardi Fuels LLC, a Limited Liability Company registered at 2020 Eagle Pkwy, Fort Worth, TX 76117, USA ("Bardi Fuels", "we"), is the controller of personal data processed through the Bardi Fuels website and iOS app. We are a US entity that offers this professional information service to users in the European Union and operate it under French/EU data-protection law. Because we offer a service to data subjects in the EU, the GDPR applies to this processing (GDPR Art. 3(2)). Contact: pierre@bardifuels.com.

What we collect

We do not use analytics or advertising SDKs, do not track you across apps or websites, and do not sell personal data.

Why we process it, and our legal basis (GDPR Art. 6)

Purpose Legal basis (GDPR Art. 6(1))
Create/authenticate your account; provide the information service Performance of a contract (Art. 6(1)(b)); to the extent pre-contract vetting/approval is involved, our legitimate interest in admitting only verified professionals (Art. 6(1)(f))
Send push notifications for market alerts Consent (Art. 6(1)(a)) — you opt in and can disable anytime
Security, abuse prevention, rate limiting, server logging Legitimate interests (Art. 6(1)(f)) — keeping the service secure and available
Comply with legal obligations Legal obligation (Art. 6(1)(c))

Where we rely on legitimate interests (Art. 6(1)(f)), you may object at any time (see Your rights).

Who processes your data, and where (GDPR Arts. 13(1)(f), 28, 44)

We use three processors. Each operates under a GDPR Art. 28 data processing agreement (DPA) that is automatically incorporated into the service terms we have accepted, and each relies on the EU–US Data Privacy Framework (DPF) as the primary cross-border transfer mechanism, with the 2021 EU Standard Contractual Clauses (Commission Decision (EU) 2021/914), Module Two (controller→processor) as the contractual fallback.

Processor Role / purpose Personal data Where processed Transfer mechanism (Arts. 44–46)
Neon (Neon, Inc.) PostgreSQL database — data at rest Email, Firebase UID, push/device tokens, timestamps Database provisioned in the EU (Frankfurt, AWS eu-central-1). Neon's control-plane / operational and support access may occur in the US DPF (primary) + 2021 SCCs Module Two (fallback) [neon memo §§2–3, 5]
Vercel (Vercel Inc.) Web hosting + serverless API compute Email, Firebase UID, push/device tokens, IPs in logs API function execution pinned to the EU (Frankfurt, fra1). Some platform-level operations — global edge/CDN routing, builds, logging/observability (which can include IPs), infrastructure backups, and outage failover — may occur outside the EU, including the US DPF (primary) + 2021 SCCs Module Two (fallback) [vercel memo §§2–3, 5]
Google LLC (Firebase) Authentication (sign-in), Cloud Messaging (push), Admin SDK Email, Firebase UID, IPs (Auth logs, kept a few weeks), push/device tokens Firebase Authentication runs only in US data centers (US-only). FCM runs on Google's global infrastructure, including the US. There is no EU data-residency option for either DPF (primary) + 2021 SCCs (UK Addendum / Swiss coverage included) (fallback) [google-firebase memo §§2–3, 5]

Honest residency statement. Our database (Neon) and our application's API compute (Vercel functions) are located in the EU (Frankfurt). However, not all data stays in the EU. Sign-in and account management run through Firebase Authentication in the United States, push notifications run through Firebase Cloud Messaging globally, and certain Vercel and Neon platform operations (edge routing, builds, logging, backups, failover, and operational/support access) may take place in the US. We do not claim that all personal data remains in the EU. These transfers to the US are lawful under the EU–US Data Privacy Framework and the 2021 EU Standard Contractual Clauses, as described above.

The previous Turso database has been decommissioned and replaced by Neon.

International transfers (GDPR Arts. 44–49)

Personal data processed by Firebase (Auth in the US, FCM globally) and by certain Vercel/Neon platform operations is transferred to the United States. We rely on:

  1. The recipient's certification under the EU–US Data Privacy Framework (and its UK Extension / Swiss-US DPF where relevant), as the primary mechanism; and
  2. The 2021 EU Standard Contractual Clauses (Decision (EU) 2021/914) incorporated into each processor's DPA, as the contractual fallback if DPF coverage does not apply or lapses.

You may request a copy of the relevant safeguards by emailing pierre@bardifuels.com.

How long we keep it

Your rights (GDPR Arts. 15–22)

You have the right to access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction (Art. 18), data portability (Art. 20), and objection (Art. 21, including objection to processing based on legitimate interests). Where we rely on consent (push notifications), you may withdraw consent at any time (Art. 7(3)) without affecting prior processing.

You can delete your account in-app (Settings → Delete account), which removes your Firebase authentication record and associated database data. To exercise any other right, email pierre@bardifuels.com; we will respond within one month (Art. 12(3)). You also have the right to lodge a complaint with a supervisory authority (Art. 77) — in France, the CNIL (www.cnil.fr).

Security (GDPR Art. 32)

Data in transit is protected by TLS/HSTS; the service uses a strict Content-Security-Policy and security response headers, Firebase-based authentication, a per-user approval gate, and rate limiting. Our processors maintain recognised security attestations (Neon: SOC 2 Type II, ISO 27001:2022, ISO 27701:2019; Vercel: SOC 2 Type 2, ISO 27001:2022; Google/Firebase: ISO 27001/27017/27018, SOC 1/2/3), with encryption at rest (AES-256) and in transit. No method of transmission or storage is 100% secure.

Notifications

Push notifications are optional and consent-based. They cover market alerts (bids/offers, recaps, in-app newsletter posts) — service/market content for our professional audience, not consumer marketing. Disable them anytime in the app or device settings.

Children

The service is a B2B tool for vetted industry professionals and is not directed to children.

Governing law

This policy and our processing are governed by French/EU data-protection law.

Changes & contact

We may update this policy; material changes will be notified in-app. Questions: pierre@bardifuels.com.