Henad
PrivacyCookiesTermsRecorder

Contents

  1. Who we are
  2. Controller and processor
  3. What we process
  4. Why we process it, and our legal bases
  5. Your workspace content
  6. AI features
  7. Line sheets and buyer links
  8. Who else processes data
  9. International transfers
  10. How long we keep data
  11. How we protect data
  12. Your rights
  13. Changes to this policy
  14. Contact

Privacy Policy

Last updated 11 August 2026Version 1.0

This policy explains what Henad does with personal data — what we hold, why we hold it, who else touches it and what you can ask us to do about it. It also draws the line between the data Henad decides about and the data a customer decides about in its own workspace, because the two lead to different answers.

1Who we are

Henad builds operations software for fashion brands: collections, products, tech packs, production, wholesale and finance in one workspace. This policy covers henad.work, the Henad application, and the public line sheets published from it.

Henad is established in Spain and operates under the EU General Data Protection Regulation and Spanish data-protection law. Write to privacy@henad.work for anything in this document.

2Controller and processor

Henad plays two different roles, and which one applies changes who decides what happens to the data.

  • Henad is the controller for its own activities: creating and administering accounts, authentication, billing, support, security monitoring, and the narrow service telemetry we need to keep the product working.
  • Henad is a processor for the business content a customer puts into its workspace, including personal data about that customer's buyers, suppliers, factories and staff. The customer decides what to collect and why; we act on its documented instructions under a data processing agreement.

If you are a buyer, supplier or employee and your data is in a brand's Henad workspace, that brand is the controller. Send your request to the brand. If you send it to us, we will pass it on and tell you we have done so.

3What we process

Account and identity

Your name, email address, workspace membership and role, and either a password we store only as a hash or the identifier of the Google account you signed in with. We never receive your Google password.

Workspace content

Everything your team creates in Henad: products, collections, materials, suppliers, tech packs, boards, orders, invoices, uploaded files, comments and the notes you write. This can contain personal data about people outside your company.

Technical and usage data

IP address, browser and device characteristics, pages and features used, timestamps, error reports and performance traces. We use this to keep the service secure and to understand which parts of the product are used.

AI feature content

The text, images and workspace records you submit to an AI feature, and the output it returns. See AI features below.

Support

The messages, screenshots and files you send us when you ask for help, and our replies.

4Why we process it, and our legal bases

  • To provide the service — performance of our contract with you or your employer. This covers accounts, authentication, storing and serving your workspace, and support.
  • To keep it secure and available — our legitimate interest in protecting the service, its customers and their confidential information. This covers logging, abuse and intrusion detection, backups and rate limiting.
  • To improve the product — our legitimate interest in understanding how Henad is used, limited to aggregated and pseudonymised measurement. We do not build cross-customer benchmarks, lead lists or commercial reports from customer content.
  • Non-essential storage on your device and any session recording — your consent. See the Cookie Policy.
  • Billing, tax and answering lawful requests — compliance with a legal obligation.

Where we rely on legitimate interests you can object, and we will stop unless we can show compelling grounds that override your rights.

5Your workspace content

A Henad workspace holds prices, margins, costs, suppliers, capacity, launch calendars, designs and buyer pipelines. That information is commercially sensitive whether or not it is personal data, so we commit to a narrower use than the law alone would require. We process customer content only to provide, secure, support and exit the service.

We do not:

  • sell customer content, or use it for advertising;
  • use it to train or fine-tune machine-learning models;
  • use one customer's content to inform, advise or supply another customer, or any fashion business connected to Henad or its founders;
  • build cross-customer benchmarks, prompt corpora or example libraries from it;
  • search across tenants. Each workspace is isolated at the database level, and application access is scoped to the workspace you are signed in to.

Henad staff have no standing access to production customer content. Access for a support investigation is requested for a stated reason, granted for a short period, logged, and reviewed afterwards.

6AI features

Some features send content to AI providers on your instruction: drafting and reading tech packs, generating flats and swatches, removing image backgrounds, taking product measurements, answering questions about your workspace, and retrieving public web results.

  • An AI request carries what that feature needs — your prompt, the records in scope and any images you attached. It does not carry other customers' data.
  • We instruct our AI providers not to train on Henad content and not to retain request payloads beyond what is needed to return a result.
  • AI output can be wrong. It is a draft for a person to check, not a decision. Nothing in Henad makes an automated decision about a person with legal or similarly significant effects.
  • We keep a record of which feature ran and whether it succeeded, so a failed run can be diagnosed.

If you would rather no content left the workspace for AI processing, ask us and we will disable the AI features for your workspace.

7Line sheets and buyer links

A brand can publish a line sheet as a private link and send it to a buyer. On that page, Henad acts as the brand's processor. The brand decides who receives a link and what the page contains.

When a buyer opens a line sheet link, we record for the brand:

  • that the link was opened, and when;
  • which items were viewed, and any quantities or notes entered;
  • a visit identifier stored in a cookie so repeat visits from the same browser are recognised as one sitting;
  • a one-way hash of the visitor's network address, not the address itself.

A line sheet page may also record the session — pointer movement, scrolling and what is typed into the page's fields — so the brand can see how its offer was read. Passwords are never recorded. This recording is described in the Cookie Policy, and where consent is required it is asked for before the recording starts.

A line sheet link is the only protection on that page, so treat it as confidential. Brands can revoke a link, set an expiry and require a password.

8Who else processes data

We use a small set of subprocessors. Each one is bound by a written agreement, receives only what its function needs, and may not use the data for its own purposes.

RecipientWhat it processesLocation
RailwayApplication hosting and the managed PostgreSQL database that holds workspace recordsEU
Cloudflare R2Uploaded files: images, tech pack artwork, documents and generated PDFsEU jurisdiction
PostHogProduct analytics, error reports, application logs and traces; line sheet visit measurementEU (eu.i.posthog.com)
GoogleSign-in, and only if you choose Google as your sign-in method: your account identifier, name and email addressEU / US, SCCs
OpenRouter and the model providers it routes toText and images you send to an AI feature, plus the workspace context that feature needsEU / US, SCCs
fal.aiImages submitted to the tech pack background-removal stepEU / US, SCCs
E2BCode and data an AI feature runs inside a sandbox on your instructionEU / US, SCCs
ExaSearch queries an AI feature issues when it retrieves public web resultsUS, SCCs

We will tell customers before adding or replacing a subprocessor that processes workspace content, so there is time to object. We also disclose data when the law requires it, and to professional advisers under confidentiality. We do not sell personal data.

9International transfers

We host the application, database, file storage and analytics in the European Union. Some AI and search providers process requests outside the EEA. Where that happens we rely on the European Commission's Standard Contractual Clauses together with an assessment of the destination country and additional technical measures such as encryption in transit, minimised payloads and no-retention instructions. Ask privacy@henad.work for the transfer mechanism that applies to a specific recipient.

10How long we keep data

  • Workspace content — for as long as the workspace is active. After a subscription ends we keep it for 30 days so it can be exported or restored, then delete it.
  • Account records — while the account exists, then deleted within 30 days of closure.
  • Line sheet visits and buyer activity — 12 months, unless the brand deletes them sooner. Session recordings are kept for a shorter period, set by the brand.
  • Application logs, error reports and traces — up to 12 months.
  • Invoices and accounting records — as long as Spanish tax and commercial law require.
  • Backups — held on a rolling schedule and overwritten within 35 days, so a deletion reaches backups on that cycle rather than instantly.

A customer can ask us to export or delete a whole workspace at any time. We confirm in writing when deletion is complete.

11How we protect data

  • Encryption in transit, and encryption at rest for the database and file storage.
  • Tenant isolation enforced in the database, so a query in one workspace cannot reach another's rows.
  • Role-based access inside a workspace, and multi-factor authentication on the administrative accounts that operate the infrastructure.
  • No standing staff access to production content; time-limited, reasoned and logged access when support requires it, with two-person control for destructive operations.
  • Audit logging, dependency and vulnerability monitoring, and tested backups.

If a breach affects your personal data we notify the Spanish Data Protection Agency within 72 hours where required, and tell affected customers and individuals without undue delay. Report a suspected vulnerability to security@henad.work.

12Your rights

You can ask for access to your data, correction of what is wrong, deletion, restriction of processing, a portable copy, and you can object to processing based on legitimate interests. Where we rely on consent you can withdraw it at any time, which does not affect processing that already happened.

Write to privacy@henad.work. We answer within one month and may extend that by two months for a complex request, telling you why. We may ask for enough information to confirm who you are.

If the data sits in a customer's workspace, we forward the request to that customer, who decides it as controller.

You can also complain to the Spanish Data Protection Agency (Agencia Española de Protección de Datos, www.aepd.es) or to the supervisory authority where you live. We would rather hear from you first.

13Changes to this policy

We update this policy when the product or our processing changes. The version and date at the top always describe the current text. For a change that materially affects how we handle personal data we notify account administrators by email at least 30 days before it takes effect, and keep the previous version available on request.

14Contact

  • Privacy and data rights — privacy@henad.work
  • Security reports — security@henad.work
  • Contracts, DPAs and the subprocessor register — legal@henad.work

© 2026 Henad. These documents are a working draft and are pending review by counsel before they are relied on.

privacy@henad.work