DPPAutomate
NowośćPakiet zgodności z Rozporządzeniem Bateryjnym 2027 jest już dostępny.Przeczytaj
DPPAutomate
Prywatność

Polityka prywatności

Jak zbieramy, wykorzystujemy i chronimy dane - dla naszych klientów i ich użytkowników końcowych.

Zaktualizowano
01

1. Introduction

DPPAutomate is a business-to-business platform for creating, managing and publishing EU Digital Product Passports (DPPs).

This policy explains what personal data we process, why, on what legal basis, how long we keep it, and what rights you have. It covers our marketing website, the DPPAutomate web application, and our public API.

We operate in accordance with the EU General Data Protection Regulation (GDPR), the UK GDPR, and the Swiss Federal Act on Data Protection (revFADP).

If your details appear inside a product passport published through our platform and you did not sign up for an account, section 3 and section 5 explain how that works and who to contact.

02

2. Who We Are

The controller for the personal data described in section 4.1 to 4.4 is:

Nico Jaroszewski (DPPAutomate)
Schlosstalstrasse 202
8408 Winterthur
Switzerland
Email: info@dppautomate.com

We are not required to appoint a Data Protection Officer under GDPR Art. 37. The controller handles all data protection matters directly and can be reached at the address above.

03

3. Our Two Roles: Controller and Processor

We handle personal data in two distinct roles, and your rights differ depending on which applies.

As controller we decide how and why data is processed. This covers account and profile data, billing data, support requests, and enquiries submitted through our marketing website.

As processor we act only on the documented instructions of our business customer. This covers everything a customer uploads into their workspace - product passport content, images, documents, and any personal data about their suppliers, employees or representatives contained within it.

If you are a supplier, employee or representative whose details appear in a passport, the company that created that passport is the controller, not us. Please direct access or deletion requests to them. We will assist them in responding, and we will forward any request you send us if you cannot identify them.

Our processor obligations are set out in our Data Processing Agreement, which forms part of our Terms and is available on the DPA page.

04

4. Data We Collect

4.1 Account and profile. Name, email address, authentication identifiers and session data. Authentication is operated by Clerk; we store a mirror of your name and email to attribute activity inside the product. We never receive or store your password.

4.2 Workspace and team. Workspace membership, assigned role, and the email addresses of people you invite to your workspace.

4.3 Billing. Billing contact name and email, company name, billing address, VAT identification number, and subscription and invoice records. Card details are collected by Stripe directly and never reach our servers.

4.4 Support and marketing enquiries. Support tickets, contact form submissions, quote requests and newsletter subscriptions, including any personal data you choose to include in the message.

4.5 Product and passport content (processed on your instructions). Everything you enter or upload into a workspace, including product attributes, images and documents. This may contain personal data about third parties - see section 5.

4.6 Usage and audit records. An activity log attributing actions to the user who performed them, AI usage counters, and API key metadata. API keys are stored only as SHA-256 hashes and cannot be recovered by us.

4.7 Public passport views. When someone scans a passport QR code we increment an aggregate counter only. We store no IP address, no user agent and no visitor identifier, so these statistics cannot be traced back to an individual.

05

5. Passport Data You Publish

Digital Product Passports are designed to be published to the open internet and read by anyone who scans the product's data carrier. This is the core purpose of the regulation and of this platform.

At the default access level (Public), a published passport exposes: the economic operator's contact email address, contact phone number, postal address and operator identifier; the name of the EU responsible person; the manufacturing facility name and identifier; and the name of any auditor or verifier recorded against the product.

Several of these are personal data relating to identifiable individuals, and once published they are accessible worldwide without authentication.

You control this per passport. Setting a passport to Restricted removes contact, production and audit details from the public view. Setting it to Confidential redacts the economic operator section entirely.

Two responsibilities are yours as controller. First, ensure you have a lawful basis for publishing any individual's details and that the individual has been informed. Consider using role-based mailboxes rather than a named person's direct contact details. Second, note that where legislation such as the EU Battery Regulation requires specific fields to be publicly accessible, a more restrictive setting does not remove that legal obligation from you.

06

6. Legal Bases for Processing

Where we act as controller we rely on the following legal bases under GDPR Art. 6:

Contract performance (Art. 6(1)(b)) - creating and operating your account, providing the platform, processing payments, and providing support.

Legal obligation (Art. 6(1)(c)) - retaining invoices and accounting records for statutory periods, and responding to lawful requests from authorities.

Legitimate interests (Art. 6(1)(f)) - securing the platform, preventing fraud and abuse, maintaining an audit trail, enforcing usage limits, and improving the product. You may object to processing based on legitimate interests at any time.

Consent (Art. 6(1)(a)) - newsletter subscriptions and non-essential analytics cookies. You may withdraw consent at any time without affecting processing carried out before withdrawal.

Where we act as processor, the legal basis for the underlying processing is determined by our customer as controller, not by us.

07

7. How We Use Your Data

  • Operating the platform - authenticating you, running workspaces, generating and publishing passports, and serving the public passport pages and API.
  • Billing - managing subscriptions, processing payments, applying usage allowances and issuing invoices.
  • Communication - sending transactional email such as workspace invitations, receipts, deadline reminders and service notices.
  • Support - responding to tickets and enquiries.
  • Security and integrity - authentication, rate limiting, abuse prevention, and maintaining the activity and audit log.
  • Product improvement - understanding aggregate feature usage and error patterns.
  • Marketing - only where you have subscribed, and you can unsubscribe from every message.

We do not sell, rent or trade personal data. We do not use your product or passport content to build profiles about you.

08

8. Artificial Intelligence Processing

The platform can generate draft passport data from product images, documents and text you supply. This uses a third-party model-routing service, OpenRouter, which forwards the request to the model provider serving the selected model.

What is sent. Only the product content you supply for that generation - images, uploaded documents, source URLs and product attribute text. The payload contains no account name, no email address, no user identifier and no billing data.

Training and retention. We do not use your content to train our own models. Every request we send carries provider preferences that exclude any provider which trains on prompt data (data_collection: deny) or retains it at rest (zdr: true), so generations are routed only to no-training, zero-retention endpoints. This is backed by an enterprise Data Processing Agreement with OpenRouter that contractually binds them and their sub-processors to no-training, zero-retention handling of your content.

Human oversight. AI output is a draft. Generated passports enter a review queue for human approval, and a quality gate forces low-confidence output into review even when automatic publishing is enabled.

Automated decision-making. We do not carry out automated decision-making producing legal or similarly significant effects concerning individuals, and we do not profile individuals.

09

9. Sub-processors and Data Sharing

We share personal data only with the service providers needed to operate the platform. Our current sub-processors are:

  • Clerk - authentication and session management.
  • Convex - application backend and database.
  • Stripe - payment processing, billing and invoicing.
  • Hostinger - SMTP relay for transactional email (current transport).
  • Resend - transactional email delivery (planned, not yet active).
  • OpenRouter - AI model routing for passport generation and the in-app assistant.
  • Google - website analytics and Search Console verification, on the marketing site only and subject to your cookie consent.
  • Vercel - website and application hosting.

The always-current list, with each provider's role, region and data categories, is published on our DPA page.

We notify customers at least 30 days before adding or replacing a sub-processor. We may also disclose data where required by law or to establish, exercise or defend legal claims. We do not sell personal data.

10

10. International Data Transfers

Current position. Our production database runs on Convex in the US East (N. Virginia) region. Our authentication provider (Clerk), payment provider (Stripe), email provider and AI routing provider are also established in the United States.

Planned change. We are migrating our production deployment to Convex EU West (Ireland). This section will be updated when that migration is complete. We publish our current processing location here rather than an aspirational one, so that you can verify it.

Safeguards. Every transfer outside Switzerland and the European Economic Area is governed by the EU Standard Contractual Clauses (Commission Implementing Decision 2021/914), Module Two, supplemented by a documented Transfer Impact Assessment, together with any additional safeguards required under GDPR Chapter V and Swiss law. Where a provider is certified under the EU-US Data Privacy Framework we rely on that certification in addition to, not instead of, the Clauses.

You can request a copy of the relevant transfer documentation at info@dppautomate.com.

11

11. Data Retention

  • Account and profile data - for as long as your account exists. Deleted when you delete your account.
  • Workspace and passport content - for as long as the workspace exists. Deleted when you delete the workspace or your account. Note that a passport you have published may have been copied or cached by third parties; we cannot recall data from outside our systems.
  • Invoices and accounting records - retained for the statutory period required by Swiss and EU law, currently ten years, even after account closure.
  • Support tickets - three years from the last message.
  • Marketing enquiries and quote requests - three years from submission.
  • Newsletter subscriptions - until you unsubscribe.
  • Activity and audit log - for the life of the workspace. Audit entries are retained to preserve an accurate record of who did what.
  • Aggregate passport view statistics - retained indefinitely. These contain no identifiers and cannot be linked to an individual.
12

12. Your Rights

Where we act as controller you have the following rights:

  • Access (Art. 15) - a copy of the personal data we hold about you.
  • Rectification (Art. 16) - correction of inaccurate or incomplete data. Most profile data can be corrected directly in your account settings.
  • Erasure (Art. 17) - deletion of your personal data, subject to records we must retain by law.
  • Restriction (Art. 18) - limitation of processing in defined circumstances.
  • Portability (Art. 20) - your data in a structured, machine-readable format. Passport content can be exported at any time from the application in JSON, JSON-LD, CSV and Excel formats.
  • Objection (Art. 21) - to processing based on legitimate interests, and to direct marketing at any time.
  • Withdraw consent (Art. 7(3)) - at any time, without affecting processing already carried out.

To exercise any right, email info@dppautomate.com. We respond within 30 days. We do not charge a fee unless a request is manifestly unfounded or excessive.

Where we act as processor, please direct your request to the customer who controls the data. See section 3.

13

13. Deleting Your Account

You can delete your account from your account settings at any time.

Deletion removes your identity from our authentication provider and triggers an erasure cascade across our database that deletes your workspaces and the records attached to them - passports and their content, drafts, activity and audit entries, notifications, API keys, learnings, support tickets, workspace memberships and pending invitations.

Records we retain after deletion, and why:

  • Invoices, payment records and the payment provider's own event log, retained to meet statutory accounting and tax obligations.
  • Aggregate passport view counters, which contain no identifiers.

Passports you published before deletion stop resolving once the underlying records are removed. Data that third parties already retrieved and stored independently is outside our control.

If you want deletion carried out on your behalf, or want written confirmation once it is complete, email info@dppautomate.com.

14

14. Cookies and Local Storage

We use the minimum storage needed to run the site and remember your choices.

Strictly necessary (no consent required):

  • locale - remembers your language preference.
  • gpc - records that your browser sent a Global Privacy Control signal.
  • Session cookies set by our authentication provider to keep you signed in.
  • cookieConsent - stores your consent choice. This is kept in your browser's local storage rather than in a cookie.

Analytics (only with your consent):

  • Google Analytics cookies, used on the marketing website only, with IP anonymisation enabled. No analytics data is collected in the application.

You can change or withdraw your choice at any time through the cookie banner or your browser settings. Withdrawing consent does not affect strictly necessary storage. Our Cookie Policy describes each item in more detail.

15

15. Security

Measures we actually operate, not aspirations:

  • Authentication and credential storage are handled by Clerk; we never see or store passwords.
  • API keys are stored only as SHA-256 hashes, displayed once at creation, and support rotation and revocation.
  • Every workspace query and mutation enforces tenant isolation through a central membership and role check, so one customer cannot reach another's data.
  • Role-based access control governs what each member of a workspace can do.
  • Rate limiting is applied to the API and to authenticated application routes.
  • Incoming webhooks from Stripe and Clerk are signature-verified with replay protection; outbound webhooks are HMAC-signed.
  • All traffic is served over TLS. Data at rest is encrypted by our infrastructure providers.
  • An immutable-by-intent activity log records security-relevant actions.

No system is perfectly secure. If a personal data breach is likely to result in a risk to your rights and freedoms, we will notify the competent supervisory authority within 72 hours and inform affected individuals without undue delay, in line with GDPR Art. 33 and 34.

To report a vulnerability, email info@dppautomate.com.

16

16. Children's Privacy

DPPAutomate is a business-to-business product intended for use by organisations and their staff. It is not directed at children and we do not knowingly collect personal data from anyone under 16.

If you believe a child has provided us with personal data, contact info@dppautomate.com and we will delete it.

17

17. Changes, Contact and Complaints

Changes. We may update this policy to reflect changes in our practices, our sub-processors or the law. The last updated date is shown at the top of this page. We notify customers of material changes by email or by a notice in the application, and we give at least 30 days' notice before adding or replacing a sub-processor.

Contact. For any privacy question or to exercise your rights, email info@dppautomate.com.

Complaints. If you are not satisfied with our response you have the right to lodge a complaint with a supervisory authority. In Switzerland this is the Federal Data Protection and Information Commissioner (FDPIC). In the EEA it is the authority in your country of residence or place of work. In the UK it is the Information Commissioner's Office (ICO).

Language. This policy is published in English, German, French, Italian and Spanish. In case of any discrepancy, the English version prevails.

Bądź marką,
która jest gotowa.