EUDigiPass← Back to home

Privacy Policy

Last updated: 1 July 2026

Summary: We collect only the data needed to operate the service. We do not sell your data. Published Digital Product Passports are retained per EU ESPR law even after account deletion — this is a legal obligation, not a choice. Everything else can be deleted on request.

1. Who we are

EUDigiPass is a brand of Sustainable Grove, a company based in Vienna, Austria (hereinafter "EUDigiPass", "we", "us", or "our"). We provide a Software-as-a-Service platform for creating, managing, and publishing EU-compliant Digital Product Passports (DPPs) under EU Regulation 2024/1781 (ESPR).

Contact us at: privacy@eudigipass.com

2. What data we collect and why

2.1 Account registration

When you create an account, we collect your email address. We use it to send you a one-time password-setup link and, thereafter, transactional messages about your account (password resets, data export confirmations, billing notices).

Legal basis: Performance of contract (Article 6(1)(b) GDPR) — the email address is necessary to authenticate you and deliver the service.

2.2 Company profile

After registration you may optionally provide your company name, address, IEC/GST numbers, contact person name, phone number, and logo. This information appears on your published Digital Product Passports and in your dashboard. It is voluntary; you can use the platform without completing it.

Legal basis: Performance of contract (Article 6(1)(b) GDPR).

2.3 Product passport data

You provide product information (materials, certifications, supply chain, labour conditions, etc.) when creating passports. This data is stored on your behalf and published publicly when you choose to publish a passport. You are the data controller for any personal data you include in passport fields.

Legal basis: Performance of contract (Article 6(1)(b) GDPR).

2.4 Passport scan analytics

When someone scans a QR code linked to one of your passports, we record: (a) a one-way SHA-256 hash of the visitor's IP address (not the raw IP — it cannot be reversed to identify a person), (b) country derived from the IP (via Vercel infrastructure), and (c) device type (mobile/desktop). We use this to provide you with scan analytics in your dashboard.

A privacy notice is displayed on every public passport page informing visitors that an anonymous scan is recorded.

Legal basis: Legitimate interests (Article 6(1)(f) GDPR) — providing usage analytics to account holders; the one-way hash ensures no personal data is processed.

2.5 Activity log

We maintain a log of account actions (login, passport creation, publication, etc.) for security and audit purposes. Logs are accessible to you in your dashboard and are deleted when your account is deleted.

2.6 Contact form submissions

If you submit the contact form on our website, we collect your name, email, company name, and message content. We use this only to respond to your enquiry.

Legal basis: Legitimate interests (Article 6(1)(f) GDPR).

3. Data retention

We keep your personal data only as long as necessary:

  • Account data (email, company profile, activity log): Retained while your account is active. Deleted within 30 days of account deletion.
  • Draft passports: Deleted when you delete them or when your account is deleted.
  • Published passports: EU Regulation 2024/1781 (ESPR) requires that published Digital Product Passport data be retained for the lifetime of the product plus a minimum of 10 years. We cannot delete published passports even if you delete your account. When an account is deleted, published passports are retained with the account ownership removed — they remain publicly accessible at their GS1 Digital Link URL as required by law, but are no longer associated with your email address or company profile.
  • Scan analytics: Retained for 3 years, then aggregated and anonymised.
  • Contact form submissions: Retained for 12 months.

4. Who we share data with

We do not sell, rent, or trade your personal data. We share data only with:

  • Supabase Inc. (USA) — database and authentication provider. Data is stored in EU-West (Ireland) region. Covered by Standard Contractual Clauses.
  • Resend Inc. (USA) — transactional email provider. We share your email address solely to send you account-related emails.
  • Vercel Inc. (USA) — hosting and CDN provider. IP addresses pass through Vercel infrastructure; Vercel extracts country information before the IP reaches our application code.

All processors are bound by data processing agreements. No data is transferred to recipients outside these providers without your consent.

5. Your rights under GDPR

If you are located in the European Economic Area (EEA), you have the following rights:

  • Right of access: Request a copy of all personal data we hold about you.
  • Right to rectification: Correct inaccurate data.
  • Right to erasure: Request deletion of your personal data. Note: published passport data cannot be erased due to the ESPR legal retention obligation described in Section 3. All other personal data (email, company profile, drafts, activity log) will be deleted.
  • Right to data portability: Export all your data as a structured JSON file — available from your dashboard under Settings → Account → Export my data.
  • Right to object: Object to processing based on legitimate interests.
  • Right to restrict processing: Request that we limit how we use your data.

To exercise any of these rights, email privacy@eudigipass.com. We will respond within 30 days. You also have the right to lodge a complaint with your national supervisory authority.

6. Cookies and tracking

We use only strictly necessary cookies — a Supabase session token stored in your browser's localStorage to keep you logged in. We do not use advertising cookies, third-party tracking scripts, or analytics services that set cookies (such as Google Analytics).

The public passport pages do not set any cookies on visitors.

7. Security

We implement appropriate technical and organisational measures to protect your data, including: TLS encryption in transit, row-level security policies in the database (each account can only access its own data), and one-way hashing of IP addresses before storage. Passwords are hashed by Supabase Auth and are never stored in plain text.

8. Children

EUDigiPass is a business service. We do not knowingly collect data from persons under 18. If you believe a minor has created an account, contact us and we will delete it.

9. Changes to this policy

We may update this policy as the service evolves. Material changes will be notified by email at least 14 days before they take effect. Continued use of the service after that date constitutes acceptance.

10. Contact

For privacy-related enquiries:
Sustainable Grove (EUDigiPass)
Heiligenstaedterstrasse 3/40, 1190 Vienna, Austria
Email: privacy@eudigipass.com
Phone: +43 699 81547257

You also have the right to lodge a complaint with the Austrian Data Protection Authority (Österreichische Datenschutzbehörde, Barichgasse 40-42, 1030 Vienna, dsb.gv.at) or with the supervisory authority in your own country of residence.

Terms of Service← Back to home