Privacy Policy

Last Updated: August 19, 2026Effective Date: August 19, 2026

1. Introduction and Data Controller

LabelEU ("we," "us," "our," or the "Company") operates a Software-as-a-Service platform that enables businesses to create, manage, and publish Digital Product Passports (DPP) for compliance with the EU Ecodesign for Sustainable Products Regulation (ESPR) and related regulations.

This Privacy Policy explains how we collect, use, disclose, and safeguard your personal data when you use our website at labeleu.app and our associated services (collectively, the "Service").

Data Controller:
LabelEU
Email: [email protected]

We are committed to protecting your privacy and processing your personal data in accordance with the General Data Protection Regulation (GDPR), the ePrivacy Directive, and other applicable EU and member state data protection laws.

2. Personal Data We Collect

2.1 Account Information

When you create an account, we collect:

  • Email address
  • Name (first and last)
  • Profile picture (if provided via social login)
  • Organization name and details (if applicable)
  • Authentication credentials (managed securely by our authentication provider, Clerk)

2.2 Billing Information

When you purchase a passport pack, we collect:

  • Billing name and address
  • Payment method details (processed by Dodo Payments; we do not store full card numbers)
  • Transaction history and invoice records
  • VAT/Tax identification numbers (for business customers)

2.3 Interest List

Passport packs are not on sale at the moment. If you ask us to get in touch when that changes, we store only what you type into that form: your email address, optionally the product category you work in, and optionally a short note about what you need. We do not track how you got to the page and we do not add you to anything else. Ask us at any time and we will delete the entry.

2.4 Product Data You Provide

When you create Digital Product Passports, you provide product information which may include:

  • Product names, SKUs, GTINs, and serial numbers
  • Manufacturer and importer information (company names, addresses)
  • Materials composition and sourcing information
  • Environmental impact data (carbon footprint, water usage)
  • Certifications and compliance documentation
  • Care instructions and recycling information

Important: You own your product data. We process it solely to provide the Service to you. See Section 5 of our Terms of Service for intellectual property provisions.

2.5 Usage and Technical Data

We automatically collect:

  • IP address (anonymized for analytics where possible)
  • Browser type, version, and language
  • Device type and operating system
  • Pages visited, features used, and time spent
  • Referral source
  • Error logs and performance data

2.6 Public Passport Scan Data

When consumers scan QR codes on published passports, we can record limited metadata about the scan:

  • Country, region and approximate city (derived from the IP address, which is then discarded)
  • Device type (mobile, tablet, desktop)
  • Referrer domain (not full URL)
  • Timestamp of scan

We do not store the IP addresses of passport viewers, and we do not link scans to a named individual. City-level location combined with a timestamp can still narrow things down, so we treat this as data to be minimised rather than as anonymous data.

We record scans only for organizations that have specifically agreed to passport scan analytics under Section 6.2(a) of our Terms of Service. That agreement is required by ESPR (Reg. (EU) 2024/1781) Art. 11, second subparagraph, which bars a passport service provider from processing passport data beyond what is necessary to provide the service unless the economic operator specifically agrees. Publishing a passport is not, by itself, that agreement.

3. How We Use Your Data

We use your personal data for the following purposes:

3.1 Service Delivery

  • Creating and managing your account
  • Processing and storing your Digital Product Passports
  • Generating QR codes and public passport pages
  • Providing customer support
  • Processing payments and managing subscriptions

3.2 Service Improvement

  • Analyzing usage patterns to improve features
  • Identifying and fixing bugs and performance issues
  • Developing new features based on user needs

3.3 Communication

  • Sending transactional emails (account confirmations, password resets)
  • Sending service-related notifications (usage alerts, policy updates)
  • Sending product updates and newsletters (only with your consent; unsubscribe anytime)

3.4 Security and Compliance

  • Detecting and preventing fraud and abuse
  • Enforcing our Terms of Service
  • Complying with legal obligations
  • Maintaining audit logs for security purposes

5. Data Sharing and Third Parties

We share your personal data only as necessary to provide our Service. We do not sell your personal data.

5.1 Service Providers (Data Processors)

We use the following third-party service providers who process data on our behalf:

ProviderPurposeData ProcessedLocation
ClerkAuthenticationEmail, name, profile picture, auth tokensUSA (EU SCCs)
Dodo PaymentsPayment processingBilling details, transaction dataUSA (EU SCCs)
CloudflareHosting, CDN, DDoS protectionAll service data, IP addresses (transit)Global (EU data centers available)

All service providers are bound by Data Processing Agreements (DPAs) that comply with GDPR Article 28 requirements.

5.2 Public Passport Data

When you publish a Digital Product Passport, certain product information becomes publicly accessible via the passport's unique URL and QR code. This is the core functionality of the Service: ESPR (Reg. (EU) 2024/1781) Art. 9 and Art. 11 describe a passport as data that anyone can reach through the data carrier on the product, so publishing is what makes a passport usable. You choose which passports are published. Retiring a published passport marks it as no longer current; see Section 7 for how long we keep published passports reachable.

5.3 Legal Requirements

We may disclose your data when required by law, court order, or government request, or when necessary to protect our rights, safety, or property.

5.4 Business Transfers

In the event of a merger, acquisition, or sale of assets, your data may be transferred to the successor entity. We will notify you of any such change and any choices you may have regarding your data.

6. International Data Transfers

Our primary infrastructure is hosted on Cloudflare's global network, with data primarily processed in the European Union. However, some of our service providers are based in the United States.

For transfers to countries outside the EEA that do not have an adequacy decision from the European Commission, we rely on:

  • Standard Contractual Clauses (SCCs) - approved by the European Commission for data transfers
  • Supplementary measures - including encryption in transit and at rest, access controls, and contractual commitments from providers

You may request a copy of the applicable transfer mechanisms by contacting us at [email protected].

7. Data Retention

We retain your data for the following periods:

Data TypeRetention PeriodReason
Account dataDuration of account + 30 daysService provision and account recovery
Published passport dataAt least 12 months from first publicationLabelEU contractual commitment (see note below)
Draft passport dataDuration of account + 30 daysService provision
Billing and transaction records7 yearsTax and accounting legal requirements
Security audit logs2 yearsSecurity monitoring and incident response
Interest list entriesUntil you ask us to remove itSo we can tell you if passport packs go back on sale. Consent, withdrawable at any time.
Passport withdrawal recordsKept after account closureEvidence of who took a passport offline and when. Establishing and defending legal claims (legitimate interest). Holds the account id, the timestamp and the action only, never passport content.
Analytics data26 monthsService improvement
Cookie consent preferences12 monthsConsent management

Note on retention: The period is our own commitment, not a period set by EU law. No EU instrument currently fixes how long a Digital Product Passport must stay available: ESPR (Reg. (EU) 2024/1781) Art. 9(2)(i) leaves the period to product-specific delegated acts and says only that it must be at least the expected lifetime of the product, and no such delegated act has been adopted for any product group yet.

We commit to a minimum because ESPR Art. 11(e) requires a passport to stay reachable even after the economic operator becomes insolvent, is liquidated or ceases trading. This used to say 10 years. We shortened it on purpose: a decade of hosting attached to a one-time payment is not something a small operator can fund or insure, and an unfundable promise is worth less to you than a shorter one we can keep. When a delegated act sets a period for a product group you sell, we will extend our commitment to match it.

What this means in practice: when you publish a passport, we keep it publicly resolvable for at least 12 months from first publication even if you stop paying or close your account, and for as long after that as we run the Service. If we ever stop, we tell you and keep it resolvable for at least 90 days from that notice, so you can export your data and move your QR codes. You may mark a passport as "end-of-life", which changes what visitors see but does not take the page down.

The commitment binds us, not you. You can unpublish or delete any passport at any time and it comes offline immediately, which also ends our hosting commitment for it. Before you confirm, we show you what that costs: every QR code already printed on the product stops resolving. See Terms Section 10.1 for the full position.

8. Your Rights Under GDPR

As a data subject in the European Economic Area, you have the following rights:

  • Right of Access (Art. 15) - Request a copy of the personal data we hold about you
  • Right to Rectification (Art. 16) - Request correction of inaccurate personal data
  • Right to Erasure (Art. 17) - Request deletion of your personal data (subject to legal retention requirements)
  • Right to Restriction (Art. 18) - Request that we limit processing of your data
  • Right to Data Portability (Art. 20) - Receive your data in a structured, machine-readable format
  • Right to Object (Art. 21) - Object to processing based on legitimate interests
  • Right to Withdraw Consent - Withdraw consent at any time (for consent-based processing)
  • Right to Lodge a Complaint - File a complaint with your local Data Protection Authority

How to Exercise Your Rights

To exercise any of these rights, contact us at [email protected]. We will respond within 30 days. We may request verification of your identity before processing requests.

Limitations

Certain rights may be limited where we have a genuine legal obligation to retain data, for example the 7-year tax and accounting records above, or where a statutory exemption applies. Our passport hosting commitment is not one of those legal obligations: it is a contractual promise we made to the publishing organization, so an erasure request that touches a published passport is handled case by case rather than refused outright. Contact us and we will tell you what we can remove.

Data Export

You can export your product data at any time from within your dashboard in CSV format. This supports your right to data portability.

9. Cookies and Tracking Technologies

9.1 Cookie Categories

We use the following categories of cookies:

Strictly Necessary Cookies

These cookies are essential for the Service to function and cannot be disabled. They include:

  • Authentication cookies (Clerk) - Maintain your logged-in session
  • Security cookies - CSRF protection and fraud prevention
  • Cookie consent preferences - Remember your cookie choices

Analytics Cookies (Optional)

With your consent, we use analytics cookies to understand how you use our Service. These help us improve features and user experience. We do not use third-party advertising cookies.

9.2 Managing Cookies

When you first visit our site, you'll see a cookie banner where you can accept or reject optional cookies. You can change your preferences at any time by clicking "Cookie settings" in the footer or by clearing your browser cookies.

You can also configure your browser to block all cookies, but this may prevent you from signing in to the Service.

9.3 Third-Party Cookies

Our authentication provider (Clerk) and payment processor (Dodo Payments) may set their own cookies when you interact with their services. These are governed by their respective privacy policies linked in Section 5.

10. Data Security

We implement appropriate technical and organizational measures to protect your personal data, including:

  • Encryption in transit - All data transmitted via HTTPS/TLS
  • Encryption at rest - Database encryption for stored data
  • Access controls - Role-based access, principle of least privilege
  • Security headers - Content Security Policy, HSTS, and other protections
  • DDoS protection - Cloudflare network protection
  • Audit logging - Monitoring of security-relevant events
  • Regular security reviews - Ongoing assessment of security posture

Despite these measures, no method of transmission or storage is 100% secure. If you discover a security vulnerability, please report it to [email protected].

11. Children's Privacy

LabelEU is a business-to-business service. We do not knowingly collect personal data from children under 16 years of age. If you believe a child has provided us with personal data, please contact us and we will delete it.

12. Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or for other operational reasons.

Material changes: For significant changes that affect your rights or how we use your data, we will notify you by email (to the address associated with your account) at least 30 days before the changes take effect.

Minor changes: For clarifications or non-material updates, we will update the "Last Updated" date at the top of this page.

Your continued use of the Service after any changes indicates acceptance of the updated policy. If you do not agree with changes, you may close your account.

13. Contact Us

If you have questions about this Privacy Policy or our data practices, please contact us:

Privacy Inquiries: [email protected]

General Support: [email protected]

Supervisory Authority:
If you are unsatisfied with our response, you have the right to lodge a complaint with your local Data Protection Authority. A list of EU DPAs can be found at edpb.europa.eu.

We use cookies

LabelEU uses essential cookies for sign-in and security. With your permission, we may also use optional analytics cookies to improve the product.

Learn more