Privacy Policy
Table of Contents
- 1. Introduction and Data Controller
- 2. Personal Data We Collect
- 3. How We Use Your Data
- 4. Legal Basis for Processing (GDPR Article 6)
- 5. Data Sharing and Third Parties
- 6. International Data Transfers
- 7. Data Retention
- 8. Your Rights Under GDPR
- 9. Cookies and Tracking Technologies
- 10. Data Security
- 11. Children's Privacy
- 12. Changes to This Policy
- 13. Contact Us
1. Introduction and Data Controller
LabelEU ("we," "us," "our," or the "Company") operates a Software-as-a-Service platform that enables businesses to create, manage, and publish Digital Product Passports (DPP) for compliance with the EU Ecodesign for Sustainable Products Regulation (ESPR) and related regulations.
This Privacy Policy explains how we collect, use, disclose, and safeguard your personal data when you use our website at labeleu.app and our associated services (collectively, the "Service").
Data Controller:
LabelEU
Email: [email protected]
We are committed to protecting your privacy and processing your personal data in accordance with the General Data Protection Regulation (GDPR), the ePrivacy Directive, and other applicable EU and member state data protection laws.
2. Personal Data We Collect
2.1 Account Information
When you create an account, we collect:
- Email address
- Name (first and last)
- Profile picture (if provided via social login)
- Organization name and details (if applicable)
- Authentication credentials (managed securely by our authentication provider, Clerk)
2.2 Billing Information
When you purchase a passport pack, we collect:
- Billing name and address
- Payment method details (processed by Dodo Payments; we do not store full card numbers)
- Transaction history and invoice records
- VAT/Tax identification numbers (for business customers)
2.3 Interest List
Passport packs are not on sale at the moment. If you ask us to get in touch when that changes, we store only what you type into that form: your email address, optionally the product category you work in, and optionally a short note about what you need. We do not track how you got to the page and we do not add you to anything else. Ask us at any time and we will delete the entry.
2.4 Product Data You Provide
When you create Digital Product Passports, you provide product information which may include:
- Product names, SKUs, GTINs, and serial numbers
- Manufacturer and importer information (company names, addresses)
- Materials composition and sourcing information
- Environmental impact data (carbon footprint, water usage)
- Certifications and compliance documentation
- Care instructions and recycling information
Important: You own your product data. We process it solely to provide the Service to you. See Section 5 of our Terms of Service for intellectual property provisions.
2.5 Usage and Technical Data
We automatically collect:
- IP address (anonymized for analytics where possible)
- Browser type, version, and language
- Device type and operating system
- Pages visited, features used, and time spent
- Referral source
- Error logs and performance data
2.6 Public Passport Scan Data
When consumers scan QR codes on published passports, we can record limited metadata about the scan:
- Country, region and approximate city (derived from the IP address, which is then discarded)
- Device type (mobile, tablet, desktop)
- Referrer domain (not full URL)
- Timestamp of scan
We do not store the IP addresses of passport viewers, and we do not link scans to a named individual. City-level location combined with a timestamp can still narrow things down, so we treat this as data to be minimised rather than as anonymous data.
We record scans only for organizations that have specifically agreed to passport scan analytics under Section 6.2(a) of our Terms of Service. That agreement is required by ESPR (Reg. (EU) 2024/1781) Art. 11, second subparagraph, which bars a passport service provider from processing passport data beyond what is necessary to provide the service unless the economic operator specifically agrees. Publishing a passport is not, by itself, that agreement.
3. How We Use Your Data
We use your personal data for the following purposes:
3.1 Service Delivery
- Creating and managing your account
- Processing and storing your Digital Product Passports
- Generating QR codes and public passport pages
- Providing customer support
- Processing payments and managing subscriptions
3.2 Service Improvement
- Analyzing usage patterns to improve features
- Identifying and fixing bugs and performance issues
- Developing new features based on user needs
3.3 Communication
- Sending transactional emails (account confirmations, password resets)
- Sending service-related notifications (usage alerts, policy updates)
- Sending product updates and newsletters (only with your consent; unsubscribe anytime)
3.4 Security and Compliance
- Detecting and preventing fraud and abuse
- Enforcing our Terms of Service
- Complying with legal obligations
- Maintaining audit logs for security purposes
4. Legal Basis for Processing (GDPR Article 6)
We process your personal data under the following legal bases:
| Processing Activity | Legal Basis |
|---|---|
| Account creation and service delivery | Contract performance (Art. 6(1)(b)) |
| Payment processing | Contract performance (Art. 6(1)(b)) |
| Analytics cookies | Consent (Art. 6(1)(a)) |
| Marketing communications | Consent (Art. 6(1)(a)) |
| Security and fraud prevention | Legitimate interests (Art. 6(1)(f)) |
| Service improvement analytics | Legitimate interests (Art. 6(1)(f)) |
| Legal compliance (tax records, etc.) | Legal obligation (Art. 6(1)(c)) |
| Public passport scan analytics | Legitimate interests (Art. 6(1)(f)), and only where the publishing organization has specifically agreed as required by ESPR Art. 11 |
| Passport hosting commitment | Contract performance (Art. 6(1)(b)) and legitimate interests (Art. 6(1)(f)) - our own commitment, not an EU legal obligation |
Where we rely on legitimate interests, we have conducted balancing tests to ensure your fundamental rights are not overridden. You may request information about these assessments by contacting us.
5. Data Sharing and Third Parties
We share your personal data only as necessary to provide our Service. We do not sell your personal data.
5.1 Service Providers (Data Processors)
We use the following third-party service providers who process data on our behalf:
| Provider | Purpose | Data Processed | Location |
|---|---|---|---|
| Clerk | Authentication | Email, name, profile picture, auth tokens | USA (EU SCCs) |
| Dodo Payments | Payment processing | Billing details, transaction data | USA (EU SCCs) |
| Cloudflare | Hosting, CDN, DDoS protection | All service data, IP addresses (transit) | Global (EU data centers available) |
All service providers are bound by Data Processing Agreements (DPAs) that comply with GDPR Article 28 requirements.
5.2 Public Passport Data
When you publish a Digital Product Passport, certain product information becomes publicly accessible via the passport's unique URL and QR code. This is the core functionality of the Service: ESPR (Reg. (EU) 2024/1781) Art. 9 and Art. 11 describe a passport as data that anyone can reach through the data carrier on the product, so publishing is what makes a passport usable. You choose which passports are published. Retiring a published passport marks it as no longer current; see Section 7 for how long we keep published passports reachable.
5.3 Legal Requirements
We may disclose your data when required by law, court order, or government request, or when necessary to protect our rights, safety, or property.
5.4 Business Transfers
In the event of a merger, acquisition, or sale of assets, your data may be transferred to the successor entity. We will notify you of any such change and any choices you may have regarding your data.
6. International Data Transfers
Our primary infrastructure is hosted on Cloudflare's global network, with data primarily processed in the European Union. However, some of our service providers are based in the United States.
For transfers to countries outside the EEA that do not have an adequacy decision from the European Commission, we rely on:
- Standard Contractual Clauses (SCCs) - approved by the European Commission for data transfers
- Supplementary measures - including encryption in transit and at rest, access controls, and contractual commitments from providers
You may request a copy of the applicable transfer mechanisms by contacting us at [email protected].
7. Data Retention
We retain your data for the following periods:
| Data Type | Retention Period | Reason |
|---|---|---|
| Account data | Duration of account + 30 days | Service provision and account recovery |
| Published passport data | At least 12 months from first publication | LabelEU contractual commitment (see note below) |
| Draft passport data | Duration of account + 30 days | Service provision |
| Billing and transaction records | 7 years | Tax and accounting legal requirements |
| Security audit logs | 2 years | Security monitoring and incident response |
| Interest list entries | Until you ask us to remove it | So we can tell you if passport packs go back on sale. Consent, withdrawable at any time. |
| Passport withdrawal records | Kept after account closure | Evidence of who took a passport offline and when. Establishing and defending legal claims (legitimate interest). Holds the account id, the timestamp and the action only, never passport content. |
| Analytics data | 26 months | Service improvement |
| Cookie consent preferences | 12 months | Consent management |
Note on retention: The period is our own commitment, not a period set by EU law. No EU instrument currently fixes how long a Digital Product Passport must stay available: ESPR (Reg. (EU) 2024/1781) Art. 9(2)(i) leaves the period to product-specific delegated acts and says only that it must be at least the expected lifetime of the product, and no such delegated act has been adopted for any product group yet.
We commit to a minimum because ESPR Art. 11(e) requires a passport to stay reachable even after the economic operator becomes insolvent, is liquidated or ceases trading. This used to say 10 years. We shortened it on purpose: a decade of hosting attached to a one-time payment is not something a small operator can fund or insure, and an unfundable promise is worth less to you than a shorter one we can keep. When a delegated act sets a period for a product group you sell, we will extend our commitment to match it.
What this means in practice: when you publish a passport, we keep it publicly resolvable for at least 12 months from first publication even if you stop paying or close your account, and for as long after that as we run the Service. If we ever stop, we tell you and keep it resolvable for at least 90 days from that notice, so you can export your data and move your QR codes. You may mark a passport as "end-of-life", which changes what visitors see but does not take the page down.
The commitment binds us, not you. You can unpublish or delete any passport at any time and it comes offline immediately, which also ends our hosting commitment for it. Before you confirm, we show you what that costs: every QR code already printed on the product stops resolving. See Terms Section 10.1 for the full position.
8. Your Rights Under GDPR
As a data subject in the European Economic Area, you have the following rights:
- Right of Access (Art. 15) - Request a copy of the personal data we hold about you
- Right to Rectification (Art. 16) - Request correction of inaccurate personal data
- Right to Erasure (Art. 17) - Request deletion of your personal data (subject to legal retention requirements)
- Right to Restriction (Art. 18) - Request that we limit processing of your data
- Right to Data Portability (Art. 20) - Receive your data in a structured, machine-readable format
- Right to Object (Art. 21) - Object to processing based on legitimate interests
- Right to Withdraw Consent - Withdraw consent at any time (for consent-based processing)
- Right to Lodge a Complaint - File a complaint with your local Data Protection Authority
How to Exercise Your Rights
To exercise any of these rights, contact us at [email protected]. We will respond within 30 days. We may request verification of your identity before processing requests.
Limitations
Certain rights may be limited where we have a genuine legal obligation to retain data, for example the 7-year tax and accounting records above, or where a statutory exemption applies. Our passport hosting commitment is not one of those legal obligations: it is a contractual promise we made to the publishing organization, so an erasure request that touches a published passport is handled case by case rather than refused outright. Contact us and we will tell you what we can remove.
Data Export
You can export your product data at any time from within your dashboard in CSV format. This supports your right to data portability.
10. Data Security
We implement appropriate technical and organizational measures to protect your personal data, including:
- Encryption in transit - All data transmitted via HTTPS/TLS
- Encryption at rest - Database encryption for stored data
- Access controls - Role-based access, principle of least privilege
- Security headers - Content Security Policy, HSTS, and other protections
- DDoS protection - Cloudflare network protection
- Audit logging - Monitoring of security-relevant events
- Regular security reviews - Ongoing assessment of security posture
Despite these measures, no method of transmission or storage is 100% secure. If you discover a security vulnerability, please report it to [email protected].
11. Children's Privacy
LabelEU is a business-to-business service. We do not knowingly collect personal data from children under 16 years of age. If you believe a child has provided us with personal data, please contact us and we will delete it.
12. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or for other operational reasons.
Material changes: For significant changes that affect your rights or how we use your data, we will notify you by email (to the address associated with your account) at least 30 days before the changes take effect.
Minor changes: For clarifications or non-material updates, we will update the "Last Updated" date at the top of this page.
Your continued use of the Service after any changes indicates acceptance of the updated policy. If you do not agree with changes, you may close your account.
13. Contact Us
If you have questions about this Privacy Policy or our data practices, please contact us:
Privacy Inquiries: [email protected]
General Support: [email protected]
Supervisory Authority:
If you are unsatisfied with our response, you have the right to lodge a complaint with your local Data Protection Authority. A list of EU DPAs can be found at edpb.europa.eu.