Status: 25 August 2026
1. Data Controller
The controller responsible for the processing of personal data in connection with DPPReady is:
Bobby Zuber
Calle Vista Valle 34, Villa 4
38768 El Paso – Santa Cruz de Tenerife
Spain
Email: support@DPPReady.de
2. Scope of this Privacy Policy
This Privacy Policy provides information about the processing of personal data when visiting dppready.de, registering for and using the DPPReady platform, publishing digital product passports, submitting support requests, and billing for paid plans. Personal data means any information relating to an identified or identifiable natural person.
3. Server Log Files and Hosting
When the website is accessed, the hosting server processes technically necessary connection data. This may include the IP address, date and time, requested address, amount of data transferred, referrer, browser identifier, operating system, and HTTP status. This processing is necessary to deliver the website, detect attacks and technical disruptions, and ensure the security and stability of the service.
The legal basis is Art. 6(1)(f) GDPR. The legitimate interest lies in the secure and reliable operation of the platform. Security-related server logs are generally deleted after 14 days, unless longer retention is necessary to investigate a specific security incident or comply with legal obligations.
Hosting is currently provided by Hetzner. Where required, a data processing agreement must be concluded with the hosting provider. The specific server location and contractually agreed subprocessors depend on the Hetzner product used and the associated data processing agreement.
4. Registration, User Account and Organisation
During registration and account use, we process in particular the email address, encrypted password, name, preferred language, organisation, roles and permissions, security and login information, invitations, recovery codes, audit events, and data required for two-factor authentication. Passwords are not stored in plain text.
Processing is carried out for the initiation and performance of the user agreement pursuant to Art. 6(1)(b) GDPR and to ensure security pursuant to Art. 6(1)(f) GDPR. Mandatory information is required to provide the account. Without this information, a user account cannot be maintained.
5. Organisation, Product and Document Data
Users may store organisation data, contact details, product information, product identifiers, materials, supply chain information, images, documents, import files, API and webhook configurations, and digital product passport content. This data may contain personal information if users enter such information.
Processing is carried out for the performance of the contract pursuant to Art. 6(1)(b) GDPR. Where a business customer enters personal data relating to its own employees, contacts, suppliers, or other persons and DPPReady processes such data solely on the customer's instructions, a data processing agreement pursuant to Art. 28 GDPR must be concluded before such processing begins. The customer remains responsible for the lawfulness, transparency, and accuracy of the data it enters.
6. Publication of Digital Product Passports
Product passports expressly published by the user are accessible at a stable public address and may be accessed via search engines, QR codes, DataMatrix codes, or NFC references. The publishing user decides which product data, images, and documents are made public. Personal data may only be published where there is a sufficient legal basis for doing so.
For published product passports, DPPReady may store aggregated access counts by date. No cross-user profiling or invasive fingerprinting technology is used for this purpose. Irrespective of this, technically necessary accesses may be included in server logs.
7. Technically Necessary Cookies
DPPReady uses technically necessary session cookies to provide login status, language, security functions, and session state. If the “stay logged in” function is selected, an additional random remember-me cookie protected against unauthorised access is set. Session cookies generally expire at the end of the browser session; the remember-me cookie is technically designed to remain valid for up to 30 days and can be revoked by logging out.
These cookies are necessary to provide the service expressly requested by the user. Consent for such technically necessary storage is generally not required pursuant to Section 25(2)(2) TDDDG. The legal basis for the associated processing of personal data is Art. 6(1)(b) GDPR or Art. 6(1)(f) GDPR. DPPReady currently does not use advertising, social media, or external analytics cookies.
8. Transactional Emails and Support
For email verification, password resets, invitations, security notifications, and contractual communications, the email address, name, message content, and technical delivery information are processed. Brevo is used for sending emails. Where required, a data processing agreement must be concluded with the provider.
The legal basis is Art. 6(1)(b) GDPR; security-related messages are additionally based on Art. 6(1)(f) GDPR. Support requests and related communications are stored for processing and subsequently for 1 year, unless legal obligations require longer retention.
9. Payment Processing via Stripe
When booking a paid plan or additional storage, the user is redirected to Stripe for payment processing. In particular, the email address, customer and contract identifiers, plan, amount, currency, payment status, and billing information are processed. Full card details are not stored on DPPReady servers but are processed by Stripe.
For customers in the European Economic Area, Stripe Payments Europe, Limited, and other Stripe entities named in Stripe's privacy notices may be involved. Depending on the processing activity, Stripe processes data as a processor and/or as an independent controller, particularly for payment processing, fraud prevention, and compliance with regulatory obligations. The legal bases are Art. 6(1)(b) and (c) GDPR and, where applicable, Art. 6(1)(f) GDPR.
Further information: https://stripe.com/de/privacy and https://stripe.com/de/legal/privacy-center
10. Recipients and Data Processors
Personal data is only made available to entities that require it for the purposes described above. These may include hosting and infrastructure providers, email service providers, Stripe, technical support providers, and advisers or authorities required for legal or tax purposes. Processors are contractually bound in accordance with Art. 28 GDPR.
Current list of processors used:
- Brevo
- Stripe
11. Transfers to Third Countries
Individual service providers may process data outside the European Economic Area or use subprocessors located there. In such cases, the requirements of Art. 44 et seq. GDPR are observed, for example through an adequacy decision or EU Standard Contractual Clauses and any necessary additional safeguards. Details can be found in the privacy notices and data processing agreements of the providers actually used.
12. Retention Period and Deletion
Account data and unpublished contractual data are generally stored for the duration of the contract. After termination of the contract, they are deleted or anonymised as soon as they are no longer required for contract administration and there are no statutory retention, evidentiary, or security interests preventing deletion. Contractual and billing data relevant under commercial and tax law are retained for the respective statutory retention period.
Publicly released product passport versions are technically designed for traceable versioning and stable addresses. Users must therefore check before publication whether the data contained therein may be made permanently publicly available. Specific requests for deletion or blocking are reviewed taking into account legal obligations, third-party rights, and the integrity of product information already published.
Backups are overwritten or deleted after 1 week. During this period, data is accessible only for recovery and security purposes.
13. Overview of Legal Bases
- Art. 6(1)(a) GDPR: Consent, where expressly obtained in individual cases
- Art. 6(1)(b) GDPR: Steps prior to entering into a contract and performance of a contract
- Art. 6(1)(c) GDPR: Compliance with legal obligations
- Art. 6(1)(f) GDPR: IT security, prevention of misuse, error analysis, and establishment, exercise, or defence of legal claims
14. Rights of Data Subjects
Subject to the applicable legal requirements, data subjects have in particular the right of access, rectification, erasure, restriction of processing, data portability, and objection. Consent that has been given may be withdrawn at any time with effect for the future. Data subjects also have the right to lodge a complaint with a data protection supervisory authority.
Requests may be sent to the contact address stated above. To prevent unauthorised disclosure of data, appropriate proof of identity may be requested.
The competent Spanish supervisory authority is, in particular, the Agencia Española de Protección de Datos (AEPD): https://www.aepd.es/
15. Automated Decision-Making
DPPReady currently does not make decisions based solely on automated processing that produce legal effects or similarly significantly affect individuals within the meaning of Art. 22 GDPR. Completeness scores and rule profiles are technical aids and do not replace professional or legal decisions on individual cases.
16. Security and Changes
DPPReady implements appropriate technical and organisational measures, including encrypted transmission, access controls, roles and permissions, password hashing, optional two-factor authentication, logging of security-related events, and separate private file storage. No system can guarantee absolute security.
This Privacy Policy will be updated when functions, service providers, or legal requirements change. The version published on this page at any given time shall apply.