OpenDPP — Privacy Policy
Last updated: 2026-07-21 · Version: 1.0
1. Who we are
Opendpp UAB, company code 308017314, registered office Švitrigailos g. 11K-109, LT-03223 Vilnius, Lithuania ("Opendpp", "we") operates the OpenDPP platform and website at opendpp-node.eu and related subdomains (the "Service"). For the processing described in this Policy, we are the controller within the meaning of the GDPR.
Contact for privacy matters: info@opendpp-node.eu (or by post to the registered office). We have not appointed a data protection officer; the nature and scale of our processing does not require one.
2. What this Policy covers — and what it doesn't
This Policy covers personal data we process for our own purposes: visitors to our website, sales enquiries, the business users of customer workspaces (accounts, security, billing) and viewers of public passport pages.
It does not cover personal data contained in the product-passport content our business customers submit and publish ("Customer Content"). For that data the customer is the controller and we act as processor under our Data Processing Addendum. Passports are product data by design; customers are contractually required to keep personal data out of them except limited business contact details (Terms of Service §9.4). If you find your personal data in a published passport, the operator identified on that passport is responsible for it; you can also notify us at info@opendpp-node.eu and we will pass the request to the responsible customer and act as required by law.
3. The data we process, why, and on what legal basis
| Context | Data | Purpose | Legal basis (GDPR Art. 6(1)) |
|---|---|---|---|
| Website visits | IP address, request metadata (URL, user agent, timestamps), technical logs | Serve the site, security, abuse and fraud prevention, debugging | (f) legitimate interest — running and defending the Service |
| Contact / demo form | Name, business email, company, job title, country, phone (optional), your message, UTM parameters, an anonymised IP (last octet removed), the consent text and timestamp | Respond to your enquiry; follow-up about the enquiry | (a) consent (the checkbox you tick) and (b) pre-contractual steps |
| Marketing updates | The above, plus your opt-in status | Occasional product and regulatory updates, until you unsubscribe | (a) consent (separate optional checkbox); withdraw any time via the unsubscribe link or by emailing us |
| Workspace accounts | Name, business email, phone and job title (optional), language/timezone, role and permissions, password hash or federated sign-in identifiers, MFA status | Provide the Service, authenticate you, team management | (b) contract (with our customer, your organisation) and (f) legitimate interest in administering B2B workspaces |
| Security records | Session records (with full IP and user agent), login, workspace activity and administrative audit trails (actor, action, target, timestamp, with full IP), API-key usage metadata | Account security, incident investigation, tamper-evident audit of administrative actions and of changes to a workspace's product passports, support-access accountability | (f) legitimate interest — security and accountability; (c) legal obligation where records are legally required |
| Billing | Billing contact, billing email, company details, VAT ID, address, purchase-order number, subscription and payment events | Charge for the Service, invoicing, tax and accounting | (b) contract; (c) legal obligation (tax/accounting) |
| Public passport pages | Anonymised IP (last octet removed), user agent, accessed passport, timestamp | Rate limiting, abuse prevention, aggregate scan statistics for the responsible operator | (f) legitimate interest — protecting a public regulatory interface |
| Support & correspondence | Whatever you send us, your contact details | Handle your request | (b)/(f) depending on context |
| Transactional email | Recipient address, delivery metadata | Account emails (invitations, password set/reset, billing and service notices) | (b) contract; (f) legitimate interest |
We do not use the data above for automated decision-making producing legal effects, and we do not sell personal data.
4. Cookies and similar technologies
The application itself sets only strictly necessary cookies:
| Cookie | Purpose | Properties |
|---|---|---|
opendpp_session |
Keeps you signed in (session token) | httpOnly; Secure (on HTTPS); SameSite=Strict; expires after 24 hours |
opendpp_imp |
Time-boxed support-access session (set only when our support staff signs into a workspace with an audited support login) | httpOnly; Secure (on HTTPS); SameSite=Strict; expires after 30 minutes |
opendpp_csrf |
Protects signed-in requests against cross-site request forgery | Secure (on HTTPS); SameSite=Strict; session lifetime; readable by the page by design |
No consent is required for these. On our marketing site, analytics load through Google Tag Manager, which in turn loads Google Analytics. These and any other third-party cookies run only where enabled and only after you give consent through the cookie banner (provided by iubenda): Google Tag Manager is held inert until you consent, so no analytics tag fires beforehand. You can change your choice at any time via the banner's privacy controls. Web fonts are self-hosted on our own infrastructure — loading our pages does not disclose your IP address to a fonts CDN.
5. Recipients and sub-processors
We use a small set of service providers, listed with locations and safeguards in our Sub-processor Register. In summary: Google Cloud (hosting, in the EU), a managed PostgreSQL platform (database), Stripe (payments — Stripe also acts as an independent controller for its own payment processing), Google/Firebase (two-factor authentication), Resend (transactional email), iubenda (cookie consent), and Google Tag Manager with Google Analytics (only with your consent). Optional integrations, where a customer or we enable them, call EU public services (e.g. the European Commission's EORI/AEO validation) and an RFC 3161 timestamping authority. We disclose personal data to authorities only where legally required, and to professional advisers under confidentiality.
6. International transfers
The Service is hosted in the European Union. Some providers (e.g. Stripe, Google, Resend) may process limited data in third countries, including the United States; where that happens we rely on an adequacy decision (including the EU–U.S. Data Privacy Framework, where the provider is certified) and/or the European Commission's Standard Contractual Clauses, with supplementary measures as appropriate. In particular, primary account sign-in (email/password) is processed in the EU, while two-factor authentication is provided via Google Firebase / Identity Platform in the United States under the EU–U.S. Data Privacy Framework and SCCs. Details per provider are in the Sub-processor Register.
7. How long we keep data
| Data | Retention (target) |
|---|---|
| Contact/demo enquiries (leads) | Up to 24 months after our last interaction; marketing opt-ins until you unsubscribe |
| Workspace accounts | For the life of the workspace; removed or anonymised after account deletion, subject to the records below |
| Session records | Cookie expires after 24 hours; server-side session records are kept briefly for security review and then purged |
| Public passport scan logs (anonymised IP) | 180 days |
| Workspace activity and administrative audit trail | 400 days |
| Platform administrative audit trail | 730 days |
| Idempotency records (API replay protection) | 24 hours |
| Billing and accounting records | Up to 10 years, as required by Lithuanian accounting and tax law |
| Published passports (Customer Content) | Per the operator's regulatory retention (15 years by default) — governed by the DPA, not this Policy |
We may keep specific data longer where necessary to establish, exercise or defend legal claims or to comply with a legal obligation.
8. Your rights
You have the rights of access, rectification, erasure, restriction, portability and objection
(Articles 15–21 GDPR), and the right to withdraw consent at any time (without affecting prior
processing). Signed-in users can self-serve an export of their own data in the account area
(/api/v1/me/export). For anything else, email info@opendpp-node.eu — we answer within one
month. You may lodge a complaint with the Lithuanian State Data Protection Inspectorate (Valstybinė
duomenų apsaugos inspekcija, vdai.lrv.lt) or the supervisory authority of your habitual
residence.
Where processing rests on legitimate interests (§3), you may object on grounds relating to your particular situation; we will stop unless compelling legitimate grounds prevail. For direct marketing, an objection is always honoured.
9. Security
We apply technical and organisational measures appropriate to the risk, including: TLS encryption in transit; encryption at rest for the database and, additionally, envelope encryption (AES-256-GCM with per-tenant keys) for signing keys and stored secrets; role- and permission-based access control; multi-factor authentication support; tamper-evident audit logging with a public seal verifier; IP anonymisation on public-interface logs; strict egress controls (SSRF protection) and a nonce-based content-security policy; EU-region hosting; and secrets management with keyless deployments. A summary is published on our Security page; the DPA's Annex 2 describes the measures applicable to Customer Content.
10. Children
The Service is a B2B product and is not directed at children. We do not knowingly process children's data.
11. Changes to this Policy
We may update this Policy from time to time. The current version is always published on our website; material changes will be signposted (e.g. by email or in-product). The "Last updated" date above tells you when it last changed.
12. Contact
Opendpp UAB · Švitrigailos g. 11K-109, LT-03223 Vilnius, Lithuania · Company code 308017314 · info@opendpp-node.eu