Skip to content
OpenDPP
Why ESPR How it works Standards Solutions Pricing FAQ Demo
Client Console Book a demo
Why ESPR How it works Standards Solutions Pricing FAQ Demo Client Console Book a demo
Terms of ServicePrivacy PolicyAPI TermsSupport PolicyData Processing AddendumSub-processor RegisterLegal Notice (Imprint)

OpenDPP — Privacy Policy

Last updated: 2026-07-21 · Version: 1.0

1. Who we are

Opendpp UAB, company code 308017314, registered office Švitrigailos g. 11K-109, LT-03223 Vilnius, Lithuania ("Opendpp", "we") operates the OpenDPP platform and website at opendpp-node.eu and related subdomains (the "Service"). For the processing described in this Policy, we are the controller within the meaning of the GDPR.

Contact for privacy matters: info@opendpp-node.eu (or by post to the registered office). We have not appointed a data protection officer; the nature and scale of our processing does not require one.

2. What this Policy covers — and what it doesn't

This Policy covers personal data we process for our own purposes: visitors to our website, sales enquiries, the business users of customer workspaces (accounts, security, billing) and viewers of public passport pages.

It does not cover personal data contained in the product-passport content our business customers submit and publish ("Customer Content"). For that data the customer is the controller and we act as processor under our Data Processing Addendum. Passports are product data by design; customers are contractually required to keep personal data out of them except limited business contact details (Terms of Service §9.4). If you find your personal data in a published passport, the operator identified on that passport is responsible for it; you can also notify us at info@opendpp-node.eu and we will pass the request to the responsible customer and act as required by law.

3. The data we process, why, and on what legal basis

Context Data Purpose Legal basis (GDPR Art. 6(1))
Website visits IP address, request metadata (URL, user agent, timestamps), technical logs Serve the site, security, abuse and fraud prevention, debugging (f) legitimate interest — running and defending the Service
Contact / demo form Name, business email, company, job title, country, phone (optional), your message, UTM parameters, an anonymised IP (last octet removed), the consent text and timestamp Respond to your enquiry; follow-up about the enquiry (a) consent (the checkbox you tick) and (b) pre-contractual steps
Marketing updates The above, plus your opt-in status Occasional product and regulatory updates, until you unsubscribe (a) consent (separate optional checkbox); withdraw any time via the unsubscribe link or by emailing us
Workspace accounts Name, business email, phone and job title (optional), language/timezone, role and permissions, password hash or federated sign-in identifiers, MFA status Provide the Service, authenticate you, team management (b) contract (with our customer, your organisation) and (f) legitimate interest in administering B2B workspaces
Security records Session records (with full IP and user agent), login, workspace activity and administrative audit trails (actor, action, target, timestamp, with full IP), API-key usage metadata Account security, incident investigation, tamper-evident audit of administrative actions and of changes to a workspace's product passports, support-access accountability (f) legitimate interest — security and accountability; (c) legal obligation where records are legally required
Billing Billing contact, billing email, company details, VAT ID, address, purchase-order number, subscription and payment events Charge for the Service, invoicing, tax and accounting (b) contract; (c) legal obligation (tax/accounting)
Public passport pages Anonymised IP (last octet removed), user agent, accessed passport, timestamp Rate limiting, abuse prevention, aggregate scan statistics for the responsible operator (f) legitimate interest — protecting a public regulatory interface
Support & correspondence Whatever you send us, your contact details Handle your request (b)/(f) depending on context
Transactional email Recipient address, delivery metadata Account emails (invitations, password set/reset, billing and service notices) (b) contract; (f) legitimate interest

We do not use the data above for automated decision-making producing legal effects, and we do not sell personal data.

4. Cookies and similar technologies

The application itself sets only strictly necessary cookies:

Cookie Purpose Properties
opendpp_session Keeps you signed in (session token) httpOnly; Secure (on HTTPS); SameSite=Strict; expires after 24 hours
opendpp_imp Time-boxed support-access session (set only when our support staff signs into a workspace with an audited support login) httpOnly; Secure (on HTTPS); SameSite=Strict; expires after 30 minutes
opendpp_csrf Protects signed-in requests against cross-site request forgery Secure (on HTTPS); SameSite=Strict; session lifetime; readable by the page by design

No consent is required for these. On our marketing site, analytics load through Google Tag Manager, which in turn loads Google Analytics. These and any other third-party cookies run only where enabled and only after you give consent through the cookie banner (provided by iubenda): Google Tag Manager is held inert until you consent, so no analytics tag fires beforehand. You can change your choice at any time via the banner's privacy controls. Web fonts are self-hosted on our own infrastructure — loading our pages does not disclose your IP address to a fonts CDN.

5. Recipients and sub-processors

We use a small set of service providers, listed with locations and safeguards in our Sub-processor Register. In summary: Google Cloud (hosting, in the EU), a managed PostgreSQL platform (database), Stripe (payments — Stripe also acts as an independent controller for its own payment processing), Google/Firebase (two-factor authentication), Resend (transactional email), iubenda (cookie consent), and Google Tag Manager with Google Analytics (only with your consent). Optional integrations, where a customer or we enable them, call EU public services (e.g. the European Commission's EORI/AEO validation) and an RFC 3161 timestamping authority. We disclose personal data to authorities only where legally required, and to professional advisers under confidentiality.

6. International transfers

The Service is hosted in the European Union. Some providers (e.g. Stripe, Google, Resend) may process limited data in third countries, including the United States; where that happens we rely on an adequacy decision (including the EU–U.S. Data Privacy Framework, where the provider is certified) and/or the European Commission's Standard Contractual Clauses, with supplementary measures as appropriate. In particular, primary account sign-in (email/password) is processed in the EU, while two-factor authentication is provided via Google Firebase / Identity Platform in the United States under the EU–U.S. Data Privacy Framework and SCCs. Details per provider are in the Sub-processor Register.

7. How long we keep data

Data Retention (target)
Contact/demo enquiries (leads) Up to 24 months after our last interaction; marketing opt-ins until you unsubscribe
Workspace accounts For the life of the workspace; removed or anonymised after account deletion, subject to the records below
Session records Cookie expires after 24 hours; server-side session records are kept briefly for security review and then purged
Public passport scan logs (anonymised IP) 180 days
Workspace activity and administrative audit trail 400 days
Platform administrative audit trail 730 days
Idempotency records (API replay protection) 24 hours
Billing and accounting records Up to 10 years, as required by Lithuanian accounting and tax law
Published passports (Customer Content) Per the operator's regulatory retention (15 years by default) — governed by the DPA, not this Policy

We may keep specific data longer where necessary to establish, exercise or defend legal claims or to comply with a legal obligation.

8. Your rights

You have the rights of access, rectification, erasure, restriction, portability and objection (Articles 15–21 GDPR), and the right to withdraw consent at any time (without affecting prior processing). Signed-in users can self-serve an export of their own data in the account area (/api/v1/me/export). For anything else, email info@opendpp-node.eu — we answer within one month. You may lodge a complaint with the Lithuanian State Data Protection Inspectorate (Valstybinė duomenų apsaugos inspekcija, vdai.lrv.lt) or the supervisory authority of your habitual residence.

Where processing rests on legitimate interests (§3), you may object on grounds relating to your particular situation; we will stop unless compelling legitimate grounds prevail. For direct marketing, an objection is always honoured.

9. Security

We apply technical and organisational measures appropriate to the risk, including: TLS encryption in transit; encryption at rest for the database and, additionally, envelope encryption (AES-256-GCM with per-tenant keys) for signing keys and stored secrets; role- and permission-based access control; multi-factor authentication support; tamper-evident audit logging with a public seal verifier; IP anonymisation on public-interface logs; strict egress controls (SSRF protection) and a nonce-based content-security policy; EU-region hosting; and secrets management with keyless deployments. A summary is published on our Security page; the DPA's Annex 2 describes the measures applicable to Customer Content.

10. Children

The Service is a B2B product and is not directed at children. We do not knowingly process children's data.

11. Changes to this Policy

We may update this Policy from time to time. The current version is always published on our website; material changes will be signposted (e.g. by email or in-product). The "Last updated" date above tells you when it last changed.

12. Contact

Opendpp UAB · Švitrigailos g. 11K-109, LT-03223 Vilnius, Lithuania · Company code 308017314 · info@opendpp-node.eu

OpenDPP

The no-code platform for EU Digital Product Passports. Issue, seal, and publish — ready before the first deadlines.

Product

How it works Solutions Pricing Interactive demo Client Console

Company

About Why ESPR Security & Trust Seal Audit Portal

Resources

ESPR timeline DPP standards (EN 182xx) EU DPP Registry Battery Passport guide API reference AI knowledge bundle (OKF) Open source

Legal

Contact Support Privacy Policy Terms of Service Cookie Policy Legal Notice
© 2026 OpenDPP UAB · ESPR 2024/1781 · EU-hosted & eIDAS-signed