DDPP
Language: EN
Join the beta

Privacy Policy

Effective 19 September 2026

This Privacy Policy explains how DDPP (Decentralized Digital Product Passport) uses personal data about the people it deals with: people who sign in to write product passports for an organization, people who scan and read passports, visitors to dppeu.cloud, and people who write to us.

DDPP is a service for businesses. An organization records its products in the DDPP app and publishes a product passport for a model, a batch or a single item, which anyone can open by scanning its QR code or NFC tag.

In this policy, "you" means the person the data is about. An "organization" is a business set up in DDPP, and a "member" is a person with their own sign-in who acts for an organization. "We", "us" and "our" mean ZincirX Bilişim Teknoloji ve Danışmanlık A.Ş., which provides DDPP.

This policy gives the information required by Articles 13 and 14 of the EU General Data Protection Regulation (GDPR) and by Article 10 of Türkiye's Law No. 6698 on the Protection of Personal Data (KVKK). For the KVKK, it is our information notice (aydınlatma metni).

How organizations may use DDPP is set out in our Terms of Service.

1. Who is responsible for your data

ZincirX Bilişim Teknoloji ve Danışmanlık A.Ş., a joint-stock company established in Türkiye, with its address at Teknopark İzmir, İYTE Kampüsü, 35430 Urla/İzmir, Türkiye, is the controller (in Turkish law, the veri sorumlusu) of the personal data this policy describes. Its registration details are on our Legal Notice.

For the content organizations put into DDPP, such as their products and passports, we act for the organization instead. Section 2 explains how.

For any question about this policy or your data, write to dpp@dppeu.cloud, call +90 536 587 41 81, or write to the address above. We have not appointed a data protection officer; privacy questions go to the people who handle them.

2. When we act for organizations

Organizations use DDPP to keep and publish their own product records: products and their data, passports, certifications and documents, and events, with their descriptions, places, positions and photos.

The organization decides what goes into these records and what is published, so it is the controller of any personal data in them, and we process that data on its behalf, as its processor, under section 19 of our Terms of Service. We process it only to provide DDPP to the organization and on its instructions. We do not sell it, and we do not use it for purposes of our own.

The DDPP app uses your phone's camera, location and photos only with your permission:

The photos and positions you add become part of the organization's records.

If your personal data appears in an organization's records, for example because you appear in a photo or your name is in a document, the organization decides how it is used. Please contact that business. If you contact us instead, we will pass your request to it and help it respond.

3. Public passport pages

When an organization publishes a passport, anyone who scans its code, opens its link or looks it up by the product's GS1 identifiers can see its public part, as a web page and in machine-readable form. Fields the organization's data marks as restricted or authority-only are not shown there.

The public part is the manufacturer's own record of its product. Organizations must not publish the personal data of consumers, meaning the people who buy or use their products, without those people's explicit consent, and should keep other personal data, such as the names of individual workers or positions that reveal where someone lives, off the public part.

After a passport is published, changes to its data are added as new revisions and earlier revisions are kept, and its events can only be added to. Where personal data in a published passport has to be corrected or removed, including from its earlier revisions, the organization can ask us at dpp@dppeu.cloud and we will do it.

A published passport stays online until the organization withdraws it. Its address then shows only that it was withdrawn.

We do not record who opens a passport page beyond the ordinary server logs described in section 10, and passport pages set no cookies.

If you believe a passport page contains illegal content, use the "Report this page" link on it, or write to dpp@dppeu.cloud with the page's address. A person reviews every report. Our Terms of Service explain what happens next.

4. The personal data we collect

As controller, we collect the following:

We do not take payments (DDPP is free while it is in testing), and we use no analytics or advertising tools.

5. Where the data comes from

Most of it comes from you, when you sign up, set up an organization or write to us. Technical data is collected automatically with each request. If you sign in with Google or Apple, that provider gives us an account identifier and, depending on your settings, your email address and name.

6. Why we use it and on what legal basis

For each purpose we give the legal basis under the GDPR and the processing condition under Article 5 of the KVKK.

Where we rely on legitimate interests, you can object, as section 12 explains. We make no decisions about anyone based solely on automated processing.

7. What you have to give us

To open an account you must give your name, an email address and a password, or sign in with Google or Apple. To set up an organization you must give its name and country, because every passport names the organization as the business responsible for the product. Without these we cannot provide DDPP. Everything else is optional.

8. Who we share it with

If you ask, we will tell you the names of the specific recipients of your personal data.

9. International transfers

We operate DDPP from Türkiye, and its servers are in Lithuania, in the European Union. Türkiye is not in the European Economic Area, and the European Commission has not adopted an adequacy decision for it.

Where the GDPR's rules on transfers apply to a transfer we make to a country without an adequacy decision, we use the standard contractual clauses adopted by the European Commission in Implementing Decision (EU) 2021/914. When you sign in with Google or Apple, your data goes between your device and those companies under their own terms; Google LLC and Apple Inc. are certified under the EU–US Data Privacy Framework, for which the Commission adopted an adequacy decision in Implementing Decision (EU) 2023/1795.

We transfer personal data out of Türkiye only on a basis that Article 9 of the KVKK allows. For regular transfers, such as to our servers in Lithuania, that basis is the standard contract announced by Türkiye's Personal Data Protection Board, notified to the Personal Data Protection Authority within five business days of its signature.

You can ask for a copy of these safeguards at dpp@dppeu.cloud.

10. How long we keep it

11. Deleting your account

You can delete your account in the DDPP app: open More, choose Delete my account and confirm. The account is deleted at once. If you cannot use the app, write to dpp@dppeu.cloud from the email address of the account, and we will delete it within 30 days and confirm by email. The steps are also at dppeu.cloud/delete-account.

When an account is deleted, we remove its name, email address, password, Google and Apple sign-in links, sign-in tokens, password reset links and memberships, and we revoke its Sign in with Apple authorization with Apple. Records the account created in an organization's content, such as products, passports, events and files, stay with the organization but no longer name the account.

Some records are kept:

12. Your rights

Depending on the law that applies to you, you have the right to:

To use any of these rights, write to dpp@dppeu.cloud or call +90 536 587 41 81. You can write in English, Turkish, German or Spanish. We answer free of charge and without undue delay: under the GDPR within one month, which we may extend by two further months for complex requests, telling you why within the first month, and under the KVKK within 30 days. We ask for proof of identity only if we have reasonable doubts about who is asking. If we do not do what you ask, we tell you why and that you can complain to a supervisory authority or go to court.

For data an organization controls, such as the contents of a passport, we pass your request to that organization and help it respond.

13. Your rights under the KVKK

Under Article 11 of the KVKK, you have the right to:

You can apply in writing to the address in section 1, or by email to dpp@dppeu.cloud from the address you registered with us. We conclude applications free of charge within 30 days at the latest; if an action has a separate cost, we may charge the fee set by the Personal Data Protection Board. If we reject your application, you find our answer inadequate or we do not answer in time, you can complain to the Board within 30 days of learning of our answer, and in any case within 60 days of your application.

14. Cookies and storage on your device

We rely on the exemption for storage that is strictly necessary to provide the service you asked for.

15. Security

We protect personal data with measures that include encrypted connections (HTTPS, with TLS 1.3 and post-quantum key exchange where your browser supports it), passwords stored only as hashes, sign-in tokens that can be revoked, access limited by each member's role, a SHA-256 fingerprint on every uploaded file, a server environment separated from other services, and daily backups. No system is completely secure. If you think your account has been misused, write to dpp@dppeu.cloud straight away.

16. Children

DDPP is a service for businesses and is not meant for children. We do not knowingly collect children's personal data. If you believe a child has given us personal data, please write to dpp@dppeu.cloud.

17. Changes to this policy

This version takes effect on 19 September 2026. We update the policy when DDPP or the law changes, and the date at the top shows the version in force. Before a significant change takes effect, we tell members by email. Before we use personal data for a new purpose, we will tell you.

18. Contact us

For questions about this policy or your personal data, write to dpp@dppeu.cloud or call +90 536 587 41 81. By post: ZincirX Bilişim Teknoloji ve Danışmanlık A.Ş., Teknopark İzmir, İYTE Kampüsü, 35430 Urla/İzmir, Türkiye. Our full company details are on our Legal Notice.