Privacy Policy
This Privacy Policy explains how DDPP (Decentralized Digital Product Passport) uses personal data about the people it deals with: people who sign in to write product passports for an organization, people who scan and read passports, visitors to dppeu.cloud, and people who write to us.
DDPP is a service for businesses. An organization records its products in the DDPP app and publishes a product passport for a model, a batch or a single item, which anyone can open by scanning its QR code or NFC tag.
In this policy, "you" means the person the data is about. An "organization" is a business set up in DDPP, and a "member" is a person with their own sign-in who acts for an organization. "We", "us" and "our" mean ZincirX Bilişim Teknoloji ve Danışmanlık A.Ş., which provides DDPP.
This policy gives the information required by Articles 13 and 14 of the EU General Data Protection Regulation (GDPR) and by Article 10 of Türkiye's Law No. 6698 on the Protection of Personal Data (KVKK). For the KVKK, it is our information notice (aydınlatma metni).
How organizations may use DDPP is set out in our Terms of Service.
1. Who is responsible for your data
ZincirX Bilişim Teknoloji ve Danışmanlık A.Ş., a joint-stock company established in Türkiye, with its address at Teknopark İzmir, İYTE Kampüsü, 35430 Urla/İzmir, Türkiye, is the controller (in Turkish law, the veri sorumlusu) of the personal data this policy describes. Its registration details are on our Legal Notice.
For the content organizations put into DDPP, such as their products and passports, we act for the organization instead. Section 2 explains how.
For any question about this policy or your data, write to dpp@dppeu.cloud, call +90 536 587 41 81, or write to the address above. We have not appointed a data protection officer; privacy questions go to the people who handle them.
2. When we act for organizations
Organizations use DDPP to keep and publish their own product records: products and their data, passports, certifications and documents, and events, with their descriptions, places, positions and photos.
The organization decides what goes into these records and what is published, so it is the controller of any personal data in them, and we process that data on its behalf, as its processor, under section 19 of our Terms of Service. We process it only to provide DDPP to the organization and on its instructions. We do not sell it, and we do not use it for purposes of our own.
The DDPP app uses your phone's camera, location and photos only with your permission:
- the camera, to scan codes and to take photos you add to an event;
- your location, only when you choose to add your current position to an event, and only at that moment;
- your photo library, only to open the photo you pick.
The photos and positions you add become part of the organization's records.
If your personal data appears in an organization's records, for example because you appear in a photo or your name is in a document, the organization decides how it is used. Please contact that business. If you contact us instead, we will pass your request to it and help it respond.
3. Public passport pages
When an organization publishes a passport, anyone who scans its code, opens its link or looks it up by the product's GS1 identifiers can see its public part, as a web page and in machine-readable form. Fields the organization's data marks as restricted or authority-only are not shown there.
The public part is the manufacturer's own record of its product. Organizations must not publish the personal data of consumers, meaning the people who buy or use their products, without those people's explicit consent, and should keep other personal data, such as the names of individual workers or positions that reveal where someone lives, off the public part.
After a passport is published, changes to its data are added as new revisions and earlier revisions are kept, and its events can only be added to. Where personal data in a published passport has to be corrected or removed, including from its earlier revisions, the organization can ask us at dpp@dppeu.cloud and we will do it.
A published passport stays online until the organization withdraws it. Its address then shows only that it was withdrawn.
We do not record who opens a passport page beyond the ordinary server logs described in section 10, and passport pages set no cookies.
If you believe a passport page contains illegal content, use the "Report this page" link on it, or write to dpp@dppeu.cloud with the page's address. A person reviews every report. Our Terms of Service explain what happens next.
4. The personal data we collect
As controller, we collect the following:
- Account data: your name, your email address, your password, which we store only as a hash, your language, and your role in each organization you belong to.
- Sign-in data: if you sign in with Google or Apple, the account identifier that provider gives us and the email address and name it shares. For Sign in with Apple, we also keep the token Apple issues so that we can revoke the sign-in when you delete your account. The app stays signed in with a token issued to your device.
- Organization data: the details an organization gives, such as its name, legal name, country, address, website, GLN and EORI number. Most of this is about a business, but some of it, such as a sole trader's name, is personal data.
- Correspondence and requests: what you tell us by email or phone, and reports of illegal content, with a name and email address if you choose to give them.
- Technical data: the IP address and the browser or device details sent with each request to dppeu.cloud and to the DDPP app's server, which we use to deliver the service, keep it secure and fix faults.
We do not take payments (DDPP is free while it is in testing), and we use no analytics or advertising tools.
5. Where the data comes from
Most of it comes from you, when you sign up, set up an organization or write to us. Technical data is collected automatically with each request. If you sign in with Google or Apple, that provider gives us an account identifier and, depending on your settings, your email address and name.
6. Why we use it and on what legal basis
For each purpose we give the legal basis under the GDPR and the processing condition under Article 5 of the KVKK.
- Creating and running accounts, signing you in and providing DDPP: GDPR Article 6(1)(b), the contract under our Terms, or Article 6(1)(f), our legitimate interest in providing the service your organization uses. KVKK Article 5(2)(c), or 5(2)(f).
- Sending service emails, such as email confirmation and password reset: GDPR Article 6(1)(b) or 6(1)(f). KVKK Article 5(2)(c) or 5(2)(f).
- Answering questions and requests: GDPR Article 6(1)(b) where the request concerns our contract, otherwise Article 6(1)(f), our legitimate interest in answering the people who contact us. KVKK Article 5(2)(c) or 5(2)(f).
- Handling privacy requests, including account deletion, and revoking a Sign in with Apple authorization on deletion: GDPR Article 6(1)(c), because the GDPR requires us to act on them, and 6(1)(b). KVKK Article 5(2)(ç) and 5(2)(c).
- Keeping DDPP and its accounts secure, preventing misuse and fixing faults: GDPR Article 6(1)(f), our legitimate interest in protecting the service and the people who use it. KVKK Article 5(2)(f).
- Handling reports of illegal content: GDPR Article 6(1)(c), because the EU Digital Services Act requires hosting services to act on such reports, otherwise 6(1)(f). KVKK Article 5(2)(f).
- Complying with orders from courts and authorities, and establishing, exercising or defending legal claims: GDPR Article 6(1)(c) where EU or Member State law requires it, otherwise 6(1)(f). KVKK Article 5(2)(ç) and 5(2)(e).
Where we rely on legitimate interests, you can object, as section 12 explains. We make no decisions about anyone based solely on automated processing.
7. What you have to give us
To open an account you must give your name, an email address and a password, or sign in with Google or Apple. To set up an organization you must give its name and country, because every passport names the organization as the business responsible for the product. Without these we cannot provide DDPP. Everything else is optional.
8. Who we share it with
- Hostinger, which provides the servers DDPP runs on, in Lithuania, and our email service.
- Google and Apple, if you choose to sign in with them. They confirm your identity to us and learn that you are signing in to DDPP. When you delete an account that signs in with Apple, we tell Apple to revoke that sign-in.
- Other members of an organization you belong to, who see your name, email address and role.
- The public, who see what organizations publish on their passport pages.
- Professional advisers, such as lawyers and accountants, when they need it to advise us.
- Courts, authorities and other public bodies, when they order us to act or to provide information, where the law otherwise requires it, or where we need it to establish or defend a legal claim. Under the EU Digital Services Act, we must tell the authorities if we learn of information giving rise to a suspicion of a criminal offence that threatens someone's life or safety.
If you ask, we will tell you the names of the specific recipients of your personal data.
9. International transfers
We operate DDPP from Türkiye, and its servers are in Lithuania, in the European Union. Türkiye is not in the European Economic Area, and the European Commission has not adopted an adequacy decision for it.
Where the GDPR's rules on transfers apply to a transfer we make to a country without an adequacy decision, we use the standard contractual clauses adopted by the European Commission in Implementing Decision (EU) 2021/914. When you sign in with Google or Apple, your data goes between your device and those companies under their own terms; Google LLC and Apple Inc. are certified under the EU–US Data Privacy Framework, for which the Commission adopted an adequacy decision in Implementing Decision (EU) 2023/1795.
We transfer personal data out of Türkiye only on a basis that Article 9 of the KVKK allows. For regular transfers, such as to our servers in Lithuania, that basis is the standard contract announced by Türkiye's Personal Data Protection Board, notified to the Personal Data Protection Authority within five business days of its signature.
You can ask for a copy of these safeguards at dpp@dppeu.cloud.
10. How long we keep it
- Account data: for as long as the account exists. Section 11 explains deletion.
- Sign-in tokens: until you sign out, the token expires after a year, or the account is deleted.
- The Sign in with Apple token: until you delete your account, when we revoke it with Apple and delete it.
- Password reset and email confirmation links: 60 minutes.
- Organization data and content: for as long as the organization keeps it in DDPP. Published passports stay online until they are withdrawn or erased.
- Correspondence and reports: as long as we need them to deal with the matter and any follow-up.
- Server and application logs: 14 days.
- Backups: 14 days, after which deleted data no longer exists in them.
11. Deleting your account
You can delete your account in the DDPP app: open More, choose Delete my account and confirm. The account is deleted at once. If you cannot use the app, write to dpp@dppeu.cloud from the email address of the account, and we will delete it within 30 days and confirm by email. The steps are also at dppeu.cloud/delete-account.
When an account is deleted, we remove its name, email address, password, Google and Apple sign-in links, sign-in tokens, password reset links and memberships, and we revoke its Sign in with Apple authorization with Apple. Records the account created in an organization's content, such as products, passports, events and files, stay with the organization but no longer name the account.
Some records are kept:
- the organizations you belonged to, with their products and passports, which belong to the organization. If you were an organization's only owner, it stays in DDPP, and we can hand it to a person the business names;
- published passports, which stay online until the organization withdraws them;
- logs and backups, until they expire as section 10 describes.
12. Your rights
Depending on the law that applies to you, you have the right to:
- access the personal data we hold about you and get a copy of it;
- have inaccurate or incomplete data corrected;
- have your data erased (for an account, as section 11 describes);
- restrict our use of your data, for example while we check a complaint that it is inaccurate;
- receive the data you gave us in a structured, machine-readable format, which we send as JSON on request;
- object, on grounds relating to your situation, to processing based on our legitimate interests;
- complain to a data protection supervisory authority, in particular in the EU Member State where you live or work or where you believe the problem arose, and, under the KVKK, to the Personal Data Protection Board, as section 13 explains.
To use any of these rights, write to dpp@dppeu.cloud or call +90 536 587 41 81. You can write in English, Turkish, German or Spanish. We answer free of charge and without undue delay: under the GDPR within one month, which we may extend by two further months for complex requests, telling you why within the first month, and under the KVKK within 30 days. We ask for proof of identity only if we have reasonable doubts about who is asking. If we do not do what you ask, we tell you why and that you can complain to a supervisory authority or go to court.
For data an organization controls, such as the contents of a passport, we pass your request to that organization and help it respond.
13. Your rights under the KVKK
Under Article 11 of the KVKK, you have the right to:
- learn whether your personal data is processed, and request information about it if it is;
- learn why it is processed and whether it is used for that purpose;
- know the third parties in Türkiye or abroad to whom it is transferred;
- have it corrected if it is incomplete or inaccurate;
- have it deleted or destroyed once the reasons for processing it no longer apply;
- have corrections and deletions notified to the third parties who received the data;
- object to a result against you that arises from analysis of your data exclusively by automated systems;
- claim compensation if unlawful processing causes you damage.
You can apply in writing to the address in section 1, or by email to dpp@dppeu.cloud from the address you registered with us. We conclude applications free of charge within 30 days at the latest; if an action has a separate cost, we may charge the fee set by the Personal Data Protection Board. If we reject your application, you find our answer inadequate or we do not answer in time, you can complain to the Board within 30 days of learning of our answer, and in any case within 60 days of your application.
14. Cookies and storage on your device
- dppeu.cloud sets no cookies. If you dismiss the note offering another language, your browser's local storage remembers that you did.
- Passport pages and the app's server set no cookies.
- The account pages where you confirm your email address or choose a new password set two cookies: a session cookie (ddpp-session) and XSRF-TOKEN, which protects the form. Both are strictly necessary and expire after two hours of inactivity.
- The DDPP app keeps your sign-in token in your phone's secure storage and your settings and saved products on your phone. It contains no analytics or advertising tools.
We rely on the exemption for storage that is strictly necessary to provide the service you asked for.
15. Security
We protect personal data with measures that include encrypted connections (HTTPS, with TLS 1.3 and post-quantum key exchange where your browser supports it), passwords stored only as hashes, sign-in tokens that can be revoked, access limited by each member's role, a SHA-256 fingerprint on every uploaded file, a server environment separated from other services, and daily backups. No system is completely secure. If you think your account has been misused, write to dpp@dppeu.cloud straight away.
16. Children
DDPP is a service for businesses and is not meant for children. We do not knowingly collect children's personal data. If you believe a child has given us personal data, please write to dpp@dppeu.cloud.
17. Changes to this policy
This version takes effect on 19 September 2026. We update the policy when DDPP or the law changes, and the date at the top shows the version in force. Before a significant change takes effect, we tell members by email. Before we use personal data for a new purpose, we will tell you.
18. Contact us
For questions about this policy or your personal data, write to dpp@dppeu.cloud or call +90 536 587 41 81. By post: ZincirX Bilişim Teknoloji ve Danışmanlık A.Ş., Teknopark İzmir, İYTE Kampüsü, 35430 Urla/İzmir, Türkiye. Our full company details are on our Legal Notice.