Terms of Service
These Terms of Service set out how your business may use DDPP (Decentralized Digital Product Passport): the DDPP app, its public passport pages at dppeu.cloud and the interfaces behind them. Section 12 covers people who only scan and read passports.
"We", "us" and "our" mean ZincirX Bilişim Teknoloji ve Danışmanlık A.Ş., which provides DDPP (section 1). "You" means the business that uses DDPP, which is set up in DDPP as an "organization". A "member" is a person with their own sign-in who acts for an organization.
The Privacy Policy explains how we handle personal data for our own purposes, and the Legal Notice gives our company details.
1. Who provides DDPP
DDPP is provided by ZincirX Bilişim Teknoloji ve Danışmanlık A.Ş., a joint-stock company established in Türkiye, whose address is Teknopark İzmir, İYTE Kampüsü, 35430 Urla/İzmir, Türkiye. It is the other party to your contract and is responsible to you for DDPP.
2. For businesses
Writing passports in DDPP is offered only to businesses. When a member accepts these Terms or uses DDPP for an organization, they confirm that they act for that business, for the purposes of its trade or profession, and that they are authorised to do so.
Because your business uses DDPP for its trade or profession, consumer protection rules do not apply to your contract with us. If a law nevertheless treats a particular contract as a consumer contract, the rights that law gives cannot be excluded, and these Terms do not limit them.
3. Accounts and sign-in
Every person who uses DDPP for your business needs their own account. They sign in with an email address and password, or with Google or Apple, and the app keeps them signed in with a token issued to their device.
Members must keep their sign-in details to themselves and must not share an account. If you think an account has been used without permission, tell us at once at dpp@dppeu.cloud; we may suspend that account to protect you and others (section 15).
Your business is responsible for what its members do in DDPP for it, and for use of a member's account by someone else where your business or the member made that use possible. It is not responsible for use that neither could reasonably have prevented, including use that results from a failure of our security.
A member can delete their own account at any time in the app (More, then Delete my account), or by writing to dpp@dppeu.cloud from the account's email address. Deleting an account does not close the organization or take its passports offline. The Privacy Policy lists what is removed and what is kept.
4. What DDPP is, and what it is not
DDPP is an online service that we host and operate. With it, your business can:
- describe its products, with their identifiers, materials, documents and certifications;
- create passports for a model, a batch or a single item, fill them in as drafts and publish them;
- record events that happen to a product, with times, places, positions and photos;
- print QR labels and write passport links to NFC tags;
- recall a published passport or withdraw it.
Every file uploaded to DDPP receives a SHA-256 fingerprint, which can show that the file has not changed since it was uploaded. A fingerprint shows only that; it says nothing about whether the content of the file is true.
A passport page shows your business's own record of a product. We do not check that the record is true, and we do not verify that a physical product is genuine. A QR code can be copied onto other goods, so a passport page cannot show that the item in someone's hand is one of those it describes.
We are not a certification body, and we do not endorse any product, claim or certificate shown on a passport page. DDPP is designed with the EU Ecodesign for Sustainable Products Regulation (Regulation (EU) 2024/1781) in mind, but we do not claim that DDPP, or any passport, meets that Regulation, a harmonised standard or any other law that applies to your products, and we are not a certified digital product passport service provider. Section 7 explains what remains your responsibility.
Nothing in DDPP is legal, regulatory or other professional advice.
5. Organizations and roles
An organization is set up in the app with its name and country, and may add its legal name, address, website, GLN and EORI number. These details appear on its published passports as the business responsible for the product, so keep them accurate and up to date.
Each member of an organization has a role: owner, admin, editor or viewer. Viewers can read; owners, admins and editors can write; only owners and admins can withdraw a published passport.
6. Passports and their identifiers
A passport starts as a draft, which only your organization's members can see. While it is a draft, its data and events can be changed or deleted freely.
Publishing a passport makes its public part visible to anyone who scans its code or opens its link, free of charge and without signing in. It also fixes the passport's identity: its product, its level (model, batch or item), and its lot or serial number.
After publishing, changes to the passport's data are added as new revisions and earlier revisions are kept, and events can only be added to, so that the record of what the passport said, and when, stays complete. This is a design choice, not an inability to delete: personal data in a published passport, including in earlier revisions, can be removed on your instruction (section 19), and specific content can be disabled as section 10 describes.
Each passport has an identifier that is never moved to another product or reused, even if you ask us to, because its code may already be on products in circulation. Where your product has a GTIN and your passport a lot or serial number, the passport also has a GS1 Digital Link address on dppeu.cloud built from them. Such an address, unlike the passport's identifier, can be guessed.
Fields marked restricted or authority-only in your data are not shown on the public page or in the public machine-readable version of the passport.
You can recall a published passport. It then stays public, with a recall notice and your reason at the top. Handling the recall itself, including informing an authority where the law requires it, is your responsibility. Owners and admins can withdraw a passport, which takes it offline for good: its address then shows only that it was withdrawn.
7. Our role as your passport service provider
When you publish passports in DDPP, your business authorises us to act as its digital product passport service provider for them, storing them and making them available to those entitled to see them. Under EU law, that authorisation comes from the business that places the product on the market, or puts it into service, in the European Union. If that is another business, such as your importer, you are responsible for making sure that it authorises us for those passports, which it can do by writing to us.
You remain the economic operator responsible for your products. Where the law requires them, that includes:
- making sure the content of each passport is accurate, complete and up to date;
- checking which kind of passport (model, batch or item), identifier and data carrier the rules for your product require, and using them;
- registering passports in the EU digital product passport registry, and giving a registration identifier to customs where required. We do not register passports on your behalf;
- arranging a back-up copy of your passports with a digital product passport service provider;
- dealing with authorities, taking corrective action and meeting every other duty the law places on you.
We process passport data only to provide DDPP and to meet our legal obligations, and we do not sell it or reuse it.
8. Your content
Your content is everything your business and its members put into DDPP: products, passports, their data and revisions, events with their places, positions and photos, certifications and documents. It remains yours. We host it; we are not its author, and publishing it on a passport page does not mean that we adopt or vouch for it.
Your business gives us a non-exclusive, worldwide, royalty-free licence to store, copy, process, display and publish its content, including on passport pages, through QR codes, NFC tags and GS1 Digital Link addresses, and through our interfaces, as far as that is needed to provide DDPP and to meet our legal obligations. The licence lasts as long as the content is in DDPP.
You confirm that your business holds the rights needed to grant this licence, including in photos and documents made by others, and that it is entitled to use every GTIN, GLN, EORI number, certificate, logo and mark it enters. We do not check who a GTIN belongs to.
You are responsible for your content being accurate, complete, up to date and lawful. We do not review content before it is published and have no general obligation to monitor it, and we do not edit it. Without your instruction we only disable access to specific content, as section 10 describes, or act on the order of a court or authority.
9. What may not be published
These rules apply to everything your business puts into DDPP, and above all to what appears on public passport pages, which anyone can see. Your content must not:
- be illegal, or concern an illegal product or activity;
- infringe anyone's intellectual property or other rights, such as the copyright in a photo or a trade mark;
- give false or misleading information about a product, such as its origin, composition, method or date of manufacture, or its environmental or social characteristics;
- claim a certificate, approval, label or mark that the product or your business does not hold, or suggest that DDPP or anyone else endorses the product when they do not;
- present another business's products as your own;
- contain other people's personal data without a legal basis, or personal data of the people who buy or use your products without their explicit consent;
- contain malware, or links meant to deceive the people who scan a code.
Names, faces and the positions recorded with events can identify the people who work for you: keep them off the public part of a passport unless you have a legal basis to publish them.
We apply these rules diligently, objectively and proportionately, with due regard to the rights and legitimate interests of everyone involved, including freedom of expression and your freedom to conduct a business.
10. Reporting illegal content, and how we moderate
Anyone can report content on a passport page, or on any other page we host, that they believe is illegal: with the "Report this page" link on every passport page, or by email to dpp@dppeu.cloud with the address of the page. A report is easiest to act on when it explains why the content is illegal and states that it is made in good faith. A name and email address are optional; with an email address, we confirm receipt and tell the person what we decided.
A person reviews every report and makes every decision about content; we do not use automated means to moderate content. If we find that content is illegal or breaches section 9, we take the least severe measure that is enough: disabling access to a specific item, such as a photo, a document or an earlier revision; disabling access to a passport's public page; or, as a last resort, suspending or closing an account (section 15). Disabling specific content in this way takes precedence over keeping earlier revisions.
When we take such a measure, we send the organization a statement of reasons at the latest when the measure takes effect: what we did, where and for how long, the facts we relied on and whether we acted on a report, the legal or contractual ground, and how the decision can be contested. We reveal who made a report only where that is strictly necessary.
If a court or another competent authority orders us to act against content or to provide information, we comply as the law requires, and we tell you unless the order or the law prevents us. If content gives rise to a suspicion of a criminal offence that threatens someone's life or safety, we inform the competent authorities.
You, a member or the person who made a report can contest any of our decisions by writing to dpp@dppeu.cloud. A person reviews it again without undue delay. Asking us for a review does not limit any other remedy, including going to court or, for decisions about content in the European Union, complaining to a Digital Services Coordinator.
11. Acceptable use
When using DDPP, your business and its members must not:
- use DDPP for anything illegal, or to deceive the people who scan your products' codes;
- try to get into accounts, organizations or data that are not theirs, or probe, test or get around our security;
- disrupt or overload DDPP or the systems it runs on, including by sending automated requests beyond the limits of our interfaces;
- copy, decompile or reverse engineer DDPP's software, except as far as the law allows;
- resell access to DDPP, or set up an account or organization with false details.
A serious or repeated breach of this section can lead to the measures in section 15.
12. Reading passports
Anyone can scan a code and read a published passport, in the DDPP app or in a browser, free of charge and without an account. Products you save in the app stay on your phone. Reading is provided as it is: a passport is its manufacturer's own record, and we do not check it (section 4). Sections 4, 9, 10, 16 and 17 apply to readers as far as they are relevant; nothing in these Terms limits the rights the law gives consumers.
13. Prices
DDPP is free while it is in testing. If we introduce prices, we will announce them at least 30 days before they apply, and nothing will be charged to your business without its agreement. Exporting your data, switching to another provider and erasure are free of charge (section 14).
14. Your data, switching and leaving
Your data is yours. An organization's owners and admins can ask us at any time for a copy of all of its data, and we send it without undue delay in a structured, commonly used and machine-readable format (JSON), with files in the format in which they were uploaded. Anyone can read the public part of each published passport as JSON.
You can end your contract with us at any time, to move your data to another provider or to your own systems, to have it erased, or both. The following applies to every business, and includes the terms the EU Data Act (Regulation (EU) 2023/2854) requires:
- an owner or admin of your organization, or someone you authorise, gives us notice by email; the notice period is 30 calendar days;
- by the end of it, you tell us whether you want a move to another provider, a move to your own systems, erasure, or a combination;
- we complete a move without undue delay and within a transitional period of 30 calendar days after the notice period, which you can extend once; if a move is technically not feasible in that time, we tell you within 14 working days of your notice and propose an alternative period of no more than seven months;
- throughout, DDPP keeps running with due care, including your passport pages, and we give you, and any provider you authorise, reasonable help;
- you then have 30 calendar days to retrieve your data, after which we erase it, except records the law requires us to keep.
For each published passport, you choose whether we erase it or keep it online. Printed codes of erased passports stop leading to your record, and their identifiers are never reused; before you ask for erasure, make sure that no law requires those passports to stay available. Passports you choose to keep stay online for as long as we provide DDPP.
Switching, exporting and erasure are free of charge, and we put no obstacle in the way of ending your contract, contracting with another provider or moving your data.
15. Suspension and termination
We may suspend or close an organization, or a member's account, only for a serious or repeated breach of these Terms, including publishing illegal content or content section 9 prohibits; for a threat to the security of an account, of the service or of others; or where the law, a court or another competent authority requires it.
Any measure is proportionate to its reason: where disabling specific content is enough, we do that instead, and we suspend rather than close where suspension is enough. Where we can, we give notice and our reasons before a measure takes effect; we act first and explain at the same time only where waiting would cause harm or the law requires it. Suspension deletes nothing, and it never stops you getting a copy of your data. You can contest any of these decisions as section 10 describes.
If we decide to stop providing DDPP altogether, we tell you as far in advance as we reasonably can, and at least 60 days before, and help you move your data as section 14 describes.
16. Our commitments and our liability
We provide DDPP with the care and skill of a diligent provider of such a service. We aim to keep it available at all times, but we do not promise that it will run without interruption or error, particularly while it is in testing; maintenance, faults and events outside our control can make it unavailable for a time.
We are not responsible for the accuracy or lawfulness of the content your business supplies, or for what third parties do with copies of your codes.
Nothing in these Terms excludes or limits our liability for intent or gross negligence, for injury to life, body or health, or any other liability that the applicable law does not allow to be excluded or limited. Apart from those cases, for damage caused by slight negligence we are liable only for damage that was typical and foreseeable when the contract was made, and our total liability for all such damage is limited to TRY 10,000.
Your business compensates us for the losses and reasonable costs we incur from claims by third parties or authorities that result from its content or its breach of these Terms, to the extent that your business is responsible for them.
17. Intellectual property
DDPP, including its software, design and documentation and the DDPP name and logo, belongs to us or to those who license it to us; open-source components are used under their own licences. These Terms transfer none of those rights to you. We give your business a non-exclusive, non-transferable right to use DDPP for its own business, as these Terms allow. Your business may print its passports' codes and addresses on its products, packaging and documents. If you send us suggestions about DDPP, we may use them freely.
18. Confidentiality
We keep confidential everything in your organization that is not published on a public passport page. Our staff, and the service providers who help us run DDPP, see it only as far as they need to and are bound to keep it confidential. We disclose it to anyone else only as these Terms allow, with your agreement, or where the law, a court or an authority requires it. Public passport pages are public by design, and showing them is not a breach of confidentiality.
19. Personal data, and processing on your behalf
We are the controller of the personal data of members, as the Privacy Policy explains. For personal data in your content, such as names, people shown in photos and positions recorded with events, your business is the controller and we process it on your behalf as your processor. This section is the contract Article 28 of the GDPR and the KVKK require for that processing:
- Subject matter and duration: providing DDPP, for as long as your content is in DDPP.
- Nature and purpose: storing, displaying and publishing your content as you direct through DDPP.
- Types of personal data and data subjects: the personal data your business puts into its content, such as names, contact details, images and positions, about its staff, its suppliers' staff and other people shown in its records.
- Instructions: we process the data only on your documented instructions, which are these Terms and your use of DDPP, unless the law requires otherwise, in which case we tell you first unless the law forbids it.
- Confidentiality and security: the people who process the data are bound to confidentiality, and we take the security measures described in the Privacy Policy.
- Sub-processors: you authorise Hostinger, which provides our servers, in Lithuania, and our email service. We tell you before we add or replace a sub-processor, and you can object; we impose the same data protection obligations on every sub-processor.
- Assistance: we help you answer requests from data subjects, and with security, breach notification, data protection impact assessments and prior consultation, as far as our role allows.
- Breaches: we tell you without undue delay after becoming aware of a personal data breach affecting your content.
- End of processing: when the contract ends, we return or erase the data as section 14 describes, unless the law requires us to keep it.
- Audits: we make available the information needed to demonstrate compliance with this section, and allow for and contribute to audits, including inspections, by you or an auditor you mandate, with reasonable notice.
- Transfers: personal data leaves Türkiye and the European Economic Area only as the Privacy Policy describes.
Your business is responsible for having a legal basis for the personal data it puts into DDPP, for informing the people concerned, and for what it chooses to publish on passport pages.
20. Accepting these Terms, and changes to them
This version of the Terms takes effect on 19 September 2026. A member accepts them for the business when they create an account or set up an organization, and confirms having read the Privacy Policy. These Terms also apply when your business uses DDPP through our interfaces. You can save or print them from this page at any time.
We may change these Terms for a valid reason, such as a change in the law, the adoption of rules for digital product passports or a change in DDPP. A change that reduces your rights or adds to your obligations takes effect for your business only after we have told its members by email at least 30 days before; if you do not accept it, you can end the contract free of charge as section 14 describes. Other changes, such as corrections and clearer wording, take effect when we publish them.
21. Governing law and courts
These Terms, and every contract made under them, are governed by the law of the Republic of Türkiye. The courts and enforcement offices of İzmir, Türkiye, have exclusive jurisdiction over any dispute arising from or in connection with these Terms. This choice does not take away any protection that a law gives you whatever law the parties choose, including rules of European Union law that apply regardless of the law that governs the contract, and it does not prevent you from complaining to a competent authority. If a provision of these Terms is invalid, the rest remain in force. If a problem arises, please tell us first, so that we can try to resolve it; that is not a condition of going to court.
22. Notices and contact
We send notices about your contract to the email addresses of your organization's owners and admins, or, where a notice concerns one person, to that member's email address. You can reach us at dpp@dppeu.cloud or on +90 536 587 41 81, in English, Turkish, German or Spanish. The address dpp@dppeu.cloud is also our single point of contact under the EU Digital Services Act, for users of DDPP and for the authorities. Our company details are on our Legal Notice.