← FIDATRA Passport

Legal

Privacy Policy

Last updated: 14 August 2026

1. Who we are

FIDATRA Passport is a digital product identity and Digital Product Passport platform operated by Gianluca Engst.

For questions concerning this Privacy Policy or the processing of personal data, please use the contact details published by FIDATRA.

2. Personal data we collect

Depending on how you use FIDATRA Passport, we may process personal data including:

  • First name and last name
  • Email address
  • Company name and company identifier
  • Account and authentication information
  • Information associated with product ownership, warranty, maintenance and Digital Product Passport records
  • Information you provide when contacting or interacting with the service
  • Technical and security information necessary to operate and protect the platform
  • For product verification analytics, an approximate country code may be derived locally from the network address. FIDATRA does not store that address, precise location, city or coordinates in the scan analytics record.

Passwords are not stored in plain text. Authentication credentials are processed using security mechanisms designed to protect account access.

3. Why we process personal data

We may process personal data to:

  • Create and manage FIDATRA Passport accounts
  • Verify email addresses and authenticate users
  • Provide and secure access to the platform
  • Create and manage Digital Product Passports and related product records
  • Manage product ownership, warranty and maintenance information
  • Provide account recovery and password reset functionality
  • Send service-related communications
  • Detect, investigate and prevent misuse or security incidents
  • Maintain and improve the reliability of the service
  • Comply with applicable legal obligations

4. Legal bases for processing

Where the General Data Protection Regulation (GDPR) applies, personal data is processed on one or more applicable legal bases, including performance of a contract or steps requested before entering into a contract, compliance with legal obligations, legitimate interests in operating and securing the service, and consent where consent is specifically required.

5. Product ownership information

FIDATRA Passport may process information relating to the ownership or transfer of products when these functions are used. Such information may be associated with a product's digital identity and lifecycle history.

Access to personal ownership information is restricted to appropriate functionality and may be subject to anonymisation, revocation or retention procedures depending on the applicable record and legal requirements.

6. Service providers

We may use service providers to operate infrastructure, hosting, email delivery, storage, monitoring, security and other technical components of FIDATRA Passport.

These providers may process information only to the extent necessary to provide their services and subject to applicable contractual and data protection requirements.

7. International data transfers

Where personal data is transferred outside the European Economic Area, appropriate safeguards will be used where required by applicable data protection law.

8. Data retention

Personal data is retained only for as long as reasonably necessary for the purposes for which it was collected, to operate and secure the service, to maintain required product lifecycle records, and to comply with applicable legal obligations.

Different categories of information may have different retention periods depending on their purpose and applicable requirements.

Product scan attempts, including any approximate country code, are automatically removed after the configured analytics retention period. Geographic dashboard results are shown only as company-level aggregates, and small country groups are suppressed.

9. Your rights

Where applicable under the GDPR, you may have rights including the right to request access to your personal data, correction of inaccurate data, deletion, restriction of processing, data portability and objection to certain processing.

Where processing is based on consent, you may withdraw that consent at any time without affecting processing that occurred before its withdrawal.

Requests concerning these rights can be submitted using the contact details published by FIDATRA.

10. Complaints

If you believe that your personal data has been processed in violation of applicable data protection law, you may contact us first so that we can investigate the matter.

You also have the right to lodge a complaint with the competent data protection supervisory authority.

11. Security

We use technical and organisational measures intended to protect personal data against unauthorised access, alteration, disclosure or loss. No internet-based service can, however, guarantee absolute security.

12. Cookies

FIDATRA Passport currently uses cookies necessary for authentication and operation of the service. More information is available in our Cookie Policy.

13. Changes to this Privacy Policy

We may update this Privacy Policy when FIDATRA Passport, our data processing activities or applicable legal requirements change. The latest version will be published on this page.

14. Contact

Privacy and data protection enquiries can be submitted through the contact details published by FIDATRA.