Privacy Policy
Last updated: 19 July 2026
This Policy explains how epassportify, established in Türkiye (“epassportify”, “we”, “us”), handles personal data through our website, application, Digital Product Passport services, support, and business communications.
1. Our roles
epassportify is the data controller for website visitors, account administrators and users, demo or pilot applicants, support contacts, and our own business communications.
Customers may upload supplier, employee, representative, or other contact data as part of Customer Content. Where we process that data only to provide the Service on the Customer’s instructions, the Customer is the controller and epassportify acts as processor. Customers are responsible for providing required notices, selecting a lawful basis, and deciding what information is made public on DPP pages. A data processing agreement may be made available where required.
Paddle independently processes checkout, payment, tax, invoice, fraud-prevention, subscription, and refund data under Paddle’s Privacy Notice.
2. Personal data we collect
2.1 Data you provide
- identity and contact data, such as name, business email, telephone number, organization, role, country, and language;
- account and organization settings, authorized-user details, and authentication-related identifiers;
- demo, pilot, sales, support, survey, and other correspondence;
- billing references and subscription status received from Paddle, but not full card details;
- Customer Content, which may include product contacts, supplier representatives, names appearing on documents, and information selected for public DPP pages.
2.2 Data collected automatically
- IP address, device and browser information, timestamps, requested URLs, referral data, and security logs;
- account activity, feature usage, error reports, audit events, QR scan events, and approximate location derived from IP where used;
- cookie or similar-technology data described in our Cookie Policy.
2.3 Data received from others
We may receive data from your organization’s account administrator, authorized users, identity provider, Paddle, service providers, referral sources, or public business records where lawful.
2.4 Collection method and point-of-collection notices
We collect data through website and application fields, account and support interactions, Customer uploads and APIs, service and security logs, cookies or similar technologies, and records supplied by Paddle or other providers. The legal basis depends on the purpose and is summarized below. Where applicable law requires a notice at the time of collection, we will also provide a concise activity-specific notice or link at the relevant form or workflow; that notice supplements this general Policy.
3. Why we process personal data
| Purpose | Typical legal basis |
|---|---|
| Create accounts, authenticate users, provide features, support subscriptions, and fulfil requests | Performance of a contract or steps requested before a contract |
| Secure the Service, prevent abuse and fraud, troubleshoot errors, maintain audit logs, and improve reliability | Legitimate interests in operating and protecting a B2B service; legal obligations where applicable |
| Respond to sales, pilot, support, privacy, and legal requests | Contract, legitimate interests, or legal obligations |
| Send product or service communications | Contract and legitimate interests; consent where required for marketing |
| Maintain tax, accounting, dispute, sanctions, and compliance records | Legal obligations and establishment, exercise, or defence of legal claims |
| Publish DPP content selected by a Customer | Performance of the Customer contract and the Customer’s documented instructions |
Legal bases can differ by jurisdiction. Where we rely on legitimate interests, we balance those interests against the rights and reasonable expectations of affected individuals.
4. Public DPP information
Content deliberately published to a public DPP page can be accessed, copied, indexed, cached, or shared by others. Customers must avoid publishing personal data or confidential information unless publication is lawful and necessary. Removing content from our Service may not remove copies previously cached or retained by independent third parties.
5. How we share data
We do not sell personal data. We may disclose data to:
- authorized personnel and contractors who need it to operate or support the Service;
- identity and access-management providers, including Clerk where used;
- hosting, database, cloud storage, content-delivery, security, monitoring, email, and support providers;
- Paddle for payment, tax, invoice, fraud-prevention, subscription, and refund administration;
- professional advisers, auditors, insurers, financing or transaction counterparties under appropriate confidentiality duties;
- courts, regulators, law enforcement, or other parties where required by law or necessary to protect legal rights and safety;
- the public, only for content a Customer instructs us to publish.
Service providers may process data only for contracted purposes and under appropriate data-protection terms. Information about material subprocessors may be requested at [email protected].
6. International transfers
Our providers and Customers may operate in different countries. Where personal data is transferred internationally, we use safeguards required by applicable law, which may include adequacy decisions, standard contractual clauses, contractual and technical protections, or another lawful transfer mechanism. No transfer mechanism eliminates all risks associated with foreign laws or government access.
7. Retention
We retain personal data only for as long as reasonably necessary for the purposes described above, including providing the Service, maintaining security and audit records, resolving disputes, and complying with tax, accounting, and legal obligations. Retention depends on the type of record, account status, contractual commitments, and applicable law.
- Account and workspace data is generally retained while the account is active and for a limited period afterward to support recovery, disputes, or legal obligations.
- Support, security, and audit records may be retained for a reasonable period after the related event.
- Paddle retains transaction and payment data under its own policy and legal obligations.
- Public DPP records may require a different retention approach from ordinary account data. Customers should contact us before account closure where continuing public availability is required.
We may anonymize data so it can no longer be associated with an identifiable person and use that anonymized data for analytics, security, and service improvement.
8. Security and data incidents
We use reasonable technical and organizational measures appropriate to the nature and risk of the data, such as access controls, encrypted transport, tenant separation, logging, and restricted administrative access. No system is completely secure, and we cannot promise that loss, unauthorized access, or interruption will never occur.
If we become aware of a personal-data breach, we will investigate, mitigate it, and notify affected Customers, individuals, or authorities where and when applicable law requires.
9. Your rights
Depending on applicable law, including the EU/EEA GDPR or Türkiye’s Personal Data Protection Law (KVKK), you may have rights to request access, correction, deletion, restriction, objection, portability, information about processing, or withdrawal of consent. Withdrawal does not affect processing already lawfully carried out.
Send requests to [email protected]. We may need to verify identity and authority. If your data was provided by a Customer organization, we may refer the request to that Customer as controller. You may also complain to the competent data-protection authority, including the Turkish Personal Data Protection Authority or the authority in your EU/EEA country.
10. Marketing choices
You may unsubscribe from marketing emails using the link in the message or by contacting us. We may still send non-marketing messages necessary for accounts, security, billing, legal notices, or support.
11. Cookies
We use strictly necessary technologies to provide and secure the website and application. Any optional analytics or marketing technologies will be used in accordance with applicable consent requirements. See our Cookie Policy.
12. Children
The Service is for businesses and professionals and is not directed to children. We do not knowingly create accounts for children.
13. Automated decision-making
We do not use personal data to make solely automated decisions that produce legal or similarly significant effects on individuals. Paddle and security providers may use automated systems for payment and fraud prevention under their own notices.
14. Changes to this Policy
We may update this Policy as the Service, providers, or legal requirements change. We will post the current version here and update the date above. We will provide additional notice where required for material changes.
15. Contact
Privacy questions and rights requests: [email protected].