Skip to content

Privacy policy

This information describes which personal data are processed when you use the EU Product Identity platform (euproductidentity.eu).

The platform is under development and operated in Early Access. Its scope of functions continues to grow; this information will be updated accordingly.

As of: September 2026

Controller

The controller for the processing is Fa. Com2u, owner Patrick Hess, Frohschammerstr. 6 RGB, 80807 München.

The detailed provider identification can be found in the legal notice.

Scope of this privacy information

When you use the platform, the following categories of personal data are processed:

  • Registration and account data: name, e-mail address and company or organisation.
  • Content data processed for passports: product and passport details as well as documents and evidence uploaded for data capture.
  • Usage data arising while working with the application.
  • Technical access data: IP address, time of access and server log files.

Legal bases

The processing is based on Art. 6(1) GDPR:

  • point (b) — performance of a contract: operating the account, creating passports and billing.
  • point (f) — legitimate interest: technical log files, operational security and prevention of misuse.
  • point (a) — consent, where consent is obtained; it can be withdrawn at any time.

Purposes

The data are processed for the following purposes:

  • Account management
  • Product and passport management
  • Billing and invoicing
  • Operational security and prevention of misuse

Hosting & processing on behalf

The platform is operated by Com2u on its own infrastructure.

For AI-supported data capture from documents the following applies: the processing remains on the platform infrastructure, customer documents do not leave the host. The generated suggestions are only transferred into the passport after human approval.

Payment service provider: the use of Stripe for payment processing is planned; no payment processing is currently activated. As soon as payments are handled via Stripe, the processing agreement with Stripe will apply.

Retention periods

Personal data are stored for as long as is necessary for the respective purpose. In detail:

  • Billing data and invoices: generally 10 years due to statutory retention periods (§ 14b UStG, German VAT Act).
  • Account data: until the account is deleted or until use ends.
  • Session data in the browser: until you sign out.

Your rights

You have the following rights:

  • Access (Art. 15 GDPR)
  • Rectification (Art. 16 GDPR)
  • Erasure (Art. 17 GDPR)
  • Restriction of processing (Art. 18 GDPR)
  • Data portability (Art. 20 GDPR)
  • Objection (Art. 21 GDPR)
  • Withdrawal of consent given (Art. 7(3) GDPR)
  • Complaint to a data protection supervisory authority — for the registered office in particular the Bavarian Data Protection Authority (BayLDA).

Cookies and technically necessary storage

No cookies are used for advertising or analytics. Technically necessary is the storage of the session token and the selected organisation in your browser’s local storage (localStorage).

No advertising or analytics trackers and no third-party scripts are used.

Contact for data protection enquiries

Please address data protection enquiries and the exercise of the rights listed above to the contact point stated in the legal notice: Fa. Com2u, owner Patrick Hess, Frohschammerstr. 6 RGB, 80807 München.

Please refer to the legal notice for the specific contact option.