Privacy Policy

    Last updated: July 26, 2026

    1. Introduction

    Axelance LTD ("we", "our", "us") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our Digital Product Passport marketplace platform.

    By using Digital-Product-Passport.PRO, you agree to the collection and use of information in accordance with this policy.

    2. Data Controller

    Company Name: Axelance LTD - TaxID 60057407Y

    Email: [email protected]

    Address: Alkaiou, 4. 3090, Limassol, Cyprus

    3. Data We Collect

    3.1 Account Information

    When you create an account, we collect:

    • Email address (required)
    • First name and last name (required)
    • Company name (required)
    • Job title or role (optional)
    • Phone number (optional)

    3.2 Profile Information

    For Solution Providers, we additionally collect:

    • Company website
    • Company description
    • Industries served
    • Geographic coverage
    • Solution types offered
    • Company logo (optional)
    • Marketing materials (for Premium members)

    3.3 Usage Data

    We automatically collect:

    • Pages viewed and features used
    • Time spent on pages
    • Search queries and filters applied
    • Assessment submissions, Demo requests, RFQ/RFI submissions and related interactions

    3.4 Technical Data

    • IP address
    • Browser type and version
    • Device type
    • Operating system

    3.5 Cookies

    See our Cookie Policy for details.

    5. How We Use Your Data

    • Service Delivery: To provide and maintain the DPP.PRO platform
    • Communication: To send service updates, RFQ notifications, and responses
    • Matching: To connect Solution Seekers with appropriate Solution Providers
    • Analytics: To understand usage patterns and improve our service
    • Marketing: To send promotional content (only with consent)
    • Security: To detect and prevent fraud, abuse, and security incidents

    6. Data Sharing and Disclosure

    6.1 With Solution Providers (incl. Premium solutions providers)

    When you submit Assessments, Demo requests or RFI/RFQ information as a Solution Seeker, we share your company information, business contact details and project details with Solution Providers in order to enable them to evaluate your needs and respond to your requests. Where you have given your consent during sign‑up, we may by default share your Assessments, Demo requests and RFI/RFQ information with Premium Solution Providers on the platform, so that they can contact you with proposals related to Digital Product Passport solutions and services. Premium Solution Providers act as independent controllers for the data they receive and are responsible for their own compliance with applicable data protection laws.

    6.2 Service Providers

    We share data with trusted service providers:

    • Supabase: Database and authentication (EU hosting)
    • Google Analytics: Usage analytics (only with cookie consent)
    • Stripe: Payment processing (for Premium subscriptions)

    6.3 Legal Requirements

    We may disclose your information if required by law, court order, or to protect our rights and the safety of our users.

    7. International Data Transfers

    Your data is primarily stored within the European Union (Supabase EU region). Some service providers may process data outside the EU, but we ensure adequate safeguards are in place (Standard Contractual Clauses, adequacy decisions).

    8. Data Retention

    • Active Accounts: We retain your data for the duration of your relationship with us
    • Deleted Accounts: 30 days retention period, then permanent deletion
    • Legal Obligations: Some data may be retained up to 7 years for accounting and legal purposes
    • Anonymized Data: May be retained indefinitely for analytics

    9. Your Rights Under GDPR

    You have the right to:

    Access

    Request a copy of your personal data

    Rectification

    Correct inaccurate or incomplete data

    Erasure

    Request deletion of your data ("right to be forgotten")

    Data Portability

    Receive your data in a structured, machine-readable format

    Object

    Object to processing based on legitimate interests

    Restrict Processing

    Request limitation of processing

    Withdraw Consent

    Withdraw consent for marketing communications at any time

    How to exercise your rights: Contact us at [email protected]

    We will respond to your request within 30 days. You also have the right to lodge a complaint with your local data protection authority.

    10. Security Measures

    We implement industry-standard security measures:

    • Encryption in transit (HTTPS/TLS)
    • Encryption at rest for database storage
    • Role-based access controls
    • Regular security audits and updates
    • Secure authentication (password hashing, OAuth)
    • Monitoring for suspicious activity

    However, no method of transmission over the internet is 100% secure. We cannot guarantee absolute security.

    11. Children's Privacy

    Our service is not directed to individuals under 18. We do not knowingly collect personal information from children. If you believe we have collected data from a child, please contact us immediately.

    12. Updates to This Policy

    We may update this Privacy Policy from time to time. Material changes will be communicated via:

    • Email notification to registered users
    • Prominent notice on our website
    • Update of the "Last updated" date

    Continued use of our service after changes constitutes acceptance of the updated policy.

    13. Contact Us

    For questions about this Privacy Policy or to exercise your rights:

    Email: [email protected]

    Response Time: Maximum 30 days

    Address: Katharinenstrasse 10, 81479 Munich