Privacy Policy
Last updated: July 26, 2026
1. Introduction
Axelance LTD ("we", "our", "us") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our Digital Product Passport marketplace platform.
By using Digital-Product-Passport.PRO, you agree to the collection and use of information in accordance with this policy.
2. Data Controller
Company Name: Axelance LTD - TaxID 60057407Y
Email: [email protected]
Address: Alkaiou, 4. 3090, Limassol, Cyprus
3. Data We Collect
3.1 Account Information
When you create an account, we collect:
- Email address (required)
- First name and last name (required)
- Company name (required)
- Job title or role (optional)
- Phone number (optional)
3.2 Profile Information
For Solution Providers, we additionally collect:
- Company website
- Company description
- Industries served
- Geographic coverage
- Solution types offered
- Company logo (optional)
- Marketing materials (for Premium members)
3.3 Usage Data
We automatically collect:
- Pages viewed and features used
- Time spent on pages
- Search queries and filters applied
- Assessment submissions, Demo requests, RFQ/RFI submissions and related interactions
3.4 Technical Data
- IP address
- Browser type and version
- Device type
- Operating system
3.5 Cookies
See our Cookie Policy for details.
4. Legal Basis for Processing (GDPR)
Contract Performance
We process your data to provide our services, including account creation, facilitating connections between seekers and providers, and delivering notifications.
Consent
We process marketing communications and non-essential cookies based on your explicit consent, which you can withdraw at any time.
Legitimate Interest
We use data for analytics, fraud prevention, and service improvement based on our legitimate business interests, balanced with your privacy rights.
5. How We Use Your Data
- Service Delivery: To provide and maintain the DPP.PRO platform
- Communication: To send service updates, RFQ notifications, and responses
- Matching: To connect Solution Seekers with appropriate Solution Providers
- Analytics: To understand usage patterns and improve our service
- Marketing: To send promotional content (only with consent)
- Security: To detect and prevent fraud, abuse, and security incidents
6. Data Sharing and Disclosure
6.1 With Solution Providers (incl. Premium solutions providers)
When you submit Assessments, Demo requests or RFI/RFQ information as a Solution Seeker, we share your company information, business contact details and project details with Solution Providers in order to enable them to evaluate your needs and respond to your requests. Where you have given your consent during sign‑up, we may by default share your Assessments, Demo requests and RFI/RFQ information with Premium Solution Providers on the platform, so that they can contact you with proposals related to Digital Product Passport solutions and services. Premium Solution Providers act as independent controllers for the data they receive and are responsible for their own compliance with applicable data protection laws.
6.2 Service Providers
We share data with trusted service providers:
- Supabase: Database and authentication (EU hosting)
- Google Analytics: Usage analytics (only with cookie consent)
- Stripe: Payment processing (for Premium subscriptions)
6.3 Legal Requirements
We may disclose your information if required by law, court order, or to protect our rights and the safety of our users.
7. International Data Transfers
Your data is primarily stored within the European Union (Supabase EU region). Some service providers may process data outside the EU, but we ensure adequate safeguards are in place (Standard Contractual Clauses, adequacy decisions).
8. Data Retention
- Active Accounts: We retain your data for the duration of your relationship with us
- Deleted Accounts: 30 days retention period, then permanent deletion
- Legal Obligations: Some data may be retained up to 7 years for accounting and legal purposes
- Anonymized Data: May be retained indefinitely for analytics
9. Your Rights Under GDPR
You have the right to:
Access
Request a copy of your personal data
Rectification
Correct inaccurate or incomplete data
Erasure
Request deletion of your data ("right to be forgotten")
Data Portability
Receive your data in a structured, machine-readable format
Object
Object to processing based on legitimate interests
Restrict Processing
Request limitation of processing
Withdraw Consent
Withdraw consent for marketing communications at any time
How to exercise your rights: Contact us at [email protected]
We will respond to your request within 30 days. You also have the right to lodge a complaint with your local data protection authority.
10. Security Measures
We implement industry-standard security measures:
- Encryption in transit (HTTPS/TLS)
- Encryption at rest for database storage
- Role-based access controls
- Regular security audits and updates
- Secure authentication (password hashing, OAuth)
- Monitoring for suspicious activity
However, no method of transmission over the internet is 100% secure. We cannot guarantee absolute security.
11. Children's Privacy
Our service is not directed to individuals under 18. We do not knowingly collect personal information from children. If you believe we have collected data from a child, please contact us immediately.
12. Updates to This Policy
We may update this Privacy Policy from time to time. Material changes will be communicated via:
- Email notification to registered users
- Prominent notice on our website
- Update of the "Last updated" date
Continued use of our service after changes constitutes acceptance of the updated policy.
13. Contact Us
For questions about this Privacy Policy or to exercise your rights:
Email: [email protected]
Response Time: Maximum 30 days
Address: Katharinenstrasse 10, 81479 Munich