Privacy policy
This information describes which personal data are processed when you use the EU Product Identity platform (euproductidentity.eu).
The platform is under development and operated in Early Access. Its scope of functions continues to grow; this information will be updated accordingly.
As of: September 2026
Controller
The controller for the processing is Fa. Com2u, owner Patrick Hess, Frohschammerstr. 6 RGB, 80807 München.
The detailed provider identification can be found in the legal notice.
Scope of this privacy information
When you use the platform, the following categories of personal data are processed:
- Registration and account data: name, e-mail address and company or organisation.
- Content data processed for passports: product and passport details as well as documents and evidence uploaded for data capture.
- Usage data arising while working with the application.
- Technical access data: IP address, time of access and server log files.
Legal bases
The processing is based on Art. 6(1) GDPR:
- point (b) — performance of a contract: operating the account, creating passports and billing.
- point (f) — legitimate interest: technical log files, operational security and prevention of misuse.
- point (a) — consent, where consent is obtained; it can be withdrawn at any time.
Purposes
The data are processed for the following purposes:
- Account management
- Product and passport management
- Billing and invoicing
- Operational security and prevention of misuse
Hosting & processing on behalf
The platform is operated by Com2u on its own infrastructure.
For AI-supported data capture from documents the following applies: the processing remains on the platform infrastructure, customer documents do not leave the host. The generated suggestions are only transferred into the passport after human approval.
Payment service provider: the use of Stripe for payment processing is planned; no payment processing is currently activated. As soon as payments are handled via Stripe, the processing agreement with Stripe will apply.
Retention periods
Personal data are stored for as long as is necessary for the respective purpose. In detail:
- Billing data and invoices: generally 10 years due to statutory retention periods (§ 14b UStG, German VAT Act).
- Account data: until the account is deleted or until use ends.
- Session data in the browser: until you sign out.
Your rights
You have the following rights:
- Access (Art. 15 GDPR)
- Rectification (Art. 16 GDPR)
- Erasure (Art. 17 GDPR)
- Restriction of processing (Art. 18 GDPR)
- Data portability (Art. 20 GDPR)
- Objection (Art. 21 GDPR)
- Withdrawal of consent given (Art. 7(3) GDPR)
- Complaint to a data protection supervisory authority — for the registered office in particular the Bavarian Data Protection Authority (BayLDA).
Cookies and technically necessary storage
No cookies are used for advertising or analytics. Technically necessary is the storage of the session token and the selected organisation in your browser’s local storage (localStorage).
No advertising or analytics trackers and no third-party scripts are used.
Contact for data protection enquiries
Please address data protection enquiries and the exercise of the rights listed above to the contact point stated in the legal notice: Fa. Com2u, owner Patrick Hess, Frohschammerstr. 6 RGB, 80807 München.
Please refer to the legal notice for the specific contact option.