AuraDPP

GDPR Compliance

How AuraDPP protects your data and complies with EU Regulation 2016/679

Our Commitment to GDPR

The General Data Protection Regulation (GDPR, EU 2016/679) is the world's most comprehensive data protection law. AuraDPP was built from the ground up with GDPR compliance as a core requirement – not an afterthought. As a platform that serves EU merchants and processes data of EU consumers, we take this responsibility seriously.

Data Processing Principles

Lawfulness & Transparency
We process data only with a valid legal basis and inform users clearly about what data we collect and why.
Purpose Limitation
Data collected for one purpose is not used for another. QR scan analytics are used only to provide merchant insights.
Data Minimization
We collect only the data necessary for the service. QR scan tracking is anonymized – we do not track individual consumers.
Storage Limitation
Data is deleted when no longer needed. Account data is purged within 30 days of deletion.
Integrity & Confidentiality
All data is encrypted in transit (TLS 1.3) and at rest (AES-256). Access is restricted by role-based controls.
EU Data Residency
All data is stored in EU data centers (Google Cloud, Belgium/Frankfurt). No data leaves the EU/EEA.

Sub-processors

We use the following sub-processors to deliver our service:

Sub-processorPurposeLocationSafeguard
Google Cloud PlatformHosting, database, storageEU (Belgium, Frankfurt)ISO 27001, SCCs, GDPR DPA
StripePayment processingEU + USAEU-US DPF, SCCs, PCI DSS
Manus AuthOAuth authenticationEUGDPR DPA

Consumer QR Scan Privacy

When a consumer scans a QR code on a Digital Product Passport, AuraDPP records the following anonymized data: timestamp, device type (mobile/desktop), browser family, and approximate country (derived from IP, then discarded). We do not store IP addresses, do not track individual consumers across scans, and do not build consumer profiles. No cookies are set on the consumer-facing DPP page.

Data Subject Rights

As a merchant using AuraDPP, you can exercise your GDPR rights at any time by contacting[email protected]. We respond within 30 days. You can also delete your account and all associated data directly from your account settings.

Data Processing Agreement (DPA)

If you use AuraDPP as a data processor on behalf of your customers (e.g., you are an agency creating DPPs for clients), you may request a Data Processing Agreement (DPA) from us. Contact[email protected].