VeroPass/Legal/Privacy

Privacy Policy.

How VeroPass collects, uses and protects personal data - explained as legibly as possible, start to finish.

Last updated15 June 2026
Versionv1.0
ScopePlatform & website

01Introduction

VeroPass builds digital product passports - verifiable records that follow an object from manufacture to recycling. To do so, we mostly process product data, not personal data. Even so, some personal information is unavoidable: the email of those requesting access, the accounts of those using the platform, and technical data from those who visit our website.

This policy explains what personal data we process, why, for how long, and what control you have over it. It applies to the veropass.eu website and to the VeroPass platform. Processing of personal data on behalf of our customers - when we act as a processor - is described on the GDPR page.

02Data controller

The controller of the data described in this policy is VeroPass, Lda., headquartered in Lisbon, Portugal. For any question relating to privacy or data protection, you can contact our Data Protection Officer at privacy@veropass.eu.

03What data we collect

We collect only what is needed to run the service and respond to those who reach out. Personal data falls into three categories:

  • Contact and access-request data - name, work email, company and role, when you fill in the early-access form or write to us.
  • Account data - credentials, username, organizational role and activity logs, for those using the platform.
  • Technical data - truncated IP address, device and browser type, and pages visited, collected in aggregate for security and service improvement.

We do not collect special categories of data (health, beliefs, biometrics) and we do not buy contact lists from third parties.

04How we use the data

We process personal data only for concrete, legitimate purposes:

  • Respond to requests - manage the early-access list, schedule demos and answer messages.
  • Provide the service - authenticate users, maintain accounts and keep the platform running.
  • Security - detect and prevent abuse, fraud and incidents.
  • Improvement - understand, in aggregate, how the product is used to make it better.
  • Legal obligations - meet accounting, tax and regulatory duties.

We do not use your data for automated decisions with legal effects, nor for behavioural advertising.

05Legal bases

Each processing operation rests on a basis set out in the GDPR:

Performance of a contract
Providing the platform to those who subscribe to the service and managing their account.
Legitimate interest
Responding to commercial requests, ensuring security and improving the product, proportionately.
Consent
Marketing communications and non-essential cookies - always revocable.
Legal obligation
Retention of records required by law.

06Who we share with

VeroPass does not sell personal data. We share information only with providers that help us operate - always under a processing agreement and with adequate safeguards:

  • Cloud infrastructure - hosting in data centres within the European Union.
  • Communication and support - email and helpdesk tools.
  • Authorities - only when legally required and strictly to the extent necessary.

The up-to-date list of processors is available on the GDPR page.

07Cookies and measurement

Our website uses a minimal set of cookies. Essential cookies ensure operation and security and require no consent. Any aggregate measurement cookies are activated only after your consent and never track your behaviour across third-party sites.

Note

You can manage or withdraw consent at any time through your browser settings or the website preferences panel.

08Retention

We keep personal data only for as long as needed for the purpose that justifies it:

  • Access requests - up to 24 months after the last contact.
  • Account data - for the duration of the contract and up to 90 days after closure.
  • Legal records - for the periods required by applicable law.

Once the period ends, data is irreversibly deleted or anonymized.

09Your rights

Under the GDPR, you have the right to:

  • Access - know what data we process about you.
  • Rectification - correct inaccurate or incomplete data.
  • Erasure - request deletion of your data.
  • Restriction and objection - restrict or object to certain processing.
  • Portability - receive your data in a structured, machine-readable format.
  • Withdraw consent - at any time, without affecting the lawfulness of prior processing.

To exercise any right, write to privacy@veropass.eu. We respond within one month at most. You also have the right to lodge a complaint with the CNPD, the Portuguese supervisory authority.

10Security

We protect data with technical and organizational measures appropriate to the risk: encryption in transit and at rest, role-based access control, tamper-proof audit logs and regular security reviews. No system is infallible, but we treat security as a core part of the product - not an extra.

11International transfers

As a principle, data is processed and hosted in the European Union. Should, exceptionally, a processor entail a transfer outside the European Economic Area, we ensure adequate safeguards - the European Commission's standard contractual clauses or an adequacy decision.

12Changes to this policy

We may update this policy to reflect changes in the service or the law. The date of the last update is always at the top. Material changes will be communicated by email or via a notice on the platform before they take effect.

13Contact

For any question about this policy or about how your personal data is handled, talk to us. We answer for real.

V

Data Protection Officer

privacy@veropass.eu · VeroPass, Lda. · Lisbon, Portugal