Privacy Policy

Last updated: February 7, 2026

Summary: We collect only what we need to provide the service, we don't sell your data, and we protect it with industry-standard security.

1. Introduction

Certico ("we", "our", "us") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, and safeguard your information when you use our Digital Product Passport platform.

We comply with the General Data Protection Regulation (GDPR) and other applicable data protection laws.

2. Information We Collect

Account Information

Product Data

Usage Data

Supplier Portal Data

3. How We Use Your Information

PurposeLegal Basis
Provide and maintain the ServiceContract performance
Process paymentsContract performance
Send service-related communicationsLegitimate interest
Improve our ServiceLegitimate interest
Provide analytics and insightsContract performance
Ensure security and prevent fraudLegitimate interest
Comply with legal obligationsLegal obligation

4. Data Sharing

We do not sell your personal data. We may share data with:

Service Providers

Public Passport Data

When you create a Digital Product Passport, certain information is intentionally made public to consumers who scan the QR code. This includes product details, materials, and supply chain information you choose to include.

Legal Requirements

We may disclose data if required by law, court order, or government request.

5. Data Security

We implement industry-standard security measures:

While we strive to protect your data, no method of transmission over the Internet is 100% secure.

6. Data Retention

7. Your Rights (GDPR)

If you are in the EU/EEA, you have the right to:

To exercise these rights, contact us at hello@certico.io. We will respond within 30 days.

8. Cookies

We use cookies and similar technologies for:

You can control cookies through your browser settings. Disabling essential cookies may affect Service functionality.

9. International Transfers

Your data may be processed in countries outside your residence. We ensure appropriate safeguards are in place, including Standard Contractual Clauses for transfers outside the EU/EEA.

10. Children's Privacy

Our Service is not directed to individuals under 16. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, please contact us.

11. Changes to This Policy

We may update this Privacy Policy periodically. We will notify you of significant changes via email or through the Service. The "Last updated" date at the top indicates when the policy was last revised.

12. Contact Us

For privacy-related questions or to exercise your rights:

13. Data Controller

Certico is the data controller for personal data collected through the Service.

Questions about your data? Contact us at hello@certico.io — we're happy to help.