Skip to content
OpenDPP
Why ESPR How it works Standards Solutions Pricing FAQ Demo
Client Console Book a demo
Why ESPR How it works Standards Solutions Pricing FAQ Demo Client Console Book a demo
Terms of ServicePrivacy PolicyAPI TermsSupport PolicyData Processing AddendumSub-processor RegisterLegal Notice (Imprint)

OpenDPP — Data Processing Addendum (DPA)

Last updated: 2026-07-21 · Version: 1.0

This Data Processing Addendum ("DPA") is incorporated into the OpenDPP Terms of Service (the "Terms", and together with the Order and Policies, the "Agreement") between Opendpp UAB ("Opendpp", the "Processor") and the Customer (the "Controller"). It applies where Opendpp processes personal data on the Customer's behalf in providing the Service. For its subject matter, this DPA prevails over the rest of the Agreement (Terms §1). Capitalised terms not defined here have the meaning given in the Terms; "GDPR" means Regulation (EU) 2016/679, and "personal data", "processing", "data subject", "personal data breach" etc. have the meanings given there.

1. Roles and scope

1.1 Processor scope ("Customer Personal Data"). Opendpp processes, as processor on the Customer's documented instructions, the personal data contained in Customer Content — in practice, the limited business contact details permitted by Terms §9.4 (Annex 1 describes the processing).

1.2 Controller scope (excluded). Opendpp acts as an independent controller — and this DPA does not apply — for Account Data: workspace user accounts and authentication, security and audit records, billing and tax records, support correspondence, and website/lead data. That processing is described in the Privacy Policy.

1.3 The Customer warrants that it has a lawful basis for the Customer Personal Data it submits, that its instructions are lawful, and that it will not submit personal data beyond what Terms §9.4 permits (no special categories of data, no data relating to criminal convictions, no children's data).

2. Instructions

2.1 Opendpp will process Customer Personal Data only on the Customer's documented instructions, including with regard to transfers, unless required to do otherwise by Union or Member State law — in which case Opendpp will inform the Customer of that legal requirement before processing, unless the law prohibits it on important grounds of public interest.

2.2 The documented instructions are: (a) this DPA and the Agreement; (b) the Customer's configuration and use of the Service (including workspace settings, API calls and the Documentation's described behaviour); (c) the publication instruction in Terms §9.3 (making published passports and their projections available to any person); (d) the regulatory-persistence instruction in Terms §9.5 (retaining and resolving published passports for the applicable retention period, 15 years by default, including after termination); and (e) reasonable further written instructions consistent with the Agreement (Opendpp may charge for instructions exceeding the Service's standard functionality).

2.3 Opendpp will inform the Customer if, in its opinion, an instruction infringes the GDPR or other Union or Member State data protection provisions; it may suspend the instruction until confirmed or withdrawn.

3. Confidentiality

Opendpp ensures that persons authorised to process Customer Personal Data are bound by contractual or statutory confidentiality obligations.

4. Security

Opendpp implements and maintains the technical and organisational measures described in Annex 2, which the parties agree provide a level of security appropriate to the risk of the processing described in Annex 1 (Art. 32 GDPR). Opendpp may update the measures from time to time, provided the overall level of security is not materially reduced during a subscription term.

5. Sub-processors

5.1 The Customer grants a general authorisation to engage sub-processors. The current list is the Sub-processor Register, which the Customer accepts as at the DPA's effective date.

5.2 Opendpp will update the Register and give notice (email or in-product) at least fourteen (14) days before a new sub-processor processes Customer Personal Data. The Customer may object on reasonable data-protection grounds within fourteen (14) days of the notice; the parties will discuss in good faith, and if no resolution is found the Customer may, as its sole and exclusive remedy, terminate the affected subscription with effect before the change applies — in which case Opendpp will refund prepaid fees for the period after termination and no early-termination charge (Terms §6.4) arises.

5.3 Opendpp imposes data-protection obligations on sub-processors materially equivalent to this DPA and remains liable to the Customer for their performance.

6. Assistance

6.1 Data subject requests. Opendpp will, taking into account the nature of the processing, assist the Customer by appropriate technical and organisational measures in fulfilling data-subject-rights requests. In the first instance this assistance consists of the Service's self-service tools: the full-workspace machine-readable export, per-passport read/update/unpublish/deletion functions per the Documentation, and each user's self-export. If Opendpp receives a request directly, it will (to the extent lawful) redirect the data subject to the Customer and not respond substantively itself.

6.2 Articles 32–36. Opendpp will assist the Customer, taking into account the nature of the processing and the information available to it, with security, breach notification, data protection impact assessments and prior consultation. Assistance beyond the self-service tools and published materials is provided at reasonable, documented cost.

7. Personal data breach

Opendpp will notify the Customer without undue delay after becoming aware of a personal data breach affecting Customer Personal Data, and will provide the information reasonably required for the Customer's obligations under Articles 33–34 GDPR as it becomes available. Notification is not an acknowledgement of fault or liability. The Customer is responsible for notifying its supervisory authority and data subjects.

8. Audits

8.1 Opendpp makes available the information reasonably necessary to demonstrate compliance with Article 28 GDPR: this DPA, the Sub-processor Register, the published security documentation, and written responses to reasonable security questionnaires (at most once per 12 months).

8.2 Where that information is insufficient to satisfy a genuine legal requirement, the Customer (or an independent auditor bound to confidentiality, not a competitor) may conduct an audit, subject to: at least thirty (30) days' written notice; at most once per 12 months (except after a personal data breach affecting the Customer, or where required by a supervisory authority); business hours; no access to other customers' data or systems; compliance with Opendpp's security policies; and the Customer bearing its own costs and Opendpp's reasonable cooperation costs. Audit results are Confidential Information.

9. Transfers

Customer Personal Data is hosted in the European Union. Opendpp will not transfer it outside the EEA except via sub-processors listed in the Register, in each case with a valid Chapter V transfer mechanism (adequacy decision — including the EU–U.S. Data Privacy Framework where certified — or Standard Contractual Clauses with supplementary measures as appropriate). The Customer authorises such transfers on these conditions.

10. Return and deletion

10.1 During the subscription and the post-termination retrieval window (Terms §10.4 — at least thirty (30) days), the Customer can retrieve Customer Personal Data via the self-service exports in structured, commonly used, machine-readable formats.

10.2 After the retrieval window, Opendpp will delete Customer Personal Data within ninety (90) days, except: (a) published passports retained under the regulatory-persistence instruction (Terms §9.5) for as long as that instruction stands; (b) data Opendpp must retain under Union or Member State law (retained only as long and for the purpose required, protected per Annex 2); and (c) copies in encrypted backups, which are erased in the ordinary rotation of those backups. On written request, Opendpp will confirm deletion.

11. Continuity

If Opendpp permanently discontinues the Service or enters insolvency or winding-up, it will use reasonable efforts to (a) keep the export interfaces available for the retrieval window, and (b) support migration of published passports (including their identifiers and resolvable links) to the Customer or a successor service, so that regulatory persistence can be maintained by another party. A binding escrow or successor arrangement, if and when established, will be announced on the Security page and incorporated here.

12. Liability, term, miscellany

12.1 The parties' aggregate liability under or in connection with this DPA is subject to the limitations and exclusions in Terms §13 (a single combined cap with the Agreement — not an additional one), except to the extent liability cannot lawfully be limited (including a party's liability to data subjects under Article 82 GDPR).

12.2 This DPA takes effect on acceptance of the Terms and lasts as long as Opendpp processes Customer Personal Data — including, for the limited scope of §10.2(a), the post-termination regulatory persistence of published passports, to which §§2–9 continue to apply.

12.3 This DPA is governed by the law and jurisdiction of Terms §20.


Annex 1 — Description of the processing (Art. 28(3) / 30(2) GDPR)

  • Subject matter: hosting and operation of the OpenDPP Digital Product Passport SaaS for the Customer.
  • Duration: the subscription term, the retrieval window, plus the regulatory persistence of published passports (Terms §9.5; 15 years by default) and legally required retention.
  • Nature of processing: collection (via API/portal/CSV ingest), storage, structuring, adaptation into interoperability projections (e.g. AAS, UNTP, JSON-LD, GS1 Digital Link), publication at the Customer's instruction, transmission (including signed webhooks to endpoints the Customer configures), retrieval/export, restriction, erasure.
  • Purposes: providing, securing and supporting the Service; publication and regulatory persistence of passports as instructed.
  • Categories of data subjects: the Customer's personnel and representatives, and business contacts of the Customer's economic operators, suppliers and facilities, to the extent they appear in Customer Content.
  • Categories of personal data: business contact details (name, business email, business phone, role/function), business identifiers that may relate to an individual (e.g. an EORI of a sole trader), and any other personal data the Customer includes contrary to or within Terms §9.4.
  • Special categories: none — contractually prohibited (Terms §9.4; §1.3).

Annex 2 — Technical and organisational measures (Art. 32 GDPR)

  • Encryption in transit: TLS for all interfaces; HSTS on public web surfaces.
  • Encryption at rest: managed-platform disk encryption for the database; additionally, envelope encryption (AES-256-GCM with per-tenant HKDF-derived keys, tenant-bound authenticated data) for signing keys, SSO secrets and stored connection secrets; central secret management with rotation procedures (documented rotation for the master encryption secret).
  • Access control: role- and permission-based access control per workspace (PBAC); scoped API keys; platform-admin actions gated by a separate RBAC layer; support access (impersonation) is time-boxed and logged; multi-factor authentication supported and enforceable per workspace.
  • Tenant isolation: per-tenant data scoping enforced in the application layer on every request; cross-tenant access re-checked at mutation time (fail-closed).
  • Integrity and accountability: append-only administrative audit trails; cryptographic sealing of passports (eIDAS advanced electronic seal over a Merkle root) with a public verification endpoint; webhook payloads HMAC-signed.
  • Network/application hardening: per-request nonce-based Content-Security-Policy; CSRF double-submit protection; strict SSRF egress guard for all outbound fetches (no redirects, pinned addresses, timeouts, size caps); global and per-endpoint rate limiting; input validation on all ingest surfaces.
  • Data minimisation: IP addresses in public-interface logs are anonymised (IPv4 /24, IPv6 /48); public error-reporting sink engineered to carry no personal data; log-retention windows for scan logs (180 days) and audit trails (400/730 days).
  • Hosting: EU region (Google Cloud, europe-west1); managed PostgreSQL platform with provider-managed backups; keyless (workload-identity) deployments; secrets held in a cloud secret manager, never in images or the repository.
  • Availability and recovery: managed-platform backups and restore; single-EU-region posture stated transparently (no multi-region failover claimed); regular automated dependency and vulnerability scanning; documented deploy pipeline with review gates.
  • Personnel and process: confidentiality obligations for authorised persons; least-privilege operational access; security documentation published on the Security page and kept current.

Annex 3 — Authorised sub-processors

The authorised sub-processors are those listed in the Sub-processor Register, as updated per §5.


Opendpp UAB · Švitrigailos g. 11K-109, LT-03223 Vilnius, Lithuania · Company code 308017314 · info@opendpp-node.eu

OpenDPP

The no-code platform for EU Digital Product Passports. Issue, seal, and publish — ready before the first deadlines.

Product

How it works Solutions Pricing Interactive demo Client Console

Company

About Why ESPR Security & Trust Seal Audit Portal

Resources

ESPR timeline DPP standards (EN 182xx) EU DPP Registry Battery Passport guide API reference AI knowledge bundle (OKF) Open source

Legal

Contact Support Privacy Policy Terms of Service Cookie Policy Legal Notice
© 2026 OpenDPP UAB · ESPR 2024/1781 · EU-hosted & eIDAS-signed