Privacy Policy
This Privacy Policy outlines how we process personal data collected via OriginPass forms, account registration and application use (in compliance with GDPR).
The English version of this Privacy Policy is the authoritative version. Translations are provided for convenience.
1. Data Controller and Privacy Contact
The data controller for personal data processed in connection with the OriginPass website, its forms, user accounts and application is Dominik Dudziński, an individual operating the service from Poland. This initiative is part of the technology ecosystem supported by the InfoDPP.eu knowledge hub — an independent resource for EU DPP regulations. For any privacy-related inquiries, you can contact us at: contact@originpass.eu.
2. Data collected, purpose, and legal basis
Through the form, we collect: email address, company name, industry, expected DPP rollout scale, and submission timestamp. We use this data to process inquiries, qualify pilot candidates, and facilitate business-related communication. The legal basis is taking steps prior to entering into a contract (GDPR Art. 6(1)(b)) and our legitimate interest in handling inquiries effectively (GDPR Art. 6(1)(f)).
2a. Account and login data
When you register an account, we process first name, last name, email address, preferred language, Supabase session data and records of Terms acceptance and Privacy Policy acknowledgement. This data is used to create the account, authenticate users, protect the service and manage access to companies and brands. The legal basis for processing account data is the performance of our agreement with you and taking steps at your request to provide the service (GDPR Art. 6(1)(b)). Authentication uses strictly necessary session cookies set by Supabase; they are required for the service to function and are not used for advertising or tracking.
2b. Data entered by customers in the application
Product data entered into the application by customers is generally not personal data. If a customer does enter personal data (for example the contact details of a person named as an economic operator), we process it solely on the customer's instructions and on their behalf, acting as a processor. The customer is responsible for the legal basis and scope of such data; we conclude a data processing agreement on request. In the test environment (Sandbox plan) we recommend that no personal or confidential data be entered.
3. Data recipients and hosting (EU strictly)
To operate the website and the application we use Netlify (hosting), Supabase (database and authentication), Resend (email delivery), and Umami (traffic analytics and basic form-interaction analytics such as field focus, select open, and option selection). We do not send the full message body or the full email address to the analytics tool. Our database (Supabase), which holds form submissions, user accounts and data entered in the application, is hosted in the EU (Ireland). Files uploaded to the application (images and documents) are stored in Cloudflare R2 in the EU jurisdiction, and public passport addresses are served through the Cloudflare network, which processes technical request data (including IP address) in order to deliver content, protect against abuse and apply rate limiting. Some processors (such as hosting and email delivery) are companies that may process limited data outside the EEA; where this happens we rely on appropriate safeguards such as the EU Standard Contractual Clauses. Access to the data is limited, and our administrative accounts in providers' consoles are protected with strong passwords and, where the provider offers it, two-factor authentication. Signing in to OriginPass itself currently uses a password; two-factor authentication for user accounts is not available yet.
4. Data retention period
We retain lead form data for up to 12 months from the last contact, unless we receive a valid erasure request earlier or applicable law requires a longer retention period. Account data is retained for as long as the account exists and for up to 30 days afterwards in backups. During closed testing, data entered in the test environment may be deleted where technically necessary; we do not guarantee its persistent storage.
5. Your rights
Under the GDPR, you have the right to request access, rectification, erasure, and restriction of processing regarding your personal data. You also have the right to data portability and the right to object to processing. Requests related to deletion or the exercise of your rights can be sent to: contact@originpass.eu. Furthermore, you can lodge a complaint with the appropriate Data Protection Authority.