# DPP GRID PRIVACY NOTICE

**Version 1.2 — 31 July 2026**

## 1. Who we are

DPP Grid is operated by **Fleeta Limited**, a company registered in England and Wales under company number **16675897**, with registered office at **50 Princes Street, Ipswich, England, IP1 1RJ** (**DPP Grid**, **we**, **us**, **our**).

This Notice explains how we use personal data when you:

- visit dppgrid.com or a public Digital Product Passport;
- create or use a DPP Grid account;
- act for a customer, supplier or other organisation;
- connect Shopify or another platform;
- sign a service, delegation or registration agreement;
- contact support, request a demonstration or receive updates; or
- interact with a Registry submission managed through DPP Grid.

For privacy requests, contact **support@dppgrid.com** with “Privacy” in the subject line.

## 2. When we are controller and when we are processor

### 2.1 We are a controller

We decide how and why personal data is used for our own account administration, contracts, billing, security, fraud prevention, service analytics, customer support, marketing choices, legal compliance and business operations. For those purposes, Fleeta Limited is the controller.

### 2.2 We are a processor for customer-controlled data

A customer may put personal data into product, supplier, evidence or lifecycle records and ask us to process it only for that customer's purposes. For that processing, the customer is normally the controller and we are its processor. Our Data Processing Addendum governs that relationship. Please contact the relevant customer first if your request concerns information that customer controls in its private workspace or public passport.

### 2.3 Other controllers

Shopify, payment providers, e-signature providers, identity providers, the European Commission and other connected services may act as independent controllers for their own processing. Their privacy notices also apply.

## 3. Personal data we collect

The data depends on how you use DPP Grid.

### 3.1 Account and identity data

- name, work email, telephone number and job role;
- password hash, authentication settings and session information;
- organisation, legal entity, trading name, company number, VAT or tax number, address and market information;
- user permissions, team membership and account status; and
- identity, authority and signatory evidence used for contracts or delegated services.

### 3.2 Contract, delegation and Registry data

- signed agreements, acceptance records, document version and hash;
- signatory name, title, email, authentication and completion certificate;
- responsible economic operator identity, role and Registry identifiers;
- verification, delegation and authorisation status;
- submission payload metadata, correlation identifiers, errors, status and Registration Proofs; and
- communications with the customer or Registry support about a submission.

### 3.3 Product, supplier and evidence data

- product identity, descriptions, SKUs, GTINs and other identifiers;
- files, certificates, declarations, images and supporting evidence;
- supplier and economic-operator contact details;
- source, provenance, review, approval and publication history;
- repair, ownership, warranty, resale and lifecycle events; and
- information imported from Shopify, spreadsheets, APIs, PIMs, ERPs, suppliers or public registries.

Product data is not always personal data. It becomes personal data where it identifies or relates to a person, such as a named supplier contact, sole trader, owner or repairer.

### 3.4 Billing and transaction data

- billing name, address, tax status, plan and subscription history;
- invoices, payment status, credits and transaction references; and
- limited payment metadata returned by our payment provider.

We do not receive or store full payment card numbers.

### 3.5 Usage, device and security data

- IP address, browser, device, operating system and user agent;
- pages and features used, timestamps and referral information;
- authentication, audit, API, webhook, integration and error logs;
- security events, rate-limit events and support diagnostics; and
- short-lived pseudonymous public-passport scan or interaction data where permitted by your privacy choice and browser settings.

### 3.6 Communications and marketing data

- support messages, emails, meeting notes and feedback;
- demo, contact and readiness-assessment submissions;
- newsletter or regulatory-update preferences;
- consent, unsubscribe and suppression records; and
- event attendance or campaign source where applicable.

### 3.7 Data we ask you not to provide

DPP Grid is a business product-data platform. Do not upload special-category personal data, criminal-offence data, personal consumer profiles, payment card numbers, passwords, private keys or other highly sensitive information unless a specific feature and written agreement require it.

### 3.8 Information required to provide the service

Information marked as required in an account, billing, support, integration, appointment or Registry workflow is needed to enter into or perform a contract, secure the service, comply with law or carry out the request you make. If it is not provided, we may be unable to create or protect the account, activate a connection, process payment, provide the requested feature or complete a Registry submission.

Optional profile fields, marketing choices, optional public analytics and activation of AI-assisted features are not required to create an ordinary DPP Grid account unless the relevant screen and customer agreement clearly state otherwise.

## 4. Where data comes from

We receive personal data:

- directly from you;
- from a workspace owner or administrator who invites you;
- from a customer, supplier, adviser or other organisation you represent;
- through Shopify or another connected service authorised by a customer;
- from documents, spreadsheets, APIs and product records;
- from public company, product or regulatory sources;
- from the EU DPP Registry or another authority in response to a submission; and
- automatically through service operation, security logs and permitted analytics.

Where we receive business contact data from another source, we use it only where we have a lawful basis and provide information required by law.

## 5. How we use personal data and our lawful bases

| Purpose | Examples | Main lawful basis |
|---|---|---|
| Create and operate accounts | authentication, workspace access, permissions, support | contract; legitimate interests |
| Provide DPP services | import, structure, host, publish, export and maintain product records | contract; legitimate interests; customer instructions as processor |
| Connect Shopify and other systems | OAuth, synchronisation, provenance, write-back | contract; legitimate interests; customer instructions |
| Execute agreements and delegation | identity, authority, e-signatures, audit evidence | contract; legitimate interests; legal obligation where applicable |
| Prepare and manage Registry submissions | operator identity, payloads, status, proof and errors | contract; legal obligation; legitimate interests; customer instructions |
| Process billing | subscriptions, invoices, payment status and tax records | contract; legal obligation |
| Secure the service | access logs, fraud detection, incident response, abuse prevention | legitimate interests; legal obligation |
| Improve DPP Grid | aggregate usage, reliability, feature performance and feedback | legitimate interests; consent where required for device storage or analytics |
| Communicate about the service | operational notices, support and security messages | contract; legitimate interests |
| Send marketing or regulatory updates | newsletters and optional campaigns | consent, or legitimate interests where business marketing law permits and an opt-out is provided |
| Establish and defend legal claims | contract records, audit trails and correspondence | legitimate interests; legal obligation |
| Comply with law and authorities | accounting, regulator, court and lawful disclosure requests | legal obligation; legitimate interests |

Where we rely on legitimate interests, we balance our interest against your rights. You may object in the circumstances described below.

Our legitimate interests are operating and securing a business product-data service, supporting users, maintaining reliable provenance and audit records, preventing fraud and misuse, improving service reliability, and establishing or defending legal claims. We assess whether each use is necessary and whether your interests, rights or freedoms override ours.

We do not use solely automated decision-making that produces legal or similarly significant effects about individuals. Readiness scores, AI suggestions and validation results support human decisions and are not decisions about a person's legal rights.

## 6. Shopify and connected platforms

When a customer connects Shopify or another system, we process only the scopes and records enabled by that customer and supported by the integration. Depending on configuration, this may include merchant and store identity, encrypted connection credentials, product and variant catalogue data, product images, app-owned passport metafields, publication and reconciliation state, and integration, synchronisation, webhook and audit metadata.

DPP Grid does not request Shopify customer or order access scopes. We write merchant-approved passport fields only to matching products. Publication access is used only when an authorised merchant explicitly confirms the typed safety-recall or unpublication action.

Shopify still sends the mandatory privacy-compliance webhooks for customer data requests, customer redaction and shop redaction. Those payloads may contain the identifiers needed to locate the request. We use them only to complete and evidence the required privacy action.

We use imported data to create and maintain customer-controlled product records. Import does not verify the accuracy or legal status of the data. Source and mapping records may be retained for provenance and troubleshooting.

We do not ask for a customer's Shopify password. Connections should use OAuth, an approved app installation or another supported delegated method. Tokens and secrets are restricted and protected in accordance with our security controls.

When an integration is disconnected, synchronisation stops. Data already imported remains until the customer deletes it, closes the account or gives another valid instruction, subject to legal retention.

## 7. Public Digital Product Passports

A public passport is designed to be accessible through a URL, QR code or similar carrier. Product information selected and approved for public publication can be viewed by anyone with access to the link.

Customers decide which customer-controlled fields become public, subject to law. Customers should not publish personal data unless they intend the information to be public and have a lawful basis.

A public passport may identify:

- the responsible economic operator;
- the brand, manufacturer, importer or other relevant organisation;
- a business compliance or safety contact where required;
- the passport host or service provider; and
- Registry status or proof where available.

DPP Grid may record short-lived pseudonymous scan or interaction events only where allowed by the visitor's preference and browser signal. We do not use public passport visits to build cross-site advertising profiles.

## 8. AI-assisted features

Where a customer activates an AI-assisted feature, we may send selected text, document extracts or structured fields to the configured AI provider to perform the requested task. We minimise the data sent and apply the customer's access and approval controls.

AI outputs are stored as suggestions with source, confidence or review information where supported. Customers decide whether to approve or publish them.

We do not use identifiable customer DPP data to train a general-purpose foundation model unless the customer expressly agrees in writing. AI assistance is available only where the workspace is entitled, the provider is configured and the applicable data-protection terms permit the requested processing. Provider information is published in our Subprocessor Notice.

## 9. Who receives personal data

We disclose personal data only where needed to operate DPP Grid, follow customer instructions or comply with law. Recipients may include:

- authorised DPP Grid personnel and contractors;
- cloud hosting, database, storage, monitoring and security providers;
- transactional email, customer support and communications providers;
- payment and billing providers;
- e-signature and identity-verification providers;
- Shopify and other customer-connected platforms;
- AI providers where an AI feature is activated;
- the European Commission's DPP Registry and relevant authorities when a registration service is activated;
- professional advisers, auditors and insurers under confidentiality; and
- courts, regulators, law enforcement or other authorities where required.

We do not sell personal data.

Our current provider list, purpose, location and transfer safeguard are published in our **Subprocessor and Third-Party Services Notice**. We update that list before a new material sub-processor begins processing customer personal data and provide the notice required by our Data Processing Addendum.

## 10. International transfers

Fleeta Limited is established in the United Kingdom. Some providers may process personal data outside the United Kingdom or European Economic Area.

Where a restricted transfer requires a safeguard, we use an applicable adequacy decision, the EU Standard Contractual Clauses, the UK International Data Transfer Agreement, the UK Addendum to the EU Standard Contractual Clauses or another legally recognised mechanism. We assess the transfer and use supplementary measures where appropriate.

A copy or summary of the relevant transfer mechanism is available on request, subject to confidentiality and security restrictions.

## 11. How long we keep data

We keep personal data only as long as reasonably needed for the purpose, legal obligations, security and claims. The following are target periods and may be shortened or extended where justified:

| Data | Typical retention |
|---|---|
| Account profile and workspace membership | while the account is active, then up to 30 days for recovery before deletion or anonymisation, subject to other rows |
| Contracts, Terms acceptances and delegation evidence | contract term plus 6 years, or longer where a live Product or legal claim requires it |
| Billing, invoice and tax records | as required by applicable accounting and tax law, generally up to 6 years |
| Private Customer Data | for the service term, then deleted or returned under the DPA and backup rotation unless law or an agreed continuity service requires longer |
| Published passport data | while the passport is active and for any required product-lifecycle or continuity period agreed with the customer |
| Registry submission history and proof | for the product and regulatory period required by law or contract, plus a reasonable claims period |
| Shopify and integration tokens | until disconnection, expiry or replacement, then promptly invalidated or deleted subject to secure backup rotation |
| Security and application logs | normally up to 12 months; longer only for an incident, fraud investigation or legal claim |
| Pseudonymous public scan events | up to 90 days, unless disabled or a shorter period is configured |
| Support correspondence | normally 3 years after the last substantive contact |
| Marketing records | until consent is withdrawn or objection is received; a minimal suppression record may be retained to respect the choice |
| Cookie consent evidence | normally up to 24 months from the last choice, unless a shorter period is configured |

We may anonymise information instead of deleting it. Data in backups may remain beyond the active deletion date until the next secure rotation and is kept beyond use in the meantime.

## 12. Security

We use technical and organisational measures designed around tenant and product-data boundaries, including server-side authorisation, restricted secrets, encryption in transit, encrypted sensitive fields where configured, private evidence storage, audit events, security headers, backup and recovery procedures and access reviews.

No service can guarantee absolute security. Customers also have responsibilities, including protecting credentials, managing permissions, reviewing connected applications and avoiding unnecessary personal data.

Please report a suspected vulnerability or incident to **support@dppgrid.com** with “Security report” in the subject line.

## 13. Your data-protection rights

Depending on the law and circumstances, you may have rights to:

- access your personal data;
- correct inaccurate or incomplete data;
- ask for erasure;
- restrict processing;
- object to processing based on legitimate interests or to direct marketing;
- receive portable data where the right applies;
- withdraw consent at any time; and
- complain to a supervisory authority.

To exercise a right, email **support@dppgrid.com** with “Privacy request” in the subject. We may verify your identity and authority before disclosing protected information.

Where DPP Grid processes data only for a customer, we may refer the request to that customer and assist it under our Data Processing Addendum.

You may complain to the **Information Commissioner's Office** in the United Kingdom. Individuals in the EEA may also contact their local supervisory authority.

## 14. Marketing choices

Marketing consent is separate from accepting the Terms. You can unsubscribe through the message link or contact us. We may still send non-marketing service, billing, security and legal notices required to operate your account.

We retain a minimal suppression record after an unsubscribe so that we do not contact you again by mistake.

## 15. Cookies and similar technologies

Strictly necessary technologies support authentication, security, fraud prevention and privacy choices. Optional analytics or similar technologies are disabled unless the required consent is given.

Our Cookie Notice and in-product preferences explain current names, providers, purposes and durations. The public privacy control presents separate choices to allow or disable optional analytics and lets you change that choice later. Browser Do Not Track is honoured for public interaction analytics.

## 16. Children

DPP Grid is a business service and is not directed at children. We do not knowingly create accounts for children. A public product passport should not include a child's personal data.

## 17. EEA representative

Where Article 27 of the EU GDPR requires Fleeta Limited to appoint a representative in the European Economic Area, the representative's identity and contact details will be published in this section and in the relevant customer documentation before the applicable processing begins.


## 18. Changes to this Notice

We may update this Notice to reflect legal, service or provider changes. We will update the version date and notify account holders of a material change where appropriate.

## 19. Contact details

Fleeta Limited trading as DPP Grid  
Company number: 16675897  
Registered office: 50 Princes Street, Ipswich, England, IP1 1RJ  
Email: **support@dppgrid.com** — subject “Privacy”
