DPP Grid legal information
DPP Grid Service Terms
Operational draft: Service terms for DPP Grid workspaces and the service boundaries they establish. Professional legal and production-fact review remains pending.
DPP GRID SERVICE TERMS
Version 1.2 — 31 July 2026
1. About these Terms
These Service Terms (Terms) govern access to and use of DPP Grid, a digital product passport platform operated by Fleeta Limited, company number 16675897, registered office at 50 Princes Street, Ipswich, England, IP1 1RJ, trading as DPP Grid (DPP Grid, we, us, our).
These Terms apply to businesses and professional users. They do not appoint DPP Grid to act as your EU Registry registration agent. Registry submission services require a separate Digital Product Passport Services and Registration Agency Agreement or equivalent written activation.
By creating an account, accepting an Order Form or using the Services, you agree to these Terms for the organisation identified in your workspace (Customer, you, your). The person accepting represents that they have authority to bind that organisation.
2. Contract documents and priority
Your agreement with us may include:
- a signed Order Form or statement of work;
- a Digital Product Passport Services and Registration Agency Agreement, where Registry or agency services are activated;
- our Data Processing Addendum;
- these Terms;
- the plan description and documentation; and
- policies expressly incorporated by reference.
If documents conflict, the higher document in that list prevails only for the subject it addresses. The Data Processing Addendum prevails for our obligations as a processor of personal data.
3. The Services
DPP Grid may provide tools for:
- product, variant, batch and item records;
- Shopify, spreadsheet, API, supplier and document imports;
- source-linked evidence and data provenance;
- AI-assisted extraction, mapping and translation;
- review, approval and immutable publication versions;
- public and restricted Digital Product Passports;
- persistent URLs, resolvers, QR codes and other data carriers;
- product lifecycle, repair, ownership and resale events;
- exports, APIs, webhooks and integrations;
- readiness checks and structured data validation;
- DPP hosting, backup and continuity services; and
- EU DPP Registry preparation and submission where separately activated.
Features, limits and availability depend on your plan, workspace settings, product group, market and the maturity of applicable legal and technical standards.
4. Accounts and organisation workspaces
4.1 Accurate information
You must provide accurate account and organisation information and keep it current. A trading name does not replace the correct legal entity information required for contracts or regulatory records.
4.2 Authorised users
You are responsible for users invited to your workspace, their permissions and their use of the Services. You must remove access promptly when no longer required.
4.3 Credentials and security
Users must keep credentials confidential, use strong passwords and enable available multi-factor authentication for privileged access. You must notify us promptly at support@dppgrid.com if you suspect compromise.
4.4 Organisational authority
Workspace owners and administrators may give instructions, approve publication, connect systems, incur Fees and manage users. You must ensure those individuals have appropriate authority.
5. Trials, plans, billing and cancellation
5.1 Trials
A trial begins only at the point displayed during signup or checkout. Trial limits and end dates appear in your account. Unless cancelled before renewal, a selected paid plan may start automatically at the end of the trial as clearly shown before confirmation.
5.2 Fees
You must pay the Fees and taxes shown at checkout, in an Order Form or on an invoice. Prices exclude VAT unless stated otherwise.
5.3 Renewals
Subscriptions renew for the selected billing interval unless cancelled before the renewal date. We will make the renewal basis and price visible before purchase and in your account.
5.4 Cancellation
You may cancel a self-service plan through the account controls. Cancellation normally takes effect at the end of the current paid period unless the interface states otherwise. Fees already paid are non-refundable except where these Terms, an Order Form or law provides otherwise.
5.5 Usage allowances
Plans may limit product models, identifiers, users, storage, translations, API calls, AI usage, integrations or other resources. We may block, queue or charge for excess usage in accordance with the displayed plan or an Order Form.
5.6 Payment providers
Payment card information is collected by our payment provider. We do not receive or store full card numbers. Your use of the payment service may also be subject to that provider's terms.
6. Customer Data and product information
6.1 Your rights
You retain your rights in data, files, evidence and content supplied by or for you (Customer Data).
6.2 Licence to provide the Services
You grant us a worldwide, non-exclusive, royalty-free licence during the contract to host, copy, format, map, translate, transmit, publish and otherwise process Customer Data as needed to provide the Services, follow your documented instructions and meet our disclosed legal obligations.
6.3 Your responsibility
You remain responsible for:
- the accuracy, completeness, legality and currency of Customer Data;
- product safety, conformity and legal market access;
- selecting the correct economic operator and product granularity;
- ensuring claims are supported by appropriate evidence;
- approving data before publication or regulatory submission; and
- keeping passports updated throughout the required lifecycle.
6.4 Public information
When you publish a passport, the information you approve for public access becomes available through its URL, QR code or other carrier. Do not put personal data, trade secrets or confidential supplier information in public fields unless the disclosure is lawful and intended.
6.5 Rights in imported material
You confirm that you have the rights and authority needed to import, copy, process and publish Customer Data, including material obtained from Shopify, marketplaces, suppliers, PIMs, ERPs, documents or other systems.
7. Shopify and other integrations
7.1 Connection authority
You may connect supported third-party services using OAuth, an approved app installation, API credentials or another supported method. You authorise us to access only the scopes shown in the connection flow.
7.2 Imported data is source data
Importing information does not verify it. Catalogue descriptions, product attributes, images, certificates, supplier records and other imported material remain subject to review and approval.
7.3 No silent overwrite
Where supported, imports are idempotent and preserve source provenance. Conflicts should be visible. We do not intentionally overwrite merchant-controlled data outside the write scope you approve.
7.4 Write-back
We write data to an external platform only through an enabled integration and within the approved scope. You are responsible for reviewing storefront presentation, translations, accessibility and theme compatibility.
7.5 Third-party terms and availability
Your use of Shopify or another provider remains subject to its terms. We are not responsible for changes, outages, account restrictions or data practices of a third-party service, except to the extent caused by our breach or negligence.
7.6 Disconnecting
You may disconnect an integration through available controls. Disconnecting may stop synchronisation but does not necessarily delete information already imported into your workspace. Deletion is handled through account controls, support or the Privacy Notice.
8. AI-assisted features
8.1 Human review
AI-assisted extraction, classification, translation, mapping and drafting features produce suggestions. An authorised person should review those suggestions before approval, publication or submission.
8.2 No guarantee
AI outputs can be incomplete, inaccurate or unsuitable. A confidence indicator or absence of a warning is not a guarantee.
8.3 Your instructions and data
You must not submit unlawful, highly sensitive, export-controlled or special-category personal data to AI features unless we have expressly agreed appropriate processing and safeguards.
8.4 Model training
We do not use identifiable Customer DPP Data to train a general-purpose foundation model unless you expressly agree in writing. Our current providers and processing terms are described in the Privacy Notice and Subprocessor Notice.
9. Publication, QR codes and identifiers
9.1 Approval
A passport is published only after the approval step configured for your workspace, except where an authorised automation rule applies.
9.2 Persistent access
We aim to provide persistent resolver URLs for published passports during the contract. Long-term continuity after cancellation, statutory backup, custom domains or migration support may require a separate service.
9.3 Carrier responsibility
You are responsible for choosing the correct product, packaging or document placement; print quality; physical durability; and any product-specific data-carrier requirements.
9.4 Versions
Published versions may be immutable for audit purposes. A correction may create a new version rather than altering historical evidence.
10. EU DPP Registry services
10.1 Separate activation
Creating a DPP Grid account does not appoint us to submit to the EU DPP Registry. Registry preparation or submission is activated only through a separate signed agreement or clearly documented enterprise arrangement.
10.2 Responsible economic operator
The customer or other correctly identified legal entity remains the responsible economic operator. DPP Grid does not become the manufacturer, importer or responsible operator merely by hosting or submitting a passport.
10.3 Conditions
Registration actions are subject to applicable product-specific law, verification of the relevant operator, verification or authorisation of DPP Grid where required, Registry functionality, customer approval and technical readiness.
10.4 Not proof of compliance
A Registry registration, unique registration identifier, proof of registration or automated validation is not a certification or guarantee that the Product or DPP meets all substantive legal requirements.
10.5 Manual and API processes
Where permitted, we may prepare or submit customer-specific files manually until a suitable delegated API route is available, and later use APIs or other supported automation. We will preserve customer separation, approval and audit controls.
11. Acceptable use
You must not use the Services to:
- break the law or another person's rights;
- publish false, misleading or unsubstantiated product claims;
- conceal or misstate the responsible economic operator;
- submit a customer product as a Fleeta Limited product without a genuine legal basis;
- upload malware, harmful code or prohibited content;
- probe, disrupt or bypass security or rate limits;
- access another customer's data;
- scrape or reverse engineer the Services except where law does not permit restriction;
- create duplicate or conflicting identifiers intended to mislead;
- use the Services for weapons, illegal goods, sanctions evasion or other prohibited activity; or
- use generated passports as a substitute for required testing, certification or professional advice.
We may investigate suspected misuse and suspend affected access where reasonably necessary.
12. Data protection
Our Privacy Notice explains how we use personal data as a controller. Where we process personal data on your behalf, our Data Processing Addendum applies.
You must provide required notices and lawful bases for personal data you place in Customer Data. You should not include personal consumer data in a product passport unless required and lawful.
13. Confidentiality
Each party must protect the other's confidential information and use it only for the contract. Disclosure is permitted to personnel, professional advisers and service providers who need access and are bound by confidentiality, and where required by law.
Confidential information excludes information lawfully public, independently developed, already known without restriction or lawfully received from another source.
14. Security
We maintain reasonable technical and organisational measures described in our Security page and Data Processing Addendum. Security measures may evolve as long as the overall level of protection is not materially reduced.
No online service is risk-free. You must configure permissions carefully, protect credentials and maintain your own source records and business continuity appropriate to your risk.
15. Intellectual property
We and our licensors own the Services, software, interfaces, templates, documentation, branding and other DPP Grid materials. Subject to payment and these Terms, we grant you a limited, non-exclusive, non-transferable right to use them during the contract for your organisation's business.
You may not copy, resell, sublicense or create a competing service from DPP Grid materials except as expressly permitted. Open-source components remain subject to their own licences.
Feedback may be used to improve DPP Grid without payment, provided we do not disclose your confidential information or identify you without permission.
16. Third-party services and links
The Services may link to or interoperate with third parties. Their services are governed by their own terms and privacy notices. We do not endorse a provider merely by supporting an integration and do not claim a partnership or approval unless expressly stated.
17. Service availability and changes
We use reasonable efforts to keep the Services available. Specific service levels apply only where agreed in an Enterprise Order Form.
We may perform maintenance and update the Services for security, reliability, legal readiness, interoperability and user experience. We will provide reasonable notice of material changes where practicable.
DPP laws, schemas, standards, APIs and Registry functions may change. We may update workflows and documentation accordingly. Substantial custom remediation may require additional Fees.
18. Suspension and termination
18.1 Suspension
We may suspend an account, Product, publication, integration or submission where reasonably necessary because of non-payment, security risk, suspected illegality, material inaccuracy, infringement, Registry prohibition, sanctions risk or material breach. We will explain the reason and allow correction where practicable.
18.2 Termination
Either party may terminate for material breach not remedied within 14 days after notice, or immediately for an irremediable breach or insolvency. Self-service customers may cancel as described in clause 5.
18.3 Export and deletion
On termination, available exports remain accessible for at least 30 days unless prohibited by law, security concerns or non-payment. After that period, we may delete or anonymise Customer Data according to the Data Processing Addendum and retention schedule.
18.4 Passport continuity
If a passport must remain available for a legal or product-lifecycle period, you must arrange continued hosting, transfer or backup before termination. Standard cancellation does not automatically include indefinite public hosting.
19. Warranties and disclaimers
We warrant that we will provide paid Services with reasonable skill and care. If we materially breach this warranty, we will re-perform the affected Service or, if that is not reasonably possible, refund the prepaid Fees for the affected period.
To the fullest extent permitted by law, we do not warrant that:
- DPP Grid alone makes a Product compliant;
- any DPP will be accepted by a regulator, customer, marketplace or Registry;
- source or AI-generated data is accurate;
- every legal change will be reflected immediately; or
- the Services or third-party systems will be uninterrupted or error-free.
DPP Grid is infrastructure and workflow support. It is not legal advice, conformity assessment, laboratory testing, customs representation or certification.
20. Indemnities
You will indemnify us against third-party claims and reasonable external costs arising from an unsafe or unlawful Product, materially inaccurate or unlawful Customer Data, infringement by Customer Data or instructions, false identification of the responsible economic operator, or your material breach of clauses 6, 8, 10 or 11, except to the extent caused by our breach, negligence or wilful misconduct.
We will defend you against a third-party claim that the unmodified DPP Grid software infringes that party's intellectual property right, subject to prompt notice, our control of the defence and your reasonable cooperation. We may modify or replace the affected feature or terminate it and refund prepaid unused Fees. This does not cover Customer Data, external services, unauthorised combinations or misuse.
21. Liability
Nothing limits liability for fraud, fraudulent misrepresentation, death or personal injury caused by negligence, deliberate misconduct, or liability that cannot be limited by law.
Subject to that:
- neither party is liable for indirect or consequential loss, or loss of profit, revenue, anticipated savings, goodwill or business opportunity; and
- each party's aggregate liability in any rolling 12-month period is limited to the Fees paid or payable in that period.
Liability for confidentiality, data-protection obligations and the indemnities above is limited to two times that general cap, unless an Order Form states a different cap or the liability cannot lawfully be limited.
22. Changes to these Terms
We may update these Terms for legal, regulatory, security or service changes. We will notify account holders of a material change before it takes effect. If a material change substantially disadvantages you, you may terminate the affected Service before the change takes effect.
The version accepted by your organisation is recorded in your account.
23. General
Neither party may assign the contract without the other's consent, not to be unreasonably withheld, except to an affiliate or as part of a business reorganisation or sale where the assignee assumes the obligations.
Neither party is liable for delay caused by events beyond reasonable control, excluding payment obligations.
A failure to enforce a right is not a waiver. If a provision is unenforceable, the remainder continues. These Terms do not create a partnership, employment or general agency relationship.
No third party may enforce these Terms under the Contracts (Rights of Third Parties) Act 1999, except where an applicable data-transfer mechanism expressly provides otherwise.
24. Governing law and contact
These Terms and non-contractual obligations arising from them are governed by the laws of England and Wales. The courts of England and Wales have exclusive jurisdiction, unless an Order Form says otherwise.
Questions or legal notices: support@dppgrid.com, with “Legal” in the subject line.
Fleeta Limited trading as DPP Grid
Company number 16675897
50 Princes Street, Ipswich, England, IP1 1RJ