Privacy policy
This notice explains what personal data we collect when you use passportdigital.eu, why we process it, and the rights you have over it under the General Data Protection Regulation (EU) 2016/679.
Last updated:
Who is responsible for your data
The operator's registered details have not been filled in yet. This policy is incomplete until they are.
Contact for privacy matters: hello@passportdigital.eu
Supervisory authority: Autorité de protection des données / Gegevensbeschermingsautoriteit (Belgium) — Rue de la Presse 35, 1000 Brussels
What data we collect
We only collect what we need to run the compliance scanner and answer you. There is no account to create and no profile is built about you.
- From the scanner: your company name, email address, website, country, VAT number, company registration number, number of product lines, and your answers to the assessment questions.
- From the contact form: your name, email address, subject and message.
- From a purchase: the reference of your Stripe payment. Your card details are entered directly with Stripe and never reach our servers.
- With your consent only: analytics data about how you use the site.
Why we use it, and on what legal basis
- To run your scan and deliver the report you bought — performance of a contract (Art. 6(1)(b) GDPR).
- To answer questions you send us — our legitimate interest in responding to enquiries (Art. 6(1)(f)).
- To meet accounting and tax obligations on purchases — legal obligation (Art. 6(1)(c)).
- To measure how the site is used — your consent, which you can withdraw at any time (Art. 6(1)(a)).
Who we share your data with
We do not sell your data and we do not share it for advertising. We use the following service providers, who process data only on our instructions:
| Service | Purpose | Location |
|---|---|---|
| Vercel | Hosting the website | EU / US |
| Neon | Storing scan results and reports | EU |
| Stripe | Processing card payments | EU / US |
| Resend | Sending reports and notifications | EU / US |
| Google Analytics | Website analytics (only with your consent) | EU / US |
| Microsoft Clarity | Session recordings and heatmaps (only with your consent) | EU / US |
International transfers
Some of our providers may process data outside the European Economic Area. Where that happens, the transfer is covered by the European Commission's Standard Contractual Clauses, together with the additional safeguards those providers apply.
How long we keep it
- Scan results that were never purchased: 12 months, then deleted.
- Purchases and the reports generated for them: for as long as the applicable accounting and tax retention periods require.
- Contact form messages: 24 months.
- Your cookie choice: stored in your browser until you clear it or change it.
Your rights
You can exercise any of these by writing to the contact address above. We will respond within one month. You can also complain to your national data protection authority.
- Access a copy of the data we hold about you.
- Have inaccurate data corrected.
- Have your data deleted.
- Restrict or object to how we process it.
- Receive your data in a portable format.
- Withdraw your consent to analytics at any time, without affecting what came before.
Security
Data is transmitted over encrypted connections and stored in a managed database with access restricted to what is needed to operate the service. Payments are handled entirely by Stripe, a PCI DSS Level 1 certified provider.
Changes to this policy
If we change how we handle personal data, we will update this page and the date shown above. If the change affects what you consented to, we will ask again.