Privacy policy

Information under Articles 13 and 14 GDPR.

Last updated: 27 Sept 2026 · Version 3.1

Mandatory details are missing

Some required details are not available yet — about the operator, the safeguards for transfers to third countries, or individual retention periods. They are marked in red below and will be added once known; they are deliberately not invented.

Draft — not reviewed by a lawyer

This text is a draft. It has not been reviewed by a lawyer and may change.

1. Controller

The controller for the processing of personal data on this platform within the meaning of Art. 4(7) GDPR is:

Controller
PackCert GmbH, Am Steinfeld 15, 2511 Pfaffstätten, Österreich
Email
info@pack-cert.com
Telephone
Matthias Zelina +43 664 5079950, Linus Schwalm +43 650 2518900, Sebastian König +43 664 5079951, Sven Olin +43 664 2112445

No data protection officer has been appointed. Whether an appointment is required under Art. 37 GDPR is currently being assessed.

2. Contact for data protection matters

For access, rectification, erasure and any other request under Chapter III GDPR, please write to info@pack-cert.com. Requests are answered in German and English.

3. Processing activities in detail

The following list names every processing activity with its data category, purpose and legal basis. The corresponding retention periods are in section 8.

User account
Name, email address, role, language preference, time of the last sign-in and a checksum of the password. Purpose: providing the account. Legal basis: Art. 6(1)(b) GDPR.
Company data
Company name, company type, VAT identification number, address, country, website and contact email. Purpose: attributing items and documents to the responsible economic operator and, for paid plans, invoicing. Legal basis: Art. 6(1)(b) GDPR.
Sign-in and session
A checksum of the session key, the network part of the IP address, the browser identification and the expiry time. The session key itself is stored only in the cookie, never in the database. The IP address is stored shortened to its network, because the network is enough to notice unusual access. Purpose: keeping the sign-in alive and detecting unauthorised access. Legal basis: Art. 6(1)(b) and (f) GDPR.
Security log
Sign-ins and failed sign-in attempts, creation and modification of accounts and companies, uploading and changing documents and revisions, publications, data exports and administrative operations — each with a timestamp, user identifier, browser identification and the IP address shortened to its network. Purpose: defence against abuse and traceability of who filed which revision. Legal basis: Art. 6(1)(f) GDPR; our legitimate interest lies in the security of the platform and in being able to evidence changes to compliance documentation.
Document retrievals
Time of retrieval, the revision retrieved and — for signed-in people — the user and company identifier. Purpose: building the customer’s document archive and the supplier’s retrieval reporting. Legal basis: Art. 6(1)(b) GDPR.
Records of consent
Time, language version, version number and a checksum of the text actually displayed, plus IP address and browser identification. Purpose: evidencing which wording was agreed to. Legal basis: Art. 6(1)(c) GDPR in conjunction with Art. 7(1) GDPR.
Contract records
On entering a paid plan: plan name, price, currency, billing period, and the versions of the terms, privacy policy and withdrawal notice in force at that moment. Purpose: evidencing the agreed contract. Legal basis: Art. 6(1)(b) and (c) GDPR.
Notifications
Notices about new document revisions and about expiring or expired documents, linked to the user identifier. Purpose: performing the user agreement. Legal basis: Art. 6(1)(b) GDPR.
Content filed by suppliers
Packaging master data and uploaded document files. These generally contain no personal data; where a supplier includes such data in a document, the supplier is responsible for it. Legal basis: Art. 6(1)(b) GDPR.

4. Retrievals without a user account

Compliance documents can be retrieved without registering. Personal data is processed in that case too, as follows:

A checksum is derived from your IP address, salted with a secret key. Only that checksum is stored, never the IP address itself. It makes it possible to attribute repeated retrievals to the same access point without knowing the address.

The sole purpose is to prevent automated bulk retrieval. The legal basis is Art. 6(1)(f) GDPR; our legitimate interest lies in protecting availability for all users. No profiling takes place, and the checksum is not combined with any other source of data.

5. Cookies

Only strictly necessary cookies are set: a session cookie for signing in and a cookie for the language preference. There is no tracking and no audience measurement. Consent is therefore not required and is not obtained.

6. Processors

The following service providers process data on our instructions under a contract pursuant to Art. 28 GDPR:

Vercel Inc. (USA)
Running and executing the application, serving the website, scheduled tasks. Processing in: European Union (Frankfurt region, fra1).
Neon Inc. (USA)
Running the database including the stored document files. Processing in: Germany (Frankfurt am Main).
IONOS SE (Deutschland)
Domain, name servers and email delivery for the pack-cert.com domain. Processing in: European Union.
Resend (Plus Five Five, Inc.) (USA)
Sending transactional email (password resets, invitations, notifications, contract confirmations). Processing in: Sending from the European Union (Ireland); account data, metadata and logs in the United States.

The platform’s source code is managed at GitHub Inc. No personal data of users is transmitted there; GitHub is therefore not listed as a processor.

No analytics, tracking or advertising services are embedded. The application loads no external script and no external fonts whatsoever. No newsletter or CRM system is used.

7. Transfers to third countries

Data is stored and processed within the European Union. Two of the service providers used are, however, companies established in the United States. Access from a third country is therefore not excluded, even though the storage location is in the EU.

Vercel Inc. (USA)
Safeguard under Art. 44 et seq. GDPR: TODO: Garantie nach Art. 44 ff. DSGVO für Vercel Inc. eintragen (Angemessenheitsbeschluss bei DPF-Zertifizierung, sonst Standardvertragsklauseln) samt Datum
Neon Inc. (USA)
Safeguard under Art. 44 et seq. GDPR: TODO: Garantie nach Art. 44 ff. DSGVO für Neon Inc. eintragen (Angemessenheitsbeschluss bei DPF-Zertifizierung, sonst Standardvertragsklauseln) samt Datum
Resend (Plus Five Five, Inc.) (USA)
Safeguard under Art. 44 et seq. GDPR: TODO: Garantie nach Art. 44 ff. DSGVO für Resend eintragen (Angemessenheitsbeschluss bei DPF-Zertifizierung, sonst Standardvertragsklauseln) samt Datum

A transfer impact assessment is maintained for these transfers. A copy of the safeguards can be requested at info@pack-cert.com.

8. Retention

The following retention periods apply to the individual categories of data:

Account and company data
until the account is deleted — needed continuously to operate the account.
Sessions
until they expire; expired sessions are deleted daily — they carry a network range and device identification and serve no purpose once expired.
Checksum derived from the IP address for retrievals without an account
7 days, then the field is cleared — serves abuse control only; the retrieval count is kept without any personal reference.
Retrieval records linked to a company
the term of the contract plus 3 years — they form the customer’s evidence archive and the supplier’s retrieval reporting.
Security log of sign-ins and failed attempts
12 months — defence against abuse; no purpose remains afterwards.
Security log of changes to items and documents
permanently; IP address and browser identification are removed 3 years after the account is deleted — chain of evidence showing who filed which revision — the event stays, the personal reference ends.
In-app notifications
24 months — of no further use to recipients beyond that.
Records of consent
the term of the contract plus 3 years — matches the general limitation period.
Invoicing and accounting data
7 years — statutory retention obligation under § 212 UGB and § 132 BAO.
Server logs held by the hosting provider
TODO: Aufbewahrungsdauer der Vercel-Plattformprotokolle beim Anbieter erfragen und eintragen — determined by the provider, not by this platform.

A daily clean-up enforces these periods. Expired sessions, log entries about sign-ins and sign-in attempts after twelve months, and notifications after 24 months are deleted automatically. The checksum derived from the IP address for retrievals without an account is removed after seven days; the retrieval record itself remains without any personal reference, because it carries the supplier’s reporting.

For retrieval records linked to a company, the document-change half of the security log, and records of consent, the period is "the term of the contract plus 3 years". These three are not deleted automatically at present, because the end of a contract is not yet recorded technically. We delete them on request under section 10.

After an account is deleted, security log entries remain, because they evidence who filed which revision of a document. The link to the user account is severed immediately. The IP address and browser identification are removed three years after the account was deleted; the event and its timestamp are kept permanently. Three years matches the general limitation period.

9. Automated processing

There is no automated decision-making, including profiling, within the meaning of Art. 22 GDPR. No person is scored, ranked or assigned probabilities.

The only automated operations are the following, all of which relate to packaging items and documents rather than to people:

  • Limiting the number of requests per access point to prevent automated bulk access.
  • Checking uploaded files for file format and file size.
  • Calculating a completeness score for the filed master data and documents.
  • Displaying a documentation status that describes only whether documents are filed, valid or expired.
  • Sending notices 90, 30 and 7 days before a document expires, and once after it has lapsed.

Marking a packaging item as non-compliant is never done automatically; it is always decided by a person.

10. Your rights

You have the right of access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20) and objection (Art. 21 GDPR).

Where processing is based on Art. 6(1)(f) GDPR — the security log and abuse prevention — you may object to it on grounds relating to your particular situation.

Exporting your own data and deleting your user account are available at any time under "Account" in the application. For anything beyond that, please write to info@pack-cert.com.

11. Right to lodge a complaint

Without prejudice to any other remedy, you have the right to lodge a complaint with a supervisory authority (Art. 77 GDPR). The competent authority is:

Authority
Österreichische Datenschutzbehörde
Address
Barichgasse 40–42, 1030 Wien, Österreich
Email
dsb@dsb.gv.at
Telephone
+43 1 52 152-0
Website
https://www.dsb.gv.at