Privacy Policy

Last updated: 20/07/2026
Contents
  1. Who we are
  2. Our roles: controller vs processor
  3. What data we collect
  4. Purposes and legal bases
  5. Supplier contacts entered by our customers
  6. Recipients and sub-processors
  7. International transfers
  8. Retention periods
  9. Your rights
  10. Security
  11. Automated decision-making and AI
  12. Cookies
  13. Children
  14. Changes to this policy
  15. Complaints — supervisory authority

1. Who we are

The DPP Central platform is operated by AGROBOX SMART FARMING PRIVATE COMPANY (trading as "AGROBOX P.C."), VAT: EL802216797, General Commercial Registry (GEMI) No: 172315444000, EUID: ELGEMI.172315444000, with registered offices at Anthimou Gazi 92A, 383 33 Volos, Greece. The company is certified to ISO/IEC 27001:2022 (certificate no. 340440745-IS, certification body NBIS — accredited by ESYD, accreditation no. 1431). Contact: [email protected].

"DPP Central" is the name of the platform/service (a trademark) — where this Policy says "we" or "the Platform", it refers to AGROBOX P.C. as the operator and, for the processing activities in section 2, the data controller.

This Privacy Policy describes how we collect and process personal data, in accordance with the EU General Data Protection Regulation (EU) 2016/679 ("GDPR") and Greek law (Law 4624/2019).

DPP Central is a B2B software-as-a-service for creating and managing Digital Product Passports under the EU ESPR framework.

Data protection contact: [email protected]. You may address any data-subject request to this address.

2. Our roles: controller vs processor

Where we act as a data controller, the controller is AGROBOX SMART FARMING PRIVATE COMPANY ("AGROBOX P.C.") — see full details in section 1. Understanding our role determines who is responsible for your data:

  • We act as a data controller for: account data of Platform users (registration, login, 2FA details), billing and subscription data, visitor data of our public website, and the security records (audit logs, IP addresses) we keep for our own security. This Policy covers those processing activities.
  • We act as a data processor under Article 28 GDPR for "Customer Content": everything a customer organization puts into its workspace — product data, uploaded documents, supplier contact details, product passport content. The customer organization is the controller of that data. That processing is governed by a Data Processing Agreement (DPA) with the customer, not by this Policy.

If your data is contained in Customer Content (for example, you are a supplier or an employee of an organization using the Platform), please direct your requests primarily to that organization, which is the controller. We will assist the organization in fulfilling your request.

3. What data we collect

  • Account data: name, email address, password (stored only in hashed form), language, timezone.
  • Two-factor authentication (2FA) data: authenticator-app (TOTP) secret and/or phone number, if you enable 2FA.
  • Billing data: company name, tax ID, address, subscription details and payment history. We never store card numbers — they are entered directly on the secure hosted pages of our payment providers (see section 6).
  • Logs and security records: IP addresses, login times, user actions on the Platform (audit logs).
  • Document content: documents you upload (e.g. certificates, technical data sheets) may incidentally contain personal data (e.g. names of signatories).
  • Website visitor data: contact-form details and — only with your consent — usage statistics (Google Analytics).
  • Google Sign-In data: if you choose "Continue with Google", we receive from Google your name, email address, unique Google account ID, email-verified status and — where available — your profile picture URL. See section 3.1.

Providing an email address is required to create an account and enter the contract; without it the service cannot be provided. Other data is optional unless indicated otherwise at the point of collection.

3.1 Google Sign-In

We offer optional sign-in/registration with your Google account, using Google's OAuth 2.0 / OpenID Connect protocol. Using this feature is entirely optional; you can always register with an email address and password instead.

  • What we receive: when you approve the request on Google's consent screen, we receive only the basic profile fields covered by the openid, email and profile scopes: name, email, Google account ID, email-verified flag and profile picture. We do not request or access your Gmail, Contacts, Calendar, Drive or any other Google account data.
  • Why: solely to create and authenticate your account on the Platform. Legal basis: Article 6(1)(b) GDPR (performance of a contract) and, for the use of the Google method itself, your consent (Article 6(1)(a)) expressed by choosing "Continue with Google" and approving Google's consent screen.
  • Email verification: where Google confirms your email address is verified, we do not ask you to complete a separate Platform email verification.
  • How we use/share it: this data is stored on your account and is never sold or shared with third parties for advertising. The Platform's use of Google user data complies with the Google API Services User Data Policy, including its Limited Use requirements.
  • Revoking access: you can revoke access at any time from Google Account → Security → Third-party apps. This does not delete your Platform account; for account deletion see section 8.

4. Purposes and legal bases

PurposeDataLegal basis (GDPR)
Account creation, authentication, 2FA, provision of the serviceAccount data, 2FAArt. 6(1)(b) — performance of a contract
Transactional emails (e.g. invitations, system notifications)Email, nameArt. 6(1)(b) — performance of a contract
Invoicing, tax records, accountingBilling dataArt. 6(1)(c) — legal obligation (tax law)
Security, fraud and abuse prevention, action traceabilityIP, audit logsArt. 6(1)(f) — legitimate interest; our legitimate interest is the security of the Platform and our customers and the prevention of fraud
AI text extraction from documents and translations (service feature)Document contentArt. 6(1)(b) — performance of a contract (as processor, on the customer's instructions)
Website usage statistics (Google Analytics)Cookies, usage dataArt. 6(1)(a) — consent (via the cookie banner)
Marketing communicationsEmailArt. 6(1)(a) — consent, withdrawable at any time

5. Supplier contacts entered by our customers

Our customer organizations may enter contact details of their suppliers (name, email, company) and invite them to the supplier portal. If you received such an invitation, your details were provided to us by the organization that invited you (data source under Article 14 GDPR) and we process them as a processor on that organization's behalf. That organization is the controller — you may contact it, or contact us at [email protected] and we will forward your request.

6. Recipients and sub-processors

We use carefully selected providers. The main categories of recipients:

RecipientRolePurpose / Notes
Hosting providerSub-processorHosting of the Platform and database within the EU/EEA.
File storage provider (S3-compatible)Sub-processorStorage of uploaded documents and images. The specific provider is designated at deployment configuration; in some deployments the customer may designate its own storage.
Email delivery provider (SMTP)Sub-processorDelivery of transactional notifications and invitations.
Google LLC — Gemini APISub-processorAI document processing (text extraction) and translations. We use the paid API tier: your data is NOT used to train Google's models. Google retains abuse-monitoring logs for up to 55 days and processes the data under its Data Processing Addendum. Transient storage outside the EEA may occur, subject to the safeguards in section 7.
Google LLC — Google Analytics 4Processor (for measurement data)Usage statistics on the public marketing site only and only after you accept analytics cookies. GA4 does not log or store IP addresses. EU-US transfers are covered by the EU-U.S. Data Privacy Framework.
Google LLC — Google Sign-In (OAuth)Independent controllerAuthentication service, only if you choose "Continue with Google". Google provides us with basic profile data (name, email, Google account ID, profile picture) — see section 3.1. Google's own processing is governed by Google's privacy policy. EU-US transfers under the EU-U.S. Data Privacy Framework.
Stripe, PayPal, Viva.comIndependent controllersPayment processing. Card details are entered directly in their own secure environments — the Platform never receives or stores card numbers. Their own privacy policies apply to their processing.
Public authoritiesRecipients under lawOnly where a legal obligation exists (e.g. tax or judicial authorities).

7. International transfers

We aim to keep data within the EU/EEA. Where a provider processes data outside the EEA (notably Google LLC, Stripe, PayPal in the US), the transfer relies on: (a) the European Commission's adequacy decision for the EU-U.S. Data Privacy Framework, for providers certified under it (Google and the major payment providers are certified), or (b) the Commission's Standard Contractual Clauses (SCCs, Implementing Decision 2021/914) with supplementary measures where required. A copy of the relevant safeguards is available on request at [email protected].

8. Retention periods

  • Account data: for as long as the account is active and up to 12 months after deletion/termination, for security and dispute-resolution purposes.
  • Logs (IP, audit logs, notifications): up to 90 days, then automatically deleted.
  • Tax/invoicing data: for the period required by Greek tax law (as a rule at least 5 years).
  • Customer Content (products, documents, passports): until deleted by the customer or until contract termination, with a 30-day export window after termination; thereafter deleted.
  • Backups: deleted on a rolling basis within a reasonable period after deletion of the primary data.

9. Your rights

To the extent we act as a controller, you have the following rights:

  • Access (Art. 15) — you can also export your data directly from the Platform (Security → Data export).
  • Rectification (Art. 16) — most details can be corrected directly in your profile.
  • Erasure (Art. 17) — submit a request to [email protected]; we will respond within one month (Art. 12(3)).
  • Restriction of processing (Art. 18).
  • Portability (Art. 20) — the Platform's structured data export serves this right.
  • Objection (Art. 21) — in particular to processing based on legitimate interest.
  • Withdrawal of consent — where processing is based on consent (cookies, marketing), you may withdraw it at any time without affecting the lawfulness of prior processing.

10. Security

We implement appropriate technical and organizational measures (Art. 32 GDPR), including: encryption in transit (TLS), hashed password storage, two-factor authentication (2FA), role-based access control, audit logging and regular backups. In the event of a data breach posing a risk to your rights, we will notify the competent supervisory authority and, where required, the affected data subjects, in accordance with Articles 33-34 GDPR.

11. Automated decision-making and AI

We use artificial intelligence (Google Gemini) to extract text from documents and to translate content. This feature does not produce decisions with legal or similarly significant effects on individuals within the meaning of Article 22 GDPR; outputs are reviewed and approved by the user. We do not carry out profiling with legal effects.

12. Cookies

Information on the cookies we use, their lifespans and how to manage your consent can be found in our Cookie Policy.

13. Children

The service is intended exclusively for businesses and professionals and is not directed at minors. We do not knowingly collect data from minors.

14. Changes to this policy

We may update this Policy from time to time. For material changes we will inform registered users by email or in-Platform notification before the changes take effect. The "Last updated" date at the top always indicates the current version.

15. Complaints — supervisory authority

You have the right to lodge a complaint with the Hellenic Data Protection Authority (Kifisias Ave. 1-3, 115 23 Athens, Greece, www.dpa.gr) or with the supervisory authority of your place of residence or work within the EU. We would however appreciate the opportunity to resolve any concern directly — contact us first at [email protected].

In case of any discrepancy between the Greek and the English version of this document, the English version prevails.

This text is provided as general information; we recommend review by legal counsel before commercial use of the Platform in a specific jurisdiction.

We only use essential functional cookies (login, language). See our policy. Cookie policy Privacy policy