The DPP Central platform is operated by AGROBOX SMART FARMING PRIVATE COMPANY (trading as "AGROBOX P.C."), VAT: EL802216797, General Commercial Registry (GEMI) No: 172315444000, EUID: ELGEMI.172315444000, with registered offices at Anthimou Gazi 92A, 383 33 Volos, Greece. The company is certified to ISO/IEC 27001:2022 (certificate no. 340440745-IS, certification body NBIS — accredited by ESYD, accreditation no. 1431). Contact: [email protected].
"DPP Central" is the name of the platform/service (a trademark) — where this Policy says "we" or "the Platform", it refers to AGROBOX P.C. as the operator and, for the processing activities in section 2, the data controller.
This Privacy Policy describes how we collect and process personal data, in accordance with the EU General Data Protection Regulation (EU) 2016/679 ("GDPR") and Greek law (Law 4624/2019).
DPP Central is a B2B software-as-a-service for creating and managing Digital Product Passports under the EU ESPR framework.
Data protection contact: [email protected]. You may address any data-subject request to this address.
Where we act as a data controller, the controller is AGROBOX SMART FARMING PRIVATE COMPANY ("AGROBOX P.C.") — see full details in section 1. Understanding our role determines who is responsible for your data:
If your data is contained in Customer Content (for example, you are a supplier or an employee of an organization using the Platform), please direct your requests primarily to that organization, which is the controller. We will assist the organization in fulfilling your request.
Providing an email address is required to create an account and enter the contract; without it the service cannot be provided. Other data is optional unless indicated otherwise at the point of collection.
We offer optional sign-in/registration with your Google account, using Google's OAuth 2.0 / OpenID Connect protocol. Using this feature is entirely optional; you can always register with an email address and password instead.
openid, email and profile scopes: name, email, Google account ID, email-verified flag and profile picture. We do not request or access your Gmail, Contacts, Calendar, Drive or any other Google account data.| Purpose | Data | Legal basis (GDPR) |
|---|---|---|
| Account creation, authentication, 2FA, provision of the service | Account data, 2FA | Art. 6(1)(b) — performance of a contract |
| Transactional emails (e.g. invitations, system notifications) | Email, name | Art. 6(1)(b) — performance of a contract |
| Invoicing, tax records, accounting | Billing data | Art. 6(1)(c) — legal obligation (tax law) |
| Security, fraud and abuse prevention, action traceability | IP, audit logs | Art. 6(1)(f) — legitimate interest; our legitimate interest is the security of the Platform and our customers and the prevention of fraud |
| AI text extraction from documents and translations (service feature) | Document content | Art. 6(1)(b) — performance of a contract (as processor, on the customer's instructions) |
| Website usage statistics (Google Analytics) | Cookies, usage data | Art. 6(1)(a) — consent (via the cookie banner) |
| Marketing communications | Art. 6(1)(a) — consent, withdrawable at any time |
Our customer organizations may enter contact details of their suppliers (name, email, company) and invite them to the supplier portal. If you received such an invitation, your details were provided to us by the organization that invited you (data source under Article 14 GDPR) and we process them as a processor on that organization's behalf. That organization is the controller — you may contact it, or contact us at [email protected] and we will forward your request.
We use carefully selected providers. The main categories of recipients:
| Recipient | Role | Purpose / Notes |
|---|---|---|
| Hosting provider | Sub-processor | Hosting of the Platform and database within the EU/EEA. |
| File storage provider (S3-compatible) | Sub-processor | Storage of uploaded documents and images. The specific provider is designated at deployment configuration; in some deployments the customer may designate its own storage. |
| Email delivery provider (SMTP) | Sub-processor | Delivery of transactional notifications and invitations. |
| Google LLC — Gemini API | Sub-processor | AI document processing (text extraction) and translations. We use the paid API tier: your data is NOT used to train Google's models. Google retains abuse-monitoring logs for up to 55 days and processes the data under its Data Processing Addendum. Transient storage outside the EEA may occur, subject to the safeguards in section 7. |
| Google LLC — Google Analytics 4 | Processor (for measurement data) | Usage statistics on the public marketing site only and only after you accept analytics cookies. GA4 does not log or store IP addresses. EU-US transfers are covered by the EU-U.S. Data Privacy Framework. |
| Google LLC — Google Sign-In (OAuth) | Independent controller | Authentication service, only if you choose "Continue with Google". Google provides us with basic profile data (name, email, Google account ID, profile picture) — see section 3.1. Google's own processing is governed by Google's privacy policy. EU-US transfers under the EU-U.S. Data Privacy Framework. |
| Stripe, PayPal, Viva.com | Independent controllers | Payment processing. Card details are entered directly in their own secure environments — the Platform never receives or stores card numbers. Their own privacy policies apply to their processing. |
| Public authorities | Recipients under law | Only where a legal obligation exists (e.g. tax or judicial authorities). |
We aim to keep data within the EU/EEA. Where a provider processes data outside the EEA (notably Google LLC, Stripe, PayPal in the US), the transfer relies on: (a) the European Commission's adequacy decision for the EU-U.S. Data Privacy Framework, for providers certified under it (Google and the major payment providers are certified), or (b) the Commission's Standard Contractual Clauses (SCCs, Implementing Decision 2021/914) with supplementary measures where required. A copy of the relevant safeguards is available on request at [email protected].
To the extent we act as a controller, you have the following rights:
We implement appropriate technical and organizational measures (Art. 32 GDPR), including: encryption in transit (TLS), hashed password storage, two-factor authentication (2FA), role-based access control, audit logging and regular backups. In the event of a data breach posing a risk to your rights, we will notify the competent supervisory authority and, where required, the affected data subjects, in accordance with Articles 33-34 GDPR.
We use artificial intelligence (Google Gemini) to extract text from documents and to translate content. This feature does not produce decisions with legal or similarly significant effects on individuals within the meaning of Article 22 GDPR; outputs are reviewed and approved by the user. We do not carry out profiling with legal effects.
Information on the cookies we use, their lifespans and how to manage your consent can be found in our Cookie Policy.
The service is intended exclusively for businesses and professionals and is not directed at minors. We do not knowingly collect data from minors.
We may update this Policy from time to time. For material changes we will inform registered users by email or in-Platform notification before the changes take effect. The "Last updated" date at the top always indicates the current version.
You have the right to lodge a complaint with the Hellenic Data Protection Authority (Kifisias Ave. 1-3, 115 23 Athens, Greece, www.dpa.gr) or with the supervisory authority of your place of residence or work within the EU. We would however appreciate the opportunity to resolve any concern directly — contact us first at [email protected].
In case of any discrepancy between the Greek and the English version of this document, the English version prevails.
This text is provided as general information; we recommend review by legal counsel before commercial use of the Platform in a specific jurisdiction.