PRIVACY POLICY
Last updated: 7 September 2026
1. Controller
Cradox, UAB, registered in Vilnius, Lithuania, is the data controller responsible for your personal data under the General Data Protection Regulation (GDPR) (EU) 2016/679.
2. Data We Collect
We collect the following categories of personal data:
- Account data: name, email address, company name.
- Product data: information you submit for Digital Product Passport generation.
- Usage data: IP address, browser type, pages visited, timestamps.
- Communications: emails and support requests you send us.
3. Legal Basis
We process your personal data on the following legal bases: performance of a contract (Art. 6(1)(b)), compliance with legal obligations under EU regulation (Art. 6(1)(c)), our legitimate interests in operating the service (Art. 6(1)(f)), and your consent where applicable (Art. 6(1)(a)).
4. How We Use Your Data
- To provide and maintain the CRADOX platform.
- To generate and register Digital Product Passports with the EU Central Registry.
- To communicate with you about your account and compliance status.
- To improve our services and product offerings.
5. Data Retention
We retain your personal data for as long as your account is active and for the period required to meet legal, regulatory, and audit obligations under EU law. Product passport data is retained for the lifecycle of the product as required by the ESPR.
6. Your Rights
Under the GDPR, you have the right to:
- Access your personal data (Art. 15).
- Rectify inaccurate data (Art. 16).
- Erasure of your data ("right to be forgotten") (Art. 17).
- Restrict or object to processing (Arts. 18, 21).
- Data portability (Art. 20).
- Lodge a complaint with your supervisory authority (Art. 77).
7. International Transfers
Your data is stored and processed within the European Union. Any transfer to a third country is carried out with appropriate safeguards under Chapter V of the GDPR.
8. Contact
For any privacy enquiries, contact us at info@cradox.eu.