DPPespr logoDPPespr

Privacy Notice

Last updated: June 2026

This notice explains how Kalchevo.com ("we", "us", "our"), the operator of DPPespr.com (the "Service"), collects, uses, shares, and protects personal data, and the rights you have over it. We are the data controller for the personal data described here, and we handle it in line with the UK GDPR and the EU GDPR.

On this page
  1. Who we are
  2. Data we collect
  3. How and why we use it
  4. Cookies
  5. Who we share it with
  6. International transfers
  7. How long we keep it
  8. Your rights
  9. Security
  10. Children
  11. Changes
  12. Contact and complaints

1Who we are

DPPespr.com is a service that helps businesses create and host EU Digital Product Passports for compliance with the Ecodesign for Sustainable Products Regulation. The Service is operated by Kalchevo.com, which is the data controller. You can reach us about privacy at [email protected].

2Data we collect

CategoryWhat it includes
Account dataYour name, business name, email address, password (stored only as a secure hash), and account settings.
Passport contentThe product information, documents, and images you add to your passports. You control this content and are responsible for any personal data you include in it.
Passport scan analyticsWhen a passport QR code is scanned by the public, we record the device type and an approximate location. The location is derived from the visitor's IP address, which we reduce to a one-way hashed value; we do not keep the raw IP address. With the visitor's permission we may also use precise device location.
Login and security dataSign-in session details including IP address, browser, and approximate location, used to keep your account secure and let you review and revoke sessions.
Support dataMessages and details you send us through support tickets or chat.
Affiliate dataIf you join our affiliate programme: your name, email, and payout details. Referral link clicks are logged with a hashed IP only.
Billing dataThe information needed to take a subscription payment, handled by our payment providers.

3How and why we use it

We use personal data to:

Our lawful bases are: performance of our contract with you; our legitimate interests in running, securing, and improving the Service; compliance with legal obligations; and your consent where it is required, for example for non-essential cookies. You can withdraw consent at any time.

4Cookies

We use essential browser storage to operate the Service and keep you signed in. With your consent we also set a single referral cookie for our affiliate programme. We do not use advertising cookies. You can set your choice through the cookie banner, and full detail is in our Cookie Policy.

5Who we share it with

We share personal data only with service providers that help us run the platform, and only as needed. These act on our instructions under appropriate agreements. They include:

We do not sell personal data. We may disclose data where required by law or to protect our rights.

For transparency, the public ledger we use to provide tamper-evidence for passports stores only cryptographic hashes. No personal data is written to it.

6International transfers

Some of our providers may process data outside the UK or EEA, including in the United States. Where that happens, we put appropriate safeguards in place, such as Standard Contractual Clauses or the UK International Data Transfer Addendum, to protect your data. You can contact us for more information about these safeguards.

7How long we keep it

8Your rights

Subject to law, you have the right to access your data, correct it, delete it, restrict or object to processing, and receive a copy in a portable format. Where we rely on consent, you can withdraw it at any time.

If you have an account, you can download a copy of your data or permanently delete your account yourself at any time from your data page. For any other request, contact [email protected] and we will respond within the time the law allows.

9Security

We use technical and organisational measures to protect personal data, including encryption in transit (HTTPS), hashed passwords, access controls, the ability to revoke sign-in sessions, and minimisation of stored IP addresses over time. No system is perfectly secure, but we work to keep your data safe.

10Children

The Service is intended for businesses and is not directed at children. We do not knowingly collect personal data from children.

11Changes

We may update this notice from time to time. We will post the updated version here with a new date, and where changes are significant we will take reasonable steps to let you know.

12Contact and complaints

For any privacy question or to exercise your rights, contact [email protected]. If you are not satisfied, you can complain to your data protection authority. In the UK this is the Information Commissioner's Office (ico.org.uk); in the EU it is the supervisory authority in your country.