EUDR Screening
  • Pricing
  • About
  • Guide

Data Processing Agreement

Effective date: 12 July 2026. This is an appendix to our Terms of Service, governing the processing of personal data contained in supplier data a customer uploads to the Service.


1. Roles

For the personal data of a customer's own suppliers (names, addresses, coordinates) contained in files the customer uploads to the Service, the customer is the controller and Gian-Luca Kaufmann, trading as EUDR Screening is the processor, within the meaning of GDPR Art. 4(7)/4(8) and, where applicable, the Swiss FADP's equivalent terms.

2. Subject matter, duration, nature and purpose of processing

  • Subject matter: processing of supplier location and identifying data uploaded by the customer, for the purpose of generating a deforestation risk screening result.
  • Duration: for the life of the customer's engagement with the Service, subject to the retention limits in Section 5 below.
  • Nature and purpose: automated geospatial analysis (satellite forest-cover/change queries against uploaded coordinates), optional geocoding of addresses/names to coordinates, and rendering the result into a table, map, and downloadable report. No other processing purpose is authorized.
  • Types of personal data: supplier/company name, address, geographic coordinates or plot boundary, country, optional lot identifier. Continuous Compliance Monitoring (Beta) adds, only if the customer opts in: a retained copy of the above for the life of a subscription (Section 5), and, only if the customer sends a "resolve this flag" link and the recipient chooses to respond, a photo, a corrected GPS location, and/or a written note submitted directly by that individual. No special-category data is knowingly processed, though a submitted photo may incidentally show identifiable details (e.g. a person's face) if the submitter chooses to include them.
  • Categories of data subjects: the customer's suppliers (which may include sole traders or smallholder farmers who are natural persons), and, for "resolve this flag" submissions specifically, whichever individual contact at a flagged supplier the customer sends that link to and who chooses to respond — collected directly from that person, not uploaded by the customer (see Privacy Policy Section 3's note on this).

3. Processor obligations

We agree to:

(a) process personal data only on the customer's documented instructions, unless required to do otherwise by EU or Swiss law, in which case we will inform the customer of that legal requirement first, unless prohibited from doing so;

(b) ensure persons authorized to process the data are bound by confidentiality;

(c) implement appropriate technical and organizational security measures;

(d) respect the conditions in Section 4 for engaging any further processor;

(e) assist the customer, taking into account the nature of processing, in responding to data subject rights requests;

(f) assist the customer with its own security, breach-notification, and impact-assessment obligations. Because the customer is the controller for its suppliers' personal data, the customer is responsible for giving those suppliers the information required under Art. 13/14 GDPR — in practice, this should mention that a screening processor is engaged for this purpose; we will provide the factual detail needed on request. Exception, "resolve this flag" submissions (Beta): because that data is collected by us directly from the individual, not passed to us by the customer, we display our own short notice on that page at the point of collection (rather than relying solely on the customer's own Art. 13/14 notice, which that individual will typically never have seen) — this does not change the controller/processor allocation in Section 1, only who physically displays the notice;

(g) at the customer's choice, delete or return all personal data at the end of the engagement, and delete existing copies unless law requires storage;

(h) make available to the customer all information necessary to demonstrate compliance with this Article, and allow for and contribute to audits, including inspections, conducted by the customer or an auditor mandated by the customer, on reasonable notice.

4. Sub-processors

We use the sub-processors listed in our Privacy Policy (Google Earth Engine, Nominatim/OpenStreetMap Foundation, Google Cloud Platform), each scoped to the specific, narrow data described there. The customer authorizes these named sub-processors as of the date of this agreement. We will not engage a new sub-processor without giving the customer reasonable prior notice and an opportunity to object.

5. Security of processing and retention

No relational database of screening results exists. A screening result and its generated PDF report are stored for 30 days on a schedule enforced by automatic, policy-based deletion, then permanently and irreversibly deleted — not retained indefinitely, and not manually curated. The only other persistent artifacts are a size-capped geocode cache and per-customer access records, neither of which constitute a retained copy of a customer's supplier list.

Continuous Compliance Monitoring (Beta) is the one opt-in exception: if the customer explicitly subscribes a supplier list to recurring re-checks, that list (and the alert recipient email) is retained for the life of the subscription plus 90 days after cancellation, then automatically and permanently deleted on the same policy-based schedule — see Privacy Policy Section 5. A customer who does not use this feature is unaffected; every result it produces is itself an ordinary screening result, still subject to the 30-day rule above.

6. Data subject rights assistance

A request received while a result is still within its 30-day window is actioned by deleting that result directly, on request, rather than waiting for the automatic deletion schedule. After 30 days, most requests are resolved by confirming no server-side copy remains beyond what the customer already controls (their own downloaded files). Requests touching the geocode cache or an access record are actioned manually.

7. International transfers

See our Privacy Policy, Section 7 — Google-operated sub-processors may involve data leaving the EU/EEA/Switzerland under Google's own transfer safeguards.

8. Term

This DPA applies for as long as the underlying Terms of Service apply, and survives their termination to the extent needed to complete deletion/return obligations under Section 3(g).

9. Liability

Nothing in this DPA expands the liability limitations set out in our Terms of Service (Section 8); this DPA allocates data-protection-specific responsibilities, not general contractual liability.

10. Governing law and acceptance

This DPA is governed by the same governing law and jurisdiction clause as our Terms of Service (Section 13). It is accepted by the customer alongside the Terms of Service — for a paying customer, by engaging our services after receiving both documents; for a pilot customer, by a short written or emailed confirmation before any real (non-demo) data is uploaded. No separate signature process is required for each individual screening run once accepted.

Screening only: not a compliance certification. This tool checks satellite forest-cover signals against the EUDR cutoff date (31 December 2020); it does not replace field verification or a formal Article 10/11 due diligence statement. GREEN does not mean compliant: it means no problem was detected at this resolution. Agroforestry and shade-grown plots can trigger false-positive RED flags on coarse satellite baselines.
Data sources: European Commission Joint Research Centre (JRC Global Forest Cover 2020, JRC Tropical Moist Forest) · USGS/NASA and University of Maryland (Hansen Global Forest Change) · Global Forest Watch / Wageningen University (RADD, GLAD-L, GLAD-S2 near-real-time alerts) · WWF HydroSHEDS (watercourse proximity) · Copernicus/ESA Sentinel-2 (before/after imagery, cloud probability) · Esri, i-cubed, USDA, USGS, AEX, GeoEye, Getmapping, Aerogrid, IGN, IGP, UPR-EGP, and the GIS User Community (map tiles) · OpenStreetMap contributors (geocoding via Nominatim). Country risk tiers: Commission Implementing Regulation (EU) 2025/1093.
Terms of Service Privacy Policy Data Processing Agreement Legal Notice