EUDR Screening
Log in
  • How it works
  • Commodities
  • Supplier locations
  • Method
  • Pricing
  • About

Data Processing Agreement

Effective date: 26 August 2026. This is an appendix to our Terms of Service, governing the processing of personal data handled through the Service.


1. Roles

For the personal data of a customer's own suppliers (names, addresses, coordinates) contained in files the customer uploads to the Service, the customer is the controller and Gian-Luca Kaufmann, trading as EUDR Screening is the processor, within the meaning of GDPR Art. 4(7)/4(8) and, where applicable, the Swiss FADP's equivalent terms.

2. Subject matter, duration, nature and purpose of processing

  • Subject matter: processing of supplier location and identifying data provided through the Service for screening and the optional case-workspace, monitoring, collection, producer-profile, flag-resolution, and internal shipment-reference features described below.
  • Duration: for the life of the customer's engagement with the Service, subject to the retention limits in Section 5 below.
  • Nature and purpose: automated geospatial analysis for either the customer's EUDR-compliance purpose or its voluntary buyer, procurement, audit-support, or internal deforestation-screening purpose; optional geocoding; rendering results, coverage, provenance, and limitations into tables, maps, reports, and purpose-scoped cases; and providing the optional ongoing services named above. No secondary use, advertising use, resale, or model-training purpose is authorized.
  • Types of personal data: supplier/company name, address, geographic coordinates or plot boundary, country, optional lot identifier. The company supplier/product catalog can add supplier reference, contact name/email and notes, plus product reference, relevant commodity, CN code, origin country and notes. Persistent cases add, only where a customer creates one: a case name and notes, supplier name/reference, product/commodity/CN code, country of production, quantity/unit, production period, EU market-placement/export date, internal workflow stage, linked-screening summaries, structured Article 2(40) legality-category conclusions and reasoning, reviewer/attestation details, uploaded legality evidence, and the versioned result CSV/case snapshot/hash manifest/PDF evidence described in Section 5. Continuous Monitoring (Beta) adds, only if the customer opts in: a retained copy of the above for the life of a subscription (Section 5), and, only if the customer sends a "resolve this flag" link and the recipient chooses to respond, a photo, a corrected GPS location, and/or a written note submitted directly by that individual. Supplier data-collection share-links and the Producer Portal (Beta) add, only where a customer uses that feature: a supplier/farmer's submitted name, GPS or free-text location, optional lot/commodity/note, a persistent producer profile identifier, and an optional legality/land-tenure document the producer attaches themselves. A submission with a usable location is also run automatically through the satellite screening engine and receives a preliminary risk badge visible only to the customer. That badge is a risk signal, not a compliance decision or the paid screening report (Privacy Policy Section 3). Internal shipment references (Beta) add, only where a customer explicitly creates one: the customer-entered or generated internal reference and note, plus a bounded snapshot of supplier name, country, commodity, lot ID, satellite flag, and hashed plot identity for the linked plots. No special-category data is knowingly processed, though a submitted photo or document may incidentally show identifiable details (e.g. a person's face) if the submitter chooses to include them.
  • Categories of data subjects: the customer's suppliers (which may include sole traders or smallholder farmers who are natural persons), and, for "resolve this flag" submissions and supplier data-collection/Producer Portal submissions specifically, whichever individual contact the customer's link reaches and who chooses to respond or submit, collected directly from that person, not uploaded by the customer (see Privacy Policy Section 3's note on this).

3. Processor obligations

We agree to:

(a) process personal data only on the customer's documented instructions, unless required to do otherwise by EU or Swiss law, in which case we will inform the customer of that legal requirement first, unless prohibited from doing so;

(b) ensure persons authorized to process the data are bound by confidentiality;

(c) implement appropriate technical and organizational security measures;

(d) respect the conditions in Section 4 for engaging any further processor;

(e) assist the customer, taking into account the nature of processing, in responding to data subject rights requests;

(f) assist the customer with its own security, breach-notification, and impact-assessment obligations. Because the customer is the controller for its suppliers' personal data, the customer is responsible for giving those suppliers the information required under Art. 13/14 GDPR. In practice, this should mention that a screening processor is engaged for this purpose; we will provide the factual detail needed on request. Direct supplier submissions (Beta): because collection, Producer Portal, and "resolve this flag" data is collected by us directly from the individual, not passed to us by the customer, we display our own short notice at the point of collection. This does not change the controller/processor allocation in Section 1, only who physically displays the notice;

(g) at the customer's choice, delete or return personal data at the end of the engagement, and delete existing copies unless law requires storage. Case evidence that the customer instructed us to preserve for the Section 5 effective deadline remains downloadable and cannot be deleted early; after that deadline, any deletion is assessed through the reviewed process described there;

(h) make available to the customer all information necessary to demonstrate compliance with this Article, and allow for and contribute to audits, including inspections, conducted by the customer or an auditor mandated by the customer, on reasonable notice.

4. Sub-processors

We use the sub-processors listed in our Privacy Policy (Google Earth Engine, Nominatim/OpenStreetMap Foundation, Google Cloud Platform and Identity Platform, the user's selected Google or Microsoft sign-in provider, and Brevo), each scoped to the specific, narrow data described there. The customer authorizes these named sub-processors as of the date of this agreement. We will not engage a new sub-processor without giving the customer reasonable prior notice and an opportunity to object.

5. Security of processing and retention

No relational database of full screening results exists. A standalone screening result and its generated PDF report are stored for 30 days on a schedule enforced by automatic, policy-based deletion, then permanently and irreversibly deleted. The customer can separately instruct five-year storage by linking the screening to a persistent case, as described below. A size-capped geocode cache and company account, membership, audit, and hashed API-key records also persist as needed to operate and secure the Service. Company-account browser sessions last no more than five days and invitations expire after seven days. During the controlled migration, existing private access tokens and one-day legacy browser cookies may remain accepted until the customer and its integrations have moved; those credentials persist until revoked.

Continuous Monitoring (Beta) is one opt-in exception: if the customer explicitly subscribes a supplier list to recurring re-checks, that list (and the alert recipient email) is retained for the life of the subscription plus 90 days after cancellation, then automatically and permanently deleted on the same policy-based schedule. See Privacy Policy Section 5. A customer who does not use this feature is unaffected; every result it produces is itself an ordinary screening result, still subject to the 30-day rule above.

Supplier data-collection share-links and the Producer Portal (Beta) are a second exception, with no automated deletion job yet: a collection link stops accepting new submissions 90 days after creation, but the customer can still review and export submissions already collected. Submissions, producer profile identifiers, and attached legality/land-tenure documents are retained without an automatic expiry until the producer or customer requests deletion. The Producer Portal does not currently import an existing plot into a new buyer's collection request. See Privacy Policy Section 5.

Internal shipment references (Beta) are a third exception. Each retains a bounded plot snapshot, not the full screening result, until the customer deletes it directly from the Shipment references page or requests deletion. Deletion is immediate and permanent. Ownership is tied to a stable company identifier, so changing a user, session, or API key does not orphan the record. The source screening still expires after 30 days. See Privacy Policy Sections 3 and 5.

The company supplier/product catalog persists for the customer relationship or until a valid deletion instruction is actioned. Archiving is reversible and is not deletion. Each case retains a bounded snapshot, so editing catalog master data does not rewrite an older case or evidence version.

Persistent cases and their evidence archive are a fourth exception and an explicit documented instruction from the customer. Mutable workspace fields and current legality-assessment projections remain available for the engagement. Every screening version linked to a case is preserved as an append-only bundle containing the exact result CSV, case snapshot, SHA-256 manifest, and any generated PDF. Each structured legality-category save creates an append-only JSON revision, and supporting evidence files are create-only. These records can include the customer's conclusion, reasoning, reviewer/attestation details, and uploaded documents. Cloud Storage currently enforces a minimum 1,827-day period from upload; the policy is deliberately unlocked and remains administratively changeable, while application credentials have create/read access but no delete permission. The effective case deadline is the later of that storage floor, the recorded EU market-placement/export date plus the configured retention horizon (currently five years), or a customer extension. A manual extension can only move the deadline later. No automatic deletion rule is active; any later deletion process must first account for the effective deadline and legal holds. A refinement creates a new version rather than overwriting evidence. Archiving is reversible and is not deletion. Standalone working copies remain subject to the 30-day rule.

Deforestation-screening cases are a separate documented instruction and do not enter the EUDR five-year store. They default to deletion 12 months after case creation in a separate bucket/path without the 1,827-day floor. The customer may request earlier deletion or explicitly extend the deadline with a recorded business reason; passive use, archiving, and the marketing preference cookie do not extend it. At the effective deadline, the active case and evidence are deleted unless a documented extension or applicable legal hold exists. Google Cloud's restricted soft-delete recovery copy expires within seven days and is not available through the Service. Standalone deforestation-screening results remain subject to the ordinary 30-day rule.

6. Data subject rights assistance

A request received while a standalone result is still within its 30-day window is actioned by deleting that result directly rather than waiting for the automatic schedule. For an EUDR case snapshot, we assist the customer in assessing the request against its record-retention obligation; the active storage policy blocks ordinary early deletion. For a deforestation-screening case, we apply the customer's earlier deletion instruction unless a documented legal hold applies. Internal shipment references can be deleted directly by the customer; requests touching another persistent feature are actioned manually.

7. International transfers

See our Privacy Policy, Section 7. Google-operated sub-processors may involve data leaving the EU/EEA/Switzerland under Google's own transfer safeguards.

8. Term

This DPA applies for as long as the underlying Terms of Service apply, and survives their termination to the extent needed to complete deletion/return obligations under Section 3(g).

9. Liability

Nothing in this DPA expands the liability limitations set out in our Terms of Service (Section 8); this DPA allocates data-protection-specific responsibilities, not general contractual liability.

10. Governing law and acceptance

This DPA is governed by the same governing law and jurisdiction clause as our Terms of Service (Section 13). It is accepted by the customer alongside the Terms of Service: for a paying customer, by engaging our services after receiving both documents; for a pilot customer, by a short written or emailed confirmation before any real (non-demo) data is uploaded. No separate signature process is required for each individual screening run once accepted.

Screening only, not certification. Results support, but do not replace, your own due diligence. Scope and limits
Sources: JRC, Hansen/UMD, GFW/Wageningen, Copernicus/ESA, WWF HydroSHEDS, Esri, and OpenStreetMap. Full attribution
Terms of Service Privacy Policy Data Processing Agreement Legal Notice