Privacy Policy
Effective date: 12 July 2026.
1. Who we are and why this policy exists
Gian-Luca Kaufmann, trading as EUDR Screening ("we", "us"), based in Röntgenstrasse 87, 8005 Zurich, Switzerland, operates the EUDR Deforestation Risk Screening Tool at eudrscreening.com (the "Service"). This policy explains what personal data the Service processes, why, and what rights you have over it.
The Service is marketed to and used by EU-based business customers, and in the course of running a screening it processes data about those customers' suppliers — which can include the names and addresses of identifiable individuals (e.g. a sole-trader or smallholder farmer). This policy covers both.
2. Why GDPR and the Swiss FADP both apply
We are established in Switzerland, not the EU. Two things bring EU data protection law into play:
- GDPR Art. 3(2)(a) reaches a non-EU business whenever its processing relates to offering goods or services to people in the EU — regardless of where the business itself is established. This Service is marketed specifically to EU SME importers.
- The Swiss Federal Act on Data Protection (FADP) applies independently as the law of our own place of establishment.
Where the two regimes differ, we apply whichever is more protective of the data subject.
3. What we process, and why
Two different roles apply. For the supplier data a customer uploads (names, addresses, coordinates), the customer is the controller and we are the processor, acting only on the customer's documented instructions (see our Data Processing Agreement). The customer is responsible for its own legal basis for collecting and sharing that data with us. For a distinct, smaller category of data — a customer's own contact details, used to run the commercial relationship itself — we are the controller.
| Data | Source | Our role | Purpose |
|---|---|---|---|
| Supplier name, address, coordinates, country, lot ID, plot boundary | Uploaded directly by the customer | Processor | Running the deforestation risk screening the customer requested |
| Geocode query text (address or name + country) | Derived from the above, only for rows without coordinates | Processor | Resolving an approximate location via Nominatim/OpenStreetMap |
| Customer contact details (name, email) for access | Provided at onboarding | Controller | Granting and managing access to the Service |
| Notification email address (optional, per screening run) | Entered directly by the user submitting that run, only if they choose to | Controller | Sending a link to that run's own results once screening or a report is ready. Never required, never reused for any other purpose, and not linked to any account. |
| Continuous Compliance Monitoring subscription (Beta, opt-in only): a retained copy of a supplier list plus a recipient email address | Created only when a customer explicitly clicks "Subscribe to Beta Monitoring" on a completed results page | Processor (the retained supplier list) / Controller (the recipient email address itself) | Re-running the same screening on a schedule (weekly/annual) and emailing the customer when a plot's status changes. Nothing here is collected or retained for any customer who doesn't take this explicit opt-in action — see Section 5. |
| "Resolve this flag" evidence (Beta, opt-in only): a photo, a corrected GPS location, and/or a written note | Submitted directly by a supplier/farmer contact, via a link a customer chooses to send them about one specific flagged plot | Processor | Giving the customer evidence of their own Article 10 investigation into a flagged plot. A photo may show identifiable details (e.g. a person's face) if the submitter chooses to include them. |
We do not process any special-category data (Art. 9 GDPR) by design — supplier records are business/location data, not health, biometric, or similarly sensitive information.
A note on the "resolve this flag" row above, since it works differently from every other row in this table: it is the only data we collect directly from the individual it's about, rather than from our customer. That individual has typically never seen our customer's own privacy notice or interacted with our customer's systems at all — they only ever see our resolve page, which is why that page carries its own short, plain-language notice (what's collected, why, who sees it, how long it's kept) rather than relying on this policy alone to reach them. We remain a processor for this data, on the same basis as the rest of a customer's supplier data: it exists to serve that customer's own due-diligence process, is shown only to them, and is never used, published, or sold for anything else.
4. What we do NOT do
We do not sell, rent, or otherwise monetize uploaded data. We do not build models, analytics, or aggregate statistics from customer-uploaded supplier lists. We do not track customers' usage of their own supplier data beyond what's needed to run and deliver the screening they asked for.
5. Retention
A screening result (and the generated PDF report, if you request one) is stored for 30 days, then automatically and permanently deleted — there is no server-side database of past results, and no way for us to look up what you screened after that window closes. If you need to keep a result longer than that (for example, as part of your own EUDR due-diligence records, which the Regulation requires you to retain for 5 years), download it before the 30 days are up; that copy is yours to manage from there. The only other persistent artifacts under our control are (a) a geocode cache (query text → resolved coordinates, size-capped), and (b) per-customer access records, which exist until access is revoked.
Continuous Compliance Monitoring (Beta) is the one exception to the 30-day window, and only for customers who explicitly opt into it. Subscribing to monitoring keeps a copy of that supplier list, and the recipient email address for alerts, for as long as the subscription is active, plus 90 days after it is cancelled (a bounded window in case you want to reactivate or need a final record, not a permanent archive). Cancelling a subscription (or simply never creating one) means this exception never applies to you — every other part of the Service still follows the 30-day rule above. Each re-check this feature runs also creates an ordinary screening result, itself still governed by the 30-day rule.
6. Who we share data with (sub-processors)
- Google Earth Engine — receives coordinates or plot boundaries only, never names/addresses/countries.
- Nominatim (OpenStreetMap Foundation) — receives the minimum geocode query text, only for rows missing coordinates.
- Google Cloud Platform — hosts the Service (compute, storage, logging).
- SendGrid (Twilio Inc.) — receives a notification email address only if a user chooses to provide one for a given screening run, used solely to deliver that run's own "your results are ready" email.
We do not use any sub-processor beyond these four. If that changes, this policy and our Data Processing Agreement will be updated first.
7. International data transfers
Google Cloud Platform and Google Earth Engine are operated by Google LLC, a US-based provider; our infrastructure is deployed in the europe-west1 (EU) region. Where personal data is transferred outside the EU/EEA/Switzerland as a result, this relies on Google's own Standard Contractual Clauses or equivalent transfer mechanism as a Google Cloud customer.
8. Your rights
If you are our direct customer: subject to GDPR Art. 15–21 and the FADP's equivalent provisions, you have the right to request access to, correction of, or erasure of your personal data, and to object to or restrict our processing of it. Contact contact@eudrscreening.com.
If you are a supplier or other individual whose name, address, or location data was uploaded by one of our customers — or whose photo, corrected location, or note you submitted yourself via a "resolve this flag" link: because that customer is the controller for that data either way (see Section 3), the correct first point of contact for exercising your rights is that customer. If you contact us directly at contact@eudrscreening.com, we will identify which of our customers appears to be the relevant one, where we can, and assist that customer in responding — including deleting a resolve-link submission on request.
You also have the right to lodge a complaint with a supervisory authority — in the EU, the data protection authority of your own Member State; in Switzerland, the Federal Data Protection and Information Commissioner (FDPIC).
9. Automated screening results
The RED/AMBER/GREEN/CANNOT_SCREEN flag and the accompanying context (due-diligence tier, data quality, nearby-pressure tier) are produced by fixed, rule-based logic over satellite data, not a trained or self-learning model. We do not consider this automated decision-making producing a legal or similarly significant effect on the supplier within the meaning of Art. 22 GDPR: the output is a screening signal delivered to our customer, who applies its own judgment before taking any action.
10. EU representative
We will designate an EU representative under GDPR Art. 27 as our processing of EU customer data becomes an ongoing, regular commercial activity — no later than our first paying customer. Once designated, their name and contact details will be added here.
11. Data breach notification
We follow a documented contain/assess/notify/document process, and will notify the relevant supervisory authority within 72 hours where required under GDPR Art. 33, and affected customers directly where a breach is likely to result in high risk to them (Art. 34).
12. Changes to this policy
This policy is reviewed periodically for legal and regulatory accuracy and may be updated as the Service evolves. Material changes will be reflected here with an updated effective date, and for any customer with an active paid or pilot engagement we will additionally notify by email before a material change takes effect.
13. Contact
contact@eudrscreening.com — Gian-Luca Kaufmann, trading as EUDR Screening, Röntgenstrasse 87, 8005 Zurich, Switzerland.