EUDR Screening
Log in
  • How it works
  • Commodities
  • Supplier locations
  • Method
  • Pricing
  • About

Privacy Policy

Effective date: 26 August 2026.


1. Who we are and why this policy exists

Gian-Luca Kaufmann, trading as EUDR Screening ("we", "us"), based in Röntgenstrasse 87, 8005 Zurich, Switzerland, operates the EUDR Deforestation Risk Screening Tool at eudrscreening.com (the "Service"). This policy explains what personal data the Service processes, why, and what rights you have over it.

The Service is marketed to businesses using either its EUDR-compliance or broader deforestation-screening purpose. In running either purpose it may process supplier data that identifies individuals, such as sole traders or smallholder farmers. This policy covers both.

2. Why GDPR and the Swiss FADP both apply

We are established in Switzerland, not the EU. Two things bring EU data protection law into play:

  • GDPR Art. 3(2)(a) reaches a non-EU business whenever its processing relates to offering goods or services to people in the EU, regardless of where the business itself is established. This Service is marketed specifically to EU SME importers.
  • The Swiss Federal Act on Data Protection (FADP) applies independently as the law of our own place of establishment.

Where the two regimes differ, we apply whichever is more protective of the data subject.

3. What we process, and why

Two different roles apply. For the supplier data a customer uploads (names, addresses, coordinates), the customer is the controller and we are the processor, acting only on the customer's documented instructions (see our Data Processing Agreement). The customer is responsible for its own legal basis for collecting and sharing that data with us. For a distinct, smaller category of data (a customer's own contact details, used to run the commercial relationship itself), we are the controller.

Data Source Our role Purpose
Supplier name, address, coordinates, country, lot ID, plot boundary Uploaded directly by the customer Processor Running the deforestation risk screening the customer requested
Functional mode preference (eudr or deforestation) Selected by the visitor and stored in a first-party cookie for up to six months Controller Remembering which public-site purpose the visitor selected. It contains no supplier data, coordinates, or stable visitor identifier.
Geocode query text (address or name + country) Derived from the above, only for rows without coordinates Processor Resolving an approximate location via Nominatim/OpenStreetMap
Company account data: verified work email, display name, company name, membership and role, invitation status, session/security timestamps, and bounded access audit events Provided during onboarding/sign-in or generated when access is managed Controller Authenticating a user, enforcing company access, administering users and scoped API keys, and investigating security events
Company supplier/product catalog: supplier name/reference, contact name/email, country and notes; product name/reference, relevant commodity, CN code, origin country and notes Entered by an authorized company user or migrated from an existing case Processor Reusing the customer's supply-chain master data across cases while preserving a separate case snapshot for historical evidence
Notification email address (optional, per screening run) Entered directly by the user submitting that run, only if they choose to Controller Sending a link to that run's own results once screening or a report is ready. Never required, never reused for any other purpose, and not linked to any account.
Continuous Monitoring subscription (Beta, opt-in only): a retained copy of a supplier list plus a recipient email address Created only when a customer explicitly clicks "Subscribe to Continuous Monitoring" on a completed results page Processor (the retained supplier list) / Controller (the recipient email address itself) Re-running the same screening on a schedule (weekly/annual) and emailing the customer when a plot's status changes. Nothing here is collected or retained for any customer who doesn't take this explicit opt-in action (see Section 5).
"Resolve this flag" evidence (Beta, opt-in only): a photo, a corrected GPS location, and/or a written note Submitted directly by a supplier/farmer contact, via a link a customer chooses to send them about one specific flagged plot Processor Giving the customer evidence of their own Article 10 investigation into a flagged plot. A photo may show identifiable details (e.g. a person's face) if the submitter chooses to include them.
Supplier data-collection share-link submissions (Beta, opt-in only): a name, GPS location or free-text location description, and optional country/commodity/lot/note Submitted directly by a supplier/farmer contact, via a link (or QR code) a customer creates and distributes themselves Processor Letting a customer collect plot location data from suppliers who haven't digitized it, without requiring them to install an app or hold an account. A submission with a usable location is run automatically through the satellite screening engine and receives a preliminary risk badge, visible to the customer reviewing that collection (never to the submitting supplier). The badge is a risk signal, not a compliance decision or the paid screening report. It is not included in the collection CSV export.
Producer Portal identity and legality/land-tenure documents (Beta, opt-in only): a persistent access identifier (not a login), plus an optional permit/title/land-use document a producer attaches to one of their own plot submissions Created automatically the first time a supplier/farmer contact submits via any collection link; the document is uploaded directly by that same contact via their own persistent producer page Processor Giving a producer a durable, bookmarkable record of submissions and supporting-document status. Anyone who receives the private page URL can view the plot details shown there. The page does not currently import an existing plot into a new buyer's collection request; each new buyer's link requires a fresh submission. A legality document is never OCR'd, parsed, or automatically evaluated. It is stored for the customer's own manual review.
Work email address and company name (sample report download) Submitted directly by a visitor requesting the downloadable sample report at /sample-report Controller Verifying a genuine business visitor before releasing the sample PDF, and following up about the Service. The report itself is delivered immediately as a direct download link in the same response, never sent by email to the address provided. Retained as a sales lead record until the visitor asks us to delete it.
Internal shipment reference (Beta, opt-in only): a customer-entered or generated reference and note, plus a bounded snapshot of the linked plots' supplier name, country, commodity, lot ID, satellite flag, and hashed plot identity Created only when a customer explicitly saves a reference from a completed screening result Processor Letting the customer find the same saved plot set for a later shipment. This is an internal lookup convenience only. It is not an official Due Diligence Statement reference number, is not submitted to TRACES NT or the EU Information System, and cannot itself be used for Article 8a grouping.
Persistent case workspace and evidence archive (opt-in): stored purpose, case name/notes, supplier/product/commodity/origin context, production period, linked-screening summaries, versioned result/case/manifest/report evidence, and review records; EUDR cases may additionally contain CN code, quantity, market/export date, scope/role, Articles 9-11 workflow, legality conclusions and evidence, and DDS-preparation fields Entered by the customer or created when the customer attaches a screening Processor Keeping a purpose-scoped evidence record. EUDR cases follow the five-year record profile. Deforestation-screening cases document supplied scope, checked signals, coverage gaps, review decisions, provenance, and limitations without presenting an EUDR workflow or compliance verdict.
Case risk-resolution records (opt-in): for a specific RED/AMBER finding within a case, the customer's recorded decision (exclude the plot, or accept the explanation), investigation notes, and any supporting evidence file; and, only if the customer chooses to request supplier clarification, a note/corrected GPS location/photo submitted directly by the flagged supplier via a one-off link Entered by the customer directly on the case's Risk resolutions page, or (the supplier's own response only) submitted directly by a supplier/farmer contact via a link the customer chooses to send Processor Recording what was investigated and decided for a specific documented finding, as part of the customer's Article 10 due-diligence record for that case. This clears the matching review flag on the case's readiness view; it is not a compliance certification and nothing is submitted to TRACES NT or any authority. A supplier's response alone never resolves a finding — the customer still records the final decision. Case-linked supplier evidence here follows the same five-year case-archive retention as the rest of the case, not the shorter window used by the separate Continuous Monitoring "resolve this flag" row above.

We do not ask for special-category data under Art. 9 GDPR. Users should not upload health, biometric, religious, political, or similarly sensitive information. A photo or supporting document could incidentally contain such details, so submitters are asked to include only what is necessary for the buyer's review.

A note on the "resolve this flag" and share-link rows above, since they work differently from every other row in this table: these are the only data we collect directly from the individual it's about, rather than from our customer. That individual has typically never seen our customer's own privacy notice or interacted with our customer's systems at all. They see our short, plain-language notice on the resolve or collection page, including the automatic preliminary satellite screen and the retention described below. We remain a processor for this data, on the same basis as the rest of a customer's supplier data. It exists to serve that customer's own due-diligence process and is never sold or used to train a model. A producer controls who receives their private-page URL; anyone with that URL can view the plot details displayed there.

4. What we do NOT do

We do not sell, rent, or otherwise monetize uploaded data. We do not build models, analytics, or aggregate statistics from customer-uploaded supplier lists. We do not track customers' usage of their own supplier data beyond what's needed to run and deliver the screening they asked for.

5. Retention

A standalone screening result (and the generated PDF report, if requested) is stored for 30 days, then automatically and permanently deleted. We cannot retrieve that standalone copy after the window closes. Deliberate use of the persistent case workspace instructs us to create the long-lived screening and/or legality evidence records described below. A size-capped geocode cache (query text → resolved coordinates) and company account, membership, audit, and API-key metadata also persist as needed to operate and secure the Service. Company-account browser sessions last no more than five days; invitations expire after seven days and are single-use. API-key secrets are stored only as hashes. During the controlled account migration, an existing private access token and its one-day legacy browser cookie may remain accepted until that company and its integrations have moved; those credentials remain until revoked.

Continuous Monitoring (Beta) is an exception to the 30-day window, and only for customers who explicitly opt into it. Subscribing to monitoring keeps a copy of that supplier list, and the recipient email address for alerts, for as long as the subscription is active, plus 90 days after it is cancelled (a bounded window in case you want to reactivate or need a final record, not a permanent archive). Cancelling a subscription (or simply never creating one) means this exception never applies to you; every full screening result still follows the 30-day rule above. Each re-check this feature runs also creates an ordinary screening result, itself still governed by the 30-day rule.

Supplier data-collection share-links (Beta, opt-in only): a collection link stops accepting new submissions 90 days after creation. Submissions already collected stay available to the customer for review and export until they revoke their own access to the Service; we do not yet run an automatic deletion job for this data, so if you want a specific submission deleted sooner, contact us at contact@eudrscreening.com.

Producer Portal identity and legality/land-tenure documents (Beta, opt-in only): a producer's profile identifier and submissions linked to it are retained without an automatic expiry so the producer's private record remains available, until the producer or a customer with a legitimate reason asks us to delete it. A legality document attached to a submission is retained the same way, with no automatic deletion job yet. To delete a specific document, submission, or profile, contact us at contact@eudrscreening.com.

Internal shipment references (Beta, opt-in only): each reference retains only the bounded plot snapshot described in Section 3, not the full screening result. It remains available to the same company across user, session, or API-key changes until the customer deletes it directly from the Shipment references page or asks us to delete it. Deletion from that page is immediate and permanent. The original screening result still expires after 30 days.

Company supplier/product catalog: reusable supplier and product records remain available for the customer relationship or until a valid deletion instruction is actioned. Archiving hides a record from active selection but is reversible and is not deletion. Cases retain their own snapshot, so later catalog edits do not rewrite protected evidence.

Persistent cases and their evidence archive (opt-in only): mutable workspace fields and current legality-assessment views remain available for the customer relationship. Linking or launching a screening from a case creates an append-only evidence snapshot containing the exact result CSV, the case fields at that point, a SHA-256 manifest, and any PDF generated for that version. Each legality-category save also creates an append-only JSON revision, and each supporting file is added without overwriting an earlier file. Cloud Storage currently protects these case-evidence objects for at least 1,827 days from upload under an active but administratively changeable, unlocked retention policy. When the customer records the actual EU market-placement/export date, the Service calculates the case deadline as at least five years from that date, or the storage floor if later; a manual extension can only move that deadline later. The retention horizon can be raised if regulatory or contractual requirements change. There is no automatic deletion rule: deletion after the effective deadline requires a future reviewed process that accounts for extensions and legal holds. A corrected location or assessment creates a new version and preserves the earlier one. This is the customer's documented instruction to retain the record for its EUDR due-diligence obligations. Archiving a case only removes it from the active workspace and is reversible; it is not deletion. Standalone working copies still expire after 30 days. Case ownership is tied to the stable company record so changing users, sessions, or API keys does not orphan it.

Deforestation-screening cases (opt-in only) use a separate storage path and bucket without the EUDR 1,827-day floor. Their explicit default deadline is 12 months from case creation. The customer may shorten it through a deletion instruction or extend it by choosing a later date and recording a business reason. An extension is never inferred from use, archiving, or the public-site mode cookie. At the effective deadline the active case and evidence are deleted unless a documented extension or applicable legal hold exists. Google Cloud's restricted soft-delete recovery copy then expires within seven days and is not available through the Service. The deadline is visible in the workspace and exports. Standalone deforestation screenings remain on the ordinary 30-day schedule.

Case risk-resolution records (opt-in only): a decision, note, and any evidence recorded against one finding follow the same case archive and retention as the rest of the case (at least five years from upload or from the recorded market-placement/export date, whichever is later; no automatic deletion). A supplier's response, submitted through a one-off link the customer creates, is added to the same case record; that link expires 30 days after it is created.

6. Who we share data with (sub-processors)

  • Google Earth Engine: receives coordinates or plot boundaries only, never names/addresses/countries.
  • Nominatim (OpenStreetMap Foundation): receives the minimum geocode query text, only for rows missing coordinates.
  • Google Cloud Platform and Identity Platform: host the Service and verify account identities/sessions.
  • Google or Microsoft sign-in: if the user chooses that provider, it verifies the identity and work email used for the company account. Email/password users do not use either provider for sign-in.
  • Brevo (EU-hosted): receives a notification email address only if a user chooses a result notification or monitoring alert, used solely to deliver that requested message.

We do not use another sub-processor for these data flows. If that changes, this policy and our Data Processing Agreement will be updated first.

7. International data transfers

Google Cloud Platform and Google Earth Engine are operated by Google LLC, a US-based provider; our infrastructure is deployed in the europe-west1 (EU) region. Where personal data is transferred outside the EU/EEA/Switzerland as a result, this relies on Google's own Standard Contractual Clauses or equivalent transfer mechanism as a Google Cloud customer.

8. Your rights

If you are our direct customer: subject to GDPR Art. 15–21 and the FADP's equivalent provisions, you have the right to request access to, correction of, or erasure of your personal data, and to object to or restrict our processing of it. Contact contact@eudrscreening.com.

If you are a supplier or other individual whose name, address, or location data was uploaded by one of our customers, or who submitted data through a collection, producer, or "resolve this flag" link: because that customer is the controller for that data (see Section 3), the correct first point of contact for exercising your rights is that customer. If you contact us directly at contact@eudrscreening.com, we will identify the relevant customer where we can and assist them in responding. Some case evidence may need to remain for the customer's legally required EUDR record; the customer must assess that retention against the request. Other submissions, profiles, documents, resolve-link responses, and internal shipment references can be deleted on a valid instruction.

You also have the right to lodge a complaint with a supervisory authority: in the EU, the data protection authority of your own Member State; in Switzerland, the Federal Data Protection and Information Commissioner (FDPIC).

9. Automated screening results

The RED/AMBER/GREEN/CANNOT_SCREEN flag and the accompanying context (due-diligence tier, data quality, nearby-pressure tier) are produced by fixed, rule-based logic over satellite data, not a trained or self-learning model. We do not consider this automated decision-making producing a legal or similarly significant effect on the supplier within the meaning of Art. 22 GDPR: the output is a screening signal delivered to our customer, who applies its own judgment before taking any action.

10. EU representative

We will designate an EU representative under GDPR Art. 27 as our processing of EU customer data becomes an ongoing, regular commercial activity, no later than our first paying customer. Once designated, their name and contact details will be added here.

11. Data breach notification

We follow a documented contain/assess/notify/document process, and will notify the relevant supervisory authority within 72 hours where required under GDPR Art. 33, and affected customers directly where a breach is likely to result in high risk to them (Art. 34).

12. Changes to this policy

This policy is reviewed periodically for legal and regulatory accuracy and may be updated as the Service evolves. Material changes will be reflected here with an updated effective date, and for any customer with an active paid or pilot engagement we will additionally notify by email before a material change takes effect.

13. Contact

contact@eudrscreening.com. Gian-Luca Kaufmann, trading as EUDR Screening, Röntgenstrasse 87, 8005 Zurich, Switzerland.

Screening only, not certification. Results support, but do not replace, your own due diligence. Scope and limits
Sources: JRC, Hansen/UMD, GFW/Wageningen, Copernicus/ESA, WWF HydroSHEDS, Esri, and OpenStreetMap. Full attribution
Terms of Service Privacy Policy Data Processing Agreement Legal Notice