Privacy Policy
Last updated: March 2026
1. Data Controller
European Foundation for Sustainability and Innovation ("EuFSI", "we", "us") is the data controller for personal data processed through the EuFSI DPP Platform. We are registered in the Netherlands and comply with the EU General Data Protection Regulation (GDPR).
2. Data We Collect
We collect personal data you provide when registering an account (name, email, company information), data generated through platform usage (product data, supply chain information), and technical data (IP address, browser type, access logs).
3. Legal Basis
We process personal data on the basis of: (a) contract performance — to provide the DPP Platform services; (b) legitimate interest — to improve our services and ensure security; (c) legal obligation — to comply with EU regulations including ESPR and GDPR; (d) consent — for optional communications.
4. Data Processing Agreement
A Data Processing Agreement (DPA) is included with all subscription plans. The DPA governs our processing of your company's product and supply chain data in accordance with GDPR Article 28.
5. Your Rights
Under GDPR, you have the right to access, rectify, erase, restrict processing, data portability, and object to processing of your personal data. You may also withdraw consent at any time. To exercise these rights, contact us at privacy@eufsi.com.
6. Data Retention
We retain personal data for as long as your account is active or as needed to provide services. Upon account deletion, personal data is erased within 30 days, subject to legal retention requirements.
7. Sub-processors
We engage the following sub-processors to deliver the platform. Each one operates under a GDPR Art. 28 Data Processing Agreement and an appropriate transfer mechanism (EU adequacy, Standard Contractual Clauses, or both). The canonical list is maintained in our internal sub-processor register and synchronised here quarterly.
- Google Cloud (Google Cloud EMEA Ltd) — production compute, object storage, database backups, and key management, all in an EU region.
- Resend (RT Labs Inc) — transactional email delivery (US/EU edge).
- Sentry (Functional Software, Inc.) — error monitoring with PII scrubbing (EU project).
- OpenAI, LLC — AI document extraction, opt-in only per controller consent (US, with EU Data Residency add-on).
- Anthropic, PBC — AI document extraction (opt-in, as above) and machine translation of passport content, per platform provider configuration (US).
- DeepL SE — machine translation of passport content, per platform provider configuration (Germany, EU).
The full list with DPA URLs and transfer mechanisms is available on request to privacy@eufsi.com.
8. Infrastructure Jurisdiction and International Access (Data Act Art. 28)
The ICT infrastructure used to process data for all platform services is deployed in a European Union region (Google Cloud, EU) and is subject to the jurisdiction of the European Union and, for the provider entity, the Netherlands.
Measures against international governmental access or transfer of non-personal data held in the Union that would conflict with Union or Member State law: EU-region-only hosting with no third-country replication of production data; encryption key custody in Google Cloud KMS (EU); contractual GDPR Art. 28 and transfer-mechanism terms with every sub-processor; and a request-handling procedure under Data Act Art. 32 — any third-country authority request is assessed against Union law, answered with the minimum permissible data if at all, and the affected customer is informed before compliance except where a sealed law-enforcement purpose lawfully prevents it.