Introduction
1.1 Who We Are. Prduct ApS (“Prduct,” “we,” “us,” “our”) provides a cloud-based platform for product data management and supply chain compliance. Our registered office is at Universitetsbyen 71, 8000 Aarhus C, Denmark (CVR: 39368226).
1.2 This Policy. This Privacy Policy explains how we collect, use, share, and protect personal information when you:
- Visit our website (prduct.com)
- Use our Platform
- Interact with us
1.3 Your Rights. You have rights regarding your personal information. See Section 9 for details.
1.4 Contact. Questions about privacy can be sent to our Data Protection Officer: dpo@prduct.com
Information We Collect
2.1Information You Provide
(a) Account Information:
- Name, email address, phone number
- Company name, job title
- Password (stored encrypted)
- Profile information
(b) Business Contact Information:
- Supplier/customer contact details you add to the Platform
- Names and emails of supply chain partners
- Business relationship data
(c) Product Data:
- Product specifications, compliance documents, certifications
- Please note. This is business data about products, not personal information about individuals
(d) Communications:
- Messages and chats within the Platform
- Support requests and correspondence
- Feedback and survey responses
(e) Payment Information:
- Billing address, VAT number
- Payment information processed by third-party payment processors (we do not store full credit card details)
2.2Information We Collect Automatically
(a) Usage Data:
- Pages visited, features used, time spent
- Search queries, filters applied
- Files uploaded/downloaded (metadata only)
- API calls made
(b) Device and Technical Data:
- IP address, browser type, operating system
- Device identifiers
- Referring URLs
- Time zone, language preferences
(c) Cookies and Tracking: See Section 3.
2.3Information from Third Parties
(a) Authentication Services:
- If you use single sign-on (Google, Microsoft), we receive basic profile information (name, email)
(b) Public Databases:
- We may enrich company data from public business registries (CVR, Companies House, etc.)
(c) Supply Chain Partners:
- If you’re invited by another Platform user, we receive your business contact information from them
Cookies and Tracking Technologies
3.1What We Use:
(a) Essential Cookies: Required for Platform functionality (session management, security). Cannot be disabled.
(b) Functional Cookies: Remember your preferences (language, display settings). Can be disabled.
(c) Analytics Cookies: Help us understand usage patterns (Google Analytics or similar). Can be disabled.
(d) Marketing Cookies: Track website visits for advertising purposes. Can be disabled.
3.2 Cookie Management: Manage cookie preferences at prduct.com/cookies or through your browser settings.
3.3 Do Not Track. We respond to Do Not Track signals where legally required.
How We Use Your Information
4.1To Provide the Platform
- Create and manage your account
- Authenticate users and prevent fraud
- Process transactions and send invoices
- Enable communication with supply chain partners
- Store and manage your product data
- Generate compliance reports and analytics
Legal Basis: Performance of contract (GDPR Article 6(1)(b))
4.2To Communicate with You
- Respond to inquiries and support requests
- Send service announcements and updates
- Notify you of security issues or breaches
- Request feedback and surveys
Legal Basis: Performance of contract or legitimate interests (GDPR Article 6(1)(b) or (f))
4.3To Improve Our Services
- Analyze usage patterns and trends
- Develop new features and functionality
- Conduct research and analytics
- Train AI/ML models using anonymized data
Legal Basis: Legitimate interests (GDPR Article 6(1)(f))
4.4For Marketing (With Consent)
- Send newsletters and product updates
- Inform you of new features or modules
- Invite you to events or webinars
Legal Basis: Consent (GDPR Article 6(1)(a)), You can unsubscribe anytime
4.5For Legal Compliance
- Comply with legal obligations (tax, accounting)
- Respond to lawful requests from authorities
- Enforce our Terms of Use
- Protect our rights and property
Legal Basis: Legal obligation or legitimate interests (GDPR Article 6(1)(c) or (f))
How We Share Your Information
5.1Service Providers (Sub-processors)
We share information with trusted service providers who help us operate the Platform:
(a) Amazon Web Services (AWS): Cloud hosting and infrastructure (EU regions)
(b) Payment Processors: Process payments (they handle payment card data, not us)
(c) Email Service Providers: Send transactional and marketing emails
(d) Analytics Providers: Analyze usage and performance
(e) Customer Support Tools: Manage support tickets
Full list: prduct.com/data-processing-agreement/sub-processors
All service providers are contractually bound to protect your information and process it only as instructed.
5.2Supply Chain Partners
- If you’re connected to other Platform users, they can see information you choose to share with them
- You control what data is visible through Platform settings
- See Section 15 of the Terms of Use for the rules that apply to connected accounts
5.3Business Transfers
If we’re acquired or merge with another company, your information may transfer to the new entity. We’ll notify you of any such change.
5.4Legal Requirements
We may disclose information if required by law or to:
- Comply with legal process (subpoenas, court orders)
- Enforce our Terms of Use
- Protect our rights, property, or safety
- Prevent fraud or security threats
- Cooperate with law enforcement
5.5With Your Consent
We may share information for other purposes with your explicit consent.
We do not:
- Sell your personal information to third parties
- Share your data for third-party marketing without consent
- Disclose your data except as described in this Policy
International Data Transfers
6.1 Data Location. Your information is primarily stored in the EU (AWS Frankfurt/Ireland regions).
6.2 Transfers Outside EU. Some service providers may access data from outside the EU. For such transfers, we use:
- Standard Contractual Clauses (SCCs): EU-approved contracts ensuring adequate protection
- Adequacy Decisions: Transfers to countries deemed adequate by the EU Commission
- Additional Safeguards: Encryption, access controls, security measures
6.3 Your Rights. You can request copies of safeguards by contacting dpo@prduct.com.
Data Retention
7.1 Account Data: Retained while your account is active and for 90 days after closure (to allow reactivation).
7.2 Communications: Chat and message history retained for 90 days.
7.3 Product Data: Retained while your account is active. Deleted within 90 days after account closure.
7.4 Backups: Data in backups deleted per backup retention schedules (up to 365 days for Enterprise tier).
7.5 Legal Retention: Some information retained longer if required by law (e.g., invoices retained 5 years per Danish accounting law).
7.6 Anonymized Data: We may retain anonymized/aggregated data indefinitely for analytics and product improvement.
Security
8.1 Our Commitment. We implement appropriate technical and organizational measures to protect your information:
(a) Encryption: TLS 1.2+ for data in transit, encryption at rest via AWS
(b) Access Controls: Role-based access, 2FA available, strong password requirements
(c) Infrastructure Security: AWS EU hosting, firewalls, intrusion detection, DDoS protection
(d) Monitoring: Security logging, anomaly detection, regular security reviews
(e) Backups: Regular automated backups with geo-redundancy (Premium/Enterprise)
(f) Testing: Vulnerability scanning, penetration testing, security audits
8.2 ISO 27001. Our security controls are aligned with ISO 27001 standards (certification in progress).
8.3 More Details: See prduct.com/security for comprehensive security documentation.
8.4 No Guarantee. While we use industry-standard security, no system is 100% secure. You’re responsible for maintaining the security of your login credentials.
Your Rights (Gdpr)
If you’re in the EU/EEA, you have the following rights:
9.1 Right to Access: Request copies of your personal information.
9.2 Right to Rectification: Correct inaccurate information.
9.3 Right to Erasure (“Right to be Forgotten”): Request deletion of your information (subject to legal retention requirements).
9.4 Right to Restriction: Limit how we process your information.
9.5 Right to Data Portability: Receive your data in a machine-readable format (CSV/JSON).
9.6 Right to Object: Object to processing based on legitimate interests or for direct marketing.
9.7 Right to Withdraw Consent: Withdraw consent for marketing or other consent-based processing (doesn’t affect prior processing).
9.8 Right to Complain: Lodge a complaint with your local Data Protection Authority (Denmark: Datatilsynet, datatilsynet.dk).
9.9 Exercising Rights: Email dpo@prduct.com with your request. We’ll respond within 30 days. We may request identity verification to prevent fraud.
9.10 No Fee. Exercising your rights is free (unless requests are excessive or repetitive).
Children’s Privacy
10.1 Not for Children. The Platform is intended for business use only, not for individuals under 16.
10.2 No Knowing Collection. We do not knowingly collect information from children under 16. If we discover we’ve collected such information, we’ll delete it promptly.
10.3 Parent Notice. If you believe we’ve collected information from a child, contact dpo@prduct.com immediately.
Marketing and Communications
11.1 Marketing Emails. We may send marketing emails about new features, updates, or events if:
- You’ve consented (opted in), OR
- You’re an existing customer and we’re promoting similar services (soft opt-in permitted under Danish law)
11.2 Unsubscribe. Opt out anytime by:
- Clicking “unsubscribe” in any marketing email
- Adjusting preferences in your account settings
- Emailing dpo@prduct.com
11.3 Transactional Emails. You cannot opt out of essential service emails (account notifications, security alerts, invoices).
Third-Party Links
12.1 External Sites. The Platform may link to third-party websites (e.g., supplier websites, certification databases). We’re not responsible for their privacy practices.
12.2 Your Responsibility. Review privacy policies of any third-party sites you visit.
Changes to This Policy
13.1 Updates. We may update this Privacy Policy to reflect:
- Changes in our practices
- Legal or regulatory requirements
- New features or services
13.2 Notice. Material changes will be notified via:
- Email to your account email
- Prominent notice on prduct.com
- In-app notification
13.3 Effective Date. Changes take effect on the date posted. Continued use after changes means acceptance.
13.4 Review Regularly. Check prduct.com/privacy-policy periodically for updates.
California Privacy Rights (Ccpa)
If you’re a California resident:
14.1 Information We Collect: See Section 2 for categories of personal information collected.
14.2Your Rights:
- Right to Know: Request what personal information we’ve collected in the past 12 months
- Right to Delete: Request deletion of your personal information
- Right to Opt-Out: We do not sell personal information, so no opt-out required
- Right to Non-Discrimination: We won’t discriminate against you for exercising CCPA rights
14.3 Exercising Rights: Email dpo@prduct.com with “California Privacy Request” in the subject line. We’ll verify your identity and respond within 45 days.
14.4 Authorized Agents: You may designate an authorized agent to make requests on your behalf (requires written authorization).
Other Jurisdictions
15.1 UK GDPR. If you’re in the UK, you have similar rights under UK GDPR. Contact: UK Information Commissioner’s Office (ico.org.uk).
15.2 Brazil (LGPD). If you’re in Brazil, you have rights under LGPD similar to GDPR. Contact Brazilian Data Protection Authority (ANPD).
15.3 Other Laws. We comply with applicable data protection laws in jurisdictions where we operate.
Business Contacts Vs. Platform Users
16.1Two Categories:
(a) Platform Users: Individuals with Prduct accounts, this Privacy Policy applies in full.
(b) Business Contacts: Supplier/customer contacts added to the Platform by users, we process their information as directed by the user who added them (user acts as Controller, we act as Processor per our DPA).
16.2 If You’re a Business Contact: If your information was added by a Platform user (e.g., you’re a supplier contact), direct privacy inquiries to the company that added you. They control your information.
Contact Us
For Privacy Questions:Data Protection Officer: dpo@prduct.com
Address: Prduct ApS, Universitetsbyen 71, 8000 Aarhus C, Denmark
Phone: +45 5020 8844 For Security Issues:
security@prduct.com For General Support:
support@prduct.com For Legal Matters:
legal@prduct.com
Supervisory Authority
Denmark:Datatilsynet (Danish Data Protection Agency)
Email: dt@datatilsynet.dk
Website: datatilsynet.dk
Contact your local Data Protection Authority: edpb.europa.eu/about-edpb/about-edpb/members_en