Legal
Privacy Policy
How we handle your personal data when you use Dexffo and the EU Sustainability Compliance Check.
Last updated:
1. Data controller
The data controller responsible for processing your personal data is Diego Ahumada, trading under the name Dexffo as a sole proprietorship (eenmanszaak) based in Amsterdam, the Netherlands. Commercial register: Kamer van Koophandel (KvK) — registration pending.
For any question about this policy or to exercise your rights, contact us at hello@dexffo.com.
2. Scope
This policy applies to all visitors of the Dexffo website, users of the public EUDR Compliance Check tool, and clients of the EUDR Due Diligence Statement (DDS) platform (the “portal”). It is written to comply with the EU General Data Protection Regulation (Regulation (EU) 2016/679, “GDPR”) and the Dutch implementing legislation (UAVG).
Two distinct roles. For the public website and Compliance Check, Dexffo acts as data controller. For personal data that clients upload into the DDS portal (including producer names and plot geolocation), Dexffo acts as a data processor on the client’s behalf — see the “EUDR DDS portal” section below and our Data Processing Agreement.
3. What data we collect
We collect the minimum data needed to operate the service:
3.1 Information you provide to us
- Assessment answers. Sector, country, company size, supply chain, reporting maturity. Used solely to compute your EUDR readiness result.
- Contact details. Name, professional email, role, and (optional) company name. Required only if you choose to receive your PDF report by email.
3.2 Information collected automatically
- Technical logs. IP address (truncated), browser type, referrer, timestamp. Retained transiently by our hosting provider for security and abuse prevention.
- Privacy-friendly analytics. If you opt in via our cookie banner, we use Plausible Analytics — a cookieless, GDPR-compliant tool that collects aggregated, non-personal usage statistics.
We do not use any advertising trackers, fingerprinting, social media pixels, or cross-site tracking technology.
4. Why we process your data and legal basis
| Purpose | Legal basis (GDPR Art. 6) |
|---|---|
| Compute and display your compliance result | Contract performance — Art. 6(1)(b) |
| Send you the PDF report by email | Contract performance — Art. 6(1)(b) |
| Log technical events for security and abuse prevention | Legitimate interest — Art. 6(1)(f) |
| Aggregate analytics (Plausible) | Consent — Art. 6(1)(a) |
| Follow up about consultancy services after you opt in | Consent — Art. 6(1)(a) |
5. How long we keep your data
- Assessment answers (anonymous). Stored in your browser (session storage) only. Cleared when you close the tab.
- Contact details and lead record. Up to 24 months after your last interaction, then deleted unless you have become a client.
- Email delivery logs (Resend). Up to 30 days, per Resend’s retention policy.
- Technical/security logs. Up to 30 days.
6. Sub-processors and third parties
We share your data with the following service providers, all of whom are bound by Data Processing Agreements compliant with GDPR Art. 28:
| Provider | Purpose | Location |
|---|---|---|
| Vercel Inc. | Web hosting and edge functions | EU (Frankfurt) + US |
| Supabase Inc. | DDS portal database (PostgreSQL) and document storage | EU (eu-central-1, Frankfurt) |
| Resend Inc. | Transactional email delivery | EU + US |
| Google Sheets (via webhook) | Lead capture spreadsheet | EU + US |
| Plausible Analytics B.V. | Cookieless usage analytics (opt-in) | EU (Germany) |
| Sentry GmbH | Error monitoring | EU (Germany) |
| Cloudflare, Inc. | CAPTCHA (Turnstile) and DDoS protection | Global edge |
| Upstash, Inc. | Rate-limiting storage | EU (Frankfurt) |
Transfers outside the EEA, where they occur, are covered by Standard Contractual Clauses or equivalent safeguards under GDPR Art. 46.
7. EUDR DDS portal — producer & geolocation data
When a client uses the paid EUDR DDS platform, Dexffo processes personal data of third parties — primarily the producers in the client’s supply chain — on the client’s documented instructions. In this context the client (operator/trader) is the data controller and Dexffo is the data processor (GDPR Art. 28). Governed by our Data Processing Agreement.
7.1 Categories of personal data in the portal
- Producer identity. Producer or landowner name associated with each production plot (Annex II, Art. 9(1)(a) EUDR).
- Geolocation. Plot coordinates (WGS84, ≥6 decimals) as points or polygons. In small communities these coordinates may indirectly identify a natural person (Art. 9(1)(d) EUDR).
- Legality documents. Land titles, harvest permits, export licences, and certifications uploaded as evidence (Art. 9(1)(d) EUDR), stored encrypted in Supabase Storage.
- Operator details. Legal name, EORI, and postal address of the operator/trader.
- Audit trail. Immutable log of actions (user, action type, UTC timestamp, IP) for compliance integrity — legal basis: legitimate interest, Art. 6(1)(f).
7.2 Legal basis and 5-year retention
Portal personal data is retained for a minimum of five (5) years from the placing of the product on the market, on the legal basis of GDPR Art. 6(1)(c) (compliance with a legal obligation) in conjunction with EUDR Art. 9(1). This reconciles the GDPR data-minimisation principle (Art. 5(1)(e)) with the mandatory EUDR record-keeping obligation. After the retention period the data is anonymised or securely deleted.
7.3 Data-subject rights in the portal (producers)
- Access & rectification: available — routed via the client (controller).
- Erasure (“right to be forgotten”): not applicable during the 5-year retention period, by virtue of the legal exception in GDPR Art. 17(3)(b) (legal obligation) + EUDR Art. 9(1).
- Portability: not applicable to third-party producer data.
7.4 Access by competent authorities
Under EUDR Art. 12(5) and Art. 16, competent authorities (customs, national competent authorities, the Commission) may require Dexffo or the client to produce the DDS and its supporting documentation. Dexffo will cooperate with lawful requests and, where not legally prohibited, notify the client first.
8. Your rights under the GDPR
You have the right to:
- Request access to the personal data we hold about you (Art. 15)
- Request rectification of inaccurate data (Art. 16)
- Request deletion (“right to be forgotten”) (Art. 17)
- Request restriction of processing (Art. 18)
- Request data portability in a machine-readable format (Art. 20)
- Object to processing based on legitimate interest (Art. 21)
- Withdraw consent at any time, without affecting prior lawful processing
- Lodge a complaint with the Dutch Data Protection Authority (Autoriteit Persoonsgegevens)
To exercise any of these rights, email hello@dexffo.com. We will respond within 30 days.
9. Security
We protect your data through HTTPS-only transport, strict Content Security Policy headers, rate limiting on lead-capture endpoints, CAPTCHA on contact forms, and least-privilege access controls. Access to lead data is restricted to the data controller.
10. Children
This service is not directed to children under 16. We do not knowingly collect personal data from children. If you believe a child has provided us with data, contact us so we can delete it.
11. Changes to this policy
We may update this policy to reflect changes in our processing activities or legal obligations. Material changes will be highlighted at the top of this page and the “Last updated” date will reflect the revision. Continued use of the service after such changes constitutes acknowledgement of the updated policy.
12. Contact
Diego Ahumada — Dexffo
Amsterdam, the Netherlands
hello@dexffo.com
See also our Terms of Service, Cookies Policy, and Data Processing Agreement.