Privacy Policy
Last updated: 26 June 2026. This is a working stub pending legal review.
Who we are
Listrar operates a multi-tenant product registry. Businesses (“tenants”) use Listrar to manage product records and publish public Digital Product Passport pages. For account and authentication data we act as the data controller; for the product data a tenant uploads, the tenant is the controller and Listrar acts as processor under a Data Processing Agreement.
What we process
- Account identity — your email address and role, used for passwordless sign-in. We never store passwords.
- Session data — a session token and its expiry.
- Security / audit logs — who performed which action and when, to keep the service secure.
- Operational logs — request metadata with personal data and secrets redacted before storage.
Lawful basis
We process account and catalogue data to perform our contract with you, and security/audit data under our legitimate interest in keeping the service safe. Public passport pages are published to meet product-compliance obligations.
Data residency
All processing and storage — application, database, logs, and error tracking — takes place in the European Union.
Retention
Account data — your users, settings and billing profile — is kept for the life of the account and deleted within 30 days of closure. Audit logs are retained for 12 months. Operational logs are kept on a short rolling window of 30 days.
Published product passports are the exception, and closing your account does not delete them. EU law, not Listrar, sets that period: a digital product passport must remain available for 10 years after the product is placed on the market, including in cases of insolvency, liquidation or cessation of activity of the economic operator that created it (Regulation (EU) 2025/2509, Article 19(2)(g); Regulation (EU) 2026/405, Article 21(2)(g)).
So when you close your account, published passports move to archived: they remain resolvable at their existing URLs, are plainly marked as historical, and are no longer maintained or updated. They are erased only once 10 years have elapsed, counted from the placed-on-market date recorded on each product. Records you never published carry no such duty and are deleted with the account.
This limits what erasure can cover. Where a passport must be retained, we can still correct inaccurate data in it and remove personal data that the regulation does not require it to carry — what we cannot do is take the record down before its statutory period ends.
Your rights
You can request access to, export of, correction of, or erasure of your personal data. Product records are edited self-service in the dashboard. Erasure has one limit, set out under Retention above: a published product passport must stay available for its statutory period and cannot be taken down early, though it can still be corrected. To exercise other rights, contact us at privacy@listrar.example.
Contact
Questions about this policy or our data practices: privacy@listrar.example.
This stub summarises the posture in our internal compliance documentation and must be reviewed by qualified counsel before production use.