Privacy Policy
How PPWR Checker collects, uses and protects personal data, and the rights you have under the GDPR.
Last updated: 2026-08-23
Who is responsible for your data
The controller of the personal data described in this policy is PPWR Checker:
What we collect, and why
The free compliance check
The applicability checker on our homepage asks three questions: the market you sell into, your product type, and your packaging materials. Those answers are carried in the page URL and are not stored unless you choose to go further.
If you then ask us to email your action plan, we store the email address and company name you enter, together with those three answers, so that we can send the plan and understand what you need.
Account data
If you create an account, we store your name, email address, and authentication data. If you sign in through Google or GitHub, we receive your basic profile from that provider.
Documents and packaging data
When you generate compliance documents, we store the packaging data you enter and the documents produced from it, so you can retrieve, revise and re-issue them. This data is yours; we do not use it to build products for anyone else.
Payments
Payments are handled by our payment processor. We receive confirmation of the transaction, the amount, and the last digits of the payment method. We never see or store full card numbers.
Technical data
Server logs record IP address, browser and device type, and pages requested. These are used to keep the service secure and working, and are kept for a limited period.
Cookies
See our Cookie Policy for what we set and how to control it.
Legal bases for processing
Under Article 6 of the GDPR we rely on:
| What | Basis | | -------------------------------------------------------------- | --------------------------------- | | Providing your account, documents and purchases | Performance of a contract | | Sending the action plan you requested and related PPWR updates | Consent, withdrawable at any time | | Keeping the service secure, preventing abuse | Legitimate interests | | Keeping invoices and tax records | Legal obligation |
How long we keep it
- Checker leads — until you unsubscribe, and no longer than 24 months after your last interaction.
- Account and document data — while your account is open, and 90 days after you close it, so the deletion can be reversed if it was a mistake.
- Invoices and payment records — for the statutory retention period that applies to us.
- Server logs — 30 days.
Who we share it with
We do not sell personal data. We share it only with processors that operate the service on our behalf, each under a data processing agreement:
- Hosting, infrastructure and database — cloud providers that run the application and store your account, packaging and document data.
- Payment processing — a payment provider that handles checkout and card details directly. We never receive your full card number.
- Transactional and marketing email — an email provider that sends account, document and action-plan emails on our behalf.
- Analytics — web analytics providers, used only where you have accepted analytics cookies.
We also disclose data where we are legally required to, or to establish or defend legal claims.
Transfers outside the EU
Some of our processors operate outside the European Economic Area, principally in the United States. Where that is the case, the transfer is covered by an adequacy decision — including the EU–US Data Privacy Framework where the provider is certified under it — or by the European Commission's Standard Contractual Clauses.
Your rights
Under the GDPR you have the right to:
- access the personal data we hold about you;
- rectify data that is inaccurate;
- erase your data, where no legal obligation requires us to keep it;
- restrict or object to processing based on legitimate interests;
- portability — receive your data in a machine-readable format;
- withdraw consent at any time, without affecting processing already carried out.
Write to support@ppwrchecker.com to exercise any of these. We respond within one month.
You also have the right to lodge a complaint with a supervisory authority in the EU Member State where you live, work, or where the issue occurred.
Personal data you upload about other people
Packaging data sometimes carries personal data belonging to other people — a supplier contact, a signatory, a colleague's name on a specification sheet.
For that data you are the controller and we act as processor on your instructions. You are responsible for having a lawful basis to provide it to us, for informing those individuals as their own privacy notice requires, and for the accuracy of what you upload. We process it only to provide the service to you, and we delete or return it in line with the retention periods above.
Security
Data is encrypted in transit. Access to production data is limited to the people who need it to run the service. No system is perfectly secure, but we review our controls and will notify you and the relevant authority of a personal data breach where the law requires it.
Children
The service is intended for businesses. It is not directed at children, and we do not knowingly collect their data.
Changes
We update this policy when our processing changes. The date at the top reflects the last update; material changes will also be notified through the service.