Privacy policy and KVKK / GDPR information notice
Last updated: 26 September 2026
This is an English translation provided for convenience. In case of any discrepancy, the Turkish version prevails.
Data controller
OrigoPass (adminorigopass@gmail.com). Manufacturers are the controllers of their own data with regard to the content they publish on the passport; OrigoPass is the processor of this data.
What data is processed?
- Account: name, email, password hash (argon2), session records, optional 2FA secret key (encrypted).
- Company: name, address, contact details, GLN, users and their roles.
- Product and batch: all fields entered, document metadata and files, supplier declarations.
- Audit log: actor, time and old/new value for every change.
- Technical: IP addresses are kept briefly and only for rate limiting and security.
Passport page and consumers
No consumer data is collected on the public passport page; no cookies, tracking or analytics are used. Only the total number of scans may be recorded.
Purpose and legal basis
Provision of the service (contract), security (legitimate interest) and preparation for EU product legislation (the manufacturer's legal obligation). No processing takes place for marketing purposes.
Retention and location
Application and database data are hosted in the configured provider regions. Encrypted backup and restore verification for published passports are part of service continuity and are operationally monitored. Retention of account/personal data is separated from the lifecycle retention required for published DPP records.
Sub-processors
Hosting (Vercel), database (Neon), configured email provider, document storage (Vercel Blob or configured S3-compatible provider), and optional document reading (Anthropic Claude API).
Your rights
Send requests under KVKK Art. 11 and GDPR Art. 15–22 to adminorigopass@gmail.com. Requests are assessed within the applicable statutory periods.