Privacy policy
Last updated: September 2026
Protecting your personal data is important to us. We process your data solely on the basis of the applicable law, in particular the General Data Protection Regulation (GDPR), the German Federal Data Protection Act (BDSG) and the German Telecommunications Digital Services Data Protection Act (TDDDG). This privacy policy explains which data we process when you visit kraftpass.com and use the Kraftpass software, for what purpose, on which legal basis and for how long.
1. Controller
Draymanstreet UG (haftungsbeschränkt) Dürener Str. 1 53947 Nettersheim Germany Phone: +49 2486 800521 E-mail: datenschutz@draymanstreet.com
For questions about data protection and to exercise your rights, please contact the e-mail address above.
2. Principles in brief
- Kraftpass is a business-to-business service. We process business contact data of users and supplier contacts – never the data of our customers' end customers.
- We set no analytics, marketing or tracking cookies and embed no third-party scripts, external fonts or advertising networks. No cookie banner is therefore required.
- All data is processed and stored in data centres in the European Union.
- For the data that customer organisations enter into Kraftpass we act as processor under Art. 28 GDPR; the respective customer organisation is the controller.
3. Hosting and server log files
When you visit the website, technically necessary data is processed automatically: IP address (truncated before storage, IPv4 to /24, IPv6 to /48), date and time, page requested, browser type and version, operating system, referring page and error messages. This data serves secure and stable operation, error analysis and the prevention of attacks. It is deleted after 30 days.
The legal basis is Art. 6(1)(f) GDPR (legitimate interest in secure operation).
The application is hosted by Vercel Inc., 440 N Barranca Ave #4133, Covina, CA 91723, USA, in the Frankfurt am Main region. The database is provided by Neon Inc., 2261 Market Street STE 22601, San Francisco, CA 94114, USA, in the Frankfurt am Main region (AWS eu-central-1). Uploaded files are kept in a private, S3-compatible object store in the EU and are accessed only through short-lived signed links. Data processing agreements are in place with all providers (see section 11).
4. Cookies
We use strictly necessary cookies only (Section 25(2) no. 2 TDDDG). No consent is required for them.
- __Secure-authjs.session-token – signed-in session; HttpOnly, Secure; 30 days, renewed on use.
- __Host-authjs.csrf-token – protects the sign-in forms against cross-site request forgery; session.
- __Secure-authjs.callback-url – return address after sign-in; session.
- NEXT_LOCALE – selected language; 1 year.
- kp-theme – selected appearance (light/dark); 1 year.
5. Free exposure check
The exposure check can be completed without an account. We store your answers (role, packaging categories, destination countries, volume bands – company-level information) and the result so that you can retrieve it via a link and download it as a PDF. If you ask to receive the result by e-mail, we also store your e-mail address.
The legal basis is Art. 6(1)(b) GDPR (pre-contractual measure) and, for the e-mail address, your consent under Art. 6(1)(a) GDPR, which you may withdraw at any time. Results without an e-mail address are deleted after 30 days, results with an e-mail address after 12 months.
6. Registration and user account
An account is required to use the software. We process your name, business e-mail address, a password (stored only as a bcrypt hash) or alternatively a single-use sign-in link (magic link, valid for 24 hours, stored hashed), language, time of e-mail verification and last sign-in, and your role in the organisation. Where offered, you can also sign in with your Google or Microsoft account; in that case the provider passes your name and e-mail address to us.
The legal basis is Art. 6(1)(b) GDPR (performance of the user agreement). Accounts are deleted on request or by the organisation owner and permanently removed 30 days after deletion; sessions expire after 30 days.
7. Use of the platform by customer organisations (processing on behalf)
Customer organisations record product and packaging data, supplier contacts, evidence documents, sales quantities and the name and function of the person signing declarations of conformity. For this data the customer organisation is the controller within the meaning of the GDPR; we process it solely on its behalf under a data processing agreement pursuant to Art. 28 GDPR.
Every change is recorded in a change log (audit log) with user id, time, changed field and truncated IP address. This serves traceability towards auditors and authorities as well as security (Art. 6(1)(c) and (f) GDPR on the part of the customer organisation).
Data subjects whose data was entered by a customer organisation should contact that organisation for access, rectification or erasure. Requests that reach us directly are forwarded within two business days.
8. Supplier portal
Customer organisations can ask their suppliers for conformity evidence by e-mail. Supplier contacts receive a personal link that lets them provide information and upload documents without an account. We process the company, name, business e-mail address and phone number of the contact person, the uploaded documents (which may contain names and signatures of signatories), the time of use and a truncated IP address.
Processing takes place on behalf of the customer organisation, which is the controller (Art. 6(1)(f) GDPR – legitimate interest in evidence from the supply chain – and Art. 6(1)(c) GDPR in conjunction with Art. 15 of Regulation (EU) 2025/40). Links expire 90 days after their last use.
9. Shop and marketplace integrations
Customer organisations can connect shop systems and marketplaces (e.g. Shopify, Amazon, Shopware, WooCommerce, JTL) to import sales quantities. Only aggregated unit counts per product, country and period are stored. Orders, names, addresses or other end-customer data are never stored; they are processed only transiently in memory during aggregation. Access tokens of the integration are stored encrypted (AES-256-GCM) and deleted immediately when the connection is removed.
10. E-mail
We send transactional e-mails only: sign-in links, invitations, reminders to suppliers and notices about your account. E-mails are sent through Resend, Inc., 2261 Market Street #5039, San Francisco, CA 94114, USA, using its EU region. We store the recipient address, template, message id and delivery status for 90 days; message contents are not logged. The legal basis is Art. 6(1)(b) and (f) GDPR. We do not send newsletters or marketing e-mails.
11. Recipients and processors
We use the following service providers, which process data on our behalf:
- Vercel Inc., USA – application hosting, Frankfurt am Main region; EU standard contractual clauses and EU-U.S. Data Privacy Framework.
- Neon Inc., USA – database, Frankfurt am Main region (AWS eu-central-1); EU standard contractual clauses and EU-U.S. Data Privacy Framework.
- Resend, Inc., USA – transactional e-mail, EU region (Ireland); EU standard contractual clauses.
- Object storage for uploaded files: Amazon Web Services EMEA SARL, Luxembourg (Frankfurt am Main region) or Hetzner Online GmbH, Germany (Falkenstein/Nuremberg).
12. Transfers to third countries
Processing takes place in data centres in the European Union. Where providers are headquartered in the USA, access from a third country cannot be entirely excluded (for example for support). For these cases EU standard contractual clauses under Art. 46(2)(c) GDPR are in place; Vercel and Neon are additionally certified under the EU-U.S. Data Privacy Framework (Art. 45 GDPR).
13. Retention
- Server log files: 30 days.
- Exposure check: 30 days without, 12 months with an e-mail address.
- User account: duration of the membership; permanent deletion 30 days after the deletion request. Sessions: 30 days.
- Sign-in links and invitations: 24 hours and 7 days respectively.
- Supplier contacts and links: duration of the supplier record; links 90 days after last use.
- E-mail log: 90 days.
- Customer organisation data (register, evidence, documents, change log): duration of the contract; permanent deletion 30 days after the organisation is deleted. Customers retain conformity documents themselves or, on instruction, in a locked archive for the statutory period of 5 or 10 years (Art. 15(3) of Regulation (EU) 2025/40).
- Backups: 30 days rolling.
- Contract and billing data: statutory retention periods of up to 10 years (German Commercial Code, Fiscal Code).
14. Contacting us
If you contact us by e-mail, we store your details to handle the enquiry and any follow-up questions (Art. 6(1)(b) and (f) GDPR). The data is deleted once it is no longer needed for that purpose and no statutory retention obligations apply. We do not pass it on without your consent.
15. Security
All connections are TLS-encrypted; data is stored and backed up encrypted. Passwords are stored only as bcrypt hashes, sign-in links are single-use. Every customer organisation is a strictly separated tenant; files are kept in private storage and are reachable only through short-lived signed links. Staff access to production systems is limited to what is necessary and protected by multi-factor authentication.
16. Your rights
With regard to the personal data concerning you, you have the following rights towards us:
- Access (Art. 15 GDPR) – in the software also as a self-service export in the settings.
- Rectification (Art. 16 GDPR).
- Erasure (Art. 17 GDPR) – in the software via Settings → Delete account.
- Restriction of processing (Art. 18 GDPR).
- Data portability (Art. 20 GDPR).
- Objection to processing based on Art. 6(1)(f) GDPR (Art. 21 GDPR).
- Withdrawal of consent with effect for the future (Art. 7(3) GDPR).
If you believe that the processing of your data infringes data protection law, you may lodge a complaint with a supervisory authority (Art. 77 GDPR). The authority responsible for us is the State Commissioner for Data Protection and Freedom of Information of North Rhine-Westphalia (LDI NRW), Kavalleriestraße 2–4, 40213 Düsseldorf, Germany, https://www.ldi.nrw.de.
17. Changes to this privacy policy
We update this privacy policy when the service, the providers we use or the legal situation change. The current version is available at kraftpass.com/en/privacy.