Controller: GeoKod. Contact: support@eudrplot.com.

We send no marketing email; this policy will be updated before we do.

Accounts, saved projects and payments

If you create an account we process your email address, your name if you give it, your answers to the onboarding questions, and records of sign-ins and changes in your workspace. A file is uploaded only when you save it to a project, after you have agreed to that once; it is encrypted before it is stored, in the EU. You can delete a project, and every version of it, at any time. Payments are processed by Paddle.com, our merchant of record, under Paddle's own privacy notice; we receive your subscription status, not your card details. See subprocessors.

When a customer asks you to send a file through a supplier link, the file you send is stored in that customer's workspace, encrypted, like a saved project; the customer is the controller for it. The name, email address and note you give with it are passed to the customer, and a truncated one-way hash of your network address is kept to limit abuse.

Products, documents and declarations

On paid plans a workspace can keep a list of its products and suppliers, documents such as land titles, permits, certificates and invoices, supplier declarations, and risk assessments. Documents are encrypted before they are stored, in the EU, and kept until the workspace deletes them with the workspace or the account: the regulation asks operators to keep due diligence records for five years. A supplier who sends a declaration or a document through a supplier link sends it to that customer, who is the controller for it; the name and email address they give with it are passed on. Documents are not sent to anyone else.

Due diligence statements

If you connect a workspace to the EU Information System, we store the web service username, client identifier and authentication key you enter; the key is encrypted and is used only to send that workspace's requests. When you file a due diligence statement, our server sends it (with the geolocation of the plots and the producer names it contains) to the European Commission's EUDR Information System, on your instruction, and keeps a record of the statement's identifiers and status in your workspace.

The API and the hosted MCP server

A file your software or AI assistant sends to the API or the hosted MCP server, which may contain producer names and plot locations, is processed in our server's memory to answer that request and is not stored or logged, unless the request saves it to a project. We record the request's time, endpoint, result status and the workspace, and count the file's distinct plots (as one-way hashes of their geometry) toward the plan's monthly allowance. We store API keys only as one-way hashes.

Deforestation monitoring

When a workspace switches monitoring on for a project, our server checks the current version's plots every week against deforestation alert maps. It loads squares of those maps of about 2.4 km (and coarser coverage maps) from Global Forest Watch's tile server (tiles.globalforestwatch.org) and the list of their latest versions from its Data API (data-api.globalforestwatch.org), and squares of the Joint Research Centre's forest map as for the forest check. These requests come from our server and contain tile numbers only, never your file, the plots' outlines or anyone's name.

For each plot with alerts, our server fetches satellite images from before and after: it asks Element 84's Earth Search catalogue (earth-search.aws.element84.com) which Sentinel-2 images cover a box of a few kilometres around the alerts, and reads parts of those public images from Amazon Web Services' open-data storage. The box is all these services learn. The images are stored encrypted with the workspace's other data.

The alerts, their measurements, the images and each review (who set which status, when, with what note) are kept with the project, for the five years the regulation asks for due diligence records (Art. 12(5)), or until the project or the workspace is deleted.

A workspace on the Consultant plan can set a webhook: our server then sends the new alerts (plot names, places, producers, areas and dates) to the address the workspace gives. The workspace chooses that recipient.

Files you check

Files you open in the checker or the free tools are read and processed by your browser, on your device. They are not sent to us or to anyone else, and we do not store them. This is enforced technically: see local-first.

A file you pass from a tool to the checker is held in your browser's session storage for that tab and deleted as soon as the checker opens it.

The embedded checker

When a website embeds our checker, the file a visitor checks in it is processed in the visitor's browser, exactly as on our own site; neither that website nor we receive it. Loading the embed sends us the ordinary request data described under "Visiting the website".

Visiting the website

Our hosting provider, netcup GmbH, processes technical data needed to deliver pages, such as your IP address, the page requested, the time, and your browser's user agent, in server logs on servers in the EU. See subprocessors.

To keep the service available we count requests per network address for a short time (minutes, at most a day). We store only a one-way hash of the address, never the address.

If a page fails in your browser, it sends us a short error report: the error message with any quoted text, numbers, email addresses and link codes removed, and the page address without its query. It never contains your file. Server errors are recorded the same way and may be forwarded, in that reduced form, to our own alerting channel.

To see how many people use the checker, we count four things per day: a file was checked, a check found errors, an account was created, and a paid plan was started (with the plan's name). The checker tells our own server the first two with a request that carries only the step's name; the other two are counted when they happen on our server. Each is a number per day and nothing else: no address, account, page, file or identifier is stored with it, so nothing ties a count to you.

We do not use third-party analytics or advertising tools, and we set no cookies apart from the one that keeps you signed in. See cookies.

Map tiles

The street and satellite maps in the checker are images loaded directly by your browser from third-party tile servers: OpenFreeMap (street) and VITO's Terrascope service (ESA WorldCover Sentinel-2 satellite imagery), with NASA's GIBS for the zoomed-out world view. These requests contain your IP address and the map area on screen, but never the contents of your file. The Plain basemap loads no tiles at all.

When you run the forest check or turn on the Forest 2020 or Loss since 2021 layer, your browser also loads parts of two maps: the European Commission Joint Research Centre's forest map from its server (ies-ows.jrc.ec.europa.eu), and the tree cover loss map from Global Forest Watch's tile server (tiles.globalforestwatch.org, run by the World Resources Institute). These requests contain your IP address and squares of the maps of about 10 km around your plots, or the area on screen, but never the contents of your file. For a report link that includes forest cover, our server makes the same requests instead of your browser.

The contact form

If you use the contact form, we process your name, email address, organisation and message to reply to you. The message is delivered to us by email through our email provider, and kept only as long as needed to handle your request.

Access by our staff

A small number of named staff can see account and workspace details (email addresses, names, plans, usage counts, dates and the activity log) to run the service and answer support requests. They cannot open saved files from their tools. When a support request cannot be answered otherwise, a staff member can view the app as you see it, read-only, for at most 30 minutes; each such view is recorded with its reason in the activity log.

Backups

The database is backed up nightly, encrypted, and each backup is kept for 14 days. Deleted data therefore disappears from backups within 14 days.

Your rights

You have the rights of access, rectification, erasure, restriction, portability and objection under the GDPR, and the right to complain to a supervisory authority. If you have an account, you can exercise access and portability yourself (Settings → Profile → Download my data) and erase your account and the workspaces only you belong to (Delete my account). Otherwise, contact us at support@eudrplot.com.