Privacy Policy & GDPR Compliance
Last updated: 2026-09-06 · Version 1.0 (Week 3 Release)
Important Legal & Compliance Disclaimer (§37)
We organize source-backed regulatory and provider information to help cross-border sellers investigate their Extended Producer Responsibility (EPR) obligations and service options. The database is informational and does not constitute legal advice. Information is candidate-research pending verification (§40).
1. Data Controller
EPRmatrix is operated as a compliance intelligence platform for non-EU distance sellers and European compliance providers. For questions regarding personal data processing or to exercise your statutory rights under the General Data Protection Regulation (GDPR), contact us at:
Email: [email protected]
2. Categories of Data We Process
We adhere to the principle of data minimisation (GDPR Art. 5(1)(c)). We only collect data necessary for specific, legitimate purposes:
- Public Browsing: We do not set tracking cookies or perform cross-site user fingerprinting. Our hosting edge (Cloudflare) records minimal standard technical request logs (IP address, user agent, timestamp) solely for security, DDoS protection, and rate limiting.
- Request Quote Submissions (Path B): When a seller requests assistance or pricing quotes, we collect business operational dimensions (destination country, waste stream, marketplace platform, GMV band, urgency) alongside business contact details (name, business email).
- Provider Claims & Corrections: When a compliance provider or Authorised Representative (AR) claims their profile or submits corrections, we collect verification details (claimant name, professional title, corporate email, legal entity documentation).
3. PII Separation Architecture (§18 & §37.5)
Under our Agent Runtime Behavior Constitution and Data Protection Architecture, EPRmatrix enforces strict structural isolation:
lead_contacts (Name, Email, Phone) ← [reference_id] → demand_events (DE / Packaging / Amazon / GMV band)
- Demand Events: Analytical compliance dimensions are stored in an append-only ledger without directly identifiable personal details.
- Lead Contacts: Identifiable contact records are stored in access-controlled environments used strictly for quote routing and fulfillment follow-up.
- Zero Canonical Pollution: Public submission forms can never write directly to canonical truth tables (Requirements, Providers, Offers). All submissions enter controlled candidate inboxes for human review.
4. Legal Bases for Processing (GDPR Art. 6)
- Performance of Pre-contractual Measures (Art. 6(1)(b)): Processing quote requests submitted voluntarily by sellers seeking compliance services.
- Legitimate Interests (Art. 6(1)(f)): Maintaining server stability, mitigating spam/bot submissions, and ensuring accurate provider verification.
- Consent (Art. 6(1)(a)): Explicit opt-in consent captured at the time of form submission for communications regarding compliance inquiries.
5. Data Retention
We retain quote inquiries and provider claim submissions only as long as necessary to facilitate compliance verification or satisfy legal accountability requirements. Analytics derived from demand events are fully anonymized and aggregated.
6. Your Rights Under GDPR
As a European Union resident or data subject under the GDPR (Articles 15–22), you have the statutory right to:
- Access (Art. 15): Request confirmation and a copy of the personal data we hold about you.
- Rectification (Art. 16): Request immediate correction of inaccurate or incomplete personal contact records.
- Erasure (Art. 17): Request deletion of your personal contact records ('Right to be Forgotten') where statutory retention grounds no longer apply.
- Restriction (Art. 18): Request restriction of processing under contested accuracy or unlawful processing grounds.
- Notification Obligation (Art. 19): We communicate any rectification or erasure of personal data or restriction of processing to each recipient to whom the personal data have been disclosed.
- Data Portability (Art. 20): Receive your personal data in a structured, commonly used, machine-readable format (JSON/CSV) or request direct transfer to another controller.
- Objection (Art. 21): Object at any time to processing based on legitimate interests (GDPR Art. 6(1)(f)).
- Automated Decision-Making & Profiling (Art. 22): You have the right not to be subject to a decision based solely on automated processing. EPRmatrix strictly enforces a human-in-the-loop verification rule (§41); no automated legal or qualification decisions are made regarding providers or sellers.
- Lodge a Complaint (Art. 77): Lodge a formal complaint with your competent EU Data Protection Supervisory Authority (e.g. BfDI in Germany, CNIL in France, AP in the Netherlands).
To exercise any of these statutory rights, please email [email protected]. We verify identity and respond to all requests within 30 calendar days.