Privacy Policy
Last updated: September 2026
This English version is provided for visitors outside the German-language site. The German version at solvedpp.com/privacy-policy/ is the legally binding one; in case of any discrepancy, the German text prevails.
Controller
ACE Holdings GmbH
Vorderdeich 9
21037 Hamburg
Germany
Email: service@solvedpp.com
Purpose and scope of processing
We process personal data in order to operate solvedpp.com and to provide our services around the creation, management and publication of Digital Product Passports (DPP).
In particular, we process:
- contact details (e.g. name, email, company)
- account and access data, and metadata from connected systems
- product, material and supply-chain data you enter to create Digital Product Passports
- support and communication data
- technical usage data (e.g. IP address, device and browser information, log data)
Legal bases (Art. 6 GDPR)
Processing is based on:
- Art. 6(1)(b) GDPR — performance of a contract and pre-contractual measures
- Art. 6(1)(c) GDPR — legal obligations
- Art. 6(1)(f) GDPR — legitimate interests, e.g. operational security, abuse prevention, product improvement
- Art. 6(1)(a) GDPR — consent, where obtained
Retention
Personal data is stored only for as long as it is needed for the relevant purpose.
Where statutory retention obligations apply — in particular under commercial and tax law — data is retained for the periods those laws require, typically six to ten years.
Recipients and processors
We use technical service providers to deliver our services, including hosting, infrastructure and support tools. The website is hosted by Netlify; server logs generated when the site is requested arise there and serve the operation and security of the site.
Where these providers process data on our behalf, data processing agreements and confidentiality obligations are in place.
Transfers to third countries
Processing generally takes place within the EU/EEA.
Where a transfer to a third country occurs in individual cases, it takes place only in accordance with the applicable legal requirements, for example on the basis of EU Standard Contractual Clauses.
Cookies and local storage
This website sets no cookies and stores no data in your browser’s local storage or session storage. Because no information is stored on or read from your device, no consent under § 25(1) TDDDG is required.
When the site is requested, technically necessary server logs are generated by our hosting provider. They serve the operation and security of the website.
Audience measurement and error diagnostics (PostHog)
To measure the reach of our content and to diagnose technical faults, we use PostHog in its cookieless mode. The provider is PostHog Inc., 2261 Market Street #4008, San Francisco, CA 94114, USA. Processing takes place in PostHog’s EU cloud on servers in Germany.
Measurement requests are routed through our own domain and forwarded from there to PostHog’s EU cloud. As a result, these requests also pass through our hosting provider’s servers.
How visitors are counted
PostHog stores no persistent identifier on your device. Instead, it derives a hash value on the server from your IP address, your browser identification (user agent) and the domain name. A random value that changes daily and is then deleted is mixed into that hash. The hash cannot be reversed. Your IP address is not stored, which also means no analysis by country or city takes place.
What is stored
- the page requested, the referring page, and campaign parameters (utm_*)
- browser, operating system and device type
- the time of the request
- specifically instrumented interactions: clicks on links to the Shopify App Store, use of the DPP configurator, and selections in the ESPR deadline checker
- unhandled JavaScript errors, with the error message and the page concerned
No data is combined across different websites. We do not build user profiles and do not attribute the data to any identified person.
Legal basis
Art. 6(1)(f) GDPR. Our legitimate interest lies in measuring the reach of our content in a data-minimising way and in detecting technical faults.
Transfer to a third country
The data is processed on servers in Germany. Where access from the United States occurs in the course of support or maintenance, the transfer relies on PostHog Inc.’s certification under the EU-U.S. Data Privacy Framework, supplemented by EU Standard Contractual Clauses.
Retention
Event data is deleted after twelve months. The daily random value used for counting is discarded at the end of each day.
Objection
You may object to this processing under Art. 21 GDPR; an email to service@solvedpp.com is sufficient. Because we deliberately store no identifier on your device, we cannot record an objection on the device itself. You can also stop the measurement yourself at any time by blocking the script in your browser settings or with a content blocker. The website continues to work unchanged.
Your rights
Under the GDPR you have, in particular, the following rights:
- access to the data processed
- rectification of inaccurate data
- erasure of your data
- restriction of processing
- data portability
- objection to processing
- withdrawal of consent with effect for the future
- to lodge a complaint with a data protection supervisory authority
To exercise your rights, contact us at service@solvedpp.com.
Obligation to provide data
Providing certain data is necessary in order to use our services.
Without it, individual functions or full use of the platform may be limited or impossible.
Changes to this privacy policy
We reserve the right to adapt this privacy policy where this becomes legally or factually necessary.
The version published on this page applies in each case.