top of page
victor-dementiev-NQibNqEQ9MQ-unsplash.jpg

Privacy Policy

conny-schneider-xuTJZ7uD7PI-unsplash.jpg

We take your privacy, data security, and transparency seriously. This page outlines the legal terms governing your use of the Protag platform, as well as how we handle your personal and organizational data.

Protag Systems AS (“Protag”, “we”, “us”, or “our”) is committed to protecting your privacy and handling your personal data with transparency, integrity, and care. This Privacy Policy explains how we collect, use, share, and protect your information when you interact with our website, application, or services, in accordance with the General Data Protection Regulation (GDPR) and relevant EU and Norwegian data protection laws.

2. What Data We Collect

We collect and process both personal and business-related data depending on how you interact with us:

a) Personal Data

  • Full name, email address, phone number

  • Job title and company affiliation

  • Login credentials (hashed)

  • IP address, device data, browser type

  • Any other data you choose to share via contact forms, onboarding, or support

b) Business and Productdata

  • Supply chain and product-level information (for DPP generation)

  • Uploaded documents and metadata

  • Certificates and declarations (e.g., CE, ISO)

  • Interaction logs with suppliers or certifiers

c) Cookies and Usage Data

  • Analytics (e.g. usage frequency, feature interaction)

  • Session identifiers

  • Language and location preferences

3. How We Use Your Data

We use the collected data to:

  • Deliver and maintain our services (including Digital Product Passport generation)

  • Ensure compliance with applicable legal and regulatory frameworks (e.g., ESPR, CSRD)

  • Improve platform performance, reliability, and user experience

  • Provide customer support and technical assistance

  • Monitor platform security and prevent misuse

  • Communicate important service updates and product enhancements

  • Where consent is given: send newsletters and promotional materials

4. Legal Basis for Processing

We process your data under one or more of the following legal bases:

  • Contractual necessity: to fulfill service obligations under our Terms of Use

  • Legal compliance: to meet obligations under EU/Norwegian law (e.g. data retention)

  • Legitimate interest: for fraud prevention, platform security, and service improvements

  • Consent: for marketing communications and cookie tracking (where applicable)

5. How We Share Your Data

We may share your information with:

  • Trusted third-party service providers (e.g., cloud hosting, analytics tools, payment processors) under strict confidentiality agreements

  • Certifiers, suppliers, and partners you explicitly authorize within the Protag ecosystem

  • Regulatory bodies or legal authorities when required by law or court order

We do not sell or lease your personal data to third parties under any circumstance.

6. Data Retention

We retain personal and business data for as long as necessary to fulfill our contractual, legal, and operational obligations, or until you request its deletion (subject to legal exceptions).

7. Your Rights Under GDPR

As a data subject, you have the right to:

  • Access the data we hold about you

  • Correct inaccuracies in your personal data

  • Request deletion (“right to be forgotten”)

  • Object to or restrict certain data processing activities

  • Withdraw your consent at any time (for consent-based processing)

  • Request data portability

To exercise these rights, contact us at legal@protag.io.

8. Data Security

Protag takes security seriously. We implement:

  • End-to-end encryption of stored and transmitted data

  • Regular third-party penetration testing

  • Role-based access controls and 2FA authentication

  • Secure cloud infrastructure compliant with ISO27001 standards (in progress)

9. International Transfers

Although Protag is based in Norway, your data may be processed in other jurisdictions through our global infrastructure partners (e.g., EU-based cloud services). We ensure all transfers are made in compliance with GDPR, including use of Standard Contractual Clauses where needed.

10. Cookies

Our website uses cookies to enhance functionality and user experience. You can adjust your cookie preferences at any time in your browser settings or through our cookie banner.

Types of cookies we use:

  • Essential cookies (required for platform operation)

  • Analytics cookies (to improve service usability)

  • Preference cookies (language, region, UI settings)

11. Updates to this Policy

We may update this Privacy Policy to reflect legal or operational changes. All updates will be posted on this page with the revised date. We encourage users to review the policy regularly.

12. Contact Us

For any privacy-related questions, data access requests, or concerns, please contact:

legal@protag.io
Protag AS, Oslo, Norway

bottom of page