Digital Vehicle Passport
Privacy Policy
Last updated: 22 August 2026
Digital Vehicle Passport respects your privacy and is committed to protecting your personal data.
This Privacy Policy explains how we collect, use, store and protect personal data when you visit digitalvehiclepassport.com (the “Website”), request a Digital Product Passport readiness assessment, download resources, contact us or otherwise interact with the Website.
This Privacy Policy is intended to comply with the General Data Protection Regulation (EU) 2016/679 (“GDPR”) and other applicable European data protection and privacy laws.
1. Data Controller
For the purposes of the GDPR, the data controller responsible for the processing of personal data through this Website is:
CodeNekt for Fleet OÜRegistry code: 17548630
Sakala tn 7-2
10141 Tallinn
Estonia
Operating the Digital Vehicle Passport knowledge platform at:
https://www.digitalvehiclepassport.com/
Email: contact@codenekt.com
In this Privacy Policy, “Digital Vehicle Passport”, “we”, “us” and “our” refer to the operator of the Website.
Digital Vehicle Passport is an independent knowledge and readiness platform focused on the evolution of Digital Product Passports and vehicle traceability within the automotive industry.
2. Scope of This Privacy Policy
This Privacy Policy applies to personal data collected through the Website, including when you:
- browse the Website;
- request a DPP Readiness Assessment;
- request or download an Executive Guide or other content;
- submit a contact or information request;
- communicate with us;
- interact with our professional content or services;
- consent to analytics or other optional technologies where applicable.
This policy does not govern personal data processed independently by third-party websites or services that may be linked from the Website.
3. Personal Data We Collect
Depending on how you interact with the Website, we may collect the following categories of personal data.
3.1 Information You Provide Directly
When you complete a form or contact us, we may collect:
- first name;
- last name;
- company or organisation name;
- professional email address;
- telephone number;
- organisation type;
- website address, where provided;
- job title or professional role, where provided;
- information contained in your message;
- information relating to your organisation's Digital Product Passport or vehicle-data readiness;
- any additional information that you voluntarily provide.
Please do not provide sensitive personal data through the Website unless specifically requested and necessary.
4. Information Collected Automatically
When you visit the Website, certain technical information may be collected automatically.
This may include:
- IP address;
- browser type and version;
- device type;
- operating system;
- language settings;
- referring website;
- pages visited;
- date and time of access;
- approximate geographic location derived from the IP address;
- session and navigation information;
- technical logs;
- cookie identifiers or similar technologies where applicable.
Some of this information is necessary for the technical operation, security and performance of the Website.
Where analytics or other non-essential tracking technologies are used, they will be activated in accordance with applicable consent requirements.
5. Why We Process Your Personal Data
We process personal data for the following purposes.
5.1 Providing Requested Resources
When you request the Digital Product Passport Executive Guide or another resource, we process your information in order to:
- provide the requested document;
- respond to your request;
- manage access to the resource;
- communicate with you regarding the requested content.
The legal basis for this processing is generally the performance of measures taken at your request under Article 6(1)(b) GDPR and/or our legitimate interest under Article 6(1)(f) GDPR in responding to professional enquiries.
5.2 DPP Readiness Assessments
When you request a readiness assessment, we may process your information to:
- evaluate your organisation's needs;
- understand your current level of readiness;
- contact you regarding the assessment;
- prepare recommendations;
- organise a consultation or meeting;
- provide information regarding relevant Digital Product Passport solutions or services.
The legal basis is generally Article 6(1)(b) GDPR, where processing is necessary to take steps at your request before entering into a potential business relationship.
5.3 Responding to Enquiries
We process contact details and messages to respond to enquiries and communicate with users of the Website.
The legal basis is our legitimate interest in managing professional communications and responding to requests under Article 6(1)(f) GDPR, or pre-contractual measures under Article 6(1)(b) GDPR, depending on the nature of the enquiry.
5.4 Business Development and Professional Follow-Up
Where permitted by applicable law, we may use professional contact information to follow up on a request, discuss Digital Product Passport readiness or provide information about services that are directly relevant to your original enquiry.
Our legal basis may be our legitimate interest under Article 6(1)(f) GDPR in developing our B2B activities and maintaining professional relationships.
Where consent is legally required for a particular form of electronic marketing, we will request consent before sending such communications.
You may object to direct marketing at any time.
5.5 Website Security
We may process technical information to:
- protect the Website;
- prevent fraud, spam and abuse;
- detect malicious activity;
- investigate security incidents;
- maintain system integrity;
- protect our users and infrastructure.
The legal basis is our legitimate interest under Article 6(1)(f) GDPR in maintaining the security and integrity of our Website.
5.6 Website Analytics and Improvement
Where permitted and, where required, with your consent, we may analyse Website usage to:
- understand how visitors use the Website;
- measure Website performance;
- identify technical issues;
- improve content and user experience;
- understand the effectiveness of our professional content.
Where consent is required, the legal basis is Article 6(1)(a) GDPR.
7. Recipients of Personal Data
We do not sell personal data.
Personal data may be accessed by authorised members of our organisation where necessary for the purposes described in this Privacy Policy.
We use HubSpot as a customer relationship management (CRM) and form-processing platform. Personal data submitted through certain forms on the Website may be transmitted to and processed by HubSpot on our behalf for purposes including managing enquiries, professional communications, lead management and business relationship follow-up.
HubSpot acts as a data processor in relation to Customer Personal Data processed on our instructions, subject to its Data Processing Agreement and applicable data protection safeguards.
We may also use carefully selected service providers to support the operation of the Website, including providers of:
- website hosting and cloud infrastructure;
- databases;
- cybersecurity and anti-spam services;
- form-processing services;
- email infrastructure;
- customer relationship management systems;
- business communication tools;
- analytics services;
- file hosting and content delivery;
- IT support;
- professional advisory services.
These providers may process personal data on our behalf and, where required by the GDPR, are subject to appropriate contractual and data protection obligations.
8. Disclosure Required by Law
We may disclose personal data where reasonably necessary to:
- comply with applicable law;
- comply with a court order or regulatory requirement;
- respond to lawful requests from public authorities;
- protect our legal rights;
- investigate fraud or security incidents;
- establish, exercise or defend legal claims.
9. International Data Transfers
Our objective is to process personal data within the European Economic Area (“EEA”) whenever reasonably possible.
However, certain technology or infrastructure providers may process data outside the EEA.
Some of our service providers, including HubSpot and its authorised sub-processors, may process personal data in jurisdictions outside the European Economic Area (“EEA”).
Where personal data is transferred outside the EEA, we rely on appropriate safeguards as required by applicable data protection law. These may include an adequacy decision adopted by the European Commission, the European Commission’s Standard Contractual Clauses, or another recognised transfer mechanism.
HubSpot’s Data Processing Agreement incorporates appropriate mechanisms for transfers of European personal data, including the European Commission’s Standard Contractual Clauses where applicable.
Where personal data is transferred to a country outside the EEA, we will use an appropriate transfer mechanism as required by the GDPR, which may include:
- an adequacy decision adopted by the European Commission;
- Standard Contractual Clauses approved by the European Commission;
- additional technical, contractual or organisational safeguards;
- another legally recognised transfer mechanism.
10. How Long We Keep Personal Data
We retain personal data only for as long as necessary for the purposes for which it was collected.
As a general principle:
Professional enquiries and assessment requests
Information relating to a potential business relationship may generally be retained for up to three years following the last meaningful interaction, unless a longer period is required or justified.
Existing business relationships
Where an enquiry results in a contractual relationship, relevant information may be retained for the duration of that relationship and afterwards for any period required by applicable accounting, tax, contractual or legal obligations.
Technical and security logs
Technical logs may be retained for a limited period necessary for security, troubleshooting and fraud prevention.
Consent records
Where we rely on consent, evidence of that consent and any subsequent withdrawal may be retained for the period reasonably necessary to demonstrate compliance with applicable law.
At the end of the applicable retention period, personal data will be deleted, anonymised or securely archived where continued storage is legally required.
11. Data Security
We implement reasonable technical and organisational measures designed to protect personal data against:
- unauthorised access;
- accidental loss;
- unlawful disclosure;
- alteration;
- destruction;
- misuse.
These measures may include access controls, encryption where appropriate, secure hosting, authentication systems, backups, monitoring and organisational access restrictions.
However, no online system can provide an absolute guarantee of security.
12. Your Rights Under the GDPR
Subject to the conditions provided by applicable law, you may have the following rights.
Right of Access
You may request confirmation as to whether we process your personal data and obtain access to that data.
Right to Rectification
You may ask us to correct inaccurate or incomplete personal data.
Right to Erasure
You may request deletion of your personal data in circumstances provided by Article 17 GDPR.
Right to Restriction
You may request that processing of your personal data be restricted in certain circumstances.
Right to Data Portability
Where applicable, you may request personal data you provided to us in a structured, commonly used and machine-readable format.
Right to Object
Where processing is based on legitimate interests, you may object to that processing on grounds relating to your particular situation.
Right to Object to Direct Marketing
You may object to processing for direct marketing purposes at any time and without providing a reason.
If you object to direct marketing, your personal data will no longer be processed for that purpose.
Right to Withdraw Consent
Where processing is based on consent, you may withdraw that consent at any time.
Withdrawal does not affect the lawfulness of processing carried out before consent was withdrawn.
Rights Relating to Automated Decision-Making
Where applicable, you have rights relating to decisions based solely on automated processing that produce legal or similarly significant effects.
We do not currently intend to make such decisions about Website visitors solely through automated processing.
13. Exercising Your Rights
To exercise your data protection rights, contact us at:
or by post:
CodeNekt for Fleet OÜSakala tn 7-2
10141 Tallinn
Estonia
We may request reasonable information necessary to verify your identity before responding to a request.
We will respond within the time limits required by applicable data protection law.
14. Right to Lodge a Complaint
If you believe that your personal data has been processed unlawfully, you have the right to lodge a complaint with a competent data protection supervisory authority.
As our data controller is established in Estonia, you may in particular contact:
Estonian Data Protection Inspectorate
Andmekaitse Inspektsioon
You may also contact the competent supervisory authority in the EU or EEA country where you live, work or believe an infringement has occurred.
15. Business Users
The Website is primarily intended for professionals and organisations operating within areas such as:
- automotive manufacturing;
- fleet management;
- leasing;
- mobility;
- insurance;
- vehicle distribution;
- remarketing;
- vehicle-data services;
- Digital Product Passport compliance.
If you submit information on behalf of an organisation, you should ensure that you are authorised to provide the relevant information.
16. Third-Party Websites
The Website may contain links to third-party websites, platforms or services, including professional social networks.
These external services operate independently and may have their own privacy policies.
We are not responsible for the privacy practices, content or security of third-party websites.
We encourage you to review their privacy notices before providing personal information.
17. No Sale of Personal Data
We do not sell or rent personal data to third parties.
Personal information collected through the Website is intended to be used for the purposes described in this Privacy Policy, including responding to professional requests, providing resources, conducting readiness assessments, managing business relationships and operating and improving the Website.
18. Children
The Website is a professional B2B information platform and is not intended for children.
We do not knowingly seek to collect personal data from children through the Website.
If we become aware that personal data relating to a child has been collected inappropriately, we will take reasonable steps to delete it.
19. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect:
- changes to the Website;
- new services or technologies;
- changes to our processing activities;
- regulatory developments;
- changes to applicable law.
The latest version will always be published on this page.
Where changes materially affect the way we process personal data, we may provide additional notice where required.
20. Contact
For questions about this Privacy Policy, the processing of personal data or the exercise of your rights, please contact:
CodeNekt for Fleet OÜRegistry code: 17548630
Sakala tn 7-2
10141 Tallinn
Estonia
Email: contact@codenekt.com
Website: digitalvehiclepassport.com
Last updated: 22 August 2026