1. Introduction
GreenTrust Engineering Consulting ("GreenTrust", "we", "us", "our") is committed to protecting your personal data in compliance with the EU General Data Protection Regulation (GDPR) (Regulation (EU) 2016/679). This Privacy Policy explains how we collect, use, store, and protect your personal data when you use the GreenTrust EUDR platform ("Platform").
2. Data Controller
The data controller for this Platform is:
Established in Greece
Email: privacy@greentrust.eu
Data Protection Officer: dpo@greentrust.eu
3. Data We Collect
3.1 Account Data
- Email address
- Full name / Company name
- Password (encrypted, managed by Auth0)
- Role (Operator/Supplier)
3.2 Business Data
- Company address, city, region, country, VAT number
- Approximate business location for the supply-chain map, derived from your city, region and country (see Section 3.4)
- Due diligence form submissions
- Plot of land data (coordinates, size, products)
- Product information and HS codes
- GeoJSON polygon data for plots
3.3 Technical Data
- IP address (for security and audit logging)
- Browser user agent
- Authentication session tokens — issued by Auth0 and stored in HttpOnly, Secure cookies on your browser (the refresh-token cookie is SameSite=Strict). JavaScript running on the platform cannot read these cookies. See Section 11 for the cookie inventory.
- Session timestamps
3.4 Approximate Business Location (Supply-Chain Map)
If you are a supplier, your business is shown at an approximate position on the supply-chain maps of the operators you are linked to. If you are an operator, your headquarters is shown on your own supply-chain map. Both also appear on the administrator map (see Section 6). We work out this position ourselves from the city, region and country in your company profile:
- Source: the city, region and country you entered, matched against an offline copy of the GeoNames geographical database (geonames.org, licensed under CC BY 4.0) held on our own servers. Your street address is never used, and your address, city or region is not sent to any external geocoding service to work out this position.
- Precision: the position is never more precise than the reference point of a city or town. We use city level only when the place name you entered matches the reference data (exactly, or as a known spelling variant) and the match is unambiguous: the name is unique in your region or in your country, or it is the best match for a major town (a capital, the seat of a region or district, or a town of at least 15,000 inhabitants). If you leave the region empty, or we cannot recognise what you entered there, we are stricter: unless the name is unique in your country, we then use city level only for a capital, a regional seat or a town of at least 100,000 inhabitants. In every other case we use a reference point for your region or, failing that, your country (its capital city); the map popup states the precision of every pin. A smaller place that shares its name with a major town may therefore be shown at that town; entering your region reduces this risk, your profile page shows the place we used, and you can ask us to correct it (see Section 8).
- What we store: the latitude and longitude of that reference point, the place name from the reference dataset, the precision level (city, region or country), the dataset version, a keyed fingerprint of the city, region and country used (so that we can detect changes), whether a restriction applies (see Section 8), and when the position was calculated.
- When it is calculated: once for existing profiles when this feature is introduced, whenever your city, region or country changes, and again when we update the reference dataset (normally every 6–12 months).
- Shown back to you: your profile page shows how your business appears on the map (place name and precision level).
- Use: the position is used only to display the maps. It is not used as plot geolocation, in due diligence statements (DDS), in risk assessments, or for any automated decision-making within the meaning of Art. 22 GDPR.
4. Legal Basis for Processing
We process your data under one of the following legal bases (GDPR Article 6). The basis depends on the data category, not on a blanket choice across the platform:
| Data category | Legal basis |
|---|---|
| Account credentials (email, password hash, Auth0 sub) | Contract performance — Art. 6(1)(b). Required to provide the service you signed up for. |
| Operator company profile, supplier declarations, plot geolocation, due-diligence evidence, DDS records | Legal obligation — Art. 6(1)(c) read with Articles 4, 9, 10, 12 of EU Reg. 2023/1115 (EUDR). The regulation creates the obligation to collect, retain, and produce this data. |
| Audit logs, IP address, user-agent, security telemetry | Legal obligation under EUDR Art. 12(4) (record-keeping) plus legitimate interest — Art. 6(1)(f) — in security monitoring and fraud detection. A documented Legitimate-Interest Assessment is available on request. |
| Approximate business location on the supply-chain map, derived from city, region and country (Section 3.4) | Suppliers: legitimate interest — Art. 6(1)(f). The interests pursued are those of the operators you are linked to, in having an accurate geographic overview of their supply chain to support their due diligence under EU Reg. 2023/1115, and ours in providing that overview as part of the Platform. The position is derived only from location details already held in your profile, is no more precise than city level, and is shown only to operators linked to you (who already have access to your city, region and country) and to platform administrators. We have assessed that this use is compatible with the purpose for which those details were collected (Art. 6(4)) and that it does not override your interests, rights and freedoms; the assessment is recorded in our Data Protection Impact Assessment. You may object at any time (Art. 21, see Section 8). Operators (your own headquarters on your own map): contract performance — Art. 6(1)(b). |
| IP address, browser user agent and viewed map area received by Esri when a map loads satellite imagery (Section 6) | Legitimate interest — Art. 6(1)(f) — in displaying the satellite imagery that the Platform's map features need. |
| Marketing or analytics communications | Consent — Art. 6(1)(a). Currently the platform does not run marketing or analytics processing; if it ever does, an explicit opt-in will be requested. |
5. How We Use Your Data
- Providing the EUDR due diligence compliance platform
- User authentication and role-based access control
- Operator-supplier relationship management
- Showing suppliers and operator headquarters at approximate positions on supply-chain maps (see Section 3.4)
- Generating compliance reports and analytics
- Security monitoring and audit logging
- Responding to your support requests
6. Data Sharing
We do not sell your personal data. We share data only with:
- Auth0 (Okta): Authentication provider — processes email, name, and password for login purposes.
- Linked Operators/Suppliers: When you are linked to an operator or supplier, relevant business data is shared as necessary for EUDR compliance.
- Supply-chain map (Section 3.4): If you are a supplier, operators with an active link to you see your approximate position, its place name and precision level, and your company name, city, region and country on their supply-chain map; your street address is not shown on the map. If you are an operator, your headquarters position is shown on your own map. Platform administrators can see both on the administrator map.
- Esri (map imagery): When you open a map on the Platform, your browser loads satellite imagery tiles directly from Esri's ArcGIS Online service (server.arcgisonline.com), operated by Environmental Systems Research Institute, Inc. (Esri, United States). As with any web request, Esri receives your IP address, your browser user agent, the address of our website, and the coordinates of the tiles requested, which reveal the map area and zoom level you are viewing (for example, the area around the pins on your map). We do not send Esri the pins, names or any other data about you or your business partners. See Section 10.
- EU Authorities: When required by EUDR regulation for compliance verification.
Approximate map positions are calculated on our own servers using an offline copy of the GeoNames dataset. No address, city name or other information about you is sent to an external geocoding service for this purpose, and no additional sub-processor is involved.
For a complete list of sub-processors and their roles, see our Sub-processor List. A Data Processing Agreement (DPA) template is also available.
7. Data Retention
- Account data: Retained while your account is active. Deleted within 30 days of an erasure request, subject to the EUDR carve-out below.
- Submission data (DDS, supplier forms, plot geolocation, supporting documents): Retained for at least 5 years from the date of submission, as required by Article 12(4) of EU Reg. 2023/1115. This obligation overrides erasure requests for the duration of the retention period — see GDPR Art. 17(3)(b)+(e).
- Audit logs: Retained for 5 years to align with the EUDR evidence-trail retention obligation under Article 12(4) of Reg. 2023/1115 and to meet GDPR accountability requirements.
- Approximate map position (Section 3.4): Kept while your company profile exists and recalculated whenever your city, region or country changes or we update the reference dataset. Deleted when your data is erased or your account is deleted; backup copies are overwritten within our 30-day backup rotation. It is not due-diligence evidence and is therefore not subject to the EUDR carve-out below.
- Session cookies: Access tokens expire with the token (currently up to 24 hours); refresh tokens are invalidated on logout, on Auth0 token rotation, or after 30 days, whichever comes first.
EUDR carve-out from erasure. If you exercise your Right to Erasure (Art. 17 GDPR) on data that we are required to keep under EUDR Art. 12(4), we will: (a) anonymise your identifying fields where doing so does not break the audit chain; (b) retain the underlying due-diligence record for the remainder of its 5-year retention window; and (c) delete the record fully once the retention period ends. We will tell you which data was retained on this basis when we respond to your request.
8. Your Rights (GDPR Articles 15-22)
You have the following rights regarding your personal data:
- Right of access (Art. 15): Request a copy of all personal data we hold about you.
- Right to rectification (Art. 16): Request correction of inaccurate data.
- Right to erasure (Art. 17): Request deletion of your personal data ("right to be forgotten").
- Right to restrict processing (Art. 18): Request limitation of how we use your data.
- Right to data portability (Art. 20): Receive your data in a structured, machine-readable format.
- Right to object (Art. 21): Object to processing based on legitimate interest.
- Right to withdraw consent (Art. 7(3)): Withdraw your consent at any time without affecting the lawfulness of processing based on consent before withdrawal.
Your map position (Section 3.4). Your profile page shows how your business appears on the supply-chain map, and the position is included in the copy of your data you can request under Art. 15. To correct it (Art. 16), update the city, region or country in your profile; the position is recalculated automatically. If your profile details are correct but the position is still wrong, contact us at privacy@greentrust.eu. To object to this processing (Art. 21), email privacy@greentrust.eu; from then on your business will be shown on the maps at country level only.
9. Data Security
- All data is encrypted in transit using TLS 1.2 or TLS 1.3.
- PII fields (operator/supplier addresses, phone numbers, contact names, VAT numbers, EORI numbers, audit-log subject emails, etc.) are encrypted at rest with Fernet (AES‑128‑CBC + HMAC‑SHA256). Account email lookup uses an HMAC‑SHA256 blind index so the plaintext email is never required at the database boundary.
- Authentication uses Auth0 OIDC with PKCE S256 (Backend-for-Frontend pattern).
Access tokens are issued by Auth0 and stored in HttpOnly, Secure cookies
(
__Host-eudr_access,__Host-eudr_id,__Host-eudr_refresh,__Host-eudr_auth_at) — JavaScript on the platform cannot read them. Logging out revokes the refresh token at Auth0. - JWT signatures are validated with RS256 against Auth0's JWKS on every request.
- Role-based access control (RBAC) is enforced on every API endpoint.
- Multi-factor authentication is required for administrator accounts.
- Same-origin enforcement on every state-changing request defends against cross-site request forgery.
10. International Transfers
The platform's primary data-processing infrastructure (application hosting at Hetzner DC Nuremberg, application database at Appwrite Cloud Frankfurt) operates within the European Economic Area (EEA).
Our identity provider, Auth0, is hosted in the EU (Frankfurt) but is owned by Okta, Inc., a US-headquartered company. To address the residual risk that US authorities could compel disclosure under the CLOUD Act, we rely on the European Commission's EU 2021/914 Standard Contractual Clauses (SCCs) contained in our Auth0 Data Processing Addendum and supplementary technical measures — encryption-at-rest, MFA on admin accounts, and minimisation of the identity attributes shared with Auth0 (email, name, MFA secret only). A Transfer Impact Assessment summarising the residual risk is available on request.
Some Forest Watch / satellite tiles consumed when an operator opens a plot map are loaded directly from Global Forest Watch (data‑api.globalforestwatch.org / tiles.globalforestwatch.org), which is hosted by the World Resources Institute (US). Those tile requests carry your IP address and the plot's lat/lng to the tile server. No personal data attached to your account is sent. We may later proxy these tile requests through our own backend to remove this transfer entirely.
Approximate map positions (Section 3.4) are calculated and stored on our EEA infrastructure; no personal data is transferred outside the EEA for that purpose. The satellite imagery shown on the Platform's maps, however, is loaded by your browser directly from Esri (server.arcgisonline.com), which is based in the United States. Those requests carry your IP address, browser user agent, the address of our website and the map area you are viewing (see Section 6), and Esri may process them outside the EEA. Esri states that it is certified under the EU–U.S. Data Privacy Framework, for which the European Commission has adopted an adequacy decision (GDPR Art. 45).
11. Cookies
We set only strictly-necessary cookies required for the platform to function:
__Host-eudr_access— access token issued by Auth0; SameSite=Lax; expires with the token (currently 24 hours).__Host-eudr_id— OIDC ID token issued by Auth0; SameSite=Lax; same lifetime as the access token.__Host-eudr_refresh— refresh token; SameSite=Strict; 30 days, renewed at each token rotation, revoked at Auth0 and deleted at logout.__Host-eudr_auth_at— your user id with the time and method of your last sign-in, signed by our server (used for the administrator 8-hour session limit, re-authentication checks and to bind the refresh token to your account); SameSite=Lax; 30 days, deleted at logout.__Host-eudr_login_bounce— a redirect-loop guard on the sign-in page; contains no personal data; SameSite=Lax; 15 seconds.__Host-session— Flask CSRF/session cookie; SameSite=Lax.
All of these cookies are HttpOnly and Secure, use Path=/ and carry no Domain
attribute. Cookies with the former names (__eudr_access,
__eudr_id, __eudr_refresh) are deleted whenever a browser still
sends them. The platform also keeps these items in browser localStorage
(not cookies):
eudr_theme,eudr_lang,eudr_cookie_consent— your dark/light mode, language choice and cookie-notice acknowledgement. UI preferences only.eudr_last_activity,eudr_expires_at,eudr_last_refresh_ok,eudr_logout— timestamps in browserlocalStoragethat let your open tabs share the 1-hour inactivity sign-out and the session renewal. They contain no token and no personal data.
We do not set analytics or advertising cookies and we do not embed third-party trackers. Strictly-necessary cookies are exempt from prior-consent requirements under EDPB Guidelines 05/2020.
12. Children's Privacy
This Platform is not intended for individuals under 16 years of age. We do not knowingly collect data from children.
13. Changes to This Policy
We may update this Privacy Policy to reflect changes in our practices or legal requirements. We will notify you of significant changes via email or an in-app notification. The "Last updated" date at the top indicates when this policy was last revised.
Change history
- Version 1.1 (September 17, 2026): Named GreenTrust Engineering Consulting (Greece) as data controller; added approximate business locations on supply-chain maps (Sections 3.4, 4, 5, 6, 7, 8 and 10); disclosed that map imagery is loaded from Esri; named the Hellenic Data Protection Authority as lead supervisory authority (Section 14).
- Version 1.0 (March 4, 2026): Initial version.
14. Contact & Complaints
If you have questions about this Privacy Policy or wish to exercise your data rights:
Data Protection Officer: dpo@greentrust.eu
If you believe your data protection rights have been violated, you have the right to lodge a complaint with a supervisory authority (Art. 77 GDPR). Our lead supervisory authority is the Hellenic Data Protection Authority (Αρχή Προστασίας Δεδομένων Προσωπικού Χαρακτήρα, www.dpa.gr). You may also complain to the data protection authority of any EU/EEA Member State, in particular the one where you live or work or where the alleged infringement took place.
← Back to Platform