Legal & Regulatory

Privacy Policy & Data Protection Directive

Last Updated: July 2026  |  Governance: EU GDPR (2016/679), CCPA/CPRA, eIDAS

1. Data Collection & Scope

DossierEngine™ ("Platform", "we", "our") operates as an enterprise-grade Digital Product Passport (DPP) infrastructure sitting above enterprise resource planning (ERP) engines. This Privacy Policy details how we process personal data, industrial telemetry, and identity metadata across our web applications and dynamic URI resolvers.

2. Role-Based Authentication & Telemetry Data

Unlike consumer software, DossierEngine processes data under strict operational segmentation:

  • Public Layer Metadata: Non-personally identifiable asset records (e.g., GS1 Digital Link URIs, material origin, carbon footprint scores) accessed via public 2D scanners.
  • Protected Utility & Clinical Layer: Credentials, multi-factor One-Time Password (OTP) tokens, and biometric eIDAS signatures used by field engineers and pharmacists to unlock technical schematics or ePI dosage logs.
  • Edge Telemetry: Outbound MQTT/HTTPS JSON payloads (e.g., Dissolved Gas Analysis, temperature sensor data) aggregated without storing personal consumer identifiers.

3. International Compliance & Cross-Border Transfers

DossierEngine complies strictly with European Union General Data Protection Regulation (GDPR) and California Consumer Privacy Act (CCPA). All data transfers across regional instances (EU Central Registry, US Smart Grid nodes) employ TLS 1.3 encryption in transit and AES-256 at rest.

4. Contact & Data Protection Officer (DPO)

For inquiries regarding data erasure, audit logs, or Data Processing Agreements (DPA), direct correspondence to:
Data Privacy Office: privacy@dossierengine.com