Legal

Privacy Policy

Last updated: 1 April 2026 · Governed by POPIA Act 4 of 2013 (South Africa)

1. Who We Are

DigitalProductPassports.co.za is operated by LinkDaddy LLC, registered at 509 N Prescott Avenue, Suite B, Clearwater, Florida 33755. We operate the National Forensic Trust Registry for South African Digital Product Passports (DPP), providing compliance infrastructure for South African exporters under the EU Ecodesign for Sustainable Products Regulation (ESPR) (EU) 2024/1781.

For all POPIA-related enquiries, contact our Information Officer at [email protected].

2. Information We Collect

We collect only what is necessary to operate the registry:

CIPC Registration NumberIdentity verification for SME onboardingMandatory
Director Smart ID NumberBiometric identity anchor for passport mintingMandatory
Business Name & AddressRegistry entity node creationMandatory
Email AddressAccount communication and compliance alertsMandatory
Declared Shipment Value2% transaction fee calculation and royalty ledgerMandatory
Document SHA-256 HashForensic fingerprint — the document itself is never storedMandatory
IP Address (hashed)POPIA consent logging and rate limiting — not stored in raw formAutomatic
Session TokensAuthentication — stored in Cloudflare KV, expire after 24 hoursAutomatic

We do not store uploaded documents. All documents are hashed client-side using SHA-256 via the Web Crypto API. Only the hash is transmitted to our servers. The original document never leaves your device.

3. How We Use Your Information

Your information is used exclusively for:

  • Verifying your business identity against the CIPC register
  • Creating and maintaining your Digital Product Passport entries
  • Calculating and logging the 2% transaction royalty on declared shipment values
  • Sending compliance deadline alerts and registry notifications
  • Responding to verification requests from EU customs authorities and AI procurement systems
  • Maintaining the POPIA consent audit trail for the DPP AI assistant

We do not sell, rent, or share your personal information with third parties for marketing purposes. Ever.

4. The 2% Transaction Fee & Financial Data

The declared shipment value you provide is used solely to calculate the 2% registry transaction fee — the same way PayFast or Peach Payments calculate their processing fees. This value is logged to the Founder's Royalty Dashboard for financial reporting purposes. It is not shared with any third party, including the South African Revenue Service (SARS), unless we are legally compelled to do so.

5. The DPP AI Assistant (Ask DPP!)

The DPP AI assistant is powered by a consensus chain of five AI models (Perplexity, Anthropic, OpenAI, Gemini, and Grok). Before using the assistant, you are asked to provide explicit POPIA consent.

We do not store your conversation with DPP. We store only the consent event (timestamp, session ID, and hashed IP address) as required for POPIA compliance. Your questions and DPP's answers are processed in-memory and discarded after each session.

6. Data Retention

Passport Registry RecordsIndefinite — these are permanent forensic records
POPIA Consent Logs5 years — as required by POPIA Section 14
Session Tokens24 hours — auto-expired in Cloudflare KV
Rate Limit Records1 hour — auto-expired in memory
Royalty Ledger Entries7 years — as required by SA tax law

7. Your Rights Under POPIA

As a data subject under POPIA Act 4 of 2013, you have the right to:

  • Access — request a copy of all personal information we hold about you
  • Correction — request correction of inaccurate personal information
  • Deletion — request deletion of personal information (subject to legal retention requirements)
  • Objection — object to the processing of your personal information
  • Complaint — lodge a complaint with the Information Regulator of South Africa at inforegulator.org.za

To exercise any of these rights, contact us at [email protected]. We will respond within 30 days as required by POPIA.

8. Security

All data is encrypted in transit (TLS 1.3) and at rest. The registry operates on Cloudflare's global edge network with enterprise-grade DDoS protection and Web Application Firewall (WAF) rules. Document hashes are stored in Cloudflare D1 (SQLite) with row-level access controls.

9. International Transfers

LinkDaddy LLC is incorporated in the United States. Data processed through the DPP registry may be transferred to and stored on servers in the United States and European Union (Cloudflare edge nodes). These transfers are made in compliance with POPIA Section 72 and are subject to appropriate safeguards.

10. Changes to This Policy

We will notify registered users by email of any material changes to this policy at least 30 days before they take effect. The current version is always available at digitalproductpassports.co.za/legal/privacy-policy.