Privacy Policy
Last updated: 26 June 2026. This is a working stub pending legal review.
Who we are
Listrar operates a multi-tenant product registry. Businesses (“tenants”) use Listrar to manage product records and publish public Digital Product Passport pages. For account and authentication data we act as the data controller; for the product data a tenant uploads, the tenant is the controller and Listrar acts as processor under a Data Processing Agreement.
What we process
- Account identity — your email address and role, used for passwordless sign-in. We never store passwords.
- Session data — a session token and its expiry.
- Security / audit logs — who performed which action and when, to keep the service secure.
- Operational logs — request metadata with personal data and secrets redacted before storage.
Lawful basis
We process account and catalogue data to perform our contract with you, and security/audit data under our legitimate interest in keeping the service safe. Public passport pages are published to meet product-compliance obligations.
Data residency
All processing and storage — application, database, logs, and error tracking — takes place in the European Union.
Retention
Account and tenant data are kept for the life of the account and deleted within 30 days of account closure. Audit logs are retained for 12 months. Operational logs are kept on a short rolling window of 30 days.
Your rights
You can request access to, export of, correction of, or erasure of your personal data. Product records are edited self-service in the dashboard. To exercise other rights, contact us at privacy@listrar.example.
Contact
Questions about this policy or our data practices: privacy@listrar.example.
This stub summarises the posture in our internal compliance documentation and must be reviewed by qualified counsel before production use.