Legal

Privacy policy

What personal data batterydigitalpassport.com collects, why, how long it is kept, and who it is shared with. In short: the contact form, and nothing else. No analytics, no tracking, no advertising.

This policy describes how Battery Digital Passport handles personal data on the website batterydigitalpassport.com. It describes what the site actually does, not what a template says a website usually does.

Who is the controller

The controller for the processing described here is Battery Digital Passport, {{COMPANY_LEGAL_ENTITY}}, {{COMPANY_ADDRESS}}, registered under {{COMPANY_REGISTRATION_NUMBER}}.

For any question about this policy or about your rights, write to {{PRIVACY_CONTACT_EMAIL}}.

We have not appointed a Data Protection Officer. Our processing is limited to occasional business enquiries and does not meet the criteria in Article 37(1) GDPR that would require one.

What data we collect

The contact form

The contact form on the contact page collects exactly five fields, all of which you type yourself:

FieldRequiredWhy it exists
Full nameYesSo we can address a reply
Work emailYesThe address the reply is sent to
CompanyYesContext for the enquiry
Battery categoryYesWhich obligations your enquiry concerns
MessageYesYour enquiry

Alongside the submission we process two technical items, neither of which is stored beyond the moment of use:

  • Your IP address, held in memory on the server for a short rate-limiting window so a single source cannot flood the form. It is not written to a database and it is not sent anywhere.
  • A timestamp recorded in your browser when the form is displayed, submitted with the form and used only to reject automated submissions. It is discarded immediately after that check.

The form also contains a hidden field that no human ever sees. If it is filled in, the submission is rejected as automated. Nothing is stored either way.

What we do not collect

We do not run web analytics of any kind. There is no Google Analytics, Plausible, Matomo, Meta pixel, LinkedIn Insight tag, or any equivalent. We do not embed third-party video, maps, fonts, chat widgets or social buttons. We do not build profiles, we do not do behavioural advertising, and we do not carry out any automated decision-making or profiling within the meaning of Article 22 GDPR.

Web server access logs are generated by our hosting infrastructure in the ordinary course of serving the site and may contain IP addresses. They exist for security and operational troubleshooting and are not used to analyse visitor behaviour. Retention is {{SERVER_LOG_RETENTION_PERIOD}}.

PurposeLegal basis (GDPR Art. 6(1))
Answering your enquiry and any follow-up correspondence(b) steps at your request prior to entering a contract, or (f) our legitimate interest in responding to business enquiries
Rejecting automated and abusive form submissions(f) our legitimate interest in keeping the form usable
Keeping server logs for security and troubleshooting(f) our legitimate interest in operating the site securely

Where we rely on legitimate interest, we have weighed it against your interests. The processing is limited to correspondence you initiated, uses the minimum data needed to reply, and is not combined with anything else.

Who your data is shared with

Your contact form submission is delivered to us as an email. That involves two processors:

  • Resend (Resend Labs, Inc.), which transmits the email. Your form fields appear in the body of that message, and your email address is set as the reply-to address.
  • {{EMAIL_HOSTING_PROVIDER}}, our email provider, which stores the resulting message in our mailbox.

The website itself is hosted by {{HOSTING_PROVIDER}}, {{HOSTING_PROVIDER_LOCATION}}.

We do not sell personal data, we do not share it for advertising, and we do not transfer it to anyone else except where we are legally obliged to.

Some of these providers may process data outside the European Economic Area. Where that happens, the transfer relies on the European Commission's Standard Contractual Clauses. If you need the specific transfer mechanism and safeguards for a named provider, ask us at {{PRIVACY_CONTACT_EMAIL}} and we will tell you.

How long we keep it

  • Contact enquiries: for as long as the conversation is live, and then in our mailbox for {{ENQUIRY_RETENTION_PERIOD}} so we have a record of what was discussed. After that they are deleted.
  • Rate-limiting IP data: minutes. It is held in server memory only and is discarded when the window closes or the process restarts.
  • Anti-automation timestamp: discarded at the moment the submission is checked.
  • Server logs: {{SERVER_LOG_RETENTION_PERIOD}}.

There is no database of visitors, subscribers or leads behind this website.

Your rights

Under the GDPR you have the right to request access to your personal data, its rectification or erasure, restriction of processing, and data portability. Where we rely on legitimate interest you have the right to object to the processing, and we will stop unless we can show compelling grounds that override your interests.

To exercise any of these, write to {{PRIVACY_CONTACT_EMAIL}}. In practice, for this site, the request is nearly always "delete my enquiry", and we will do so and confirm.

You also have the right to lodge a complaint with a supervisory authority — the data protection authority in your EU country of residence, work or of the alleged infringement. Our lead supervisory authority is {{LEAD_SUPERVISORY_AUTHORITY}}.

Cookies and local storage

This site sets no cookies for analytics, advertising or tracking. The one thing stored in your browser is your light/dark theme preference, kept in localStorage. The cookie policy explains that in full, including why it does not require a consent banner.

Children

This site is aimed at businesses placing batteries on the EU market. It is not directed at children and we do not knowingly collect data from them.

Security

The site is served over HTTPS. Contact submissions are transmitted to our email provider over TLS. We do not operate a customer database behind this website, which removes the largest category of risk rather than mitigating it.

We make no certification claim here. We do not hold an ISO 27001 certificate, a GDPR compliance certification under Article 42, or any equivalent, and you should treat any vendor page that claims one without naming the certifying body with caution.

Changes to this policy

If this policy changes materially we will update the date below. Because the site collects so little, the realistic trigger for a change is adding a tool that collects more — and if we ever do, this page changes before the tool ships.

Last updated: 19 July 2026.