Privacy notice
Last updated: 17 Aug 2026
Who is responsible
FloraPass is a service of the company named below, which is the controller for account, security and service-administration data. A customer organisation is the controller for the professional-operator, supplier and recipient data it enters to create its plant-passport records; for that data FloraPass acts as its processor under the Data processing agreement. Questions or data requests can be sent to support@florapass.eu.
The controller's registered company name, registered office address and company-register and VAT numbers are published on the legal notice page.
Data we use
- Account data: email address, display name, password hash, confirmation and recovery state.
- Organisation data: customer and professional-operator names and registration codes.
- Plant-passport records: species, lots, traceability values, origin and recipient details supplied by the operator.
- Security and usage data: API-key identifiers, login/session records, issuance counts and technical request data needed for rate limiting and troubleshooting.
Passwords and API-key secrets are not stored in readable form. Authentication tokens are stored in the browser's session storage, or local storage only when “Remember me” is chosen. FloraPass uses optional analytics and advertising conversion measurement only after you give consent in the cookie banner. If you choose not to consent, no third-party measurement tag is loaded. You can change your choice at any time using Cookie settings in the footer.
With consent, the integration sends page views and the limited event names needed to measure sign-up, email verification, first passport issuance and plan upgrades. It deliberately does not send email addresses, account names, plant-passport contents, supplier or recipient data, payment data, or confirmation-link parameters.
When a plant passport's public verification page is opened — typically by scanning the QR code on a printed label — FloraPass records an anonymous scan event for the operator that issued the passport: the passport concerned and the moment of the scan, and nothing else. No network address, location, scanner identity or device characteristic is stored, and automated crawlers are excluded. These events are shown to the issuing operator only as aggregate counts.
Why we use it
Data is used to create and secure accounts, provide the requested service, isolate each customer's records, issue and verify plant passports, keep regulatory traceability records, measure plan usage, prevent abuse and respond to support requests. Depending on the data and relationship, the applicable basis may be performance of a contract or steps requested before a contract, compliance with a legal obligation, or legitimate interests in operating and securing the service. FloraPass does not use this data for automated eligibility or credit decisions.
Storage and sharing
FloraPass requires the production application, database, backups and operational logs to remain in an EU region. Three sub-processors process data on FloraPass's behalf, each limited to what its service needs: a hosting and infrastructure provider that supplies compute, database storage and backups; a transactional email delivery provider that sends account and service emails; and a payment provider that runs checkout, stores the payment method and issues invoices. Each one is named, with its role and its location, on the sub-processor page, and the list is available on request via support@florapass.eu.
Two of the three are established outside the EU or EEA, or transfer onward to a country outside it. Those transfers are made under the European Commission's standard contractual clauses, and the sub-processor page identifies which supplier each transfer concerns. No plant-passport record, supplier list or credential is transferred to either of them: the records themselves stay with the EU-based hosting provider.
FloraPass does not sell personal data.
Retention
Account data is retained while the account is active. An authenticated user can submit a password-verified erasure request from Account settings; completion anonymises sign-in, profile, tenant and operator identity and revokes active credentials. Issued and voided plant-passport traceability records remain stored for audit and may need to be preserved for at least three years under applicable plant-health rules. FloraPass currently uses the issue date as a conservative retention starting point because a separate supply date is not yet recorded.
Your rights
Depending on the circumstances, you may ask for access, correction, deletion, restriction, portability or object to processing. Send a request to support@florapass.eu; identity may need to be verified before account information is disclosed or changed. A deletion request may be limited where records must be retained by law.
You may complain to the data-protection authority responsible for your location. The authority competent for the controller follows its place of registration and will be named here, and on the legal notice page, once the entity is registered.
Changes
Material changes will be reflected by a new date on this page.