EPRCLEARSign inScan your portfolio

Privacy Notice

Last updated: August 10, 2026

This notice explains what personal data EPR Clear processes, why, and the rights you have. It covers this website (eprclear.com), the EPR Clear console at app.eprclear.com, and the exposure-scan intake mailbox. It describes what the product actually does today, and we update it whenever the product's data flows change.

1. Who we are

EPR Clear is operated by Athanix OÜ, Sepapaja tn 6, 15551 Tallinn, Estonia ("EPR Clear", "we", "us"), which is the controller of the personal data described in this notice. Our registration details are on the Imprint.

For privacy questions or to exercise your rights, email privacy@eprclear.com.

2. This website runs no trackers

The public pages on eprclear.com (the landing, the free checkers, coverage, guides, and this notice) use no browser storage and load no analytics, advertising, or third-party tracking of any kind. That is why this site shows no cookie banner: consent is required for non-essential cookies, and we set none.

The one cookie the public pages use is visitor_country: a first-party preference cookie holding only a two-letter country code, derived from the network's coarse geolocation of your request, so the free-checker links can point at your country's national register instead of a default one. It identifies no one, stores no IP address, is never shared, and requires no consent banner because it only adapts the page you asked for. You can delete it in your browser at any time; the links then fall back to the default register.

One application serves both this site and the console, so the sign-in page is reachable on this domain too. Signing in is the only other action here that sets cookies: the strictly necessary session and language cookies described in section 5, and nothing else.

3. The public register search and the free checkers

The search on the landing page queries the register snapshots we hold (section 6). The name or identifier you type is sent to our server, used once to answer that search, and not stored; your IP address is used transiently for rate limiting and nothing else. Results show what the source registers publish (business name, country, register presence, registration status, capture date), with the source register named; we display no addresses, no validity periods, and no register annotations on this public surface. If you object to your register data appearing in public search results, contact privacy@eprclear.com (see section 6); suppression is applied at the serving layer.

The checker pages (/check/...) run entirely in your browser. The registration number you type is matched locally against the example scenarios that were prepared when the page was built; the page is marked "Demo data" while this is the case. The number you enter is not transmitted to us or to anyone else, and we do not store it. When live per-number checks replace the demo scenarios, this section will be updated first to say exactly what a live check sends and keeps.

4. The exposure scan

The form on /exposure-scan does not upload anything. When you submit it, the page shows you our intake mailbox (scans@eprclear.com); the email you then choose to send, from your own mail client, is the data we receive. That email typically contains your work email address and a CSV of your sellers (seller names, and VAT or EPR registration identifiers).

We use it solely to produce the readiness report you asked for. Your file is deleted after the scan; we keep only the aggregate report you receive, and your email address for replying to you. Legal basis: steps you request prior to entering into a contract, and our legitimate interest in answering you (GDPR Art. 6(1)(b) and (f)).

5. The console (app.eprclear.com)

If you hold an account, we process:

  • Your email address, to sign you in. Sign-in is passwordless: we email you a magic link that is valid for 15 minutes and can be used once. Sign-in tokens and session tokens are stored hashed (SHA-256); the plain values exist only in the email we send you and in your browser.
  • Sign-in protection data: the requesting IP address and email are used for rate limiting, and the response never reveals whether an email has an account.
  • The seller and verification data your organization loads into its workspace, processed to provide the service and produce your evidence log.

The console sets the following cookies, and no others:

CookiePurposeTypeLifetime
aithanor_epr_sessionKeeps you signed in (httpOnly, secure)Strictly necessaryUp to 30 days
epr_localeRemembers the interface language, set only when you pick onePreference, set on your actionUp to 12 months

Neither requires a consent banner: the session cookie is strictly necessary, and the locale cookie only stores the choice you just made. Both are first-party; there are no advertising or tracking cookies.

6. Register data we process, including some personal data

EPR Clear verifies seller registration numbers against national producer registers (packaging, WEEE, batteries). To do that we capture and archive snapshots of public register data, and we keep those snapshots as verification evidence. Verification evidence under best-efforts standard; registers remain the authoritative sources.

Most register rows describe companies. Some describe sole traders, whose business name identifies a natural person; those rows are personal data even though the register is public. We process them under legitimate interest (GDPR Art. 6(1)(f)): marketplaces are required by PPWR Article 45 to verify seller registrations, and verification is impossible without reading the registers. We process what the public register publishes, we do not enrich it into profiles, and we use it only for verification evidence and for the register search described in section 3, which summarizes register presence with its source credited.

Sources are credited on the surfaces that show their data (for example ADEME SYDEREP, reused under Licence Ouverte / Open Licence 2.0, with the as-of date). If you are a sole trader and object to your register data appearing in our verification evidence, contact privacy@eprclear.com; we will assess your objection against the marketplace verification duty and respond within the statutory time.

7. Who processes data for us

We use a small set of infrastructure providers acting on our instructions: Brevo (Sendinblue SAS, France, EU) for transactional email delivery such as magic-link and service email, Vercel for application hosting, Neon for our managed EU-region PostgreSQL database, and Cloudflare R2 for object storage of register snapshots. When paid plans are billed, payments are processed by Stripe, which receives your billing details directly; we never see full card numbers. Each provider processes data under a contract that restricts its use to providing its service.

We do not sell personal data, we run no advertising, and we do not use your data to train models.

We may disclose information where the law requires it or to protect the rights, safety, or property of EPR Clear or others.

8. International transfers

We design processing to run in the European Union: email delivery is EU-based (Brevo, France) and register snapshots are stored with Cloudflare R2. Several of our providers are US-incorporated companies (in particular Vercel, Cloudflare, and Stripe), so they may be subject to US law even when they host data in the EU, and some processing can occur outside the EEA. Where personal data is transferred outside the European Economic Area, we rely on an adequacy decision where one applies (such as the EU-US Data Privacy Framework) or on the European Commission's Standard Contractual Clauses. You can ask us for the safeguards that apply to a given transfer at privacy@eprclear.com.

9. How long we keep data

  • Exposure-scan files: deleted after the scan; the aggregate report is kept.
  • Magic-link tokens: 15 minutes, single use.
  • Console sessions: up to 30 days.
  • Account data: for the life of the account, then as required by law.
  • Register snapshots and verification evidence: retained as the audit archive the service exists to provide; sole-trader objections are handled per section 6.

10. Your rights

Where the GDPR applies, you have the right to access, correct, and erase your personal data, to restrict or object to processing, to data portability, and to withdraw consent where processing is based on consent (none of our current processing is). Write to privacy@eprclear.com. You can also complain to a supervisory authority; our lead authority is the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon), and you may also contact the authority in your country of residence.

11. Children

The service is for businesses and is not directed at children.

12. Changes to this notice

We update this notice when the product's data flows change, and the date above with it. Material changes to console processing are announced to account holders by email.

13. Contact

Privacy: privacy@eprclear.com. General: support@eprclear.com. Postal address: section 1 above, and on the Imprint.