EU Label Compliance

Privacy notice

In force from 19 September 2026 · version 1.0 · Controller: Europe Services SE, Prague, Czech Republic

This notice explains what happens to personal data when you use eulabelcompliance.com. It is written to be read, not to be survived. Where a term comes from the General Data Protection Regulation (Regulation (EU) 2016/679, "GDPR"), it has the meaning given there.

1. Who is responsible

The controller is Europe Services SE, Na Čečeličce 425/4, Smíchov, 150 00 Praha 5, Czech Republic, IČO 03571785. Contact: info@eulabelcompliance.com, +420 775 397 884.

We have not appointed a data protection officer, because our processing does not meet the conditions in article 37 GDPR. Questions about data protection go to the address above and are answered by the company's statutory body.

2. What we collect

When you create an account

Company name, VAT number, billing address, the name and business email address of the person registering, optionally a phone number, and the verification code we send to that address.

When you generate a label

The product data you enter: manufacturer name and address, responsible person details, product identifiers, category, materials, warnings, countries of sale, and any artwork or images you upload. Most of this is company information rather than personal data, but a sole trader's name and address is personal data and is treated as such.

When you pay

Amount, currency, date, plan, invoice number, and a payment reference returned by Mollie. We never receive or store your card number.

When you simply browse

Our web server records the request: IP address, date and time, page requested, referring page, browser and operating system string. These logs exist to keep the service running and secure.

When you write to us

Your message and the address it came from, plus anything you attach, for as long as the matter is open and for the period in section 5.

3. Why, and on what basis

PurposeDataLegal basis
Creating and running your account, generating labels, serving the record pageAccount and product dataPerformance of a contract, art. 6(1)(b)
Verifying that the registration email is realEmail, verification codePerformance of a contract, art. 6(1)(b)
Invoicing, accounting, tax and VAT recordsBilling and payment dataLegal obligation, art. 6(1)(c)
Renewal reminders and service messages about your accountEmail, plan, datesPerformance of a contract, art. 6(1)(b)
Answering your questions by email, phone or video callCorrespondenceLegitimate interests, art. 6(1)(f) — replying to the person who contacted us
Keeping the service secure, preventing abuse and fraud, server logsTechnical data, IPLegitimate interests, art. 6(1)(f) — security of the service
Establishing or defending legal claimsWhatever is relevant to the claimLegitimate interests, art. 6(1)(f)

We do not profile you, we do not take automated decisions with legal effect, and we do not sell or rent data to anyone. We do not send marketing to people who have not asked for it.

4. The public record page

The point of the service is that a label code resolves to a page anyone can open. That page shows only the information that has to appear on the label itself: manufacturer name and address, responsible person, product identifier, warnings, and the date the record was last updated. It does not show your account email, your phone number, your VAT number, your payment history or any internal notes.

If you are a sole trader, your own name and business address are the manufacturer details and will therefore be public — that is what the labelling rules require, and it is the reason we ask you to confirm it during onboarding. Public record pages are indexable by search engines.

5. How long we keep it

DataRetention
Account and product records, active subscriptionFor the life of the subscription
Account and product records after cancellation30 days, then deleted
Invoices, receipts and accounting records10 years, as Czech accounting and VAT law requires
Trial accounts that never subscribe30 days from the end of the trial
Email correspondence24 months from the last message
Web server logs12 months
Data relevant to an open or foreseeable legal claimUntil the claim and any appeal period ends

6. Who else sees it

We use a small number of processors, each under a written agreement under article 28 GDPR:

Beyond processors, we disclose data only to our accountant and auditors under professional secrecy, and to a public authority or court where the law requires it. We will tell you about such a request unless we are legally barred from doing so.

7. Transfers outside the EEA

Our processing and storage take place inside the European Economic Area. Where you order a Canadian or British pack, the product data needed to issue it is shared with our group company in that country; for Canada the transfer relies on the European Commission's adequacy decision for Canadian commercial organisations, and for the United Kingdom on the adequacy decision for the UK. Where a provider's support organisation can access data from outside the EEA, the transfer is covered by the European Commission's standard contractual clauses together with the provider's supplementary measures. You may ask us for a copy of the clauses in force.

8. Security

Traffic runs over TLS with certificates renewed automatically. Passwords are stored hashed, never in clear. Administrative access is limited to named accounts, over authenticated sessions, on a server with a restricted firewall. Backups are taken daily and kept encrypted. Repeated failed logins lock the account. We review access and update the server's software regularly.

No system is beyond reach. If a breach is likely to result in a risk to your rights, we notify the Czech supervisory authority within 72 hours as article 33 requires, and we tell you directly when article 34 requires it.

9. Your rights

Under articles 15 to 22 GDPR you may ask for: access to your data and a copy of it; correction of anything inaccurate; erasure, where we have no overriding obligation to keep it; restriction of processing; portability of the data you gave us, in a machine-readable file; and objection to processing based on our legitimate interests. Where we rely on consent, you may withdraw it at any time, without affecting what was done before.

Write to info@eulabelcompliance.com. We reply within one month, and we say so if a request is complex enough to need the two-month extension article 12(3) allows. Exercising these rights is free; we charge only for a manifestly unfounded or repetitive request, and we say so before doing anything.

Note the limit that follows from the service itself: we cannot erase the manufacturer details from a public record page while that record is the one identified on labels in circulation, because the labelling rules require those details to be available. Cancelling the subscription takes the page offline.

10. Cookies and measurement

The public pages set no profiling, advertising or analytics cookies, which is why you are not asked to dismiss a banner. One technical cookie carries your session after you log in; it is necessary for the account area to work and expires when the session ends.

If we later add advertising measurement, a consent banner will appear before any such cookie is set, refusing will be as easy as accepting, and this section will be updated with the names and lifetimes of the cookies concerned.

11. Children

The service is for businesses. We do not knowingly collect data about anyone under 18. If you believe a child's data has reached us, write to us and we will delete it.

12. Changes

When this notice changes we publish the new version here with a new date and version number. If a change materially affects how we use data about identified account holders, we tell them by email before it takes effect.

13. Contact and complaints

Europe Services SE · Na Čečeličce 425/4, Smíchov, 150 00 Praha 5, Czech Republic · IČO 03571785
info@eulabelcompliance.com · +420 775 397 884

You also have the right to complain to a supervisory authority, in the member state where you live or work, or where you believe an infringement took place. Ours is the Office for Personal Data Protection of the Czech Republic (Úřad pro ochranu osobních údajů), Pplk. Sochora 27, 170 00 Praha 7, uoou.cz. We would rather you told us first.