yellow3
Research Digital Product Passport Platforms Insights Advisory About Contact
Get in touch →
Effective 5 August 2026

Privacy Notice

Effective date: 5 August 2026
Applies to yellow3.io, the DPP Supplier Register, the DPP Buyer Platform, advisory services and related communications.

  • yellow3 publishes independent research, operates a public Digital Product Passport provider register and supplies a private buyer platform.
  • For public research, account administration, billing and website operation, yellow3 normally acts as data controller.
  • For personal data placed inside a buyer’s private programme, the buyer normally acts as controller and yellow3 acts as processor under the Buyer Platform Terms.
  • We do not sell personal data. We do not use buyer-private programme data to train shared or publicly available artificial-intelligence models without explicit written agreement.

This opening summary is provided for convenience. The complete notice below explains the processing in detail.

1. Scope of this notice

This Privacy Notice explains how yellow3 ApS collects, uses, discloses, stores and protects personal data when we act as data controller. It also explains the limited circumstances in which yellow3 acts as a processor for a customer using the DPP Buyer Platform.

This notice applies when you:

  • visit yellow3.io or another website or application operated by yellow3;
  • contact us, subscribe to communications or participate in an event;
  • purchase or use a yellow3 service;
  • create or administer an account;
  • appear in, contribute to or communicate with us about the DPP Supplier Register;
  • claim, correct or update a Provider profile;
  • respond to a buyer evidence request sent through the DPP Buyer Platform; or
  • otherwise interact with yellow3 in a professional capacity.

This notice should be read together with our Terms of Service, Cookie Policy and, where applicable, the Buyer Platform Terms and their Data Processing Addendum.

2. Who is responsible for your personal data

The data controller is:

yellow3 ApS
CVR no. 44954087
Hovedgaden 43
2970 Hørsholm
Denmark
Email: hello@yellow3.io

yellow3 has not appointed a data protection officer. Questions and requests concerning this notice may be sent to the address above.

3. When yellow3 is controller and when yellow3 is processor

3.1 yellow3 as controller

yellow3 acts as controller when we determine why and how personal data is processed, including for:

  • operation, security and administration of our websites and accounts;
  • independent research and operation of the public DPP Supplier Register;
  • Provider profile verification, corrections and communications;
  • customer relationship management, contracting, support and billing;
  • service improvement, fraud prevention, legal compliance and the protection of our rights; and
  • marketing communications where permitted by law.

3.2 yellow3 as processor

When a customer places personal data inside its private DPP Buyer Platform programme, the customer normally determines the purpose of that processing. For that data, the customer is controller and yellow3 is processor.

That processing is governed by the Data Processing Addendum incorporated into the Buyer Platform Terms. The customer is responsible for its own privacy information, legal basis and instructions.

If your personal data appears in a customer programme, you should normally direct your request to that customer. Where we receive the request directly, we may forward it to the relevant customer and assist it in responding.

yellow3 may still act as controller for separate account, security, billing and legal records connected with the same Platform relationship.

4. Personal data we process

Depending on your relationship with yellow3, we may process the following categories.

CategoryExamples
Identity and professional detailsName, job title, organisation, department, professional biography, role and business affiliation.
Contact detailsBusiness email address, telephone number, postal address and professional social-media or repository profile.
Account and authentication dataUser identifier, organisation, role, permissions, authentication events, login records and account-security settings.
Customer and transaction dataCompany details, orders, contracts, invoices, subscription information, payment status and limited payment metadata. Complete card details are normally handled by the payment provider.
CommunicationsMessages, enquiries, support requests, correction submissions, evidence requests, Provider responses, meeting notes and records of consent or preferences.
Public research dataPublic professional information, company affiliations, public statements, source URLs, publication dates, repository contributions, public filings and the provenance of a research finding.
Technical and usage dataIP address, device and browser information, timestamps, security events, pages or features used, diagnostic information and cookie identifiers where applicable.
Submitted contentDocuments, logos, screenshots, evidence, questionnaires, correspondence and other material supplied to a yellow3 service.
Inferences and workflow recordsResearch classifications, proposed findings, uncertainty states, comparison criteria and records showing how an output was produced.

We do not intentionally collect or publish special-category personal data, criminal-offence data, private residential addresses or other highly sensitive personal data through the Register. Customers must not submit such data to the Platform unless yellow3 has expressly agreed in writing and appropriate safeguards have been established.

5. Where personal data comes from

We may obtain personal data:

  • directly from you, your employer or another person acting for your organisation;
  • from a customer that has authorised you to use the Platform;
  • from a Provider responding to a customer-authorised evidence request;
  • from public company websites, technical documentation, repositories, professional profiles, standards materials, press releases, public filings, registers and other publicly accessible sources;
  • from payment, hosting, authentication, analytics, communications and security providers;
  • from public authorities, advisers or counterparties where necessary for legal or contractual matters; and
  • through cookies, server logs and similar technologies when you use our Website or Platform.

Where personal data was not obtained directly from you, this section identifies the categories of sources used. Where applicable law requires individual notice, we provide it directly unless a lawful exception applies.

6. Why we process personal data and our legal bases

The table below summarises the principal purposes and legal bases. More than one basis may apply to the same record where it is used for different purposes.

Processing activityPurposeLegal basis
Website and Platform deliveryProvide pages and features, authenticate Users, maintain sessions and respond to technical requests.Contract, and legitimate interests in providing and operating secure services.
Security and misuse preventionProtect accounts, systems, Customer Data and research datasets, investigate incidents and enforce our terms.Legitimate interests, and legal obligations where applicable.
Enquiries and pre-contract communicationsRespond to questions, proposals, service requests and other communications.Steps requested before a contract, contract, or legitimate interests.
Customer administration and supportCreate accounts, deliver purchased services, manage Users, provide support and maintain the business relationship.Contract and legitimate interests.
Payments, accounting and taxProcess payments, maintain invoices and records, collect debts and meet bookkeeping and tax duties.Contract, legal obligation and legitimate interests.
Public Register and independent researchIdentify relevant organisations, document public evidence, publish dated findings, maintain provenance, support corrections and improve market transparency.Legitimate interests in independent business research, transparent sourcing and maintaining an evidence-backed Register.
Provider profile claims and correctionsVerify authority, prevent impersonation, review evidence, publish authorised company-supplied material and retain an audit trail.Contract or steps requested by the Provider, and legitimate interests.
Service improvement and analyticsUnderstand service performance, identify errors and improve usability, research methods and workflows.Legitimate interests, or consent where non-essential cookies or similar technologies require it.
Communications and marketingSend requested publications, event information or marketing messages and record preferences.Consent, or another basis permitted by applicable direct-marketing law.
Legal and corporate mattersComply with law, respond to authorities, conduct audits, obtain advice and establish, exercise or defend legal claims.Legal obligation and legitimate interests.

7. Our legitimate interests

Where we rely on legitimate interests, we assess whether the processing is necessary and balance our interests against the rights and reasonable expectations of the individuals concerned.

Our relevant interests include:

  • operating a secure and reliable Website, Register and Platform;
  • conducting and publishing evidence-backed business research;
  • making the sourcing and assessment of DPP Providers more transparent;
  • protecting the independence, accuracy and provenance of our findings;
  • preventing impersonation, fraud, scraping and misuse;
  • supporting customers, improving services and maintaining business records; and
  • establishing, exercising and defending legal rights.

Public Register processing is limited primarily to professional information connected with an organisation and its publicly presented capabilities. We avoid publishing unnecessary personal details and provide routes for correction and objection.

8. The DPP Supplier Register and published research

8.1 What may be published

The Register concerns organisations and products. It may nevertheless contain limited professional personal data, such as the name and role of a founder, executive, author, repository contributor or authorised company representative.

Published records may include the individual’s professional affiliation, a public statement, the source in which the information appeared and the date on which yellow3 reviewed it.

8.2 Public availability

Information published in the Register is available to internet users worldwide and may be indexed, quoted, archived or republished by third parties. yellow3 cannot control independent copies made lawfully by other persons, but we will correct or remove the yellow3-controlled version where required.

8.3 Profile claims and verification

Where a person claims a Provider profile, we may process their name, business contact details, domain, verification records, account activity and submitted materials.

Profile verification establishes control of the relevant account, domain or organisational channel. It does not certify the individual, Provider or capability.

8.4 Corrections, objections and historical records

A Provider or individual may request correction of inaccurate personal data or object to processing based on legitimate interests. We will assess the request against the evidence, the public and commercial context, our legal obligations and any overriding legitimate grounds.

An objection does not automatically require removal of accurate public professional information. Where a current record is corrected, we may retain a restricted historical record where necessary to document provenance, prevent repeated error or establish, exercise or defend legal claims.

9. The DPP Buyer Platform

9.1 Account and administration data

yellow3 acts as controller for Platform User accounts, access administration, subscription management, billing, support, service communications, security monitoring and enforcement of the Buyer Platform Terms.

9.2 Buyer-private programme data

Programme material entered or uploaded by a customer is buyer-private. For personal data in that material, yellow3 normally acts as processor on the customer’s documented instructions.

We do not disclose which buyers are assessing a Provider, or that a Provider is being assessed, unless the buyer chooses to send an evidence request, instructs disclosure or disclosure is required by law.

9.3 Provider responses

A Provider response supplied for a specific buyer engagement is kept within that engagement and is not automatically published as a general Register finding.

A public fact independently established from a public source may be retained as Independent Research, but the buyer’s identity, requirements, private context, negotiated commitments and confidential correspondence are not reused as general research.

9.4 Retention controlled by the customer

The customer controls the principal retention and deletion instructions for Customer Personal Data. Default Platform retention is described in the Buyer Platform Terms and Data Processing Addendum.

yellow3 may retain separate controller records for billing, security, support and legal purposes under this notice.

10. Artificial intelligence and automated systems

yellow3 may use automated systems and artificial intelligence to assist with research, extraction, classification, drafting, comparison, workflow execution, inconsistency detection and preparation of proposed findings or outputs.

When personal data is processed through an artificial-intelligence service:

  • we limit the information submitted to what is reasonably necessary;
  • we use contractual and technical settings intended to prevent the service provider from using buyer-private data for its own model training;
  • the provider is treated as a processor or subprocessor where required;
  • international-transfer safeguards apply where processing occurs outside the European Economic Area; and
  • material outputs remain subject to evidence, uncertainty and review controls appropriate to the service.

yellow3 does not use buyer-private programme data to train or fine-tune a general-purpose, shared or publicly available model unless the customer has expressly agreed in writing.

yellow3 does not make decisions based solely on automated processing that produce legal effects or similarly significant effects concerning an individual. The Platform supports organisational procurement and programme decisions. The relevant customer remains responsible for the decision it makes.

11. Who receives personal data

We may disclose personal data to the following categories of recipient where necessary:

  • authorised yellow3 personnel and contractors subject to confidentiality obligations;
  • website, cloud-hosting, database, authentication, storage, communications, analytics, security and support providers;
  • payment processors, banks, bookkeeping providers, accountants and auditors;
  • artificial-intelligence service providers used under appropriate business or API terms;
  • professional advisers, insurers, prospective investors, acquirers or transaction advisers subject to appropriate safeguards;
  • Providers or customers where you or the relevant customer instructs the communication;
  • public authorities, courts, law-enforcement bodies or regulators where disclosure is required or legally justified; and
  • the public, where professional personal data is intentionally published as part of the Register or published research.

Current service providers may include Vercel for website and application hosting, Supabase for database, authentication and storage services, Stripe for payments and fraud prevention, Resend for outbound email delivery (including sign-in links, invitations, evidence requests to providers and enquiry notifications), and OpenAI business or API services for authorised artificial-intelligence processing.

The specific suppliers used may change. For Buyer Platform processing, an up-to-date subprocessor list is available on request or through the Platform where provided.

We do not sell or rent personal data and do not disclose it to third parties for their independent advertising purposes.

12. International transfers

Some recipients or infrastructure providers may process personal data outside Denmark or the European Economic Area.

Where the GDPR requires transfer safeguards, we rely on one or more of:

  • a European Commission adequacy decision;
  • the European Commission’s Standard Contractual Clauses;
  • binding corporate rules or another approved safeguard;
  • supplementary technical, contractual or organisational measures where required; or
  • a specific derogation available under applicable law.

You may contact us for information about the safeguards relevant to a particular transfer. Commercially sensitive and security-related information may be provided in a redacted or summarised form.

Because the Register is public, personal data intentionally published there can be accessed from any country. That public availability is different from yellow3 appointing a service provider to process data outside the European Economic Area.

13. Cookies and similar technologies

We use cookies and similar technologies to provide essential Website and Platform functions, maintain security and, where enabled, understand service usage.

Strictly necessary technologies may be used without consent where permitted by law. Non-essential analytics, preference or marketing technologies are used only where the required consent has been obtained.

Further information is provided in our Cookie Policy. You may withdraw a cookie consent through the consent controls made available on the Website. Browser deletion alone may not record your withdrawal for future visits.

14. Marketing and service communications

Service communications, security notices, invoices and messages necessary to administer an account or deliver a purchased service are not marketing communications.

We send newsletters, event announcements and other marketing messages where you have requested them, consented, or another lawful basis is available under applicable direct-marketing rules.

You may unsubscribe through the link in a marketing email or by contacting us. We may retain a minimal suppression record so that we continue to respect the opt-out.

15. How long we retain personal data

We retain personal data only for as long as reasonably necessary for the purpose for which it was collected, including legal, accounting, security, research-integrity and claims requirements.

Record typeTypical retention
Website security and server logsNormally up to 12 months, unless a longer period is needed to investigate an incident or establish a legal claim.
Contact forms and general enquiriesNormally 12 months after the matter is closed, or longer where the communication leads to a customer relationship, dispute or legal obligation.
Customer accounts and relationship recordsFor the active relationship and normally up to 24 months afterwards, subject to longer contractual, legal or claims records.
Contracts, invoices and bookkeeping materialAt least five years from the end of the financial year to which the material relates, or longer where another legal duty applies.
Marketing recordsUntil consent is withdrawn or the communication is no longer relevant. A limited suppression record may be retained afterwards.
Provider claim and verification recordsFor the life of the claimed profile and normally up to 24 months afterwards. Material fraud, correction or dispute records may be kept for the applicable limitation period.
Public Register findings and source recordsCurrent findings are retained while relevant to the Register. Superseded findings and provenance records are reviewed and may be retained for up to seven years where needed for research integrity, corrections or legal claims.
Buyer Platform Customer Personal DataAs instructed by the customer and described in the Buyer Platform Terms and Data Processing Addendum. Separate yellow3 controller records follow this notice.
BackupsDeleted data may remain in protected rolling backups for a limited period, normally no more than 90 days, before being overwritten.
Legal and security recordsFor as long as necessary to meet a legal duty or establish, exercise or defend a legal claim.

A shorter or longer period may apply where required by law, requested by the relevant controller, necessary for an active investigation or justified by the nature of a historical research record.

At the end of the applicable period, personal data is deleted, anonymised or placed beyond ordinary use, subject to protected backups and lawful archival or claims requirements.

16. Your data-protection rights

Subject to the conditions and exceptions in applicable law, you may have the right to:

  • obtain confirmation of whether we process your personal data and receive access to it;
  • have inaccurate personal data corrected and incomplete data completed;
  • request deletion of personal data;
  • request restriction of processing;
  • object to processing based on legitimate interests, including public Register processing;
  • object at any time to direct marketing;
  • receive qualifying data in a structured, commonly used and machine-readable format and transmit it to another controller;
  • withdraw consent at any time, without affecting processing carried out before withdrawal; and
  • lodge a complaint with a competent supervisory authority.

These rights are not absolute. For example, we may retain data where processing is required by law, necessary for legal claims, protected by freedom-of-expression or information rules, or supported by compelling legitimate grounds.

Where you object to processing based on legitimate interests, we will stop the processing unless we demonstrate compelling legitimate grounds that override your interests, rights and freedoms, or the processing is required for legal claims.

To protect you and other Users, we may request information necessary to verify your identity and authority. We normally respond within one month. The period may be extended by up to two additional months for a complex or numerous request, in which case we will inform you.

We do not normally charge for a request. A reasonable fee may be charged, or a request may be refused, where it is manifestly unfounded or excessive as permitted by law.

17. Complaints

Please contact yellow3 first so that we have an opportunity to address your concern.

You may also complain to the Danish Data Protection Agency, Datatilsynet, or another competent supervisory authority. Datatilsynet’s complaint information is available online.

Datatilsynet’s contact details are:

Datatilsynet
Carl Jacobsens Vej 35
2500 Valby
Denmark
Telephone: +45 33 19 32 00
Email: dt@datatilsynet.dk

18. Security

yellow3 implements technical and organisational measures designed to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure and unauthorised access.

Measures may include:

  • role-based access and least-privilege controls;
  • multi-factor authentication for privileged access;
  • logical separation of customer organisations;
  • encryption in transit and encryption at rest where supported;
  • managed credentials and secrets;
  • security logging, monitoring and incident response;
  • backups, restoration procedures and continuity measures;
  • vulnerability, dependency and change management; and
  • contractual confidentiality and data-protection duties for relevant personnel and suppliers.

No online service can guarantee absolute security. You are responsible for protecting your credentials, using appropriate account settings and notifying us promptly of suspected unauthorised access.

19. Confidentiality and public information

Customer-private programme material and non-public business communications are handled as confidential information under the applicable agreement.

Public Register sources, public statements and company-supplied material intended for publication are not confidential merely because they concern an organisation or professional representative.

Do not send trade secrets, private personal information or information you are not authorised to disclose through a public profile, public correction route or ordinary email.

20. Children

yellow3’s services are designed for organisations and professional users. They are not directed to children, and we do not knowingly offer accounts or paid services to persons under 18.

If you believe a child has supplied personal data to us without appropriate authority, contact us so that we can investigate and take appropriate action.

21. Third-party websites

Our websites and research may link to third-party websites, repositories, documents or services. Those third parties determine their own processing and are responsible for their privacy information.

A link or source citation does not mean that yellow3 controls or endorses the third party’s privacy practices.

22. Changes to this notice

We may update this Privacy Notice to reflect changes to our services, technology, suppliers, research methods or legal obligations.

The current version will be published at yellow3.io/privacy with its effective date. Where a change materially affects an active paid service or requires new consent, we will provide additional notice where appropriate.

23. Contact

For questions, rights requests or privacy concerns, contact:

yellow3 ApS
Hovedgaden 43
2970 Hørsholm
Denmark
CVR no. 44954087
Email: hello@yellow3.io
Website: www.yellow3.io

For a correction relating to a public Register profile, you may also use the correction route displayed on the relevant profile. For personal data controlled by a Buyer Platform customer, please contact that customer first.

yellow3
yellow3 lab

We use emerging technology to make business less complicated.

Platforms

naffe.ai Software All platforms

Research

Research areas AI model adoption EU AI Act DPP Supplier Register

Company

About Advisory Insights Contact

Get in touch

Email us
Copenhagen, Denmark
© 2026 yellow3 ApS. All rights reserved.
Privacy Terms Cookies