yellow3
Research Digital Product Passport Platforms Insights Advisory About Contact
Get in touch →
Last updated - 5 August 2026

Terms of Service

These Terms of Service replace all previous terms governing yellow3.io and the services described below.

Plain-language summary

This summary is provided for convenience only. If it conflicts with the operative provisions below, the operative provisions apply.

yellow3 ApS publishes independent research, operates a free public register of Digital Product Passport providers and supplies a paid buyer platform that supports organisations planning, procuring, implementing and evidencing Digital Product Passport programmes.

Providers do not pay yellow3 to appear in the register and cannot pay to change, suppress or improve an independent finding.

yellow3 does not operate Digital Product Passports, certify providers or guarantee legal or regulatory compliance.

A finding that public evidence was not established is a dated statement about the available evidence. It is not a statement that the provider lacks the relevant capability.

Part I - General provisions

1. Parties and scope

These Terms of Service are entered into between:

yellow3 ApS
CVR no. 44954087
Hovedgaden 43
2970 Hørsholm
Denmark
Email: hello@yellow3.io

referred to as “yellow3”, “we”, “us” or “our”,

and each person or organisation that accesses the Website, submits information to the Register, purchases a Service or uses the Platform, referred to as “you” or “Customer”, as applicable.

These Terms govern:

  1. the website operated under the yellow3.io domain, referred to as the “Website”;
  2. yellow3’s published research, datasets and research instruments;
  3. the DPP Supplier Register;
  4. the DPP Buyer Platform;
  5. advisory services, briefings, workshops and masterclasses; and
  6. related services supplied by yellow3.

By accessing the Website, creating an account, submitting information, accepting an Order or using a Service, you agree to the provisions that apply to that activity.

Part C, together with sections 1 to 8, Part E and Schedule 1, constitutes the Buyer Platform Terms. A reference in an Order, invoice or other agreement to the “Buyer Platform Terms” incorporates those provisions.

2. Definitions

In these Terms:

“Applicable Data Protection Law” means the General Data Protection Regulation, the Danish Data Protection Act and any other data-protection law applicable to the relevant processing.

“Board Decision Snapshot” or “Snapshot” means a locked, point-in-time record generated by the Platform showing the requirements, evidence, findings, assumptions and decision state recorded at the time of generation.

“Customer Data” means information, documents, instructions, requirements, correspondence and other material submitted to the Platform by or on behalf of a Customer. It does not include Independent Research or aggregated information that no longer identifies the Customer or any individual.

“Customer Personal Data” means personal data contained in Customer Data that yellow3 processes on behalf of a Customer.

“DPP” means Digital Product Passport.

“Independent Research” means research, findings, source records, methods and datasets developed or maintained independently by yellow3, including public facts researched following a Customer request, provided that the Customer’s identity, requirements, private context and confidential communications are not disclosed.

“Order” means an accepted order form, invoice, online checkout, proposal, statement of work or other document identifying a paid Service.

“Output” means a report, comparison, shortlist, questionnaire, procurement package, implementation plan, Snapshot or other deliverable generated for a Customer through a paid Service.

“Platform” means the DPP Buyer Platform.

“Provider” means an organisation that supplies or claims to supply DPP-related products, technology or services.

“Register” means the public DPP Supplier Register operated by yellow3.

“Service” means any free or paid service provided by yellow3 under these Terms.

“User” means a natural person authorised to use a Customer’s Platform account.

3. Business use

Paid Services are offered exclusively to businesses, public authorities, institutions and persons acting for purposes connected with their trade, business or profession.

By purchasing a paid Service, you represent that:

  1. you are not acting as a consumer;
  2. you have authority to bind the organisation identified in the Order; and
  3. the information supplied during ordering and account creation is accurate.

4. Services

yellow3 may provide:

  1. free public research and research instruments;
  2. the free public DPP Supplier Register;
  3. the paid DPP Buyer Platform;
  4. advisory services, briefings, workshops and masterclasses; and
  5. related research, implementation and decision-support services described in an Order.

Features, availability and descriptions may evolve over time. Paid Services remain subject to the applicable Order and section 45.

5. Order of precedence

If documents conflict, the following order applies:

  1. Schedule 1 governs to the extent the conflict concerns processing of Customer Personal Data;
  2. the applicable Order governs commercial and service-specific matters;
  3. Part C governs the Platform;
  4. the remaining provisions of these Terms govern; and
  5. other Website descriptions or marketing materials have informational effect only.

An Order changes these Terms only where it expressly identifies the provision being changed.

Part A - Independence and role of yellow3

6. Independence

Inclusion in the Register is free.

Providers do not pay yellow3:

  1. to be included;
  2. to be assessed;
  3. to be assessed sooner;
  4. to receive a particular finding;
  5. to be described more favourably;
  6. to change, soften, suppress or remove a finding; or
  7. to receive sponsored placement or preferential visibility.

yellow3 does not accept advertising, sponsorship, referral fees, commissions or placement fees from Providers in exchange for any treatment in the Register.

A finding changes when the relevant evidence changes, an error is identified or the research methodology requires correction.

yellow3 has a commercial interest in the DPP market because it sells services to buyers selecting and implementing DPP solutions. That interest does not permit Providers to influence the Register or yellow3’s independent findings.

7. yellow3 does not operate Digital Product Passports

Unless expressly agreed in a separate written agreement, yellow3 does not:

  1. issue, host or publish product passports;
  2. act as the economic operator responsible for a passport;
  3. operate a passport repository, resolver or registry;
  4. maintain product data on behalf of the economic operator;
  5. provide conformity assessment; or
  6. assume the operational obligations of a selected Provider.

yellow3 may structure requirements, support procurement, produce implementation plans, review evidence and help a Customer maintain an auditable decision record.

The Customer and its selected Provider remain responsible for operating the relevant passport system and fulfilling their respective contractual and regulatory obligations.

8. No certification or compliance guarantee

Nothing published or provided by yellow3 constitutes:

  1. legal advice;
  2. regulatory advice;
  3. a conformity assessment;
  4. an audit opinion;
  5. certification or accreditation;
  6. approval by a notified body or public authority;
  7. a guarantee that a Provider, product or programme complies with law; or
  8. a guarantee that future legal requirements will be satisfied.

The Platform may help a Customer identify, structure and evidence requirements. It cannot determine future requirements that have not yet been legally defined.

Each Customer remains responsible for obtaining legal, technical, cybersecurity, regulatory, accounting and other specialist advice appropriate to its programme.

Part B - Public research and the DPP Supplier Register

9. Research methodology

Register findings are developed through review of publicly available material, which may include:

  1. Provider websites;
  2. technical documentation;
  3. public repositories;
  4. standards materials;
  5. corporate and public filings;
  6. product demonstrations;
  7. public statements;
  8. publications; and
  9. other publicly accessible artifacts.

yellow3 records, as applicable:

  1. what was reviewed;
  2. the source;
  3. the date of review;
  4. the passage or artifact supporting a finding;
  5. the domains or repositories inspected; and
  6. where evidence was not established, relevant search terms or search routes.

Findings are point-in-time research records. They are not permanent statements about a Provider.

10. Public finding states

The public Register may use the following finding states.

10.1 Demonstrated

Demonstrated means yellow3 opened a public artifact that showed the relevant capability or fact and recorded the material supporting the finding.

Demonstrated does not mean that yellow3 has audited the Provider’s internal systems, tested the capability in production or certified the Provider.

10.2 Provider states

Provider states means the Provider publicly asserts the relevant capability or fact, but yellow3 has not independently established it through a qualifying public artifact.

10.3 Not established

Not established means that, on the stated date, yellow3 searched for qualifying public evidence and did not establish it.

Not established:

  1. is a finding about publicly available evidence;
  2. is not a finding that the capability is absent;
  3. is not a finding that the Provider made a false statement;
  4. must not be described as “failed”, “incapable”, “non-compliant” or equivalent; and
  5. must be quoted together with its checked date and meaning.

10.4 Not applicable

Not applicable means the relevant check does not apply to the Provider or product, with the reason recorded.

10.5 Not assessed

Not assessed means yellow3 has not completed the relevant assessment or did not have sufficient information to apply the check.

10.6 Does not meet is not a public Register state

A conclusion that a Provider does not meet a requirement may be recorded only within a specific buyer engagement where the Provider has confirmed in writing that it cannot satisfy that buyer’s identified requirement.

Such a conclusion:

  1. is private to the relevant buyer engagement;
  2. is not inferred from silence or missing public evidence;
  3. is not automatically published in the Register; and
  4. does not establish that the Provider is unsuitable for other buyers or requirements.

11. No public score or endorsement

The public Register does not produce:

  1. a composite score;
  2. a league table;
  3. a star rating;
  4. a certification badge;
  5. a general ranking;
  6. a paid recommendation; or
  7. a yellow3 endorsement.

The Platform may produce Customer-specific comparisons or recommendations based on that Customer’s recorded requirements. Such an Output is not a general public ranking or endorsement.

12. Corrections and Provider responses

A Provider may request review of information concerning it.

Where qualifying evidence establishes that a finding is inaccurate or outdated, yellow3 may:

  1. correct the finding;
  2. replace it with a new dated finding;
  3. append a correction;
  4. identify the date and reason for the change; or
  5. withdraw the finding while it is reviewed.

Corrections are free and do not require a commercial relationship.

A Provider does not have a right to remove an accurate finding solely because it is unfavourable or because the Provider would prefer the information not to be published.

Where yellow3 and a Provider disagree, yellow3 may publish a concise Provider response alongside the finding, provided that the response:

  1. is relevant;
  2. is lawful;
  3. does not disclose confidential or personal information improperly;
  4. does not infringe third-party rights; and
  5. is presented in a format reasonably determined by yellow3.

yellow3 may decline repetitive, abusive, misleading or unsupported correction requests.

13. Claimed profiles and submitted information

A Provider may be permitted to claim its profile after yellow3 verifies control of an appropriate organisational domain or completes another verification process.

Profile verification confirms control of the verified account or domain. It does not certify the Provider, its capability or its legal status.

A person submitting information represents and warrants that:

  1. they are authorised to act for the relevant organisation;
  2. the information is accurate to the best of their knowledge;
  3. the submission does not infringe third-party rights;
  4. the submission does not contain information they are prohibited from disclosing;
  5. any logo, image, document or other material may lawfully be supplied and displayed; and
  6. the submission complies with applicable law.

The submitting organisation grants yellow3 a worldwide, non-exclusive, royalty-free licence to host, reproduce, format, display and publish the submitted material for the operation, promotion and historical documentation of the Register.

Company-supplied material is identified as such and remains visually and structurally separate from Independent Research.

yellow3 may edit formatting, reject a submission, request evidence, remove unlawful material or retain a historical record of corrections and previous statements.

Do not submit trade secrets, confidential information, special-category personal data or information concerning criminal offences through a public profile.

14. Accuracy, completeness and currency

yellow3 takes reasonable care to apply its stated research method accurately.

yellow3 does not warrant that:

  1. the Register is complete or exhaustive;
  2. every relevant Provider has been identified;
  3. all public material was discoverable when the search was performed;
  4. a source remained available after the checked date;
  5. a finding remains current after the checked date;
  6. a Provider’s public statement is accurate;
  7. a public artifact accurately represents production capability; or
  8. the Register is free from error.

Absence of an organisation from the Register carries no meaning.

Users should review the source record and checked date before relying on a finding.

15. Permitted use of individual findings

Subject to section 16, individual findings may be quoted or reproduced for:

  1. journalism;
  2. criticism or review;
  3. academic or market research;
  4. internal business decision-making;
  5. regulatory or legal reporting; and
  6. other uses permitted by law.

Any quotation must:

  1. attribute yellow3 lab;
  2. include the finding date;
  3. preserve the applicable definition in section 10;
  4. avoid implying certification, endorsement or a composite score; and
  5. avoid presenting “not established” as absence of capability.

Nothing in these Terms restricts rights that cannot lawfully be restricted, including lawful quotation, reporting, whistleblowing, regulatory disclosure and use in legal proceedings.

16. Database rights, copyright and text and data mining

The Register and yellow3 research datasets may be protected by copyright and by the database rights available under applicable Danish and European law.

yellow3 has made substantial investment in obtaining, verifying, organising, maintaining and presenting the contents of the Register and its research datasets.

Except where permitted by law or expressly authorised in writing, you may not:

  1. extract or re-utilise all or a substantial part of a protected database;
  2. repeatedly or systematically extract or re-utilise insubstantial parts in a manner that conflicts with normal exploitation of the database or unreasonably prejudices yellow3’s legitimate interests;
  3. copy the structure or selection of the Register to create a substitute service;
  4. reproduce the Register as a competing directory, dataset or comparison product; or
  5. circumvent access controls, rate limits or technical protections.

Reservation of text and data mining rights

To the extent permitted by law, yellow3 expressly reserves its rights in relation to text and data mining, including extraction, reproduction and analysis for:

  1. training or fine-tuning artificial intelligence or machine-learning models;
  2. creating embeddings or vector datasets;
  3. grounding retrieval systems;
  4. model validation, benchmarking or evaluation;
  5. building commercial knowledge bases; and
  6. producing competing datasets or derived commercial products.

This reservation is made for the purposes of section 11 b of the Danish Copyright Act and Article 4(3) of Directive (EU) 2019/790.

yellow3 may also express this reservation through machine-readable means, including metadata, HTTP headers, robots instructions or other appropriate technical measures. The contractual reservation in these Terms supplements such machine-readable reservation.

Nothing in this section restricts text and data mining that yellow3 cannot lawfully reserve, including qualifying scientific-research uses under mandatory law.

17. Automated access

Automated access to the Website or Register is prohibited unless:

  1. it is ordinary search-engine indexing permitted by yellow3’s technical instructions;
  2. it is necessary for accessibility technology;
  3. it is expressly permitted by law; or
  4. yellow3 has given prior written permission.

Prohibited activity includes scraping, crawling, bulk downloading, automated account creation and attempts to bypass rate limits or technical restrictions.

yellow3 may block automated access and suspend accounts used for prohibited extraction.

Part C - DPP Buyer Platform

18. Nature of the Platform

The Platform is a business subscription service supporting the planning, procurement, implementation and evidencing of DPP programmes.

Its product principle is:

Plan it. Buy it. Implement it. Prove it.

The Platform may help a Customer:

  1. define programme requirements;
  2. assess readiness;
  3. review Providers;
  4. record evidence and assumptions;
  5. generate questionnaires and evidence requests;
  6. compare responses;
  7. create shortlists;
  8. prepare RFI or RFP materials;
  9. produce implementation plans;
  10. establish governance and responsibility models;
  11. monitor evidence and revalidation requirements; and
  12. generate Board Decision Snapshots.

Sections 7 and 8 apply fully. The Platform does not operate product passports and does not certify compliance.

19. Accounts and access

Access is granted only to named Users authorised by the Customer.

The Customer must appoint at least one account administrator responsible for:

  1. approving and removing Users;
  2. assigning appropriate permissions;
  3. keeping Customer contact information current; and
  4. informing yellow3 promptly when a User should no longer have access.

Credentials are personal and must not be shared.

The Customer is responsible for activity conducted through its accounts, except to the extent the activity results from yellow3’s breach of its security obligations.

The Customer must notify yellow3 promptly if it suspects unauthorised access or compromise.

yellow3 may require password resets, multi-factor authentication or other reasonable security measures.

20. Orders, fees and payment

The applicable fees, currency, payment schedule, subscription period and included usage are stated in the Order.

Unless the Order states otherwise:

  1. fees are payable in advance;
  2. invoices are due 14 days from the invoice date;
  3. fees exclude VAT and other applicable taxes;
  4. the Customer is responsible for taxes other than taxes on yellow3’s net income;
  5. fees are non-refundable except as expressly stated in these Terms or the Order; and
  6. the Customer may not withhold or set off amounts unless required by mandatory law.

Overdue amounts may accrue interest and recovery costs in accordance with the Danish Interest Act.

yellow3 may suspend a paid Service for undisputed overdue amounts after giving reasonable written notice and an opportunity to cure.

Payment card services may be provided by an independent payment processor. yellow3 does not receive or store complete card details where they are processed directly by that provider.

21. Subscription term and renewal

The initial subscription term is stated in the Order.

A subscription renews only where the Order expressly states that automatic renewal applies.

Where automatic renewal applies:

  1. renewal occurs for the period stated in the Order;
  2. yellow3 will provide notice of any price change before renewal; and
  3. either party may prevent renewal by giving the notice specified in the Order, or 30 days’ notice if the Order is silent.

Where the Order does not address renewal, the subscription ends at the conclusion of the stated term.

22. Buyer-private Customer Data

Customer Data is buyer-private.

Subject to these Terms and the Customer’s instructions, yellow3 will not disclose Customer Data to:

  1. other Customers;
  2. Providers;
  3. the public Register; or
  4. unauthorised third parties.

Customer Data is logically isolated by organisation within the Platform.

yellow3 does not sell Customer Data.

yellow3 does not disclose which buyers are evaluating a Provider, or that a Provider is being evaluated, unless:

  1. the Customer chooses to send an evidence request;
  2. disclosure is necessary to provide a Customer-authorised Service;
  3. the Customer instructs yellow3 to disclose it; or
  4. disclosure is required by law.

The Customer retains ownership of Customer Data.

The Customer grants yellow3 a limited, non-exclusive licence to host, copy, transmit, format and otherwise process Customer Data solely as necessary to:

  1. provide and secure the Service;
  2. follow the Customer’s documented instructions;
  3. provide support;
  4. prevent abuse;
  5. comply with law; and
  6. exercise yellow3’s rights under these Terms.

23. Customer responsibilities

The Customer is responsible for:

  1. the legality, accuracy and quality of Customer Data;
  2. having appropriate rights and legal grounds to submit Customer Data;
  3. defining its requirements and decision criteria;
  4. reviewing material Outputs before relying on them;
  5. deciding whether to contact, shortlist or contract with a Provider;
  6. obtaining professional advice where required;
  7. complying with laws applicable to its programme;
  8. maintaining appropriate internal approvals and governance; and
  9. ensuring Users comply with these Terms.

The Platform is not intended for special-category personal data, criminal-offence data, medical records, employee disciplinary records or other highly sensitive personal data.

The Customer must not submit such data unless yellow3 has expressly agreed in writing and appropriate safeguards have been established.

24. Evidence requests and Provider responses

The Platform may allow a Customer to send evidence requests or questionnaires to Providers.

The Customer controls whether an evidence request is sent and is responsible for:

  1. the request’s purpose and content;
  2. the lawfulness of the communication;
  3. any contractual or confidentiality obligation applying to the request; and
  4. the decision to rely on the response.

A Provider response is recorded as the Provider’s statement for the relevant Customer engagement.

A Provider response:

  1. is displayed separately from Independent Research;
  2. does not automatically change a public finding;
  3. is not automatically reused for another Customer;
  4. is not treated as independently verified merely because it was supplied through the Platform; and
  5. may be subject to confidentiality obligations imposed between the Customer and Provider.

A commitment made during a specific negotiation does not establish a general public capability.

yellow3 does not become party to an agreement or non-disclosure agreement between a Customer and Provider unless yellow3 expressly accepts that agreement in writing.

25. Reuse of Independent Research

Public facts established through independent research may be used to maintain the Register or support other Customers.

yellow3 will not reuse as Independent Research:

  1. the Customer’s identity;
  2. the Customer’s requirements;
  3. the Customer’s internal context;
  4. private Provider correspondence;
  5. commercially negotiated commitments;
  6. Customer-specific scoring or weighting; or
  7. confidential information.

Where a Customer request leads yellow3 to research a public fact, yellow3 may retain and reuse the resulting public source and general finding without identifying the Customer.

26. Automated systems and artificial intelligence

The Platform may use automated systems and artificial intelligence to assist with:

  1. research;
  2. source classification;
  3. drafting;
  4. comparison;
  5. extraction;
  6. workflow execution;
  7. identifying inconsistencies;
  8. generating proposed findings; and
  9. preparing Outputs.

Automated Outputs may contain errors, omissions or inappropriate inferences.

Where material conclusions are presented, the Platform is designed to associate those conclusions with relevant records, evidence, assumptions or uncertainty states.

The Customer must review Outputs appropriate to the importance and risk of the decision.

yellow3 will not use Customer Data to train or fine-tune a general-purpose, shared or publicly available artificial-intelligence model unless the Customer has expressly agreed in writing.

Where an artificial-intelligence subprocessor handles Customer Data, yellow3 will use available contractual and technical configurations intended to prevent the subprocessor from using that data for its own model training.

27. Board Decision Snapshots, export and retention

A Board Decision Snapshot is locked after generation and cannot be silently overwritten through ordinary Platform use.

Where a correction, deletion or legal requirement affects a Snapshot:

  1. the original decision state may be retained where lawful;
  2. the correction or redaction will be recorded as a dated event;
  3. the Snapshot may identify that its completeness has been reduced; and
  4. yellow3 will not silently reconstruct the historical decision.

The Customer may export available programme data and Outputs during the subscription in a commonly used format supported by the Platform.

Unless the Order states otherwise:

  1. active programme data is retained while the subscription remains active;
  2. after a programme is closed, Customer Data may be retained for up to 24 months to support reopening, audit and export;
  3. the Customer may request earlier deletion, subject to legal obligations and agreed Snapshot retention;
  4. Snapshots may be retained for up to seven years at the Customer’s instruction to preserve an auditable decision record;
  5. personal identifiers not required for the evidential purpose of a retained Snapshot will be deleted or irreversibly anonymised after 24 months where reasonably practicable; and
  6. accounting, security and legal records may be retained for the period required by law or necessary to establish, exercise or defend legal claims.

At termination, the Customer will normally have 30 days to request or complete an export, unless access has been suspended for unlawful conduct or a serious security risk.

28. Security, availability and support

yellow3 will implement appropriate technical and organisational measures designed to protect Customer Data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure or unauthorised access.

The minimum security commitments are described in Schedule 1.

The Customer acknowledges that no online service can guarantee absolute security or uninterrupted operation.

Unless an Order includes a specific service-level commitment:

  1. the Platform is supplied without a guaranteed uptime;
  2. yellow3 may perform planned and emergency maintenance;
  3. functionality may be temporarily unavailable;
  4. yellow3 may take immediate action to address security threats; and
  5. support is provided through the contact route designated by yellow3.

yellow3 will use commercially reasonable efforts to avoid unnecessary disruption and to restore material functionality following an incident.

29. Data protection

For Customer Personal Data:

  1. the Customer is the controller;
  2. yellow3 is the processor; and
  3. Schedule 1 forms the binding data-processing agreement between the parties.

For personal data yellow3 processes for its own purposes, including account administration, billing, security, Website operation and public research, yellow3 acts as controller.

yellow3’s Privacy Notice explains its controller processing.

If the Customer is a processor acting for another controller, yellow3 acts as the Customer’s subprocessor and the Customer warrants that it is authorised to appoint yellow3.

30. Licence to Customer Outputs

Subject to payment of all applicable fees, yellow3 grants the Customer a perpetual, non-exclusive, worldwide, royalty-free licence to use, copy and adapt Customer-specific Outputs for:

  1. internal business purposes;
  2. board and management review;
  3. procurement and implementation;
  4. sharing with group companies;
  5. sharing with professional advisers;
  6. sharing with regulators, auditors and financing parties where reasonably required; and
  7. sharing relevant extracts with candidate Providers.

The Customer may not:

  1. resell Outputs as a standalone product;
  2. use Outputs to build a competing register, dataset or comparison platform;
  3. remove source, date or uncertainty information in a misleading manner;
  4. present an Output as certification or regulatory approval; or
  5. publish confidential Provider responses without authority.

The licence does not transfer ownership of yellow3’s underlying methods, templates, taxonomies, research systems, software, Independent Research or pre-existing intellectual property.

31. Acceptable use

The Customer and Users must not:

  1. resell, rent, sublicense or share Platform access outside the Customer organisation;
  2. allow credentials to be used by multiple people;
  3. use the Platform to build a competing register, research dataset or comparison service;
  4. systematically extract Platform or Register data;
  5. reverse engineer or attempt to discover source code except where mandatory law permits;
  6. bypass access controls or usage limits;
  7. upload malware or harmful code;
  8. use the Platform unlawfully or fraudulently;
  9. infringe intellectual-property, privacy or confidentiality rights;
  10. harass Providers or send unlawful communications;
  11. misrepresent a finding;
  12. present an Output as certification, accreditation or a compliance guarantee;
  13. use the Platform to make unlawful discriminatory decisions; or
  14. interfere with the security or operation of the Service.

32. Suspension

yellow3 may suspend all or part of the Platform where reasonably necessary to:

  1. address a security threat;
  2. prevent unlawful use;
  3. protect other Customers or Providers;
  4. respond to a legal or regulatory requirement;
  5. address material breach of these Terms; or
  6. respond to undisputed overdue payment.

Where practicable, yellow3 will provide prior notice and an opportunity to cure.

Where immediate action is required, yellow3 may suspend first and notify the Customer promptly afterwards.

yellow3 will limit a suspension to the scope and duration reasonably necessary.

33. Termination

Either party may terminate an Order:

  1. where the other party materially breaches the agreement and fails to cure the breach within 30 days after written notice;
  2. immediately where a breach cannot reasonably be cured;
  3. immediately where continued performance would be unlawful;
  4. where the other party enters insolvency, liquidation or a similar proceeding, subject to mandatory law; or
  5. as otherwise stated in the Order.

yellow3 may terminate immediately for deliberate misuse of the Register, unlawful extraction, serious security abuse, fraud or repeated infringement of third-party rights.

Termination for convenience is available only where stated in the Order.

34. Effect of termination

On termination or expiry:

  1. the Customer’s right to use the Platform ends;
  2. outstanding fees become payable;
  3. the Customer may exercise available export rights under section 27;
  4. yellow3 will process or delete Customer Personal Data in accordance with Schedule 1;
  5. licences already granted to the Customer for paid Outputs survive;
  6. confidentiality obligations survive;
  7. accrued rights and liabilities remain unaffected; and
  8. provisions intended by their nature to survive will continue, including sections concerning intellectual property, restrictions, liability, retention, confidentiality and governing law.

Part D - Advisory services, workshops and masterclasses

35. Bookings and payment

Advisory sessions, workshops, briefings and masterclasses may be purchased through the Website or an Order.

Prices and included services are stated at the time of purchase.

By completing a purchase, the Customer confirms that:

  1. it is authorised to make the booking;
  2. payment information is accurate;
  3. attendees are participating for business or professional purposes; and
  4. it will provide information reasonably required to deliver the session.

Additional work, travel, research or deliverables are included only if stated in the Order.

36. Cancellation and rescheduling

Unless an Order states otherwise:

  1. the Customer may cancel at least seven days before the scheduled date for a refund;
  2. cancellations made less than seven days before the scheduled date are non-refundable;
  3. a late cancellation may be rescheduled once without an additional session fee, subject to availability;
  4. failure to attend without notice is treated as a late cancellation; and
  5. approved non-refundable travel or third-party costs remain payable.

If yellow3 cancels, the Customer may choose between:

  1. a full refund of the affected session fee; or
  2. rescheduling without additional charge.

37. Session confidentiality, materials and recordings

Each party must keep confidential non-public business information disclosed during an advisory engagement, subject to section 39.

Materials supplied by yellow3 may be used internally by the Customer but may not be sold, publicly redistributed or used to create a competing commercial product.

No session may be recorded, transcribed by an external service or broadcast without the prior consent of all participants.

Customer-specific deliverables are subject to the licence in section 30 unless the Order states otherwise.

Part E - General legal terms

38. Intellectual property

Except for Customer Data and third-party material, all rights in the Website, Platform, Register, research instruments, datasets, software, methods, templates, taxonomies, designs, graphics, logos and content belong to yellow3 or its licensors.

No right is granted except as expressly stated in these Terms.

The yellow3 name, logo and other brand elements may not be used in a way that suggests sponsorship, certification, endorsement or partnership without prior written permission.

39. Confidentiality

“Confidential Information” means non-public information disclosed by one party to the other that is identified as confidential or that should reasonably be understood to be confidential given its nature and the circumstances of disclosure.

Confidential Information does not include information that the receiving party can demonstrate:

  1. is or becomes public without breach;
  2. was lawfully known without confidentiality restriction;
  3. was independently developed without use of the disclosing party’s information; or
  4. was lawfully received from a third party without confidentiality restriction.

The receiving party must:

  1. use Confidential Information only to perform or receive the Services;
  2. protect it using at least reasonable care;
  3. disclose it only to personnel, advisers and subprocessors who need it and are subject to appropriate confidentiality duties; and
  4. notify the disclosing party of unauthorised disclosure where legally permitted.

A party may disclose Confidential Information where required by law, court or regulator, provided it gives prior notice where legally permitted and reasonably assists efforts to limit the disclosure.

These obligations continue for five years after disclosure. Trade secrets remain protected for as long as they remain trade secrets under applicable law.

40. Feedback

Where a User voluntarily provides suggestions or feedback concerning a Service, yellow3 may use that feedback without restriction or payment, provided that yellow3 does not identify the Customer or disclose its Confidential Information.

41. Third-party services and links

The Website and Platform may use or link to third-party services.

Third-party services may be governed by separate terms and privacy notices.

yellow3 is not responsible for:

  1. third-party content;
  2. Provider websites;
  3. services selected independently by a Customer;
  4. changes made by a third-party service;
  5. a Provider’s acts, omissions or performance; or
  6. a Customer’s contract with a Provider.

Where a third party processes Customer Personal Data on yellow3’s behalf, Schedule 1 applies.

42. Warranties and disclaimers

yellow3 warrants that paid Services will be performed with reasonable skill and care and will materially conform to the applicable Order.

If yellow3 materially breaches this warranty and the Customer notifies yellow3 promptly, yellow3 may, at its option:

  1. reperform the affected Service;
  2. correct the material non-conformity; or
  3. refund the proportion of prepaid fees attributable to the materially non-conforming Service.

This is the Customer’s primary contractual remedy for breach of the service warranty.

Subject to this express warranty and mandatory law:

  1. free research and public Services are provided on an “as available” basis;
  2. yellow3 does not warrant uninterrupted or error-free operation;
  3. yellow3 does not warrant that all sources are complete or authentic;
  4. yellow3 does not warrant the conduct or performance of any Provider;
  5. yellow3 does not guarantee a procurement, implementation or regulatory outcome; and
  6. the Customer remains responsible for its decisions and use of Outputs.

43. Limitation of liability

Nothing in these Terms excludes or limits liability to the extent it cannot lawfully be excluded or limited, including liability for:

  1. fraud;
  2. fraudulent misrepresentation;
  3. death or personal injury caused by negligence;
  4. wilful misconduct; or
  5. any other liability that cannot be limited under Danish law.

Subject to the preceding paragraph, neither party is liable for:

  1. indirect or consequential loss;
  2. loss of profit;
  3. loss of revenue;
  4. loss of anticipated savings;
  5. loss of business opportunity;
  6. loss of goodwill; or
  7. loss arising from a Provider’s acts, omissions, systems or performance.

yellow3 is not liable merely because:

  1. a Provider was not included in the Register;
  2. public evidence was not discoverable;
  3. a source changed after the checked date;
  4. a Provider supplied inaccurate information;
  5. a Customer selected or rejected a Provider; or
  6. future law differed from assumptions recorded in an Output.

For paid Services, yellow3’s aggregate liability arising from or connected with an Order will not exceed the fees paid or payable by the Customer for the affected Service during the 12 months immediately preceding the event giving rise to the claim.

For a Service supplied for less than 12 months, the cap is the total fees paid or payable for that Service.

The liability cap does not apply to:

  1. the Customer’s payment obligations;
  2. a party’s deliberate infringement of the other party’s intellectual-property rights;
  3. liability under section 44; or
  4. liability that cannot legally be limited.

For free Services, yellow3 has no liability except to the extent required by mandatory law.

44. Customer indemnity

The Customer will indemnify yellow3 against third-party claims, damages, liabilities and reasonable external legal costs arising directly from:

  1. Customer Data infringing a third party’s rights;
  2. the Customer’s unlawful use of a Service;
  3. communications sent to Providers by or at the instruction of the Customer;
  4. the Customer’s breach of confidentiality owed to a Provider; or
  5. a material breach of section 31.

The indemnity does not apply to the extent the claim results from yellow3’s breach, negligence or unauthorised modification of Customer Data.

yellow3 must:

  1. notify the Customer promptly of the claim;
  2. provide reasonable cooperation at the Customer’s expense; and
  3. allow the Customer to control the defence and settlement, provided that no settlement admits fault by yellow3 or imposes obligations on yellow3 without its written consent.

45. Changes to Services and Terms

yellow3 may change free Services, research methods and public Website features at any time.

For a paid Service during an active term, yellow3 will not materially reduce its core contracted functionality without:

  1. providing reasonable notice;
  2. offering a substantially equivalent alternative; or
  3. allowing the Customer to terminate the materially affected Service and receive a pro-rata refund of prepaid unused fees.

yellow3 may make immediate changes required for:

  1. law or regulation;
  2. security;
  3. prevention of abuse;
  4. third-party dependency changes; or
  5. protection of users or data.

yellow3 may update these Terms.

Material changes affecting an active paid term will normally take effect:

  1. at renewal; or
  2. earlier where required by law, security or a regulator.

Where a material change takes effect during an active term and materially disadvantages the Customer, the Customer may terminate the affected Service before the change takes effect and receive a pro-rata refund of prepaid unused fees.

Continued use after the effective date of a validly notified change constitutes acceptance.

46. Force majeure

Neither party is liable for delay or failure caused by circumstances beyond its reasonable control, including natural disasters, war, terrorism, civil disorder, government action, widespread telecommunications failure, widespread cloud-infrastructure failure, labour dispute or interruption of essential utilities.

The affected party must:

  1. notify the other party where reasonably practicable;
  2. take reasonable steps to mitigate the effect; and
  3. resume performance when reasonably possible.

Force majeure does not excuse payment obligations already due or a failure that reasonable security or continuity measures should have prevented.

47. Notices

Operational notices may be provided through:

  1. the Platform;
  2. the Website;
  3. the Customer administrator’s registered email address; or
  4. hello@yellow3.io.

Notices concerning breach, termination or legal claims must be sent by email and by another method reasonably capable of proving delivery.

A Customer must keep its account and billing contact details current.

48. Assignment and subcontracting

The Customer may not assign an Order without yellow3’s prior written consent, which will not be unreasonably withheld.

yellow3 may assign these Terms or an Order:

  1. to an affiliate;
  2. as part of a merger, restructuring or sale of all or substantially all relevant assets; or
  3. to a successor operating the relevant Service,

provided that the assignment does not materially reduce the Customer’s rights.

yellow3 may use subcontractors to provide the Services. yellow3 remains responsible for their performance to the extent required by these Terms and Applicable Data Protection Law.

49. Severability and waiver

If a provision is invalid or unenforceable, it will be modified to the minimum extent necessary to make it enforceable. If modification is not possible, it will be removed without affecting the remaining provisions.

A failure or delay in exercising a right is not a waiver of that right.

A waiver is effective only if made in writing and applies only to the specific circumstances identified.

50. Entire agreement and relationship

These Terms, the applicable Order and any incorporated schedules constitute the entire agreement concerning the relevant Service and replace prior discussions, representations and agreements concerning that subject.

Nothing creates:

  1. a partnership;
  2. a joint venture;
  3. an employment relationship;
  4. a fiduciary relationship;
  5. an agency relationship; or
  6. authority for one party to bind the other.

Except as expressly stated, no third party has a right to enforce these Terms.

Electronic acceptance, electronic signatures and electronic records have the same contractual effect as paper acceptance and signatures.

51. Governing law, venue and language

These Terms and any non-contractual obligations connected with them are governed by Danish law, without regard to conflict-of-law principles.

The courts of Denmark have exclusive jurisdiction.

The competent court for the place of yellow3’s registered office will be the agreed court of first instance, unless mandatory law requires another venue.

The governing version of these Terms is the English-language version. A translation is provided for convenience only.

52. Contact

Questions concerning these Terms may be sent to:

yellow3 ApS
Hovedgaden 43
2970 Hørsholm
Denmark
CVR no. 44954087
Email: hello@yellow3.io

Register correction requests should be submitted through the correction route displayed in the Register or by email.

Data-protection requests should be submitted through the contact route stated in the Privacy Notice.

Schedule 1 - Data Processing Addendum

This Schedule forms part of the Buyer Platform Terms and applies where yellow3 processes Customer Personal Data on behalf of the Customer.

1. Roles and instructions

The Customer is the controller and yellow3 is the processor.

Where the Customer acts as processor for another controller, yellow3 is a subprocessor.

yellow3 will process Customer Personal Data only:

  1. on the Customer’s documented instructions;
  2. as necessary to provide, secure and support the Platform;
  3. as described in this Schedule and the applicable Order; or
  4. where required by European Union or Member State law.

The Customer instructs yellow3 to process Customer Personal Data for the purposes described in Appendix A.

The Customer may issue additional reasonable written instructions that are consistent with the Service and Applicable Data Protection Law. Additional work or material cost resulting from such instructions may require an agreed fee.

If yellow3 believes an instruction infringes Applicable Data Protection Law, yellow3 will notify the Customer unless legally prohibited and may suspend the affected processing while the parties resolve the issue.

2. Customer obligations

The Customer warrants that:

  1. it has a lawful basis for the processing;
  2. it has provided required privacy information;
  3. its instructions comply with Applicable Data Protection Law;
  4. it has authority to appoint yellow3;
  5. Customer Personal Data is relevant and limited to what is necessary; and
  6. it will not submit prohibited sensitive data without prior written agreement.

The Customer is responsible for responding to data subjects and determining whether their requests are valid.

3. Confidentiality

yellow3 will ensure that persons authorised to process Customer Personal Data:

  1. are bound by confidentiality obligations;
  2. receive appropriate data-protection and security instructions;
  3. access data only where necessary for their role; and
  4. process data only in accordance with the Customer’s instructions.

Confidentiality obligations continue after a person’s access ends.

4. Security

yellow3 will implement and maintain technical and organisational measures appropriate to the risk, including the measures described in Appendix B.

yellow3 may update those measures provided the overall level of protection is not materially reduced.

The Customer is responsible for assessing whether the measures are appropriate for its processing and for configuring Customer-controlled security features appropriately.

5. Personal-data breaches

yellow3 will notify the Customer without undue delay after becoming aware of a personal-data breach affecting Customer Personal Data.

The notification will provide available information concerning:

  1. the nature of the breach;
  2. affected data and data subjects;
  3. likely consequences;
  4. mitigation and remediation measures; and
  5. a contact for follow-up.

Information may be provided in stages as it becomes available.

yellow3’s notification does not constitute an admission of fault or liability.

The Customer is responsible for notifications to data subjects and supervisory authorities unless the parties agree otherwise.

6. Assistance

Taking into account the nature of the processing and information available to yellow3, yellow3 will reasonably assist the Customer with:

  1. data-subject requests;
  2. security obligations;
  3. personal-data-breach assessments;
  4. data-protection impact assessments;
  5. prior consultation with supervisory authorities; and
  6. demonstrating compliance.

Where assistance requires substantial work beyond normal Service operation, yellow3 may charge reasonable fees agreed in advance, except where the assistance is required because of yellow3’s breach.

7. Subprocessors

The Customer gives yellow3 general authorisation to appoint subprocessors.

yellow3 will:

  1. maintain an up-to-date list of subprocessors;
  2. make the list available to the Customer on request or through the Platform;
  3. provide reasonable advance notice of a new subprocessor that will process Customer Personal Data;
  4. impose data-protection obligations materially equivalent to those in this Schedule; and
  5. remain responsible for the subprocessor’s performance to the extent required by law.

The Customer may object to a new subprocessor on reasonable and documented data-protection grounds.

The parties will attempt to resolve the objection in good faith.

If no reasonable solution is available, the Customer may terminate the materially affected part of the Service before the subprocessor begins processing and receive a pro-rata refund of prepaid unused fees for that affected part.

Where an artificial-intelligence service acts as subprocessor, yellow3 will use available enterprise or API terms and settings intended to prevent use of Customer Personal Data for the provider’s own model training, unless the Customer expressly agrees otherwise.

8. International transfers

yellow3 will not transfer Customer Personal Data outside the European Economic Area unless:

  1. the destination is subject to a valid adequacy decision;
  2. appropriate safeguards are implemented;
  3. a permitted derogation applies; or
  4. the transfer is otherwise lawful.

Appropriate safeguards may include the European Commission’s standard contractual clauses then in force, together with supplementary measures where required.

The Customer authorises yellow3 to enter into applicable standard contractual clauses on the Customer’s behalf where necessary to appoint an authorised subprocessor.

9. Data-subject requests

If yellow3 receives a request directly from a data subject concerning Customer Personal Data, yellow3 will:

  1. notify the Customer promptly;
  2. not respond substantively unless instructed or legally required; and
  3. provide reasonable assistance through available Platform functionality or support processes.

10. Audits and compliance information

yellow3 will make available information reasonably necessary to demonstrate compliance with this Schedule.

Where available, yellow3 may first satisfy an audit request through:

  1. security documentation;
  2. audit reports;
  3. certifications;
  4. penetration-test summaries;
  5. subprocessor information; or
  6. written responses.

If that information is insufficient, the Customer may conduct one audit in any 12-month period, unless a breach, regulator or material risk reasonably requires an additional audit.

An audit must:

  1. take place on reasonable written notice;
  2. occur during normal business hours;
  3. avoid unreasonable disruption;
  4. protect other customers’ information and yellow3’s security;
  5. be conducted by an independent auditor subject to confidentiality; and
  6. be paid for by the Customer, unless the audit identifies a material breach by yellow3.

No audit may require disclosure of information that would compromise another customer, security controls or yellow3’s legal obligations.

11. Return and deletion

During the Service, the Customer may export Customer Personal Data using available functionality.

Following termination, expiry or a valid deletion instruction, yellow3 will delete or return Customer Personal Data in accordance with section 27, unless:

  1. law requires retention;
  2. the Customer has instructed Snapshot retention;
  3. retention is necessary to establish, exercise or defend legal claims; or
  4. the data is contained in a backup that cannot reasonably be isolated immediately.

Data retained in backups will remain protected and will be deleted or overwritten through the normal backup lifecycle.

Where yellow3 retains data because law requires it, yellow3 will process it only for that legal purpose.

12. Government and legal requests

If yellow3 is legally required to disclose Customer Personal Data, yellow3 will notify the Customer before disclosure unless prohibited by law.

yellow3 will disclose only the data legally required and will reasonably challenge disproportionate or unlawful demands where appropriate.

13. Processing records and cooperation

yellow3 will maintain records of processing activities required of it as a processor.

yellow3 will cooperate with competent supervisory authorities in accordance with Applicable Data Protection Law.

14. Liability and precedence

Liability arising under this Schedule is subject to section 43 of the Terms, except to the extent Applicable Data Protection Law prohibits that limitation.

If this Schedule conflicts with another provision concerning processing of Customer Personal Data, this Schedule prevails.

Appendix A - Processing details

Subject matter

Operation, hosting, security, support and administration of the DPP Buyer Platform and Customer programmes.

Duration

For the subscription term and the applicable export, retention and deletion periods described in the Terms or Order.

Nature of processing

Processing may include:

  1. collection;
  2. recording;
  3. organisation;
  4. structuring;
  5. storage;
  6. adaptation;
  7. retrieval;
  8. consultation;
  9. comparison;
  10. automated analysis;
  11. transmission to authorised recipients and subprocessors;
  12. export;
  13. restriction;
  14. anonymisation; and
  15. deletion.

Purposes

  1. creating and administering User accounts;
  2. operating Customer workspaces;
  3. recording programme requirements;
  4. managing Provider assessments;
  5. transmitting Customer-authorised evidence requests;
  6. recording Provider responses;
  7. generating Outputs and Snapshots;
  8. providing support;
  9. securing and monitoring the Service;
  10. preventing fraud and abuse;
  11. maintaining backups and business continuity; and
  12. complying with documented Customer instructions and applicable law.

Categories of data subjects

  1. Customer Users;
  2. Customer employees and representatives;
  3. Customer contractors and advisers;
  4. Provider representatives;
  5. prospective Provider representatives;
  6. individuals copied in programme correspondence; and
  7. other professional contacts included by the Customer.

Types of personal data

  1. names;
  2. business contact details;
  3. job titles and organisations;
  4. account and authentication information;
  5. User identifiers;
  6. programme roles and responsibilities;
  7. professional correspondence;
  8. Provider responses;
  9. usage records;
  10. audit logs;
  11. support communications; and
  12. personal data contained in uploaded business documents.

Sensitive data

The Service is not intended for special-category personal data, criminal-offence data or similarly sensitive information unless expressly agreed in writing.

Processing locations

Processing locations are determined by yellow3’s authorised infrastructure and subprocessors and are subject to sections 7 and 8 of this Schedule.

Appendix B - Minimum technical and organisational measures

yellow3 will maintain measures appropriate to the risk, including:

1. Access control

  1. named User accounts;
  2. role-based permissions;
  3. least-privilege access;
  4. controlled privileged access;
  5. prompt removal of unnecessary access; and
  6. multi-factor authentication for privileged administrative access.

2. Tenant separation

  1. logical separation of Customer organisations;
  2. database and application controls restricting cross-customer access; and
  3. testing of material access-control changes.

3. Encryption and communications

  1. encryption of data in transit using current, commonly accepted transport-security protocols;
  2. encryption at rest where supported by the relevant infrastructure;
  3. secure management of credentials and secrets; and
  4. prohibition on transmitting production credentials through insecure channels.

4. System security

  1. security patching appropriate to risk;
  2. dependency and vulnerability management;
  3. restricted production access;
  4. secure development and change-management practices;
  5. review of material security changes; and
  6. safeguards against malicious code and common application attacks.

5. Logging and monitoring

  1. logging of relevant administrative and security events;
  2. monitoring for suspicious access or material failures;
  3. protection of logs against unauthorised alteration; and
  4. retention of logs appropriate to their security purpose.

6. Availability and resilience

  1. backups appropriate to the Service;
  2. restoration procedures;
  3. business-continuity planning;
  4. incident-response procedures; and
  5. reasonable measures to reduce single points of failure.

7. Organisational measures

  1. confidentiality obligations;
  2. access reviews;
  3. security awareness;
  4. documented incident escalation;
  5. supplier and subprocessor due diligence; and
  6. data-protection obligations in relevant supplier contracts.

8. Data minimisation and deletion

  1. collection limited to Service purposes;
  2. retention controls;
  3. secure deletion procedures;
  4. restriction of test-data use; and
  5. anonymisation or pseudonymisation where appropriate.

9. Artificial-intelligence processing

Where artificial-intelligence services process Customer Personal Data:

  1. only authorised services may be used;
  2. data sent to the service will be limited to what is necessary;
  3. available no-training or equivalent controls will be used;
  4. access will be governed through managed credentials;
  5. outputs will not be treated as automatically accurate; and
  6. processing will remain subject to the subprocessor and transfer provisions of this Schedule.
yellow3
yellow3 lab

We use emerging technology to make business less complicated.

Platforms

naffe.ai Software All platforms

Research

Research areas AI model adoption EU AI Act DPP Supplier Register

Company

About Advisory Insights Contact

Get in touch

Email us
Copenhagen, Denmark
© 2026 yellow3 ApS. All rights reserved.
Privacy Terms Cookies