Terms of Service
Last updated: October 8, 2026
For accounts registered before October 8, 2026, this version applies from November 8, 2026.
1. About These Terms
These Terms of Service ("Terms") govern your use of TracePass: the website (tracepass.eu), the application portal at app.tracepass.eu, the public passport resolver, and the REST API (together, the "Service"). By registering an account, subscribing to a plan, or using the website, the application portal or the REST API, you agree to these Terms.
Business use only. The Service is offered only to businesses. By registering or subscribing, you confirm that you act for the purposes of your trade, business or profession, and not as a consumer. People who only view published passports through the public resolver are not parties to these Terms.
The legal entity is TracePass LTD (Bulgarian UIC 208790302), registered at Shtrossmayer Street, 1309 Sofia, Bulgaria, EU.
2. Service Status
TracePass is a live, production service. Paid plans are available and billed through Stripe. Key points:
- The Free, Basic, Starter, Growth, Scale, Pro, and Enterprise plans defined on the pricing page are all available for self-serve sign-up (Enterprise via contact)
- Pricing changes. Pricing is the public list price at the time of subscription. TracePass reserves the right to change pricing — including plan fees, included quotas (e.g. passport allowances, EPCIS event allowances), and overage rates — for future billing periods. Any price increase, quota reduction, or overage-rate increase affecting an active paid subscription is notified by email to the workspace owner at least 30 days before it takes effect. The notice email states the change, the effective date, and the customer's options (continue at the new price, downgrade, or cancel before the effective date). On a plan with a minimum term, your current price, quotas and overage rates stay unchanged until that term ends; a change applies to you only from the end of the term. Price decreases, quota increases, and new lower-cost plans may take effect immediately and require no notice.
- Feature descriptions represent current platform behaviour at the time of publication; the changelog at /regulatory/changelog records material changes that affect compliance scope
- Compliance claims describe how TracePass models EU regulation today; they are design statements, not certifications or guarantees
3. Account Registration
To use the platform you create an account at app.tracepass.eu. By registering you:
- Confirm that you register on behalf of a business, for the purposes of its trade, business or profession, and not as a consumer
- Confirm you are entitled to bind the legal entity you register on behalf of and that the information you provide is accurate
- Agree to receive transactional email related to your account (billing, plan-limit warnings, security notices, regulatory-changelog digests). Marketing email is opt-in and unsubscribable separately
- Become responsible for the security of your credentials and for activity carried out under your account, including by team members and API keys you issue
The Free plan is available without payment details and creates real, public passports up to the plan's allowance. There is no time limit on the Free plan.
4. Intellectual Property
All content on this website — including text, graphics, logos, icons, and software — is the property of TracePass or its licensors and is protected by applicable intellectual property laws.
You may not reproduce, distribute, modify, or create derivative works from our content without prior written permission.
5. Disclaimer of Warranties
This website and its content are provided "as is" and "as available" without warranties of any kind, either express or implied.
In particular:
- We do not warrant that the information on this website is complete, accurate, or current
- Regulatory information is provided for informational purposes only and does not constitute legal advice
- References to EU regulations (ESPR, Battery Regulation 2023/1542, etc.) are based on publicly available sources and may not reflect the latest amendments
- Compliance claims describe our design intent — TracePass does not guarantee regulatory compliance of generated passports
6. Customer Responsibility for Passport Data
TracePass is a software platform for producing Digital Product Passports. The data inside your passports is yours, and its accuracy, lawfulness, and regulatory truthfulness are your responsibility — not ours.
By using TracePass to publish Digital Product Passports you agree that:
- You own the data. You are solely responsible for the accuracy, completeness, lawfulness, and regulatory compliance of every value in every passport you publish through your account — material composition, carbon footprint, test-report references, supplier information, recycled-content percentages, safety claims, and anything else that appears on a published passport page.
- TracePass is a platform, not a data source. Passport data originates from you, from documents you upload, or from suppliers you invite via our portal. We read, structure, and display that data. We do not fact-check it.
- AI suggestions are suggestions. AI-extracted field values shown in your review queue are proposals with confidence scores. Every proposal requires your explicit review and approval before it appears on a published passport. We make no representation and give no warranty as to the factual correctness of any AI-extracted value.
- Economic-operator status remains with you. For EU regulatory purposes — including but not limited to the Ecodesign for Sustainable Products Regulation (EU 2024/1781), Battery Regulation (EU 2023/1542), Packaging and Packaging Waste Regulation (EU 2025/40), Construction Products Regulation (EU 2024/3110), Toy Safety Directive, and REACH — you remain the economic operator (manufacturer, importer, distributor, or authorised representative as applicable) responsible for the truthfulness of every declaration in the passport. TracePass is not your compliance officer and does not audit your claims against the physical product, laboratory test results, or supplier attestations.
- Indemnification. You agree to indemnify, defend, and hold harmless TracePass and its personnel from and against any third-party claim, regulatory investigation, enforcement action, fine, penalty, damages, legal fees, or loss arising out of or connected to inaccurate, misleading, incomplete, or unlawful data published through your account.
7. Limitation of Liability
This section applies to the whole Service: the website, the application portal, the public passport resolver and the REST API.
To the maximum extent permitted by applicable law, TracePass shall not be liable for any indirect, incidental, special, consequential, or punitive damages arising from your use of or inability to use the Service.
This includes, but is not limited to, damages for loss of profits, data, or business opportunities, even if we have been advised of the possibility of such damages.
Each party's total liability arising out of or in connection with these Terms is limited to the fees paid or payable by you for the Service in the 12 months before the event giving rise to the claim.
None of these limitations applies to damage caused intentionally or through gross negligence, to your indemnification obligations under section 6, or to any other liability that cannot be limited or excluded under applicable law.
8. Third-Party Links
This website may contain links to third-party websites. We are not responsible for the content, privacy practices, or terms of any third-party sites.
9. Changes to These Terms
We reserve the right to modify these Terms at any time. Material changes are notified to active subscribers by email at least 30 days before they take effect; non-material changes are posted on this page with an updated date.
You may reject a material change by written notice before it takes effect. If you do, the current Terms continue to apply to you until your commitment (defined in section 10) ends, or you may instead leave with no early-exit fee, on the exit date set out in section 10. If you do not reject a change, continued use of the Service after it takes effect constitutes acceptance of the new Terms.
10. Billing & Subscriptions (Paid Plans)
The following apply to all paid plans, in addition to the pricing and plan terms published on the pricing page:
- Minimum term. On monthly billing, the Scale, Pro, and Enterprise plans have a minimum term of 3, 6, and 12 calendar months respectively. The term starts on the date you first buy one of these plans or move to one from another plan, and a later plan change never shortens a term that is already running. Annual billing prepays 12 calendar months on any plan. A running minimum term, or a prepaid annual year, is a "commitment" in these Terms. You can leave at any time during a commitment, with the early-exit fee set out below. Upgrades take effect immediately. A downgrade to a lower plan (including Free) made during a commitment takes effect when the commitment ends; a downgrade is not leaving the Service. Cancellations and plan changes are made in the billing section of the TracePass application.
- Voluntary cancellation. You can cancel at any time in the billing section of the TracePass application. Your plan then ends at the end of the current billing month (the "exit date"): on monthly billing, the end of the current billing period; on annual billing, the next monthly anniversary of your subscription start date. Your subscription stays active until the exit date. After your paid subscription ends, your published Digital Product Passports remain publicly resolvable via QR code and Digital Link for 30 days at no additional charge. During this 30-day grace window, QR codes printed on physical products continue to resolve to the passport. If you operated on a custom domain (every paid plan), the grace window is the time to re-point your DNS record to a successor vendor's resolver — the URL on the printed QR is yours forever because the domain is yours. After the 30 days, shared-domain URLs return an "expired" notice and TracePass stops serving the custom domain. Resubscribing at any time restores access: within the 30 days nothing is interrupted, and afterwards expired passports are returned to published automatically, up to the number of published passports your new plan includes.
- Early-exit fee. If a commitment is still running on the exit date, an early-exit fee applies: the number of commitment months left after the exit date, up to a maximum of 3, multiplied by the monthly fee. The monthly fee is the plan's monthly price, or the annual price divided by 12 on annual billing. The fee is never more than you would have paid by staying until the commitment ends, and once the commitment has ended there is no fee. On monthly billing, the fee is charged once, on the exit date, as a separate invoice. On annual billing, nothing extra is charged: you are refunded the unused whole months at the annual price divided by 12, less the fee, and the refund is never below zero. Examples:
- Scale at €1,000 per month, cancelled in month 1: the plan ends at the end of month 1; 2 months of the term are left, so the fee is €2,000.
- Pro at €2,000 per month, cancelled in month 1: 5 months are left, so the fee is capped at 3 × €2,000 = €6,000.
- Pro on monthly billing, cancelled in month 5: 1 month is left, so the fee is €2,000.
- Pro on monthly billing, cancelled after month 6: the term has ended, so the plan ends at the end of the billing period with no fee.
- Pro on annual billing, cancelled in month 3: the plan ends at the end of month 3; 9 months are unused and the fee is 3 months, so 6 months at the annual price divided by 12 are refunded.
- Termination for cause (below): the plan ends immediately, with no fee and a pro-rata refund.
- Renewal. Paid plans renew automatically for successive billing periods (monthly or annual) until cancelled. When a minimum term ends, the plan continues on the same billing period with no new minimum term, unless you move into a plan that has one.
- Failed payment (past due). If a recurring charge fails and is not resolved, the account enters a "past due" state. During past due, creating new passports, running AI data processing, and sending new supplier requests are paused; published passports stay publicly accessible. If the account remains past due for 14 days, the same 30-day grace window starts — after which passports stop resolving publicly. Settling the outstanding invoice at any time lifts all restrictions automatically; if the grace window has already ended, expired passports are returned to published, up to the number of published passports your plan includes.
- Termination for non-payment. If fees that you do not dispute remain unpaid, TracePass may terminate your subscription by giving you 30 days' written notice. If the fees are still unpaid when the notice period ends, the subscription ends and any early-exit fee under "Early-exit fee" above falls due.
- Data export & portability. The data you enter into TracePass remains yours and is exported at no additional charge, on every plan including Free; section 10a lists the exportable data, the formats, and how long you can retrieve it after you leave. Every plan, including Free, includes the full-account export in the dashboard (Settings → Data export): one ZIP file with all the exportable data listed in section 10a, plus quick JSON-LD and EPCIS downloads, available to an account administrator whatever the billing status, including after you cancel. The REST API, available on every plan, reads your passports and products programmatically; its daily caps apply only to Free (100 writes and 100 passport reads per API key) and Basic (200 of each) as free-tier abuse prevention — Starter and above are unlimited. Scale plan and above additionally include downloadable compliance PDF reports. Every field carries full audit trail (who entered it, when, from which source document) and provenance is preserved in export. Ending a subscription does not erase your data straight away: public hosting of passports stops after the grace windows above, and the data itself is kept until the erasure date set out in section 10a. Resubscribing before then restores full access. The GS1 Digital Link URL is portable on every paid plan via the custom-domain resolver: you control the URL through your own DNS, and the URL on the printed QR survives any vendor switch.
- Archived passports. Passports you mark as archived in the dashboard stop resolving publicly immediately. Regulators holding an authority-level access token retain read access for compliance purposes; archiving does not delete your data.
- Plan changes. Upgrades apply immediately with prorated charges. A downgrade made during a commitment takes effect when the commitment ends. Downgrades that reduce the passport cap may trigger an overage charge on the remaining passports at the new plan's per-DPP rate; you are warned before confirming the change.
- Termination for cause. If TracePass materially breaches these Terms and does not cure the breach within 30 days of your written notice, you may terminate your subscription with immediate effect, including during a commitment. This right is in addition to your rights under applicable law. Written notice includes email to info@tracepass.eu. No further fees and no early-exit fee are owed after termination, and prepaid fees for the unused part of the period are refunded pro rata.
10a. Switching and Exit (EU Data Act)
This section sets out how you switch to another provider, move your data to your own infrastructure, or leave, under Chapter VI of the EU Data Act (Regulation (EU) 2023/2854). It applies to every plan, including Free.
- Notice. You can start switching or leaving at any time by cancelling in the billing section of the TracePass application. The notice period runs until the exit date set out in section 10, at the end of the current billing month, so it is never longer than one month. When you cancel, you can tell us whether you are switching to another provider (with its details), moving to your own infrastructure, or want your data erased. The Free plan has no billing period and no fee: you can export your data and leave at any time.
- Transition period. On request, the Service continues for a transition period of up to 30 days after the exit date, so that you can complete the move. During the transition period you pay the plan's standard fees, pro rata for the days it lasts, and we give you and the providers you authorise reasonable assistance with the move. You may extend the transition period once, for a period you consider more appropriate for your purposes. If a 30-day transition period is technically unfeasible, we will notify you within 14 working days of your request, explain why, and propose an alternative transition period of no more than 7 months, during which the Service continues.
- Exportable data. The data and digital assets you can export are exactly the following:
- products and passports, with all field values, translations, the audit trail and provenance;
- EPCIS events;
- uploaded documents, as the original files, with an index;
- supplier requests, with the suppliers' responses and submitted values;
- passport version history, including the signed credentials;
- battery measurements;
- daily scan analytics per passport, by country and device type (no personal data).
How to export: all of the above is in one ZIP file built by "Export everything" in Settings → Data export in the dashboard; we email you when it is ready, and the download stays valid for 7 days, after which you can build a new one. The same page offers "Download JSON-LD" (products and passports) and "Download EPCIS" (the EPCIS events of published passports) straight away. Products, passports, passport versions, battery measurements and the EPCIS events of each passport can also be read through the REST API. These exports are available to an account administrator on every plan, including Free, whatever the billing status and after you cancel.
- Data that is not exportable. The following data is specific to the internal functioning of the Service and is exempt from export, because exporting it would put TracePass's trade secrets at risk: the AI prompts and models, the learning data aggregated across customers, and security logs. This exemption never delays or blocks your switch.
- Formats. Products and passports: JSON-LD (the full-account export and the JSON-LD download) and JSON (the REST API, described by the public OpenAPI specification). EPCIS events: EPCIS 2.0 JSON-LD. Documents: the original files as uploaded, with a JSON index. Supplier requests, passport versions and battery measurements: JSON. Scan analytics: CSV. The field definitions of every category template are public in the @tracepass/dpp-schemas package.
- Retrieval period. You can retrieve your exportable data for at least 30 days after the exit date or, if there is a transition period, after the transition period ends.
- Erasure. 12 months after the retrieval period ends, TracePass erases all your exportable data, unless you resubscribe before then or ask in writing for earlier erasure.
- No switching charges. TracePass charges nothing for switching, for exporting your data, or for the assistance described above. The early-exit fee in section 10 and the standard fees for the transition period are not switching charges.
The same procedure, with the data formats and where the data is held, is summarised on the trust page.
11. Service-Level Commitments
For all paid plans, TracePass commits to two distinct service-level targets, measured monthly:
- Application portal availability — 99.9%, excluding scheduled maintenance announced at least 48 hours in advance. The application portal is the dashboard surface where customers and their teams operate (passport creation, editing, supplier management, billing).
- Public resolver availability — 99.95%. The public resolver is the surface that authority systems and consumers hit when scanning a QR code; we hold it to a higher target because, from a regulatory standpoint, a passport that does not resolve is a passport that does not exist.
Outage credits apply per surface independently. A portal-only outage does not require a resolver outage to trigger portal credits, and vice versa. Service-level targets do not apply to the Free plan.
12. Data Processing Roles
For all customer product data processed through the platform, the customer is the data controller as defined in Article 4(7) of the General Data Protection Regulation (GDPR); TracePass is the data processor acting on the customer's documented instructions.
A standard processor Data Processing Agreement (DPA) is available on request before customer data flows to the platform. The DPA codifies sub-processor disclosure (Article 28 advance notification), breach notification (72 hours from confirmed incident), and the data-deletion process at end of term.
Most fields inside Digital Product Passports are product data, not personal data, and fall outside GDPR scope. GDPR risk concentrates in the analytics surface where consumer scan events may carry IP addresses or user-agent strings — those events are governed by the DPA and the privacy notice.
13. Source Code Escrow
Enterprise customers may opt into a source code escrow arrangement with an independent third-party escrow agent at no additional cost. A tagged copy of the TracePass application source code is deposited and updated on a recurring cadence agreed in the escrow agreement.
Release triggers — typically vendor insolvency, sustained material breach uncured beyond a defined window, or sustained outage beyond an agreed threshold — are codified in the escrow agreement, not in these Terms. Source code escrow is not included in Free, Basic, Starter, Growth, Scale, or Pro plans; it is negotiated as part of the Enterprise contract.
14. Governing Law
These Terms are governed by and construed in accordance with the laws of the Republic of Bulgaria and applicable EU law. Any disputes shall be subject to the exclusive jurisdiction of the competent courts in Sofia, Bulgaria.
These Terms are published in English, Bulgarian, German and Italian. If the language versions differ, the English version prevails.
15. Contact
For questions about these Terms:
Email: info@tracepass.eu
TracePass LTD, Shtrossmayer Street, 1309 Sofia, Bulgaria, EU
Written notice under these Terms may be given by email to info@tracepass.eu.