This policy describes which personal data we process when you use epc.is, the sign-in at auth.epc.is and the Digital Link addresses under epc.is and id.epc.is. Terms such as "processing" and "controller" are used as defined in Art. 4 of the General Data Protection Regulation (GDPR).
1. Controller
benelog GmbH & Co. KG, Maarweg 133, 50825 Köln, Germany
E-mail: info@benelog.com, phone: +49 221 472540 001
Represented by the managing director Thomas Hirsch
Data protection contact: Sven Böckelmann, sboeckelmann@benelog.com
2. Visiting the website and server logs
Whenever a page is requested, our servers necessarily process the IP address, date and time, the requested address, the status code, the amount of data transferred, the referrer and the browser identifier. We use this data only to provide the platform, analyse errors and fend off attacks. The legal basis is Art. 6(1)(f) GDPR; our legitimate interest is secure and stable operation. We delete log data after 30 days at the latest, unless a specific security incident requires longer retention to investigate it.
3. Cookies and local storage
We use no cookies or similar techniques for analytics, advertising or tracking, and we embed no third-party services such as analytics tools, maps, videos or external fonts. Fonts and scripts are served from our own servers.
Strictly necessary, and only once you sign in or on the way there, we set:
- a session cookie of epc.is that keeps you signed in;
- a cookie that remembers for at most 10 minutes which page to return to after sign-in;
- the session and language cookies of the sign-in service auth.epc.is (Keycloak), needed for sign-in, registration and sign-out.
These cookies are strictly necessary for the service you explicitly requested (§ 25(2) no. 2 of the German TDDDG) and therefore need no consent. The subsequent processing is based on Art. 6(1)(b) GDPR.
4. Registration and user account
For an account we process your username, e-mail address, first and last name, a password (stored only as a hash), your preferred language, the time you accepted the terms of use and the information you choose to give about your company. We send you an e-mail to confirm your address. The legal basis is Art. 6(1)(b) GDPR (the agreement on using the beta). We keep the data until you have your account deleted or the beta ends.
5. Applying for access to a tenant
To approve access we process the information in your application: the company's name and address, the GS1 company prefix you claim, a GTIN or GLN as evidence, and the status of the review. The reviewing staff receive an e-mail about the application; you receive an e-mail once a decision has been made.
If you provide an access key from GS1 Germany, we transmit it to GS1 Germany GmbH, Maarweg 133, 50825 Köln, Germany, to check which number ranges belong to your company. We do not store the key; we keep only the result of the check.
The legal basis is Art. 6(1)(b) GDPR and Art. 6(1)(f) GDPR; our legitimate interest is that only authorised persons publish data about a company's GS1 numbers. We keep application data for as long as the account exists.
6. Data in your tenant and its publication
The content of your tenant (product, location and company data, events, links) is primarily business data. Where it contains business contact details, such as a contact person, we process them to store and publish them the way you configure (Art. 6(1)(b) GDPR). Data you mark as public can be retrieved worldwide. We register links for your GS1 numbers with the GS1 registry; GS1 receives the number, the target address and the type of link.
7. Visits to public product pages and scans
When someone opens a public Digital Link address, for example by scanning a QR code, we count the request for the statistics of the company concerned. We store neither the IP address nor any identifier of the device or person, only the requested number, the time and the country derived from the network. Unique visits are estimated with a method that uses a key held only in memory and never written to disk. Small counts are suppressed in the statistics. The legal basis is Art. 6(1)(f) GDPR.
8. Contact by e-mail
If you write to us, we process your information to answer the request (Art. 6(1)(b) or (f) GDPR) and delete it once it is no longer needed for that, subject to statutory retention periods. We keep reports of illegal content and objections to suspensions as long as needed to keep the decision traceable, at most 12 months after the case is closed.
9. Suspension of accounts
If an account breaches the terms of use, we process the data needed for that (account, content concerned, times, reasons) to protect the platform and third parties (Art. 6(1)(f) GDPR) and to meet our obligations under Regulation (EU) 2022/2065 (Art. 6(1)(c) GDPR).
10. Hosting, recipients and third countries
epc.is runs on servers in Germany. We operate the platform ourselves, including sending e-mail. We pass personal data only to the recipients named above (GS1 Germany for the check, the GS1 registry for links) and to authorities where the law requires it. No data is transferred to countries outside the EU or EEA.
11. Security
All connections are encrypted with TLS. Sign-in uses OpenID Connect with PKCE; tenants are separated from each other. We take technical and organisational measures under Art. 32 GDPR.
12. Your rights
You have the right to
- access (Art. 15 GDPR),
- rectification (Art. 16 GDPR),
- erasure (Art. 17 GDPR),
- restriction of processing (Art. 18 GDPR),
- data portability (Art. 20 GDPR), and
- object to processing based on Art. 6(1)(f) GDPR on grounds relating to your particular situation (Art. 21 GDPR).
You may also lodge a complaint with a supervisory authority, for example the authority responsible for us, the State Commissioner for Data Protection and Freedom of Information of North Rhine-Westphalia (www.ldi.nrw.de).
13. Obligation to provide data, no automated decisions
Without the account data we cannot set up an account, and without the application data we cannot grant access. Beyond that you are not obliged to provide data. Applications are decided by people; there is no automated decision-making within the meaning of Art. 22 GDPR.
14. Changes
We update this policy when the platform or the law changes. The current version is always at epc.is/privacy.
The German version of this policy is authoritative.
Version: 6 October 2026