European Product Evaluation Institute

Privacy Policy

DOC / PRIVACYPublic information

Last updated: 28 July 2026 — Controller: smartzone GmbH, Faltermaierweg 7, 84524 Neuötting, Germany

Deutsche Kurzfassung (German summary)

Verantwortlicher: smartzone GmbH, Faltermaierweg 7, 84524 Neuötting, Deutschland, Telefon +49 (0)8671 9581227, E-Mail [email protected]. Ein Datenschutzbeauftragter ist nicht benannt; eine gesetzliche Pflicht hierzu besteht derzeit nicht.

Wir verarbeiten personenbezogene Daten nur, soweit dies für den Betrieb dieser Website und des Hersteller-Portals, für die Durchführung von Produktprüfungen sowie für die geschäftliche Kontaktaufnahme zu Unternehmen (B2B) erforderlich ist — auf Grundlage von Art. 6 Abs. 1 lit. b, c und f DSGVO. Diese Website setzt keine Analyse- oder Marketing-Cookies ein; ein technisch notwendiges Sitzungs-Cookie wird nur beim Login gesetzt. Soweit wir geschäftliche Kontaktdaten nicht bei Ihnen selbst erhoben haben (z. B. aus öffentlichen Hersteller-Websites oder Registern), informieren wir Sie darüber spätestens in unserer ersten Nachricht (Art. 14 DSGVO).

Sie haben das Recht auf Auskunft, Berichtigung, Löschung, Einschränkung der Verarbeitung und Datenübertragbarkeit sowie das Recht, einer Verarbeitung zu Zwecken der Direktwerbung jederzeit und ohne Angabe von Gründen zu widersprechen (Art. 21 Abs. 2 DSGVO) — am einfachsten über den Abmelde-Link in jeder unserer E-Mails oder per Nachricht an [email protected]. Sie können sich zudem bei einer Datenschutz-Aufsichtsbehörde beschweren, z. B. beim Bayerischen Landesamt für Datenschutzaufsicht (BayLDA), Promenade 18, 91522 Ansbach. Die vollständigen Informationen folgen in englischer Sprache; die vollständige deutsche Fassung dieser Datenschutzerklärung finden Sie unter /privacy?lang=de, die chinesische Fassung unter /privacy?lang=zh.

1. Controller and contact

The controller for all processing described here is smartzone GmbH, Faltermaierweg 7, 84524 Neuötting, Germany, phone +49 (0)8671 9581227, e-mail [email protected] (see the Imprint). A data protection officer has not been appointed; there is currently no legal obligation to do so.

2. What this policy covers

This policy covers the EPEI public website, the manufacturer portal, the pre-check, the public award register, our assessment operations, and our business (B2B) communication by e-mail. Our services are directed at businesses; we do not knowingly process consumer customer data.

3. Hosting, server logs and security

The platform runs on servers operated by us in Germany. To deliver the website securely we route public traffic through Cloudflare (Cloudflare, Inc., USA) as a reverse proxy / content delivery network; Cloudflare processes connection data (including IP addresses) as our processor. Transfers to the USA are safeguarded by the EU–US Data Privacy Framework and/or EU standard contractual clauses (Art. 45, 46 GDPR).

When you access the site, we process connection data (IP address, timestamp, requested URL, user-agent) in server logs to operate, secure and debug the service, and we maintain short-lived, IP-based counters to limit abuse of public forms (rate limiting). Legal basis: Art. 6(1)(f) GDPR (secure and reliable operation). Log data is kept only as long as needed for these purposes and is then deleted in the course of log rotation; rate-limit counters are deleted after 2 days.

4. Cookies

We use no analytics, tracking or marketing cookies and no third-party advertising technology. Only one strictly necessary, first-party cookie is used, and only once you sign in:

Cookie Purpose Storage period
epei_session Keeps you signed in to the portal/admin area (signed session, includes CSRF protection) 14 days

Because this cookie is strictly necessary for a service you explicitly request, no consent banner is required (§ 25(2) No. 2 German TDDDG). Visitors who do not sign in receive no cookies.

5. Manufacturer portal accounts

When you register for the portal or accept a team invitation, we process your name, business e-mail address, password (stored as a salted hash), company, country, role and account activity in order to provide the portal (Art. 6(1)(b) GDPR). Team administrators can see the members of their own organisation. Accounts are kept until deleted; afterwards, data is retained only where statutory retention duties apply (see section 15).

6. Pre-checks and product submissions

If you submit a product for a free pre-check, we process the product details you provide and — if you choose to leave one — your e-mail address, to run the pre-check, send you the result link and follow up on a possible full assessment (Art. 6(1)(b) GDPR; for follow-up contact to businesses, Art. 6(1)(f) GDPR). Manufacturer-submitted data supplied during an assessment is stored as evidence with its origin clearly labelled.

7. Complaints and corrections

If you report an error or seal misuse, we process the report and — if provided — your name and e-mail address to investigate and to respond (Art. 6(1)(f) GDPR; where the report relates to legal obligations, Art. 6(1)(c) GDPR). Reports are kept as part of the corrections register.

8. B2B outreach and business contact data (Art. 14 GDPR information)

To offer the award programme to manufacturers, we process business contact data of company representatives: name, business role, business e-mail address, business phone, company, country, language, and the history of our correspondence.

Sources. Where we did not obtain this data from you directly, it comes from publicly accessible sources: manufacturer websites (e.g. press or contact pages), commercial and company registers, trade-fair and industry directories, and professional networks. We record the source and retrieval date for every contact.

Purpose and legal basis. We use this data to contact companies about the assessment and award programme and to manage the resulting business relationship. Legal basis: Art. 6(1)(f) GDPR — our legitimate interest in offering a relevant B2B service (recital 47 GDPR: direct marketing). We apply per-country rules for electronic business communication and do not send electronic marketing where the law of the recipient's country does not permit it.

Your right to object (Art. 21(2) GDPR). You may object to processing for direct marketing at any time, free of charge and without giving reasons — most easily via the one-click unsubscribe link contained in every e-mail we send, or by writing to [email protected]. After an objection we will no longer process your data for direct marketing.

Suppression list. To make an objection permanently effective, we keep the affected e-mail address on an internal suppression list (Art. 6(1)(c) and (f) GDPR in conjunction with Art. 21(3) GDPR). Every future contact import is checked against this list; entries on it are never contacted again.

Storage. Prospect contacts that never entered an active business relationship are deleted automatically 12 months after the last contact. Correspondence that constitutes a business record is retained per section 15.

9. E-mail communication

We store business correspondence (including e-mail threads with manufacturers) to manage the relationship and to meet statutory documentation duties (Art. 6(1)(b), (c), (f) GDPR). Outbound e-mail is dispatched through Amazon Simple Email Service in the AWS Europe (Frankfurt) region, operated by Amazon Web Services EMEA SARL (38 Avenue John F. Kennedy, 1855 Luxembourg) as our processor; processed are the recipient address, the message content and delivery events such as delivery, bounce and complaint. Inbound e-mail to our addresses is received through Cloudflare Email Routing and delivered to our own mail system on servers in Germany; a copy may be forwarded to a mailbox operated for us by Google Ireland Limited (Gordon House, Barrow Street, Dublin 4, Ireland). Our outbound e-mails state our identity, the reason you are receiving them, and contain a one-click opt-out.

10. Payments and invoicing

Offers are paid through our billing system; payment execution is handled by payment service providers (currently Stripe and/or PayPal, depending on the payment method offered in the checkout). The payment provider processes your payment data under its own responsibility; we receive confirmation of payment and the data needed for invoicing (Art. 6(1)(b) and (c) GDPR). Invoicing data is retained under statutory commercial and tax law (see section 15).

11. AI-assisted processing

We use large-language-model services of Anthropic (Anthropic PBC, USA) to help analyse public product data and to draft business correspondence. Where business contact data (e.g. a recipient's name and company) is included in such processing, Anthropic acts as our processor; API data is not used by Anthropic to train models. Transfers to the USA are safeguarded by the EU–US Data Privacy Framework and/or EU standard contractual clauses. Outbound correspondence is marked as prepared with automated assistance; assessment results are determined by the published deterministic methodology, not by an AI's judgement.

12. The public award register

Verification pages and public reports show company (manufacturer) and product information, the score, methodology and category-benchmark versions, dates and licence status. They are not intended to contain personal data of natural persons; contact persons of manufacturers are never published there.

13. Recipients and processors

We share personal data only with: IT and hosting providers (Germany/EU), Cloudflare (CDN/proxy and e-mail routing), the e-mail service providers named in section 9 (Amazon Web Services EMEA SARL, Google Ireland Limited), payment service providers (section 10), Anthropic (section 11), and our professional advisers where required (Art. 6(1)(c), (f) GDPR). All processors are bound by data processing agreements (Art. 28 GDPR). We never sell personal data or share it with third parties for their own advertising.

14. International data transfers

Where data is transferred outside the EU/EEA — currently to Cloudflare and Anthropic in the USA, and where group companies of the e-mail service providers named in section 9 process data in third countries — the transfer is based on an adequacy decision (in particular the EU–US Data Privacy Framework, Art. 45 GDPR) and/or EU standard contractual clauses (Art. 46(2)(c) GDPR).

15. Storage periods

  • Server logs: short-term, deleted through log rotation (section 3).
  • Rate-limit counters: 2 days.
  • Portal accounts: until account deletion, then only per statutory duties.
  • Prospect contacts without an active business relationship: deleted after 12 months of inactivity.
  • Suppression list: retained permanently, solely to honour objections.
  • Business correspondence, contracts, offers, invoices and assessment/award records: statutory commercial and tax retention periods (six to ten years under German HGB/AO).
  • Cached copies of fetched public product pages: 30 days.

16. Your rights

You have the right to access (Art. 15 GDPR), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20) and — where processing is based on consent — withdrawal at any time with effect for the future (Art. 7(3)). To exercise your rights, contact [email protected].

You also have the right to lodge a complaint with a supervisory authority (Art. 77 GDPR), in particular with the authority competent for us: Bayerisches Landesamt für Datenschutzaufsicht (BayLDA), Promenade 18, 91522 Ansbach, Germany, www.lda.bayern.de.

17. Your right to object (Art. 21 GDPR)

Where we process your data on the basis of legitimate interests (Art. 6(1)(f) GDPR), you have the right to object at any time on grounds relating to your particular situation. Where your data is processed for direct marketing, you have the right to object at any time, without giving reasons and free of charge; we will then stop processing your data for this purpose. The easiest way is the one-click link in any of our e-mails or a message to [email protected].

18. No automated individual decision-making

Product assessments are automated evaluations of products, not of natural persons. We do not make automated decisions producing legal or similarly significant effects concerning natural persons within the meaning of Art. 22 GDPR.

19. Changes to this policy

We update this policy when our service or the legal situation changes; the current version with its date is always published on this page.