Trust, security and service commitments
What we actually do to protect your product data — no aspirational claims, everything on this page is in place today.
Availability and support
- Uptime objective: 99.5% monthly. The platform runs on redundant EU infrastructure with hosting-level monitoring and our own external uptime checks.
- Support in business hours (Monday to Friday, 9:00–18:00 CET), by email — [email protected] — with a reply within one business day. Replying to any email you received from us reaches the same inbox.
- We deliberately do not advertise 24/7 support: we would rather commit to what we reliably deliver. Public passport pages, QR codes and the API keep working around the clock regardless.
Your data (GDPR)
- Data controller: METIS SAS, 120 Chemin de Ceinture, 13400 Aubagne, France.
- All data is hosted in the European Union (France) — application, database and backups. Nothing is transferred outside the EU.
- Payments are processed by Stripe. Card data never touches our servers.
- A Data Processing Agreement (DPA) is available on request for business customers.
- You can close your account yourself from the settings page. Closure tombstones the account: your email address is released and personal data is removed from the live system.
- Onboarding emails carry a one-click unsubscribe link. Transactional email (invitations, receipts) is only ever triggered by your own actions.
Security measures
- Encryption in transit: TLS everywhere, HSTS with preload, and a strict Content-Security-Policy on every page.
- Two-factor authentication (TOTP) is available on every account, on every plan, at no cost — Dashboard → Security.
- Per-plan API rate limiting and idempotency keys protect the API against abuse and duplicate writes.
- Hosting-level web application firewall and malware scanning, plus our own security-event logging.
- Daily backups of database and files, with a 14-day rolling retention, verified by an automated log we actually read.
- Passport version history is immutable. Every published version of a passport remains retrievable — the audit trail the ESPR (Regulation (EU) 2024/1781) expects. Deleting a product archives its passports instead of destroying them, so a printed QR code never dies silently.
Honest regulatory information
Many DPP vendors sell urgency with invented deadlines. Our position is simpler: we tell you the legal status as it stands — adopted regulations with their real dates (batteries: Regulation (EU) 2023/1542, February 2027), and planned or indicative timelines clearly labelled as such (textiles, electronics, furniture — delegated acts not yet adopted). You will never find a made-up compliance date in our product, our passports or our emails.
Service level summary
- Uptime objective: 99.5% monthly
- Support: business hours (CET), 1 business day response
- Backups: daily, 14-day retention, EU
- Data location: European Union (France)
- DPA: on request — [email protected]
Last reviewed: 28 July 2026. If anything on this page is unclear, or you need a security questionnaire filled in for procurement, write to [email protected].