Privacy Policy

Last updated: July 2026 · Hoken Tech S.r.l.

1. Data Controller

Hoken Tech S.r.l.
Via Ippolito Nievo, 25
70056 Molfetta (BA), Italy
Email: support@hokenpass.com
VAT / Tax Code: IT086677120720
REA: BA 642341
PEC: hokentech@pec.it

2. Data Protection Officer (DPO)

Contact: support@hokenpass.com

3. Types of Personal Data Processed

We process the following categories of personal data:

  • Account Data: name, email address, password (hashed)
  • Organization Data: company name, VAT number, country, role (admin/editor/viewer)
  • DPP Data: product information, passport content, digital signatures
  • Blockchain Data: transaction IDs, payload hashes (SHA-256), timestamps
  • Usage Data: IP address, browser type, pages visited, actions performed
  • Payment Data: billing information (processed by Stripe — see their privacy policy)
  • Consent Records: cookie consent, marketing consent, timestamps

4. Legal Basis for Processing

Processing is based on:

  • Art. 6(1)(b) GDPR — Performance of a contract (service provision)
  • Art. 6(1)(a) GDPR — Consent (marketing, analytics cookies)
  • Art. 6(1)(c) GDPR — Legal obligation (tax, accounting, anti-money laundering)
  • Art. 6(1)(f) GDPR — Legitimate interest (security, fraud prevention, service improvement)

5. Purpose of Processing

  • Providing the Hoken Pass SaaS platform
  • Creating and managing Digital Product Passports
  • Blockchain notarization and timestamping on EOS/Vaulta
  • Generating QR codes, digital links, PDF/JSON exports
  • Team management and role-based access control
  • Payment processing and subscription management
  • Sending transactional emails (welcome, password reset, team invitations)
  • Analytics and service improvement (with consent)
  • Compliance with EU regulations (ESPR, CAD, eIDAS)
  • Security monitoring and fraud prevention

6. Data Recipients

Your data may be shared with:

  • Supabase — Database hosting (EU-based, GDPR compliant)
  • Cloudflare — File storage (R2) and CDN
  • Stripe — Payment processing (PCI DSS Level 1)
  • Brevo — Transactional email delivery
  • InfoCert / Openapi — Qualified timestamping (QTSP, eIDAS compliant)
  • EOS/Vaulta (Jungle4) — Blockchain notarization (hash only, no personal data)

7. International Data Transfers

All primary data processing occurs within the EU/EEA. Where data is transferred outside the EU (e.g., blockchain nodes), we ensure appropriate safeguards are in place:

  • Standard Contractual Clauses (SCCs) per Art. 46(2)(c) GDPR
  • Adequacy decisions where available
  • Only the minimum necessary data is transferred (hash-only on blockchain)

8. Data Retention

  • Account data: Duration of the account + 30 days after deletion
  • DPP data: Duration of the subscription + 90 days for backup
  • Blockchain data: Permanent (immutable by design, but non-linkable after off-chain deletion)
  • Payment records: 10 years (Italian tax law)
  • Usage logs: 12 months
  • Consent records: 3 years from last interaction
  • Marketing data: Until consent is withdrawn

9. Your Rights (GDPR Arts. 15-22)

You have the right to:

  • Access (Art. 15) — Request a copy of your personal data
  • Rectification (Art. 16) — Correct inaccurate data
  • Erasure (Art. 17) — Request deletion of your data
  • Restriction (Art. 18) — Restrict processing in certain cases
  • Portability (Art. 20) — Receive your data in a machine-readable format
  • Objection (Art. 21) — Object to processing based on legitimate interest
  • Withdraw consent — At any time, without affecting prior lawful processing

To exercise your rights, contact: support@hokenpass.com

10. Blockchain and Right to Erasure (EDPB 02/2025)

In compliance with the EDPB Guidelines 02/2025 on blockchain and personal data:

  • Only keyed hashes (HMAC-SHA256) are stored on-chain — no personal data
  • All personal data is stored off-chain in our encrypted database
  • Upon erasure request, we delete all off-chain data and destroy the HMAC key, rendering on-chain hashes non-linkable (effective erasure)
  • A Data Protection Impact Assessment (DPIA) has been conducted for all blockchain processing
  • We maintain a Record of Processing Activities (ROPA) per Art. 30 GDPR

11. eIDAS Compliance

For qualified timestamps and electronic seals:

  • Timestamps are provided by InfoCert S.p.A., a Qualified Trust Service Provider (QTSP) on the EU Trust List
  • Timestamps comply with eIDAS Regulation (EU) 910/2014, Art. 42
  • Each timestamp binds a UTC date/time to the document hash using a QTSP-signed RFC 3161 token

12. CAD Compliance

In compliance with the Italian Digital Administration Code (D.Lgs. 82/2005):

  • All documents maintain integrity via SHA-256 hashing
  • Certified timestamps provide legal proof of existence date
  • Document metadata follows AgID guidelines
  • Audit trails are maintained for all passport operations

13. Security Measures

  • TLS 1.3 encryption for all data in transit
  • AES-256 encryption for sensitive data at rest
  • Role-based access control (RBAC) with admin/editor/viewer roles
  • Regular security assessments and vulnerability scanning
  • Incident response procedures aligned with ACN (National Cybersecurity Agency) guidelines

14. Complaints

If you believe your data protection rights have been violated, you may lodge a complaint with:

Garante per la protezione dei dati personali
Piazza Venezia 11, 00187 Roma, Italy
www.garanteprivacy.it

15. Changes to This Policy

We may update this Privacy Policy. Material changes will be notified via email or platform banner. The latest version is always available at this URL.