1. Introduction
This Privacy Statement and Legal Disclaimer ("Policy") governs the collection, processing, storage, and disclosure of information by PassCell, Inc. ("PassCell," "we," "us," or "our"), a technology company incorporated and operating in the United States, in connection with its battery passport registry platform and related services (collectively, the "Services").
PassCell provides business-to-business (B2B) software enabling economic operators—battery manufacturers, importers, distributors, and fleet operators—to generate, manage, and publish digital battery passports compliant with Regulation (EU) 2023/1542 concerning batteries and waste batteries. Because our Services process data relating to products placed on the European Union market, this Policy is expressly designed to align with the General Data Protection Regulation (GDPR, Regulation (EU) 2016/679), the EU Battery Regulation, and applicable United States privacy frameworks including state consumer privacy laws where relevant to our U.S. operations.
By accessing or using the Services, your organization acknowledges that it has read, understood, and agreed to the terms set forth herein. If you do not agree, you must discontinue use of the Services immediately.
2. Data Controller & Representative Designation
For purposes of the GDPR, PassCell, Inc. acts as the data controller with respect to account-level, billing, and platform administration data processed on behalf of registered factory operators.
With respect to battery passport content submitted by economic operators, PassCell generally acts as a data processor under Article 28 GDPR, processing such data strictly on documented instructions from the subscribing manufacturer (the "Customer" or "Controller"). Public passport disclosure pages contain product and compliance metadata only—not personal data of natural persons—unless explicitly supplied by the Customer in violation of applicable law.
2.1 EU Representative
Pursuant to Article 27 GDPR, PassCell maintains an appointed representative within the European Union for matters relating to data protection compliance. Contact details are provided in Section 13.
3. Scope of Processing
This Policy applies to:
- The PassCell web application, including factory dashboards, demo environments, and authorization terminals;
- Public compliance portal pages rendered when a battery passport QR label is scanned;
- API integrations, bulk CSV ingestion pipelines, and QR sticker generation workflows;
- All cloud infrastructure, backup systems, and audit logs supporting the above.
This Policy does not apply to third-party websites, customs authority systems, or recycler facilities that may independently process information outside the PassCell platform.
4. GDPR Compliance & EU Database Sovereignty
PassCell recognizes that battery passport records constitute regulated product compliance data with heightened expectations for territorial integrity, immutability, and lawful cross-border handling under EU law.
All passport records originating from or destined for the European Union market are routed through PassCell's secure global cloud node architecture, with authoritative primary storage and replication confined to European localized storage structures physically located within GDPR-adequate jurisdictions—principally the European Economic Area (EEA) and, where applicable, territories subject to European Commission adequacy decisions.
Specifically, PassCell implements the following sovereignty controls to fully guarantee EU GDPR database sovereignty:
- Regional Data Residency: Battery passport ledger entries, Annex XIII technical metadata, sustainability audit records, and associated cryptographic integrity hashes are persisted exclusively in EU-designated availability zones. U.S.-based processing nodes handle only anonymized routing metadata and do not retain EU passport payload data at rest.
- Geo-Fenced Replication: Backup, disaster recovery, and read-replica instances are geo-fenced to EEA regions. Cross-region replication to non-adequate jurisdictions is prohibited by contractual and technical policy controls.
- Immutable Registry Semantics: Once a passport record is committed to the historical ledger and authenticated on the global compliance network, write operations are restricted to append-only audit events, preserving regulatory traceability required under the EU Battery Regulation.
- Standard Contractual Clauses (SCCs): Where limited administrative access from PassCell's U.S. headquarters is necessary for platform maintenance, such access occurs under Module Two/Three EU Standard Contractual Clauses supplemented by Transfer Impact Assessments (TIAs) and supplementary technical measures including encryption in transit and at rest.
5. Cloud Infrastructure Architecture
PassCell deploys its Services across a multi-node cloud topology designed for high availability, regulatory segregation, and defense-in-depth security:
- Global Edge Routing Layer: An anycast content delivery and request routing tier directs inbound traffic to the nearest healthy node while enforcing geo-routing policies that bind EU passport resolution to EU-origin endpoints.
- European Primary Storage Cluster: Authoritative passport databases, object storage for QR artifacts, and encrypted ledger backups reside in ISO 27001-certified facilities within the EEA.
- U.S. Administrative Control Plane: Non-payload operational tooling—billing, account provisioning, and internal monitoring—operates from U.S. infrastructure segregated from EU passport data stores by network policy and identity boundaries.
- Encryption: All data in transit is protected by TLS 1.3 or higher. Data at rest is encrypted using AES-256 with customer-managed key options available under Enterprise Pro subscriptions.
PassCell does not sell, license, or monetize passport registry data. Infrastructure providers are bound by Data Processing Agreements (DPAs) incorporating GDPR Article 28 obligations.
6. Categories of Data Processed
6.1 Customer Account Data (B2B)
Information provided during factory registration and login, including corporate manufacturer email addresses, factory identifier tokens, export jurisdiction selections, and authentication credentials. This data is processed to administer accounts and fulfill contractual obligations.
6.2 Battery Passport Product Data
Technical and compliance metadata submitted via factory dashboards: serial codes, battery category classifications, capacity and voltage specifications, material chemistry recycled-content percentages, carbon footprint figures, and service/repair operation notes. This data is product information, not personal data, unless a Customer improperly includes personal identifiers.
6.3 Public Scan Resolution Data — Zero PII Collection
When any party—including a European customs border officer, port authority inspector, recycler, or consumer—scans a physical battery QR label, PassCell's public compliance portal serves a static read-only registry page. No personally identifiable information (PII) is collected from the scanning party. PassCell does not record the inspector's name, employee ID, device identifiers tied to an individual, IP address for geolocation purposes, GPS coordinates, camera metadata, or any form of behavioral telemetry associated with the scan event.
This zero-PII, zero-location design satisfies non-tracking regulatory privacy assurance obligations and ensures that public passport access does not create surveillance vectors against government officials or downstream supply chain actors.
6.4 Technical Log Data (Restricted)
Aggregated, anonymized infrastructure metrics (e.g., request volume, error rates) may be collected for platform reliability. Such logs are stripped of IP addresses at ingestion for EU-facing endpoints and retained for no longer than ninety (90) days.
7. Legal Bases for Processing (GDPR Article 6)
PassCell relies on the following legal bases depending on processing activity:
- Contractual Necessity (Art. 6(1)(b)): Processing account and passport data necessary to deliver subscribed Services to B2B Customers.
- Legal Obligation (Art. 6(1)(c)): Retention and disclosure of passport data as required by Regulation (EU) 2023/1542 and implementing acts.
- Legitimate Interests (Art. 6(1)(f)): Platform security, fraud prevention, and service improvement, balanced against data subject rights and overridden where EU law mandates stricter treatment.
- Consent (Art. 6(1)(a)): Where applicable for optional marketing communications to business contacts; not relied upon for core passport registry operations.
8. International Data Transfers
PassCell is headquartered in the United States. Transfers of limited administrative data from the EEA to the U.S. are conducted exclusively under approved transfer mechanisms, including EU Standard Contractual Clauses and, where applicable, the EU-U.S. Data Privacy Framework for certified subprocessors.
Battery passport records subject to EU sovereignty requirements are not transferred to the United States for storage or primary processing. U.S. personnel access to EU passport data is restricted to break-glass support scenarios under multi-factor authentication, time-limited privileged access, and full audit logging.
9. Data Retention
Battery passport records are retained for the operational lifetime of the battery plus the minimum statutory period required under Regulation (EU) 2023/1542 and applicable national transposition measures—typically a minimum of ten (10) years following placement on the market unless a longer period is mandated.
Customer account data is retained for the duration of the subscription and up to three (3) years thereafter for legal, tax, and dispute resolution purposes. Customers may request earlier deletion of account data subject to regulatory retention overrides.
10. Security Measures
PassCell maintains administrative, technical, and organizational measures including:
- Role-based access control (RBAC) with factory-scoped data isolation;
- Multi-factor authentication for all production system access;
- Annual penetration testing and vulnerability management programs;
- SOC 2 Type II-aligned control frameworks (in progress / available under NDA);
- Incident response procedures with seventy-two (72) hour GDPR breach notification capability.
11. Data Subject Rights
Where PassCell acts as data controller, individuals located in the EEA may exercise rights under GDPR Articles 15–22, including access, rectification, erasure, restriction, portability, and objection. Requests may be submitted to the contact in Section 13. PassCell will respond within thirty (30) days unless extension is permitted by law.
Where PassCell acts as processor, data subject requests pertaining to passport content must be directed to the subscribing economic operator (Customer), who remains the primary point of contact for product-level data matters.
Individuals have the right to lodge a complaint with a supervisory authority in their EU member state of residence or place of work.
12. Legal Disclaimer
THE PASSCELL SERVICES, INCLUDING ALL SOFTWARE, DOCUMENTATION, DEMO ENVIRONMENTS, QR CODE OUTPUTS, AND COMPLIANCE PORTAL PAGES, ARE PROVIDED ON AN "AS IS" AND "AS AVAILABLE" BASIS. TO THE MAXIMUM EXTENT PERMITTED BY APPLICABLE LAW, PASSCELL, INC. DISCLAIMS ALL WARRANTIES, EXPRESS OR IMPLIED, INCLUDING WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE, NON-INFRINGEMENT, AND REGULATORY COMPLIANCE.
PassCell is a technology platform provider. Use of the Services does not, by itself, constitute legal, regulatory, or customs compliance. Customers remain solely responsible for verifying that submitted passport data is accurate, complete, and satisfies all obligations under Regulation (EU) 2023/1542, national implementing legislation, and applicable export control regimes in the United States and destination markets.
PassCell makes no representation that the Services will satisfy customs authorities, notified bodies, or market surveillance agencies in every jurisdiction. Demonstration, sandbox, and preview environments are not production registries and must not be relied upon for commercial placement of batteries on the EU market.
IN NO EVENT SHALL PASSCELL, ITS DIRECTORS, OFFICERS, EMPLOYEES, AGENTS, OR AFFILIATES BE LIABLE FOR ANY INDIRECT, INCIDENTAL, SPECIAL, CONSEQUENTIAL, OR PUNITIVE DAMAGES, INCLUDING LOST PROFITS, REGULATORY PENALTIES, OR MARKET ACCESS DENIAL, ARISING FROM USE OF OR INABILITY TO USE THE SERVICES, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGES. PASSCELL'S AGGREGATE LIABILITY FOR DIRECT DAMAGES SHALL NOT EXCEED THE FEES PAID BY THE CUSTOMER IN THE TWELVE (12) MONTHS PRECEDING THE CLAIM.
This Policy is governed by the laws of the State of Delaware, United States, without regard to conflict-of-law principles, except where mandatory GDPR or EU consumer protection provisions apply to data processing activities within the EEA.
13. Contact Information
For privacy inquiries, data subject requests, or EU representative correspondence:
PassCell, Inc. — Data Protection Office
1200 Battery Compliance Way, Suite 400
Austin, TX 78701, United States
Email: privacy@passcell.com
EU Representative: PassCell EU Data Services B.V.
Herengracht 124, 1015 BT Amsterdam, Netherlands
Email: eu-rep@passcell.com
Document ID: PC-LEGAL-PRIV-2026-02 · Version 1.2 · This Policy may be updated periodically. Material changes will be communicated to registered Customers via email and posted on this page with a revised effective date.