Regulatory complexity
The platform had to distinguish current requirements, adopted frameworks, binding dates and schemes that are still pending, without presenting unfinished rules as mandatory.
Design and development of a complete SaaS platform for Digital Product Passports.
“Turning complex regulation into a practical workflow.”
DPPora was created to solve a concrete problem: helping manufacturers and economic operators prepare, structure, publish and maintain Digital Product Passports without relying on spreadsheets, fragmented processes or complex enterprise interfaces. FARO defined the product, designed the experience, built the technical architecture and integrated the external systems required to turn that idea into a working platform.
A Digital Product Passport is not a single page or a simple QR code. It is a living system of product data, company identity, evidence, regulatory requirements, versions, translations and permanent public access.
The platform had to distinguish current requirements, adopted frameworks, binding dates and schemes that are still pending, without presenting unfinished rules as mandatory.
Information needed to be organised around organisations, products, identifiers, materials, evidence, regulatory data and published versions.
A technically complex process had to become a guided journey that a small manufacturer could use without an in-house compliance team.
The product needed plans, publishing limits, teams, billing, upgrades, downgrades and entitlements without duplicating business rules.
Before building screens, we defined the operating model: an organisation maintains a catalogue; each product keeps a structured record; the passport is prepared in stages; publishing creates a permanent public output; and later changes can evolve without destroying history.
The public experience was designed around one simple idea: product data becomes lasting trust. In parallel, the private application was conceived as a guided workspace with clear states, progressive validation and visible next steps.
The platform combines Cloudflare for global delivery and edge logic with Supabase for authentication, PostgreSQL, storage and backend services. Separating interface, data, translation and external services allows each layer to evolve without turning the product into a difficult-to-maintain monolith.
Organisations, users, products, passports, versions, evidence, subscriptions and events are structured as related entities.
Authentication, organisation-scoped access control, Turnstile at sensitive entry points and server-side operation validation.
Cloudflare is used for delivery, protection and processes that benefit from execution and caching close to the visitor.
Integrations are isolated behind specific routes and functions so the whole application is not tightly coupled to one provider.
Organisation onboarding does more than ask a user to type a company name. DPPora performs business-registry lookups according to jurisdiction. In the UK, for example, the platform queries Companies House and returns the registered details for confirmation.
EU businesses can use VIES validation where applicable. The flow also supports individual professionals and jurisdictions where automated lookup is unavailable, allowing manual entry without breaking onboarding.
The workspace organises products by passport status and supports search by name, SKU, GTIN, UPI, date or material. Each product moves through four stages: identity, passport data, EU regulatory information and preview/publish.
The goal was for the platform to explain what is missing and what happens next. States, contextual help and validation reduce the chance of publishing an incomplete or inconsistent record.
DPPora accepts identifiers such as GTIN/EAN and SKU and includes barcode scanning to accelerate data capture. Materials include percentage and country of origin, with validation ensuring composition reaches exactly 100%.
Beyond composition, a record can store repair, recycling and sustainability information plus supporting evidence. Contextual tooltips explain the purpose of complex fields inside the workflow itself.
One of the most important product decisions was not to pretend that every DPP scheme is fully defined. The EU regulatory module separates voluntary preparation from mandatory schemes and retains schema identifiers, versions, registry status and correlation fields for future integrations.
This allows customers to organise data now and evolve records as delegated acts, semantic schemas and official systems become concrete.
The product was designed for a European market from the start. The public site and portal are localised, and published passports can be served in multiple languages. Automatic translations are cached to avoid repeated work and can be manually corrected when an editorial version is required.
The architecture keeps source content separate from translated output so a passport update can invalidate or refresh affected translations without losing version control.
On publication, DPPora generates a permanent URL and downloadable QR code that can be placed on a product or its packaging. The QR does not point to a static image: it opens the public record maintained by the platform.
Publishing was designed as a clear transition from draft to live, showing the operator exactly which URL and QR to use.
The commercial layer was built as part of the product rather than bolted on later. Plans control published-passport limits, users and capabilities. The dashboard shows current usage, the next renewal and the expected next payment.
Upgrades calculate prorated cost, VAT where applicable, amount due today and the next charge. Billing-period changes and downgrades are handled as explicit operations so subscription state remains understandable.
DPPora extends beyond the private application. A public regulation tracker distinguishes binding deadlines, adopted frameworks and ESPR priorities. Each sector can show what to prepare and link back to the relevant official source.
This turns regulatory research into a useful acquisition and education tool, helping prospective customers understand readiness before they register.
The portal and public site were tested and adjusted for mobile, including compact navigation, long forms, language selectors, modals, on-screen keyboards and controls that could overflow narrow displays.
Intermediate states — such as opening the workspace or updating a subscription — were also designed so asynchronous operations did not look like freezes or errors.
The solution combines managed infrastructure with custom code to retain development speed without giving up control over data, business logic or user experience.
Guided workflow from identity through publication.
Mathematical validation of material totals.
Downloadable public link for every published passport.
Versioned model for future schemas and registries.
The result is a working SaaS platform bringing product data, compliance, translation, publishing, billing and administration into one coherent flow. More importantly, the architecture is prepared to evolve as European DPP requirements mature.
FARO helped define flow, priorities, states, messaging and the commercial model in addition to building the software.
Business registries, payments, authentication, translation, QR and cloud services were integrated into one coherent experience.
The system separates preparation from obligation and uses versioning so regulatory change does not invalidate the product.
Development included real registration, billing, device, language and publishing tests, fixing friction as it appeared.
FARO designs and develops custom digital products from architecture and UX through integrations, payments and production launch.
Talk to FARO