Privacy.
What the access, application, garment-register and Instagram comment services process, and why.
Controller
Rabenreiter UG (haftungsbeschränkt) · iam@ditissim.com
Access data
The access dialog uses first name, last name and a three-digit issue number only to compare a submitted combination with active ownership records. Successful access creates an access-grant ID and garment relationship set, with source, resolution type, timestamps, visit count, expiry, status, locale and any linked application. Failed names and issue numbers are not retained, and raw IP addresses are not stored.
Attribution
QR access is attributed to its exact garment. Direct access is attributed to every active garment matching the submitted owner name and issue number. A snapshot of those owner and garment references is stored with the access grant and copied to an application so later ownership changes do not alter its history. We do not retain page-by-page browsing history.
Application data
We process your first name, last name, city and country, international telephone number, email address, size, colour, preferred number, written statement, interface language, consent version and submission time. Telephone numbers are normalized to E.164 solely as contact information. Email addresses are normalized, confirmed through a time-limited link and protected with a keyed hash to prevent more than one active application per email and garment series. We also retain the confirmation time and the owner and garment reference through which the application was accessed.
Email confirmation and abuse prevention
An unconfirmed application reserves its email and selected number for 30 minutes and then expires. DITISSIM's Hostinger mailbox and, when needed, Resend deliver confirmation and internal notification emails. Cloudflare Turnstile assesses technical browser and network signals to distinguish legitimate use from automated abuse. Upstash stores short-lived rate-limit counters. Names and telephone numbers are not used for duplicate detection.
Instagram comments
Automated Instagram comment processing is currently disabled. If it is enabled after a separate privacy review, Meta may send us webhook events so we can moderate and respond; the notice will be updated before that processing begins.
Purpose and legal basis
Application data are processed to take steps at your request before any possible contract (Article 6(1)(b) GDPR). Consent-based fields are processed under Article 6(1)(a). Security, access, garment-register integrity, abuse prevention and limited service analytics rely on our legitimate interests under Article 6(1)(f), balanced against your rights. Records required by law are processed under Article 6(1)(c).
Garment register
A protected garment record may contain a garment ID, series and issue number, QR code, product and issuance details, ownership intervals and access events. Garment records are not exposed as public results.
Retention
Unconfirmed applications expire after 30 minutes but remain subject to the approved deletion or anonymisation schedule. Unsubmitted access grants are retained for 12 months. Application-linked grants follow the application's documented retention schedule. Declined or expired applications and security records are deleted or anonymised according to the approved operational and legal schedule; rate-limit counters expire automatically.
Processors and backups
When configured, service providers include Supabase for the canonical PostgreSQL database, Hostinger and Resend for confirmation and notification emails, Cloudflare for Turnstile abuse prevention, restricted Google Drive and Sheets for the garment and ownership register and backups, Upstash for rate limiting and Plausible for aggregate cookieless analytics. Administrators may separately use OpenAI Codex to prepare synthetic social content. The production site does not send application data, user data or creative prompts to OpenAI.
Your rights
Subject to applicable law, you may request access, correction, deletion, restriction or portability, object to processing, withdraw consent where consent is used, and complain to a competent data-protection authority.
Local storage and security
The signed access cookie contains only the access-grant ID, access scope and expiry. It is HTTP-only, Secure in production and SameSite=Lax. Administrative systems use least-privilege access, validation, audit records and rate limits; no internet service can promise absolute security.