Privacy Policy
Information on the processing of personal data (GDPR).
1. Controller
Controller for personal data processed via D3 Passport: D3 Chain, Andersenstrasse 4, 59557 Lippstadt, Deutschland. Contact: kontakt@d3chain.com.
Responsible person for content/contact: Alexander Denner.
2. What we process
Account data: email address, authentication identifiers, company membership and role.
Customer Content: product passport data you enter (may include business contact details of your organisation).
Billing data: processed by our payment provider (e.g. Stripe) as independent or joint controller according to their terms.
Technical logs: IP address, timestamps, security/event logs needed to operate and protect the Service.
3. Purposes and legal bases (GDPR)
Contract performance (Art. 6(1)(b) GDPR): provide accounts, passports, publish/timestamp features, support.
Legitimate interests (Art. 6(1)(f)): security, abuse prevention, service improvement (balanced against your rights).
Legal obligations (Art. 6(1)(c)): tax/accounting retention where applicable.
Consent (Art. 6(1)(a)) where we expressly ask for it (e.g. optional marketing).
4. Recipients and processors
Hosting/infrastructure (e.g. Vercel), database/auth (e.g. Supabase), payments (e.g. Stripe), and Time Stamping Authorities for RFC 3161 tokens.
Processors act under contracts (Art. 28 GDPR). Transfers outside the EEA use appropriate safeguards (e.g. SCCs) where required.
5. Retention
Account data is kept while your account is active and deleted or anonymised within a reasonable period after closure, unless longer retention is required by law.
Published passport data and related integrity evidence (hashes, timestamp tokens, backups) may be retained as long as needed for the Service purpose and legal obligations you or we must meet.
6. Your rights
You may request access, rectification, erasure, restriction, portability, and object to processing based on legitimate interests, subject to GDPR conditions.
Contact kontakt@d3chain.com. You may lodge a complaint with a supervisory authority (in Germany typically the authority of the federal state where the controller is established, or your local authority).
7. Security
We apply technical and organisational measures appropriate to the risk (access control, encryption in transit, least-privilege service keys). No method is 100% secure.
8. Cookies
Essential cookies/storage are used for authentication, locale preference (e.g. d3_locale), and security. Non-essential analytics cookies are not loaded unless introduced and disclosed separately with consent where required.
9. Updates
Last updated: 22 July 2026. Draft for launch review. Contact: kontakt@d3chain.com.
