Privacy Policy
Information on the processing of personal data (GDPR).
1. Introduction and controller
We inform you how personal data is processed when you use D3 Passport at d3chain.com. Personal data means any information relating to an identified or identifiable natural person.
Controller: Alexander Denner, D3 Chain, Andersenstrasse 4, 59557 Lippstadt, Deutschland. Tel.: +49 17642849702. Email: kontakt@d3chain.com.
2. Data collected when visiting the website
If you use the site for information only (without registering), we process server log data that your browser transmits, such as page requested, date/time, amount of data transferred, referrer, browser/OS and IP address (possibly truncated). Processing is based on Art. 6(1)(f) GDPR (legitimate interest in stability, security and functionality). We do not use these logs for profiling.
The site uses TLS encryption (HTTPS).
3. Hosting
Hosting and delivery of the website/app: Vercel Inc., USA (EU–US Data Privacy Framework / SCCs as applicable). We have a data processing agreement in place.
Database, authentication and related backend services: Supabase (processor under Art. 28 GDPR). Transfers outside the EEA use appropriate safeguards where required.
4. Cookies / storage
Essential cookies or local storage are used for authentication, locale preference (e.g. d3_locale) and security. Session cookies are deleted when you close the browser; persistent settings may remain longer. You can configure your browser to refuse cookies; some features may then not work.
Non-essential analytics cookies are not loaded unless introduced and disclosed separately with consent where required (Art. 6(1)(a) GDPR).
5. Contact
When you contact us (e.g. by email), we process the data you provide solely to handle your request (Art. 6(1)(f) and, where applicable, Art. 6(1)(b) GDPR). Data are deleted when the matter is closed, subject to statutory retention.
6. Customer accounts
When you open an account we process the data required for registration (email, authentication identifiers, company membership and role) under Art. 6(1)(b) GDPR. You may request deletion of your account by contacting us; data are then deleted unless contracts remain to be settled or legal retention / legitimate interests require otherwise.
7. Contract performance and payments
Customer Content (product passport data you enter) is processed to provide the Service (Art. 6(1)(b)). Published passport pages may be publicly accessible as you configure.
Payments: Stripe Payments Europe Ltd., Dublin, Ireland. Payment data are transmitted for payment processing (Art. 6(1)(b)). Stripe may process further data under its own responsibility according to its terms.
RFC 3161 time-stamping authorities receive cryptographic hashes / tokens as needed to provide timestamp features — not for unrelated marketing.
Consumers with paid ongoing subscriptions may cancel electronically via billing settings where provided (legal obligation / contract performance).
8. Your rights
Under GDPR you may have rights of access, rectification, erasure, restriction, notification, data portability, withdrawal of consent (Art. 7(3)), and complaint to a supervisory authority (Art. 77).
OBJECTION: Where we process data based on legitimate interests (Art. 6(1)(f)), you may object on grounds relating to your particular situation. We will stop processing unless we demonstrate compelling legitimate grounds or the processing serves the establishment, exercise or defence of legal claims. You may also object at any time to processing for direct marketing.
Contact: kontakt@d3chain.com.
9. Retention
Retention depends on legal basis, purpose and statutory retention (e.g. commercial/tax). Consent-based data until withdrawal; contract data until expiry of retention / settlement; legitimate-interest data until successful objection unless compelling grounds apply.
Published passport data and integrity evidence (hashes, timestamp tokens, backups) may be retained as long as needed for the Service purpose and legal obligations.
10. Security and updates
We apply technical and organisational measures appropriate to the risk (access control, encryption in transit, least-privilege keys). No method is 100% secure.
Last updated: 10 September 2026. Contact: kontakt@d3chain.com.
