Privacy

Privacy notice

Last updated: 5 October 2026

This notice explains how we handle personal data when you use usetrama.eu, write to us, receive a message from us, use the Trama platform or open a digital product passport page. It is provided under Articles 13 and 14 of Regulation (EU) 2016/679 ("GDPR"). The Italian text is the reference version.

1. Who is the controller

Giacomo Cavalcabò, sole proprietorship ("Trama"), Via Carlo Farini 56, Milan (Italy), VAT no. IT13808610961. Privacy contact: hello@usetrama.eu.

We have not appointed a Data Protection Officer (DPO): we are not required to.

When we are not the controller. For the data a brand customer enters into the platform and for the pages of its passports, the brand is the controller and Trama acts as its processor (Art. 28 GDPR). If a brand is your customer or employer and you have questions about your data there, please write to the brand first.

2. What data we handle, why and on what legal basis

2.1 If you visit the website. Page visited, referring page, device and browser type, country. Cloudflare Web Analytics collects them and does not use cookies. Your IP address necessarily reaches the servers that deliver the pages (Vercel, Cloudflare) for the technical duration of the request and may appear in their technical logs. Purpose: to run and protect the site and to understand which content is of interest. Legal basis: Trama's legitimate interest (Art. 6(1)(f)). You are not obliged to provide this data, but without it the site cannot be delivered.

2.2 If you write to us (contact form or email). Name, email address, company (optional), topic and message text. The form stores nothing on the site: it sends an email to hello@usetrama.eu, where the message stays. Purpose: to answer your request and, if you ask, to start a discussion. Legal basis: pre-contractual steps at your request (Art. 6(1)(b)) or our legitimate interest in replying to people who write to us (Art. 6(1)(f)).

2.3 If we contact you (prospects, partners, collaborators). We write to people who work at textile and apparel companies, or at bodies working on the digital product passport, to propose the service or ask for an opinion. We inform you here because you did not give us your data yourself (Art. 14).

  • Data: first and last name, role, company, work email address, link to your public professional profile, country and language, the source we obtained the contact from, the history of our exchanges.
  • Where it comes from: companies' public web pages, public lists of exhibitors and associations, public professional profiles, or you wrote to us. Every message tells you which source concerns you.
  • Legal basis: Trama's legitimate interest (Art. 6(1)(f)) in offering a B2B service to companies in the sector. The processing is contained: little data, one contact at a time, no disclosure to third parties.
  • Objection: you can tell us at any time to stop writing to you, including by replying "no" to the message. We stop immediately (section 7).
  • We do not write to sole proprietors or to certified-mail (PEC) addresses.

2.4 If you use the Trama platform. Anyone can create a free account. A new account belongs to no company and sees nobody's data: working on a company's passports takes an invitation from its administrator or from Trama.

  • Account data: name, email, password (stored only as a hash, never in clear), role, brand, account creation and email verification dates.
  • Brand content: uploaded documents (technical sheets, certificates) may contain names or signatures. We use them for nothing else and send them to no artificial-intelligence provider: automatic data extraction is switched off.
  • Access security: counters of login, password-recovery and invitation attempts, by IP address and by email, to counter brute-force attacks. Each counter is valid for 15-60 minutes and is deleted shortly after it expires, normally within a day.
  • Service emails (invitations, email confirmation, password reset), sent through Resend. We send no marketing messages to platform users without their consent.
  • Roles: if you created the account yourself and belong to no company, Trama is the controller of the account data (legal basis: performance of a contract, Art. 6(1)(b)). Once you join a company by invitation, for the account and content the controller is that company and Trama is its processor. For access security, and for invoicing and contract communications, the controller is Trama. Trama's legal bases: legitimate interest in security (Art. 6(1)(f)); performance of the contract with the brand (Art. 6(1)(b)).

2.5 If you open a passport page (QR scan). The page is published by the brand that printed the QR on the product: the brand is the controller and Trama runs the page on its behalf. It shows product data (composition, origin, care, certifications) and, if the brand publishes it, a compliance contact.

  • We record nothing about your visit: not your IP address, not your location, no viewing statistics. The page sets no cookies and loads no third-party measurement tools. Country flags are served by Trama.
  • As with any website, your IP is seen by the servers that deliver the page for the duration of the request (section 4).
  • Content chosen by the brand: if the brand picked a custom typeface, your browser downloads it from Google Fonts; if it added a YouTube or Vimeo video, or images and a logo hosted on another site, your browser downloads them from those services. In those cases the service receives your IP. YouTube videos are embedded in privacy-enhanced mode (youtube-nocookie.com), which according to YouTube stores no information about the visitor until the video is played; Vimeo videos with the "do not track" option. If you play a video, the platform's own policy applies.

3. Cookies and similar tools

  • Technical access-security cookies (Auth.js): on the site, even if you do not sign in, we set two technical cookies, a protection token against forged requests (CSRF) and the return address after login. After signing in to the platform there is also a session cookie, which lasts 7 days. They do not identify you, do not profile you and need no consent. Passport pages set no Trama cookies (for videos added by the brand see section 2.5).
  • Site measurement: Cloudflare Web Analytics, on Trama's site only and not on passport pages. According to Cloudflare's documentation it works without cookies and does not build user profiles.
  • We use no advertising or profiling cookies and no social-network pixels.

4. Who we share data with

We do not sell data and do not hand it to third parties for their own purposes. These providers help us deliver the service and are appointed as our processors (or sub-processors):

ProviderWhat it is forData
Supabasedatabase and file storage, EU region (Frankfurt)account data, uploaded content, commercial contacts
Vercelapplication hosting and functions, EU region (Frankfurt)data in transit, technical logs (including IP)
Resendsending service emails and contact-form notificationsrecipients' name and email, message text
Google Workspacethe hello@usetrama.eu mailbox and Trama's personal mailboxesemails received and sent, including form messages
GitHubdaily database backup, encrypted before it leaves our environment (GitHub does not hold the key)encrypted copy of platform data
CloudflareDNS and cookieless site measurementnetwork data, aggregate statistics
Google Fontstypefaces on passport pages, only if the brand picks a custom oneIP and browser technical data, sent by the visitor's browser
YouTube, Vimeo or other sites chosen by the brandvideos, images or a logo the brand adds to the passport while hosting them elsewhereIP and browser technical data, sent by the visitor's browser; video-platform cookies only once the video is played

The list of providers that process data on behalf of a brand is attached to the contract with the brand. We use no artificial-intelligence provider: if we switch automatic data extraction on in future, we will update this notice first. Data is accessible only to Trama people who need it, bound by confidentiality.

5. Transfers outside the European Economic Area

The database and file storage are in the EU. Some providers (Vercel, Resend, Google, GitHub, Cloudflare) are also based or operate infrastructure outside the EU, in particular in the United States. When data leaves the EU, the transfer relies on a European Commission adequacy decision (EU-US Data Privacy Framework) for providers that participate, or on the standard contractual clauses of Implementing Decision (EU) 2021/914. You can ask us which instrument applies to a specific provider.

6. How long we keep data

DataRetention
Form messages and correspondenceup to 24 months after the last useful exchange, then deleted
Commercial contacts (prospects)12 months after our last message with no reply; 24 months after the last exchange if there is a conversation
"Do not contact" listthe email address only, for as long as needed to avoid writing to you by mistake
Accounts with no companyuntil you ask us to delete it (write to hello@usetrama.eu); an account never confirmed by email may be deleted at any time
Platform accountsfor the duration of the brand's contract; deleted within 30 days of termination or of the brand's request, unless the law requires otherwise
Published passport (product data, versions, supporting documents)10 years after the last placing on the market of the product, or the different period set by the applicable rules; this is not the visitor's personal data
Anti-abuse counters (IP, email)valid 15-60 minutes, then deleted periodically (normally within a day)
Encrypted backups90 days; deleted data also disappears from backups within this period
Accounting and tax records10 years, as required by law

7. Your rights

You can ask us for access to your data, rectification, erasure, restriction and portability (Arts. 15-20 GDPR), and object to processing based on legitimate interest (Art. 21), including commercial contact. Write to hello@usetrama.eu. We reply within one month. To be sure it is you, we write back to the address you asked from. For data whose controller is a brand customer, we refer you to the brand.

If you ask us to delete your commercial data, we delete it from our contact list, mailbox, drafts and notes. We keep only your email address on a "do not contact" list, to honour your objection, and a record of the request (date and outcome) so that we can show we complied. If you prefer total deletion, tell us, but without the list we cannot guarantee we will not write to you again.

8. Complaints

You have the right to lodge a complaint with the Italian data protection authority (Garante per la protezione dei dati personali, garanteprivacy.it) or with the authority of your country of residence.

9. Automated decisions

We take no decisions based solely on automated processing that produce effects on you, and we do not use data to profile visitors.

10. Changes

If we change this notice, we publish the updated version with the new date. If the controller changes (for example on forming a company), we will say so here.