Privacy notice
Last updated: 5 October 2026
This notice explains how we handle personal data when you use usetrama.eu, write to us, receive a message from us, use the Trama platform or open a digital product passport page. It is provided under Articles 13 and 14 of Regulation (EU) 2016/679 ("GDPR"). The Italian text is the reference version.
1. Who is the controller
Giacomo Cavalcabò, sole proprietorship ("Trama"), Via Carlo Farini 56, Milan (Italy), VAT no. IT13808610961. Privacy contact: hello@usetrama.eu.
We have not appointed a Data Protection Officer (DPO): we are not required to.
When we are not the controller. For the data a brand customer enters into the platform and for the pages of its passports, the brand is the controller and Trama acts as its processor (Art. 28 GDPR). If a brand is your customer or employer and you have questions about your data there, please write to the brand first.
2. What data we handle, why and on what legal basis
2.1 If you visit the website. Page visited, referring page, device and browser type, country. Cloudflare Web Analytics collects them and does not use cookies. Your IP address necessarily reaches the servers that deliver the pages (Vercel, Cloudflare) for the technical duration of the request and may appear in their technical logs. Purpose: to run and protect the site and to understand which content is of interest. Legal basis: Trama's legitimate interest (Art. 6(1)(f)). You are not obliged to provide this data, but without it the site cannot be delivered.
2.2 If you write to us (contact form or email). Name, email address, company (optional), topic and message text. The form stores nothing on the site: it sends an email to hello@usetrama.eu, where the message stays. Purpose: to answer your request and, if you ask, to start a discussion. Legal basis: pre-contractual steps at your request (Art. 6(1)(b)) or our legitimate interest in replying to people who write to us (Art. 6(1)(f)).
2.3 If we contact you (prospects, partners, collaborators). We write to people who work at textile and apparel companies, or at bodies working on the digital product passport, to propose the service or ask for an opinion. We inform you here because you did not give us your data yourself (Art. 14).
- Data: first and last name, role, company, work email address, link to your public professional profile, country and language, the source we obtained the contact from, the history of our exchanges.
- Where it comes from: companies' public web pages, public lists of exhibitors and associations, public professional profiles, or you wrote to us. Every message tells you which source concerns you.
- Legal basis: Trama's legitimate interest (Art. 6(1)(f)) in offering a B2B service to companies in the sector. The processing is contained: little data, one contact at a time, no disclosure to third parties.
- Objection: you can tell us at any time to stop writing to you, including by replying "no" to the message. We stop immediately (section 7).
- We do not write to sole proprietors or to certified-mail (PEC) addresses.
2.4 If you use the Trama platform. Anyone can create a free account. A new account belongs to no company and sees nobody's data: working on a company's passports takes an invitation from its administrator or from Trama.
- Account data: name, email, password (stored only as a hash, never in clear), role, brand, account creation and email verification dates.
- Brand content: uploaded documents (technical sheets, certificates) may contain names or signatures. We use them for nothing else and send them to no artificial-intelligence provider: automatic data extraction is switched off.
- Access security: counters of login, password-recovery and invitation attempts, by IP address and by email, to counter brute-force attacks. Each counter is valid for 15-60 minutes and is deleted shortly after it expires, normally within a day.
- Service emails (invitations, email confirmation, password reset), sent through Resend. We send no marketing messages to platform users without their consent.
- Roles: if you created the account yourself and belong to no company, Trama is the controller of the account data (legal basis: performance of a contract, Art. 6(1)(b)). Once you join a company by invitation, for the account and content the controller is that company and Trama is its processor. For access security, and for invoicing and contract communications, the controller is Trama. Trama's legal bases: legitimate interest in security (Art. 6(1)(f)); performance of the contract with the brand (Art. 6(1)(b)).
2.5 If you open a passport page (QR scan). The page is published by the brand that printed the QR on the product: the brand is the controller and Trama runs the page on its behalf. It shows product data (composition, origin, care, certifications) and, if the brand publishes it, a compliance contact.
- We record nothing about your visit: not your IP address, not your location, no viewing statistics. The page sets no cookies and loads no third-party measurement tools. Country flags are served by Trama.
- As with any website, your IP is seen by the servers that deliver the page for the duration of the request (section 4).
- Content chosen by the brand: if the brand picked a custom typeface, your browser downloads it from Google Fonts; if it added a YouTube or Vimeo video, or images and a logo hosted on another site, your browser downloads them from those services. In those cases the service receives your IP. YouTube videos are embedded in privacy-enhanced mode (youtube-nocookie.com), which according to YouTube stores no information about the visitor until the video is played; Vimeo videos with the "do not track" option. If you play a video, the platform's own policy applies.
3. Cookies and similar tools
- Technical access-security cookies (Auth.js): on the site, even if you do not sign in, we set two technical cookies, a protection token against forged requests (CSRF) and the return address after login. After signing in to the platform there is also a session cookie, which lasts 7 days. They do not identify you, do not profile you and need no consent. Passport pages set no Trama cookies (for videos added by the brand see section 2.5).
- Site measurement: Cloudflare Web Analytics, on Trama's site only and not on passport pages. According to Cloudflare's documentation it works without cookies and does not build user profiles.
- We use no advertising or profiling cookies and no social-network pixels.
4. Who we share data with
We do not sell data and do not hand it to third parties for their own purposes. These providers help us deliver the service and are appointed as our processors (or sub-processors):
| Provider | What it is for | Data |
|---|---|---|
| Supabase | database and file storage, EU region (Frankfurt) | account data, uploaded content, commercial contacts |
| Vercel | application hosting and functions, EU region (Frankfurt) | data in transit, technical logs (including IP) |
| Resend | sending service emails and contact-form notifications | recipients' name and email, message text |
| Google Workspace | the hello@usetrama.eu mailbox and Trama's personal mailboxes | emails received and sent, including form messages |
| GitHub | daily database backup, encrypted before it leaves our environment (GitHub does not hold the key) | encrypted copy of platform data |
| Cloudflare | DNS and cookieless site measurement | network data, aggregate statistics |
| Google Fonts | typefaces on passport pages, only if the brand picks a custom one | IP and browser technical data, sent by the visitor's browser |
| YouTube, Vimeo or other sites chosen by the brand | videos, images or a logo the brand adds to the passport while hosting them elsewhere | IP and browser technical data, sent by the visitor's browser; video-platform cookies only once the video is played |
The list of providers that process data on behalf of a brand is attached to the contract with the brand. We use no artificial-intelligence provider: if we switch automatic data extraction on in future, we will update this notice first. Data is accessible only to Trama people who need it, bound by confidentiality.
5. Transfers outside the European Economic Area
The database and file storage are in the EU. Some providers (Vercel, Resend, Google, GitHub, Cloudflare) are also based or operate infrastructure outside the EU, in particular in the United States. When data leaves the EU, the transfer relies on a European Commission adequacy decision (EU-US Data Privacy Framework) for providers that participate, or on the standard contractual clauses of Implementing Decision (EU) 2021/914. You can ask us which instrument applies to a specific provider.
6. How long we keep data
| Data | Retention |
|---|---|
| Form messages and correspondence | up to 24 months after the last useful exchange, then deleted |
| Commercial contacts (prospects) | 12 months after our last message with no reply; 24 months after the last exchange if there is a conversation |
| "Do not contact" list | the email address only, for as long as needed to avoid writing to you by mistake |
| Accounts with no company | until you ask us to delete it (write to hello@usetrama.eu); an account never confirmed by email may be deleted at any time |
| Platform accounts | for the duration of the brand's contract; deleted within 30 days of termination or of the brand's request, unless the law requires otherwise |
| Published passport (product data, versions, supporting documents) | 10 years after the last placing on the market of the product, or the different period set by the applicable rules; this is not the visitor's personal data |
| Anti-abuse counters (IP, email) | valid 15-60 minutes, then deleted periodically (normally within a day) |
| Encrypted backups | 90 days; deleted data also disappears from backups within this period |
| Accounting and tax records | 10 years, as required by law |
7. Your rights
You can ask us for access to your data, rectification, erasure, restriction and portability (Arts. 15-20 GDPR), and object to processing based on legitimate interest (Art. 21), including commercial contact. Write to hello@usetrama.eu. We reply within one month. To be sure it is you, we write back to the address you asked from. For data whose controller is a brand customer, we refer you to the brand.
If you ask us to delete your commercial data, we delete it from our contact list, mailbox, drafts and notes. We keep only your email address on a "do not contact" list, to honour your objection, and a record of the request (date and outcome) so that we can show we complied. If you prefer total deletion, tell us, but without the list we cannot guarantee we will not write to you again.
8. Complaints
You have the right to lodge a complaint with the Italian data protection authority (Garante per la protezione dei dati personali, garanteprivacy.it) or with the authority of your country of residence.
9. Automated decisions
We take no decisions based solely on automated processing that produce effects on you, and we do not use data to profile visitors.
10. Changes
If we change this notice, we publish the updated version with the new date. If the controller changes (for example on forming a company), we will say so here.