Privacy Policy
As at 24 August 2026
Controller
The controller for the processing described here is:
Provider: Bartis.Dev, sole trader Darius Achilles
Address: Goethestr. 30, 39397 Schwanebeck, Germany
Email: darius@bartis.dev
We have not appointed a data protection officer; we are below the thresholds that would require one. Use the address above for any data protection matter. The provider details are also in the imprint.
No tracking, no cookies
This website sets no cookies, embeds no analytics, no advertising and no social media plugins, and there is no consent banner because there is nothing to consent to. If you sign in to the store, your session token is stored in your browser's local storage so that you stay signed in. That is strictly necessary for the function you asked for; it never leaves your browser except as the authorisation header on requests to our own API, and signing out deletes it.
Visiting the website
Our reverse proxy writes an access log entry for each request, containing your IP address, the time, the requested path, the HTTP status, the referrer and the user agent. We need this to operate the service and to recognise attacks and faults, which is our legitimate interest under Article 6(1)(f) GDPR.
These entries sit in a size-capped rotating buffer and are overwritten automatically as new ones arrive. They are not archived, not aggregated, not combined with a store account and not used to build a profile.
Store account and sign-in
Creating a store account requires an email address. We sign you in with a one-time code sent to that address instead of a password, so we store the code and its expiry until it is used or expires. The legal basis is Article 6(1)(b) GDPR, performance of a contract and steps taken at your request before entering into one.
If you link your Dylaris panel account to your store account, we additionally store your panel user id, the email address and the username held there, so that a purchase can be applied to the right account and shown to you without a live lookup.
Purchases and payment
Payments are handled by Stripe. Your card or bank details are entered on Stripe's side and are never sent to us and never stored by us. What we keep is the Stripe transaction reference, the amount, the currency, a description, the status, and the subscription and quantities you bought, so that we can enforce what you paid for, answer questions about a charge, and issue and retain invoices. The legal basis is Article 6(1)(b) GDPR for performing the contract and Article 6(1)(c) GDPR for the statutory retention of accounting records.
Enquiries
If you send us an enquiry through the site, we store the email address you gave, the subject and the message so that we can answer it. The legal basis is Article 6(1)(b) GDPR where the enquiry concerns a contract, and otherwise Article 6(1)(f) GDPR, our legitimate interest in responding to people who contact us.
Processors
We use the following service providers, each under a data processing agreement:
- Hetzner Online GmbH, Gunzenhausen, Germany, hosting. The website, the store and its database run on servers we rent from them in the European Union.
- Stripe, payment processing. Stripe acts as an independent controller for the payment itself and processes data in the United States as well; the transfer is covered by the EU standard contractual clauses and Stripe's certification under the EU-US Data Privacy Framework.
- Resend, delivery of transactional email such as your sign-in code. Processing takes place in the United States on the basis of the EU standard contractual clauses.
We do not use a content delivery network, so no third party sits between your browser and our servers. Our DNS is hosted at Cloudflare, which resolves names but does not see your traffic.
How long we keep things
- Access logs: until they are overwritten by the automatic rotation described above.
- Sign-in codes: until they are used or expire, a matter of minutes.
- Store account and its link to a panel account: until you delete the account or ask us to.
- Invoices and accounting records: ten years, as required by Section 147 of the German Fiscal Code (AO). Deleting your account does not remove them, because we are not allowed to.
- Enquiries: until the matter is settled, and then for as long as any statutory retention period applies.
Your rights
Under the GDPR you have the right to:
- access the personal data we hold about you (Article 15),
- have inaccurate data corrected (Article 16),
- have data erased (Article 17), within the limits of the retention obligations above,
- have processing restricted (Article 18),
- receive your data in a portable form (Article 20),
- object to processing based on our legitimate interest (Article 21).
Write to darius@bartis.dev and we will deal with it. You can also complain to a data protection supervisory authority. The one competent for us is the Landesbeauftragter für den Datenschutz Sachsen-Anhalt, but you may approach the authority where you live or work instead.
Automated decision-making
We do not use automated decision-making or profiling that produces legal effects for you. Account limits are enforced automatically against what you purchased, which follows directly from the contract and involves no assessment of you as a person.