Privacy Policy
Effective Date: August 1, 2026
1. Introduction
Diits ("we," "our," or "us") provides customizable 3D-printed physical NFC cards paired with hosted digital business card profiles. This Privacy Policy explains how we collect, store, and protect your data when you purchase physical cards, configure your digital profile, or interact with a Diits profile link, tap, or contact exchange feature.
Our Core Security & Privacy Commitments:
- We Never Sell Your Data: We do not monetize, rent, or sell your personal details, contact information, or profile interactions to third parties.
- High-Grade Encryption: Profile data, credentials, and system records are encrypted using TLS 1.3 in transit and AES-256 at rest.
- Zero Tracking Cookies: We do not use third-party tracking pixels or behavioral cookies. Platform navigation and profile viewing rely solely on essential session tokens.
2. Information We Collect
- Digital Profile Data (Information You Direct Us to Share): Profile information you explicitly upload to display on your digital business card (e.g., full name, job title, company, bio, profile photo, phone numbers, email addresses, social media links, and website URLs).
- Account & Order Details: Contact name, email address, shipping address for physical NFC card delivery, billing details, and transaction histories.
- NFC & Digital Profile Interaction Data: When someone taps your physical Diits card or opens your digital profile URL, our servers log essential connectivity metrics (IP address, operating system, device type, and time of tap/view) strictly for system stability, security, and basic view counters.
- Contact Exchange & Scanned Data: Information saved into your connection library, including contacts exchanged via profile views, CSV/vCard exports, and details extracted via our AI Business Card Scanner.
- No Third-Party Cookies: We do not deploy third-party advertising cookies, cross-site trackers, or marketing pixels.
3. How We Use Your Data
- Programming physical NFC cards and delivering them to your shipping address.
- Hosting, rendering, and managing your digital business card profile for sharing.
- Managing secure account authentication, login credentials, and tier-based feature access (Free, Lite, Pro, Team).
- Processing AI-driven business card scanning and contact library management.
- Delivering order updates, technical notices, and customer support.
- Safeguarding infrastructure against misuse, automated scraping, or unauthorized access attempts.
4. Third-Party Service Providers
We share minimal required data strictly with trusted service providers who help run our physical and digital operations:
- Payment Gateways: To handle billing and subscriptions securely (e.g., Stripe) without storing full credit card numbers on our servers.
- Database & Backend Infrastructure: To manage user authentication, secure file storage, and database records (e.g., Supabase, protected by Row Level Security).
- AI Processing: To extract text and contact details from physical business cards when utilizing our optional AI scanner feature (e.g., OpenAI).
- Shipping & Logistics: To dispatch physical 3D-printed NFC cards to your address.
5. Data Control & Rights
You maintain ownership and control over what appears on your digital card:
- Instant Profile Edits: You can add, edit, or remove contact links and details on your profile at any time through your account dashboard.
- Account & Data Deletion: Under UK GDPR, you have the right to request full erasure of your account, hosted digital profile, and captured contact libraries ("right to be forgotten"), subject to standard legal tax/transaction retention rules.
6. Contact Us
For any privacy-related queries, data requests, or to exercise your rights under UK GDPR, please reach out to:
Email: support@diits.io
Appendix: Cloudflare Turnstile Privacy Addendum
1. Purpose & Overview
To protect Diits against automated attacks, spam, credential stuffing, and malicious bot activity, we integrate Cloudflare Turnstile (and Cloudflare’s Challenge Platform), operated by Cloudflare, Inc. Turnstile is a privacy-preserving security tool designed to distinguish human visitors from automated bots without requiring intrusive user challenges or cross-site tracking.
2. Information & Technical Signals Processed
When you access our platform, Cloudflare evaluates minimal client-side technical signals ("Signals") strictly necessary to evaluate bot risk. These Signals include:
- Client IP address
- TLS Fingerprint
- Browser User-Agent header
- Sitekey and associated origin metadata
Neither Diits nor Cloudflare utilizes these Signals to directly identify, profile, or track individual users across non-affiliated web properties.
3. Data Processing Roles & Legal Basis (UK / EU GDPR)
Under the UK GDPR and EU GDPR, data processing responsibilities are allocated as follows:
- Site Security (Processor Role): We process Signals based on our Legitimate Interest (GDPR Article 6(1)(f)) in maintaining the security, integrity, and operational safety of our web properties. For this purpose, Diits acts as the Data Controller, and Cloudflare acts as our Data Processor, handling Signals solely on our behalf and according to our instructions.
- Security Model Improvement (Controller Role): To the extent that Cloudflare processes anonymized or aggregated Signals to refine its threat-detection algorithms and adapt to evolving web threats, Cloudflare acts as an independent Data Controller. Cloudflare relies on its legitimate interests in securing web infrastructure globally.
4. Cookies & Storage
Turnstile relies on strictly necessary session verification tokens to establish whether a visitor is human. It does not deploy third-party, cross-site tracking cookies, nor does it monetize user data.
5. Data Subject Rights & Inquiries
If you have questions or wish to exercise any data protection rights regarding how security signals are processed on Diits, please contact us directly at support@diits.io. For inquiries specifically concerning Cloudflare's independent data processing operations, you may contact Cloudflare’s Data Protection Officer at dpo@cloudflare.com.