DRINSE.de

Privacy notice

Effective: July 20, 2026

Controller

Emircan Kaya
c/o IP-Management #4896
Ludwig-Erhard-Str. 18
20459 Hamburg
Germany

Email: drynse@drise.ai

Data, purpose, and necessity

The form processes company, store URL, country, Shopify Plus status, script type and count, migration state, available source material, your description of critical logic, contact name, business email, and language. Do not submit passwords, tokens, customer data, or files.

The required fields are needed to assess fit and jurisdiction and answer your request. Without them, no eligibility check can be provided. The required box only acknowledges that you saw this notice; it is not consent and is not used as a legal basis.

For abuse prevention, the application stores the IP address only as a daily rotating HMAC value. The raw IP address is not stored in the lead database. Hestia web-server logs technically contain the raw IP address, user agent, requested path, and time.

Legal bases and legitimate interests

Assessing your self-initiated B2B request and taking requested pre-contractual steps rely on GDPR Article 6(1)(b), where applicable. Secure and auditable business communication, abuse prevention, and protection of the web service rely on Article 6(1)(f). Our interests are processing genuine requests reliably and preventing attacks and repeated submissions; short retention, pseudonymisation, and the absence of tracking limit the impact.

There is no solely automated decision-making and no profiling.

Retention and recipients

Requests that do not proceed are deleted by the next hourly cleanup after 90 days, at most roughly one hour later. Rate-limit records are deleted by the next hourly run after 48 hours. Hestia rotates access and error logs weekly and retains four compressed rotations, resulting in practical retention of roughly four to five weeks.

A rolling local backup may contain a previous copy until the next successful backup. After any restore, the deletion routine must run again immediately.

Recipient categories are limited to necessary hosting/server administration and the internal Drinse mailbox. The internal notice contains only lead ID, market-access status, and language; form data remains in the protected database. No third-country recipient is deliberately engaged for the intake. Technical internet or email routing may be international; additional recipients are reviewed before use. There is no newsletter enrollment, sale of data, or reuse for direct marketing.

Strictly necessary session

The session cookie is used only for CSRF protection and form security. It is strictly necessary for the form service explicitly requested by the visitor (Section 25(2)(2) TDDDG). No analytics, advertising, or third-party cookies are set.

Your rights and response time

You may request access, correction, deletion, restriction, and portability where the statutory conditions apply. Email drynse@drise.ai. We generally respond within one month under GDPR Article 12(3); only the complex cases covered there permit an extension after timely notice.

Right to object under Article 21 GDPR

You may object on grounds relating to your particular situation to processing based on Article 6(1)(f). If data were ever processed for direct marketing, you could object at any time without giving reasons; no such processing currently occurs.

Complaint

You may complain to the Hamburg Commissioner for Data Protection and Freedom of Information, Ludwig-Erhard-Str. 22, 20459 Hamburg, Germany.

Back to the offer