1. Who we are (data controller)
Design2Pattern is an online pattern-design service available through design2pattern.com and its application. The controller is:
ELIORA ApSVadumvej 16
7860 Spøttrup, Denmark
Company registration (CVR) no.: 43577646
Email: start@design2pattern.com
We have not appointed a statutory Data Protection Officer. Please direct privacy matters to the email address above.
2. Scope of this policy
This policy explains how we collect, use, share, retain, and protect personal data when you visit the website, create an account, contact us, subscribe, and use the Design2Pattern application. Our processing is governed by the EU General Data Protection Regulation and applicable Danish data-protection law.
3. Data we collect
- Account data: email address, optional name, language, authentication credentials stored as a secure hash, and account status.
- Project data: charts, palettes, settings, written instructions, files, and exported documents you create or save.
- Billing data: plan, subscription status, transaction references, and invoice-related information. We do not store complete payment-card numbers.
- Contact data: your email address, message, and information you voluntarily provide when contacting us.
- Technical and security data: IP address, session identifiers, timestamps, device and browser details, error logs, and security events.
- Analytics data: only after consent, page views, referrers, device/browser information, campaign information, and product events sent to our self-hosted Matomo instance.
4. How we use data and our legal bases
- Contract (Art. 6(1)(b) GDPR): create accounts, provide the editor, store projects, generate exports, manage subscriptions, and answer service requests.
- Legitimate interests (Art. 6(1)(f)): secure, maintain, troubleshoot, and improve the service, balanced against your rights.
- Legal obligation (Art. 6(1)(c)): accounting, tax, and lawful authority requests.
- Consent (Art. 6(1)(a)): optional analytics and any other processing for which we specifically ask permission. Consent may be withdrawn at any time.
We do not sell personal data or use it for automated decisions producing legal or similarly significant effects.
5. Payments
Subscription payments are processed by Stripe and its group companies. Payment details are entered directly into Stripe’s systems. We receive limited billing and subscription information but not complete card numbers. Stripe processes payment information under its own privacy terms and may act as processor or independent controller depending on the activity.
6. Service providers and recipients
We use providers only where necessary to operate the service, including ALL-INKL.COM – Neue Medien Münnich for EU hosting and infrastructure, Stripe for payment processing, email infrastructure for transactional messages, and a self-hosted Matomo installation at zone-seven.de for consent-based analytics. We may also disclose data where required by law or necessary to protect legal rights.
7. International transfers
Our hosting and analytics infrastructure is located in the EU. Some providers, including Stripe, may process data outside the EEA. Where required, transfers rely on recognised safeguards such as adequacy decisions or the European Commission’s Standard Contractual Clauses.
8. Cookies, sessions and analytics
Essential session, security, language, and consent-preference cookies keep the service working and remember your choices. They are not used for advertising. Matomo analytics is disabled until you actively consent through the privacy settings.
You can change or withdraw your choice at any time using . Withdrawing consent prevents future analytics tracking and removes Matomo tracking cookies where technically available.
9. Retention
Account and project data is kept while your account is active and as needed to provide the service. Contact messages are normally deleted within 12 months after resolution. Raw Matomo visitor data is configured for deletion after no more than 12 months; aggregated reports may be retained longer. Billing and accounting records may be retained for the statutory period, generally up to five years under Danish law. Backups expire through the normal backup cycle.
10. Security
We use proportionate technical and organisational safeguards, including encrypted transport, password hashing, access controls, secure session cookies, backups, and logging. No online service can guarantee absolute security.
11. Your rights
Subject to applicable conditions, you may request access, rectification, erasure, restriction, portability, object to processing based on legitimate interests, and withdraw consent. Contact start@design2pattern.com. We may verify your identity before acting.
You may complain to a supervisory authority. In Denmark this is Datatilsynet, Carl Jacobsens Vej 35, 2500 Valby, Denmark — datatilsynet.dk.
12. Children
The service is intended for adults and is not directed at children. We do not knowingly collect personal data from children under 16 or the applicable age of digital consent.
13. Changes
We may update this policy when the service or legal requirements change. Material changes will be identified by a revised date and, where appropriate, an additional notice.
14. Contact
Questions and privacy requests: start@design2pattern.com.