Privacy policy
Information pursuant to Art. 13 and 14 GDPR · Last updated: September 2026
This is a courtesy translation. The German version is the only legally binding version.
Controller
Missus GmbH
Ulrichsweg 53/2
8045 Graz, Austria
Email: contact (at) difora (dot) eu
We have not appointed a data protection officer, as the statutory conditions for doing so are not met. For any privacy question, please contact us at the address above.
(I) This website
This website is deliberately built to process as little data as possible: it uses no cookies, no analytics or tracking services, no social media plugins, and loads no content (such as fonts, scripts or images) from third parties. A cookie banner is therefore not required.
Server log files
When you visit this website, the web server automatically processes technical access data (in particular IP address, date and time of access, page requested, browser type) to the extent technically necessary to deliver the website and ensure its stability and security. The legal basis is our legitimate interest in the secure operation of the website (Art. 6(1)(f) GDPR). This data is not combined with other sources and is deleted after a short period.
Design partner enquiry
If you submit the form on this website, we process the details you provide (email address and, optionally, name, company and your message) together with the language version you selected, in order to answer your enquiry. The legal basis is Art. 6(1)(b) GDPR (pre-contractual measures) or our legitimate interest in responding to your enquiry (Art. 6(1)(f) GDPR). We do not use this data for newsletters or any other advertising. The data is deleted once it is no longer required and no statutory retention obligations apply.
(II) User account and service
To use Difora you create an account. We process your email address, your name, your organisation name and a password, which is stored exclusively as a cryptographic hash (bcrypt). During operation we additionally process project names, branch and commit information, access tokens for your CI environment (stored as a hash only) and usage counters for billing. The legal basis is performance of the contract (Art. 6(1)(b) GDPR) and, for billing and retention periods, compliance with legal obligations (Art. 6(1)(c) GDPR).
After you sign in, the application stores a session token in your browser's local storage. This is technically necessary to operate the service and serves no analytics or advertising purpose.
(III) Processing on your behalf: screenshots and build data
We process the screenshots and build metadata that you or your CI environment transmit to Difora exclusively on your behalf. In this respect you are the controller and we are the processor within the meaning of Art. 28 GDPR. We process this content solely to provide the service (storage, image comparison, display for approval) and not for our own purposes.
Screenshots may contain personal data if your user interface displays such data (for example names or email addresses in test data). You decide what content you transmit; we expressly recommend using synthetic test data for visual tests. We conclude a data processing agreement (DPA) with you before processing begins.
You can delete your content at any time through the application. After the contractual relationship ends, we delete the content processed on your behalf within 30 days unless you agree otherwise with us.
(IV) Processors and storage location
Operation, database, object storage and backups take place exclusively with providers established and operating data centres in the European Union. Your content is not transferred to third countries outside the EU/EEA. We provide the current list of processors on request and as an annex to the data processing agreement, and inform you in advance of any intended changes.
Support requests concerning customer content are handled exclusively within the EU. Your content is not processed by artificial intelligence systems.
(V) Disclosure to third parties
We disclose your data to third parties only where necessary to perform the contract (for example to the processors mentioned above), where you have consented, or where we are legally obliged to do so. We do not sell data.
If you enable the GitHub integration, we transmit the result of a check run (passed / changes to review / rejected) and a link to the review view to GitHub, in order to display the status on your pull request. This integration is optional and enabled by you per project; screenshots are not transmitted.
(VI) Retention periods
- Server log files: short-term, then deleted
- Form enquiries: until your enquiry has been dealt with, at the latest until you withdraw
- Account and project data: for the duration of the contract
- Content processed on your behalf (screenshots): until you delete it, at the latest 30 days after the contract ends
- Invoicing and accounting data: seven years pursuant to § 132 of the Austrian Federal Fiscal Code (BAO)
(VII) Security
All transmission is encrypted (TLS). Passwords are stored as a bcrypt hash and CI tokens as a SHA-256 hash; we do not know the plaintext values. Object storage is encrypted at rest. Access to production systems is restricted to those who require it.
(VIII) Your rights
You generally have the right of access (Art. 15 GDPR), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20) and objection (Art. 21). An informal email to the address above is sufficient to exercise your rights.
If you believe that the processing of your data infringes data protection law, you may lodge a complaint with the Austrian Data Protection Authority: www.dsb.gv.at.