Privacy policy
In force since September 17, 2026.
What data we process, why, how long we keep it and what you can do about it.
Missing detail: the identification of the controller (legal name, tax number, address and registry details) We will publish it before the service opens to the public.
What data we process
From your account: name, corporate email address, preferred language and a cryptographic hash of your password. We never store the password in clear text.
From your sessions: IP address, the browser and operating system they declare, and the dates of first and last use. They let you see and close your open sessions and help us detect improper access.
From your work: the 3D models you upload, the drawings generated from them and the options you choose. Also the technical record of each job.
An audit log of the actions that modify data, with who performed them, when and from which address. Passwords and one-time codes are replaced by a marker before being stored.
Why, and on what basis
To provide the service you signed up for: without the account data and the files there is nothing to process. The basis is performance of the contract.
To keep the service secure: sign-in attempt limits, the audit log and abuse detection. The basis is our legitimate interest in protecting the service and the data of every client company.
To meet legal billing and retention obligations where they apply.
We do not profile people or make automated decisions about them, and we do not sell data to anyone.
Who can see your data
Inside the service, only the people in your own company. Each company is a separate space and the server checks that separation on every query, not just when drawing the screen.
Our technical staff may access data to resolve a specific incident, and that access is logged.
We use infrastructure providers to host the service, serve the site and send the application emails. They act as processors and handle the data only to provide us with that service.
How long we keep it
Generated drawings are kept for the retention period of your plan, which you can see on the pricing page, and are deleted afterwards.
Account data is kept while the account is active. When it is closed the data is deleted or anonymised, except for what must be kept by legal obligation.
The audit log is kept for security reasons for a limited period and is not used for any other purpose.
Your rights
You can request access to your data, its rectification or erasure, restriction of or objection to processing, and portability. From your own account you can already view and change your profile and close your sessions.
If you believe we have not handled your request properly, you can complain to the Spanish Data Protection Agency.
Security
Traffic is encrypted. Passwords are stored with a slow derivation function and a server-side pepper. The session travels in a cookie that the page JavaScript cannot read, and the database stores only its hash, not the identifier.
Files are stored outside the tree served by the website and are downloaded through a signed link that expires in five minutes and also requires your session and your company.
Changes to this policy
If we change anything material we will tell you through the application or by email before it takes effect. The date above tells you which version you are reading.
How to contact us
You can write to us from the Contact page about anything related to this document.
Missing detail: the email address and the address for legal notices We will publish it before the service opens to the public.