Privacy policy
Last updated: 13 August 2026.
Data controller: [Nombre y apellidos del titular] ([NIF/NIE del titular]), [Domicilio o dirección de notificaciones], contact [correo de contacto].
1. Data we process
- Account: name, surname, email and password (stored as an argon2id hash, never in plain text), plus your chosen language preference.
- Security: IP address and browser agent for sessions and login attempts, to limit abuse and protect accounts.
- Workshop work: cut lists, plans, inventory and files uploaded by the workshop, visible only to that workshop's members.
- Support and communications: the content of messages you send and the data needed for verification and recovery emails.
2. Purposes and legal basis
There is no behavioural advertising, third-party analytics or profiling, and we do not sell data. We do not collect payment data: the service is currently free.
- Provide the contracted service (contract performance).
- Account and system security (legitimate interest).
- Operational emails: verification, reset and account notices (contract performance).
- Meet legal obligations and rights requests (legal obligation).
3. Processors
The bucket is not used for advertising or public file sharing: it is private and encryption is enabled. Any region, provider or configuration change must be reflected in this policy before taking effect.
- netcup GmbH (Germany): the server running the application and self-hosted PostgreSQL database.
- Backblaze B2: encrypted storage for uploaded files and generated documents in a private bucket, EU Central region (endpoint s3.eu-central-003.backblazeb2.com).
- Brevo (Sendinblue SAS, France): transactional email delivery.
4. Retention
- Account data: while the account exists.
- Expired sessions and attempt counters: purged daily.
- Workshop data: while the workshop exists or until its administrator deletes it.
- Support messages: as long as needed to resolve the request and meet legal responsibilities.
5. Your rights
You may request access, correction, deletion, objection, restriction or portability by writing to [correo de contacto]. You may also complain to the Spanish Data Protection Agency (aepd.es).
6. Cookies
We only use technical and preference cookies: the session cookie and language cookie. There are no advertising or tracking cookies. Details, duration and purpose are explained in the cookie policy.
7. International transfers
We aim to use providers and regions in the European Economic Area. If a provider or region is outside the EEA, the transfer will use a valid legal basis and GDPR safeguards, and this policy will be updated.
8. Automated decisions
We do not make automated decisions with legal or similarly significant effects on people. Cutting-plan calculations affect workshop work, not the assessment of a person.