Privacy policy
What data we handle, what for, for how long, who else sees it and what you can demand from us at any time.
Last updated · 1 September 2026
Who is responsible for your data
The data controller is Roberto Riveros, tax number 60797652G, registered at Av. José Antonio Corrales 6, 28055 Madrid. For anything to do with your personal data, write to cutstudioapp@gmail.com.
What we process and why
We only ask for what the service needs to work. There is no advertising profiling, we neither buy nor sell data, and we do not pass your information to third parties for commercial purposes.
| Data | What for | Legal basis | How long |
|---|---|---|---|
| Email address, name and workshop name | Creating your account, signing you in and setting up your workshop | Performance of the contract | While the account is active |
| Password | Authenticating you. Stored hashed with a key-derivation function; nobody can read it, ourselves included | Performance of the contract | While the account is active |
| Second factor and recovery codes | Protecting the account when you turn on two-step verification | Performance of the contract | Until you turn it off |
| Preferred language and units | Showing you the application in your language and your units | Performance of the contract | While the account is active |
| Projects, parts, materials, inventory and quotes | Running the service: storing your work so you can get it back | Performance of the contract | Until you delete them or close the account |
| Billing and payment details | Charging the subscription and issuing the invoice | Performance of the contract and legal obligation | Six years, under commercial and tax law |
| Email of the people you invite to the workshop | Sending them the invitation and giving them access with their role | Legitimate interest in running the workshop | Until the invitation is accepted or expires |
| Technical fingerprint of the visit | Counting distinct visitors without identifying you, to see whether the service is growing | Legitimate interest in measuring our own audience | In aggregate only, with no way back to the source |
Your customers’ data is yours, not ours
If you use quotes, you will store your workshop’s customer data in Cut Studio App: name, tax number, email, phone, address and notes. For that data you are the controller and we act as a processor under article 28 of the General Data Protection Regulation.
That means we only process it on your instructions and to run the service for you; we never use it for purposes of our own; everyone who handles it on our side is bound by confidentiality; we apply the security measures described below; and when you close the account we delete it.
Collecting that data on a valid legal basis and informing your customers is your responsibility. The terms of service record this arrangement in writing.
Who else sees your data
To run the service we rely on suppliers acting as processors, under a signed contract and without using your data for anything of their own.
| Supplier | What for | Where it processes the data |
|---|---|---|
| MongoDB Atlas | The service database | Frankfurt, Germany (European Union) |
| Hetzner | The servers the application runs on | Germany (European Union) |
| Resend | Sending verification, invitation and notice emails | European Union and United States |
| Stripe | Charging subscriptions and billing | European Union and United States |
Data leaving the European Union
The database and the servers are in Germany, inside the European Union. Stripe and Resend may process data in the United States; where they do, the transfer relies on the standard contractual clauses approved by the European Commission and on the EU-US Data Privacy Framework where the supplier is certified under it.
Your card details never pass through our servers at any point: Stripe collects them directly in its own payment environment.
How long we keep things
While the account is active, everything of yours is kept so you can carry on working. If you close the account we delete your data and your customers’ data, except what the law requires us to keep: invoices and payment records are held for six years under commercial and tax law.
Technical security and audit logs are kept for twelve months.
How we count visits
We use no Google Analytics, no advertising pixels and no third-party tool that follows you around other websites. The measurement is our own and works like this: on arrival an irreversible cryptographic digest (SHA-256) of your IP address and browser is computed, truncated to 32 characters, and only that result is stored.
The IP address is never stored. The digest exists so the same visitor is not counted twice in a day, and it cannot identify you or be turned back into the original IP.
What you can demand from us
You have the right to access your data, correct it, erase it, restrict or object to its processing, and receive it in a portable format. To exercise them, write to cutstudioapp@gmail.com saying which right you want to exercise; we will answer within one month at the latest.
Much of this needs no email at all: from inside the application you can correct your details, export your projects and close the account.
If you think we have not handled your request properly, you can complain to the Spanish Data Protection Agency (www.aepd.es), C/ Jorge Juan 6, 28001 Madrid.
Automated decisions
We take no automated decisions producing legal effects concerning you, and we build no behavioural profiles.
Security
Traffic is encrypted end to end with TLS. Passwords are stored hashed and cannot be recovered. Sessions use server-only cookies with a strict same-site policy. Access to a workshop’s data is limited to the people in that workshop and to the role each of them holds.
Were a security breach ever to occur with a risk to your rights, we would tell you and notify the supervisory authority within the deadlines set by the Regulation.
Changes to this policy
If we change anything material we will update the date in the header and, when the change genuinely affects you, tell you by email before it takes effect.