Legal
Privacy Notice
What personal data Kraftius handles, why we need it, which companies help us run the service, where it physically sits, how long it stays, and what you can ask us to do with it. This is information we are required to give you — it is not a request for your consent.
Last updated:
Two kinds of data, and who is responsible for each
Kraftius holds two kinds of personal data, and our responsibilities differ for each. Getting this distinction right matters more than anything else in this notice.
The first kind is about the people who use Kraftius — your name, email address, which workshop you belong to, what you did in the app. We decide what to collect and why, so we are the controller for it. Ask us directly about that data.
The second kind is about your customers — everything a workshop records about the people it prints for. A workshop decides which customers to record, what to note about them, and why. We only process that data to run the service. So for it, the workshop is the controller and Kraftius is its processor. If you are a customer of a workshop that uses Kraftius, the workshop is who your rights are exercised against; we will help them answer you, but we cannot decide on their behalf.
[FOUNDER: whether a data-processing agreement is offered to each workshop, and its terms.]
What we hold
About the people who use Kraftius: your name and email address, which workshop you belong to and your role in it, which projects you are assigned, and an attribution record on the things you create or change — who added a project, who moved stock, who recorded a payment. Those attribution records deliberately survive someone leaving, so the workshop’s history stays readable.
About your customers, entered by your workshop: name, email address, phone number, postal address, company, tax identifier, and any free text a workshop writes in a note, tag, project name or quote message. Uploaded photographs and model files are included, along with their original filenames.
About your business: workshop name, business contact details and logo, workshop address, and the technical details of your printers.
Automatically, from using the service: request records needed to operate and secure it, rate-limiting records that include the IP address of anyone submitting the public contact form, and — where enabled — error and performance reports when something breaks.
If you write to support: your name, email address and whatever you put in the message.
Where it comes from
Most of it comes from you and your colleagues typing it in. Your name and email address come from Clerk, which handles sign-in, and are updated in Kraftius when you change them there.
Data about your customers is entered by your workshop, not collected by us from those people directly. They will usually not have heard of Kraftius, which is why the workshop is responsible for telling them their supplier processes their details.
Why we use it, and on what basis
We use personal data to run your account and workshop, store your files, calculate quotes and stock, answer support requests, keep the service secure and available, prevent abuse, and diagnose faults.
We do not sell personal data. We do not use your workshop’s content for advertising, and we do not use it to train machine-learning models. There is no advertising or analytics technology anywhere in the product — no tracking pixels, no analytics scripts, no third-party advertising tags of any kind.
Kraftius is offered in Türkiye, the EU and EEA, and beyond, so both the Turkish data protection law (KVKK) and the GDPR apply to how we handle personal data. [FOUNDER: the specific lawful basis for each purpose under each, mapped one by one rather than listed as possibilities.]
- Providing the service you asked for and administering your account.
- Keeping accounts, tenants and infrastructure safe from abuse and unauthorised access.
- Meeting accounting, tax and other legal duties where they apply.
- Consent, used only where a purpose genuinely needs it — and asked for separately, never bundled into acceptance of this notice.
Who else sees it
Running Kraftius needs a small number of infrastructure providers. Each processes data on our instructions, for the purpose named, and nothing else.
- Clerk — sign-in, accounts and workshop membership. Your password and any second factor are held by Clerk and never reach Kraftius.
- Neon — the database, which holds everything described above.
- Vercel — application hosting, and the private store that holds uploaded images and files.
- Cloudflare — off-site backups, and bot protection on the sign-in and sign-up pages.
- Sentry — error and performance monitoring, when enabled. It is configured not to collect IP addresses, request headers, cookies or request bodies.
- When someone pastes a link into a project, we fetch that page’s title from the site it points to. Only a short list of known model-sharing and document hosts is allowed, and the request comes from our server rather than your browser.
Where your data physically is
Uploaded images and files are stored in Frankfurt, in the European Union.
The database is currently hosted in the United States (Northern Virginia). A replacement in Frankfurt has been prepared and verified, and the database will move there; until it does, personal data in the database — including the customer records your workshop enters — is processed in the United States. [FOUNDER: the transfer basis relied on for that processing, under KVKK Article 9 and Chapter V of the GDPR — both apply.]
Off-site backups are held with Cloudflare, which does not currently pin them to a specific region. [FOUNDER: whether to pin backups to the EU jurisdiction, or state the transfer basis for them too.]
Clerk and Sentry process data according to their own arrangements as our providers. [FOUNDER: confirm the contracted entity and region for each before this notice becomes effective.]
Uploaded files
Images, models and attachments are stored privately. They have no publicly guessable address: every read is authorised against your session and your workshop first, and only then is a short-lived link issued, which expires within minutes. A link that leaks after that point no longer works.
Deleting a project removes its files from storage. Because copying a project shares the underlying file rather than duplicating it, a file is only removed once nothing else refers to it.
How long we keep it
Active workshop data is kept while the workshop is in use. Deleting a customer, project or printer inside Kraftius hides it and keeps the record, so it can be restored and so that historical projects still make sense — the underlying details are retained until the workshop itself is closed and purged.
Closing a workshop marks it closed and stops access. The data is then retained for [FOUNDER: retention period] before being permanently deleted, including uploaded files, so an accidental closure can be undone.
Two things are kept deliberately beyond that. The record that you were shown and accepted these documents — who, which version, when, and in which language — is the evidence that we met our duty to inform you, so it outlives the workshop. And records we are required by law to retain, such as accounting records, are kept for their statutory period. [FOUNDER: retention periods for support messages, security and rate-limiting records, and for off-site backups.]
Off-site backups are a separate copy taken on a regular cadence. Data erased in the live service remains in existing backups until those backups age out. [FOUNDER: backup retention period — this is what makes the previous sentence true or false.]
How it is protected
Every request is authenticated and scoped to a single workshop, so one workshop’s data cannot be reached from another. Within a workshop, what each person can see and do is controlled by their role, and financial figures are hidden from people who are not meant to see them. Connections are encrypted, uploaded files are private and individually authorised, incoming webhooks are signature-verified, and operations that move stock or money run as database transactions so they cannot half-happen.
Backups are taken to a second, independent provider and tested by real restores rather than assumed to work. The most recent test reproduced every table and every record, and every project priced identically afterwards.
No system is perfectly secure, and we would rather say what we have not done than imply otherwise: Kraftius has not had an independent penetration test, and no external monitoring service currently watches it. If you believe you have found a security problem, write to info@kraftius.com.
Your rights, and how to use them
Under KVKK and the GDPR you have the right to be told what we hold, to get a copy, to have it corrected or deleted, to restrict or object to how it is used, to receive it in a portable form, and to complain to a data protection authority. Some of these are limited where we are required to keep records by law. Exercising them is free, and we will not treat you differently for it.
To exercise any of them, write to info@kraftius.com. We will ask enough to be confident of who you are before acting, and respond within [FOUNDER: response time]. You may also complain to a data protection authority: [FOUNDER: the Turkish authority and, for EU/EEA users, the relevant supervisory authority, with how to reach each.]
If you are a customer of a workshop that uses Kraftius, your request generally needs to go to that workshop, because they decide what is recorded about you and why. Contact them, or contact us and we will pass it on and help them respond.
What a workshop administrator can do today without asking us: export the workshop’s records as a single file from Settings → Data, and close the workshop. The export covers projects, customers, printers, materials, inventory, ledger entries, calendar notes and settings; it does not yet include the file contents themselves, nor team-membership, support-message or subscription records — ask us for those. Deleting your sign-in account is done through your account profile, and does not by itself remove the workshop records attributed to you; write to us if you want those addressed as well.
Changes to this notice
When this notice changes materially, the new version is shown to you the next time you sign in, and we record which version you were shown and when. Minor corrections that do not change how data is handled are made without asking again.
The version and date of the current notice are shown at the top of this page.
Who to contact
This service is provided by [FOUNDER: full legal name of the provider], [FOUNDER: company type and registration or tax number], at [FOUNDER: postal address].
For privacy questions and requests about personal data: info@kraftius.com. For anything else: the support page.
[FOUNDER: whether a data protection officer or a representative has been appointed, and their contact details if so.]