1. Scope and roles
This policy applies to PowderQuote accounts, website use, support, product analytics and billing-related administration. For account, security, service-improvement and business administration data, the Provider acts as controller. Where a business customer uploads personal data contained in drawings, quotations or customer records and determines the purposes of that processing, the customer is normally the controller and the Provider acts as processor under the DPA.
2. Data we process
We may process account/contact data; business profile and quotation data; uploaded DXF, PDF, STEP or other supported drawing data and derived geometry; subscription and billing identifiers/status from Paddle; security and technical data; and the limited product analytics described in Cookies & Analytics. Paddle handles payment-card processing; PowderQuote does not store raw card details.
3. Purposes and legal bases
We process data to provide accounts, the calculator, quotations, PDFs and subscriptions under Article 6(1)(b) GDPR; for security, abuse prevention, reliability and narrowly scoped cookieless analytics under Article 6(1)(f); for invoices, tax/accounting and required records under Article 6(1)(c); and on consent under Article 6(1)(a) where consent is specifically required.
4. Analytics and cookies
The reviewed production code uses PostHog EU Cloud with persistence disabled and does not enable autocapture, automatic pageviews, session recording, heatmaps, surveys, performance capture or automatic exception capture. Limited explicit product events are sent and common direct identifiers such as email, customer name and filenames are filtered. Signed-in users may be represented by an internal user identifier. See Cookies & Analytics for the current configuration.
5. Recipients and processors
Personal data is disclosed only as needed to operate the service, comply with law or protect legitimate rights. Current named providers include PostHog for limited product analytics and Paddle for checkout, subscription and payment administration. Production hosting/infrastructure providers also process data and must be kept current on the Subprocessors page. Professional advisers or authorities may receive data where necessary or legally required.
6. International transfers
We prefer EEA processing where practical. Where personal data is processed outside the EEA, a valid GDPR Chapter V mechanism must be used, such as an adequacy decision or European Commission Standard Contractual Clauses, with supplementary safeguards where required.
7. Retention
Account and active-service data is kept while the account is active and as reasonably needed to provide the service. Quotation records remain until deleted or removed under the applicable retention process. Uploaded drawing workspace files may be temporary. Billing, tax and accounting records are retained as required by Czech/EU law. Security logs, analytics and backups are retained only for proportionate operational periods and normal backup cycles. Exact production retention periods should be verified before public launch.
8. Your GDPR rights
Subject to applicable conditions and exemptions, you may request access, rectification, erasure, restriction and data portability, object to processing based on legitimate interests, and withdraw consent where processing relies on consent. Where Article 22 applies, you also have rights regarding solely automated decisions with legal or similarly significant effects. PowderQuote pricing calculations are business tools and are not intended as such automated legal decisions.
9. Complaints
You may contact us first. You also have the right to lodge a complaint with a competent supervisory authority. In the Czech Republic, this is the Office for Personal Data Protection (Úřad pro ochranu osobních údajů, ÚOOÚ).
10. Customer-controlled data and requests
If your personal data was entered into PowderQuote by one of our business customers, that customer may be the controller responsible for your request. We will assist the customer as required by the DPA and GDPR.
11. Security
We use technical and organisational measures appropriate to the nature of the service and risk. No internet service can guarantee absolute security. Customers remain responsible for appropriate credentials, access permissions and the data they upload.
12. Changes and contact
We may update this policy when the service, providers or law changes and will publish the effective date. Privacy requests may be sent to support@zatforge.com.