01 Who is responsible for your data
The controller of your personal data is SimplySolid3D, a sole proprietorship (eenmanszaak) registered in the Netherlands, trading as OrbitStudio.
- Chamber of Commerce (KvK): 42111792
- VAT number: NL005501927B66
- Registered address: De Meulencamp 15, Meijel, Netherlands
- Contact: [email protected]
We are not required to appoint a Data Protection Officer, so you can reach us directly at the address above for any privacy question.
02 What we collect and why
| Data | Why | Legal basis |
|---|---|---|
| Email address, password (stored only as a salted hash — we never see your password), validation code, account tier and credit balance | To create and secure your account, let you sign in, and give you the access you bought | Performance of our contract with you |
| Your generations: selected coordinates, model settings, any text you engrave, and the resulting model files | To produce your models, let you download them, and support you if something fails | Performance of our contract with you |
A generation made without an account: the same coordinates, settings,
engraved text and model files as above, together with the random identifier your
browser makes up for itself (orbit_guest) and your IP address
|
To let you see that the generator works before you decide whether to back the campaign or create an account, to hand back the model you just asked for, and to keep automated traffic from running up the cost of producing them | Our legitimate interest in letting you try the product before you pay for it, and in not paying for abuse. Weighed against you: the identifier is a random number that says nothing about who you are, we never join it to anything else, and it disappears together with the model after 48 hours. Create an account inside that window and the model moves onto it, after which the row above applies instead |
| Whether you asked to hear from us, when you asked, and which wording you agreed to | To email you occasionally about OrbitStudio — new places to print, new features. Only if you ticked the optional box; it is never part of accepting the terms, and an account works exactly the same without it | Your consent, which you can withdraw at any time from your account bar or the link in any such email. Withdrawing does not affect emails we must send about your account, such as a password reset or notice that these terms are changing |
| Technical data: IP address, browser type, timestamps, request and error logs | To keep the service secure and available — rate limiting, abuse and fraud prevention, and debugging | Our legitimate interest in a secure, working service |
| Messages you send us — by email, or through the report form in the app: what you write, the address you give us if you choose to give one, and the technical details of what you were doing at the time (the model you were working on, the settings you had chosen, the error the service returned, and your browser type) | To answer your question, fix the fault you report, and weigh up your suggestion | Our legitimate interest in helping our users and in a service that works |
We do not sell your data, we do not share it for advertising, and we do not use it to build profiles or make automated decisions with legal effects for you.
05 Transfers outside the EEA
Your data is stored in the EU: our application runs on Google Cloud in Belgium, and our database sits in Ireland. Storage location and access are two different things, though — several providers can reach that data from outside the European Economic Area:
- Supabase, which hosts our database, is Supabase Pte. Ltd., a Singapore company. Your data itself stays in their Irish region, but the company is outside the EEA and its US affiliate provides support, so staff in Singapore and the United States can access it. This transfer is covered by the European Commission's Standard Contractual Clauses.
- Resend is based in the United States. Even where email is dispatched from an EU region, Resend's account data and delivery logs are stored in the US. Resend is certified under the EU-US Data Privacy Framework, which provides the legal basis for this transfer.
- Cloudflare and Google operate global networks and may process data outside the EEA. These transfers are covered by the European Commission's Standard Contractual Clauses and, where applicable, the EU-US Data Privacy Framework.
Only the data needed for each service is shared: Resend receives your email address and the contents of the account email being sent. When you send us a report from inside the app, Resend also carries that report to us, so it passes through Resend in the same way.
06 How long we keep it
- Account data — for as long as your account exists. If you delete your account, we remove it within 30 days, except where we must keep records by law.
-
Generated models and job data — we keep the files for a number of your most recent
models so you can find and re-download them in the app: 6 on Starter Pass,
12 on Premium Pass, 25 on Lifetime Creator and 50
on Lifetime Commercial. You can delete any of them yourself at any time.
A model you have downloaded is kept for as long as your account exists. A model you have not downloaded is kept for 12 months, and that period starts again each time you open it, download it, or press Keep in the app; when it runs out we remove the files. Each model shows its own date in the app.
Beyond those files, a small record of each generation (the region you picked and the settings you used) is kept while your account exists, because it is what enforces the fair-use limits in our terms. Download links are temporary and expire 24 hours after they are issued. The library is a convenience rather than a backup, so keep your own copies of anything you want to be sure of. - Models generated without an account — 48 hours, the files and the record of the generation together. Creating an account inside that window moves the model onto it, after which it is kept like any other.
- Security and error logs — normally up to 12 months, then deleted or aggregated.
- Support emails and reports sent from the app — up to 24 months after your question is resolved. A report you send from the app is stored with it and removed on the same clock; the copy emailed to us lives in our mailbox for the same period.
-
Backups — we back the database up so an outage or a mistake cannot wipe your
account. Our own hourly snapshots are kept in our object storage for 30 days, and
our database provider keeps its own daily backups for 7 days.
This matters for deletion: when you delete your account it disappears from the live service immediately, but a copy remains inside those backups until they expire. We do not open backups to remove individual records — doing so would risk the very data the backups exist to protect — so a deleted account is fully gone once the last backup containing it has aged out. Backups are only ever used to restore the service after a failure, never to bring back an account you asked us to remove.
07 How we protect it
- All traffic runs over HTTPS.
- Passwords are stored only as salted hashes (PBKDF2) — they cannot be read back, not even by us.
- Access to production systems is restricted and authenticated.
- Rate limiting and abuse protection guard against automated attacks.
- Download links are time-limited and tied to your account.
No system is perfectly secure. If a data breach ever occurs that is likely to present a risk to you, we will notify the Dutch Data Protection Authority and, where required, you — without undue delay.
08 Your rights
Under the GDPR you have the right to:
- access the personal data we hold about you;
- rectify data that is incorrect or incomplete;
- erase your data ("right to be forgotten") — see the note on backups in section 6 for what this means in practice;
- restrict or object to our processing, including processing based on legitimate interest;
- data portability — receive your data in a structured, machine-readable format;
- withdraw consent at any time, where processing is based on consent.
Email us at [email protected] and we will respond within one month. We may need to verify your identity first, so that nobody else can request your data.
You also have the right to lodge a complaint with the Dutch Data Protection Authority (Autoriteit Persoonsgegevens, autoriteitpersoonsgegevens.nl) or with the supervisory authority in your own country. We would appreciate the chance to fix it first.
09 Children
OrbitStudio is not directed at children under 16. If you believe a child has given us personal data without the consent of a parent or guardian, contact us and we will delete it.
10 Changes to this policy
If we change how we handle personal data, we will update this page and the date at the top. If a change is significant, we will tell you by email or in the app.
11 Contact
Any privacy question, request or concern: [email protected]. See also our Terms of Service.