Privacy Policy
Cutting Studio — a Prozense product. Prozense ApS, Spinderigade 14, 2. th, 2500 Valby, Denmark. CVR 39161877.
Last updated: 28 August 2026. Effective from: 28 August 2026.
We are the data controller for everything described here. Under the GDPR you can write to us at cutting-studio@prozense.com about any of it.
The short version
- We collect what is needed to cut your design and post it to you. Nothing more, and nothing for advertising.
- We do not track you. No analytics, no advertising pixels, no third-party cookies. The only cookie we set is the one that keeps you signed in.
- We never see your card number. Stripe handles payment.
- Your design is yours. We use it to cut your order and for nothing else.
What we collect, and why
When you use the studio without an account
Your design stays in your own browser, in its local storage. It is not uploaded, and we cannot see it. Clearing your browser data deletes it, and we have no copy to restore.
We do not set analytics or advertising cookies, so browsing the site anonymously leaves nothing with us.
When you create an account
| What | Why | Legal basis |
|---|---|---|
| Name, email address | To identify you and send you a sign-in code | Performance of a contract, art. 6(1)(b) |
| A one-time code, until it expires | To sign you in | Contract |
| Session record: token, expiry, IP address, browser user-agent | To keep you signed in and to spot abuse | Legitimate interests, art. 6(1)(f) |
We sign you in with a code sent to your email. There is no password unless you have been given one for an administrative account, in which case it is stored hashed and never in plain text.
When you place an order
| What | Why | Legal basis |
|---|---|---|
| Name, email, phone, company name (if given) | To fulfil the order and to reach you about it | Contract |
| Delivery address, or the pick-up shop you chose | To send you the parcel | Contract |
| Delivery note, if you write one | To pass to the workshop | Contract |
| Your design, and the cutting file made from it | To cut the order | Contract |
| What you ordered, what it cost, and the order's status | To fulfil it and to keep our books | Contract, and legal obligation for accounting |
| Stripe session and payment identifiers | To match a payment to an order | Contract |
| Tracking number and shipping label | To send the parcel and let you follow it | Contract |
We never receive or store your card details. Payment happens on Stripe's own page. What comes back to us is an identifier and whether the payment succeeded.
What we do not collect
No analytics, no advertising or tracking pixels, no behavioural profiling, no third-party cookies, no location beyond the delivery address you type, and no automated decision-making or profiling with legal effect.
Who else sees it
We use these processors. Each has been chosen for a specific job and gets only what that job needs.
| Processor | What it does | What it gets | Where |
|---|---|---|---|
| Vercel | Hosting and file storage | Everything the site handles, plus your design and cutting files | Frankfurt, EU (fra1) |
| Neon | The database | Accounts and orders | Frankfurt, EU (eu-central-1) |
| Stripe | Taking payment | Your email, the amount, the order reference | EU/US, SCCs |
| Shipmondo | Buying carriage and labels | Name, address, phone, parcel size and weight | Denmark, EU |
| Brevo | Sending our emails | Your email address and the contents of the message | France, EU |
| The workshop cutting your order | Cutting and packing it | Your design, the cutting files, and the delivery address | Varies |
Where a processor is outside the EU/EEA, the transfer rests on the European Commission's Standard Contractual Clauses. [CONFIRM: that a DPA is signed with each of the five.]
Workshops are our subcontractors, not independent controllers. They receive what they need to cut and post your order and may not use it for anything else. Their obligations are in our subcontractor agreement with them, which binds them as our data processors and lets them use what they are given for your order and nothing else. Ask us and we will tell you what it requires of them.
We do not sell your data, and we never will.
How long we keep it
| What | How long |
|---|---|
| Account, while it is open | Until you delete it |
| Orders and invoices | 5 years from the end of the financial year — required by the Danish Bookkeeping Act |
| Designs and cutting files | 2 years from the order, so you can reorder, then deleted |
| Shipping labels | 1 year |
| Sessions | Until they expire |
| One-time sign-in codes | Minutes |
None of this is left to somebody remembering. A job runs every night and deletes whatever has passed the times above — the design and the cutting files at two years, the shipping label a year after the parcel went, the order record once the Bookkeeping Act has finished with it, and expired sessions and sign-in codes as they expire.
You can close your account yourself: under your name, choose Delete account. Your profile goes and you are signed out everywhere, at once. That does not remove orders already placed: we are required to keep those records, and the workshop that cut them has its own obligations. What is left of them is what the law requires us to keep, no longer tied to an account — and the sweep above still comes for it in the end.
A workshop's account cannot be closed from the button, because doing so could lock a company out of its own orders. Write to us and we will close it by hand.
Your rights
Under the GDPR you can ask us to:
- See what we hold about you, and get a copy.
- Correct anything wrong.
- Delete it, where we are not required to keep it.
- Restrict or object to how we use it, including anything we do on the basis of legitimate interests.
- Take it elsewhere, in a machine-readable form.
One of these you can do yourself, right now: under your name, choose Edit profile and then Delete account.
For the rest, write to cutting-studio@prozense.com and we will answer within one month.
If you think we have got it wrong, you can complain to Datatilsynet, Carl Jacobsens Vej 35, 2500 Valby, Denmark — datatilsynet.dk.
Cookies
We set one cookie: the session cookie that keeps you signed in. It is strictly necessary, so it needs no consent banner, and it carries no advertising or analytics identifier.
Your browser's local storage also holds your current design and some studio settings. That is not a cookie, is never sent to us, and is cleared along with your browsing data.
If analytics is ever added, this section and a consent banner have to come first.
Security
Everything travels over HTTPS. Designs, cutting files and shipping labels are kept in a private store that cannot be read without a server-side credential, and every request for one is checked against who is asking: only the customer who placed the order and the workshop cutting it can retrieve it.
If a breach puts your rights at risk, we will tell Datatilsynet within 72 hours and tell you without undue delay.
Changes
We will post any change here and update the date at the top. If a change matters to you, we will email you before it takes effect.