In accordance with the General Data Protection Regulation (GDPR)
Version 1.1 · Last updated: 16 juli 2026
Also read our
Privacy 2.0
— our privacy philosophy in plain language, alongside this formal statement.
We value your privacy. This privacy statement explains which personal data we process, why we do so, how long we retain data and what rights you have. We are a production company providing 3D printing services — not a data or advertising company. In principle, we use personal data only to provide our services, keep the website secure and comply with legal obligations.
Also read our
Privacy 2.0
for our privacy philosophy in plain language.
1. Who is responsible?
Printics
(hereinafter: “Printics”, “we” or “us”) is the data controller for personal data processed through our website, customer portal, email and other channels.
Under the GDPR, Printics is generally not required to appoint a Data Protection Officer (DPO). For all privacy questions and requests, you can contact us via
[email protected].
2. Scope
This privacy statement applies to:
visiting and using our website (including the price calculator, contact form and information pages);
the customer portal (account, orders, messages, uploads);
quote and contact requests;
orders, payment, production and delivery;
communication by email or phone in connection with our services.
The processing of personal data by third parties (for example Mollie for payments) is also subject to that party's privacy terms. We refer to these where relevant.
3. What data do we process?
Depending on your relationship with us, we may process the following categories:
3.1 Identity and contact details
For example: name, email address, phone number, company name (if applicable).
3.2 Account and login details
For a customer account: email address, session data, profile preferences, address book (shipping and billing addresses). Login is via a personal one-time login link sent by email (magic link). Customers who have optionally enabled two-factor authentication (2FA) also have a hashed password stored.
3.3 Order and invoicing data
Order number, order lines, prices, VAT information, payment status, invoice details, delivery method, track-and-trace information.
3.4 Files and production data
3D model files (STL, OBJ, etc.), attachments to contact/quote requests, print settings, production and quality data required to carry out your order.
3.5 Communication
Contents of contact messages, quote requests, messages in the customer portal, email correspondence and any attachments.
3.6 Technical and security data
IP address, browser and device information (user agent), timestamps, server logs, session identifiers, data on failed login attempts, rate limiting, anti-bot challenges and IP blocks in cases of abuse.
Cloudflare Turnstile may process technical signals (including IP address, browser/device characteristics and challenge results) to distinguish bots from people.
3.7 Data without an account (guest)
Temporary session data for the cart, calculator uploads and anonymous visitor flows, linked to a technical session or visitor identifier. Without creating an account, no persistent customer profiles are built for marketing purposes.
4. Purposes and legal bases
We process personal data solely for the purposes below and on the stated legal basis under Article 6 GDPR:
Purpose
Legal basis
Performance of a contract (order, production, delivery, customer portal)
Art. 6(1)(b) — performance of a contract
Quote, contact and customer service
Art. 6(1)(b) (steps prior to a contract) or (f) (legitimate interest: answering questions)
Payment processing via Mollie
Art. 6(1)(b) — performance of a contract
Shipping via PostNL or a comparable carrier
Art. 6(1)(b) — performance of a contract
Administration, invoicing and tax obligations (including 7-year retention)
Art. 6(1)(c) — legal obligation
Website security, fraud and abuse prevention (rate limits, anti-bot, IP blocks)
Art. 6(1)(f) — legitimate interest (security of systems and users)
Checks for prohibited or illegal orders (including weapons legislation and Wwft due-diligence obligations)
Art. 6(1)(b) (performance) or (c) (legal retention obligation for remaining data)
Technically necessary cookies and sessions (login, cart, CSRF protection)
Art. 6(1)(f) — legitimate interest / provision of the service
No marketing profiles: we do not use your data for targeted advertising, sale to data brokers or profiling for commercial purposes outside our own services. We do not place third-party tracking or marketing cookies (such as Google Analytics or advertising pixels).
5. Retention periods
We do not retain personal data longer than necessary for the purpose for which it was collected:
Category
Period
Guest session (calculator, cart without an account)
Up to approximately 72 hours, followed by automatic cleanup where applicable
Contact/quote messages without an order relationship
For as long as needed to handle the request; afterwards deleted or anonymized, unless a legal retention obligation applies
Customer account, orders and production files
For the duration of the customer relationship; files may be cleaned up after production — also see § 5.1
Invoice and administrative data
7 years (tax retention obligation); anonymized where possible after the customer relationship ends
Payment details (card, bank account)
Not stored by Printics; processed by Mollie in accordance with its policy
Anti-bot and security logs (IP, timestamps)
Temporary; soft blocks for a maximum of 24 hours; log data and completed enforcement records are cleaned up periodically
Server logs
Limited period for security and fault analysis (generally several weeks to several months)
5.1 3D files — not a storage service
Printics is a printing service, not cloud storage for your designs. Files are retained to produce your order and to keep them available in the customer portal for your convenience. We do not guarantee unlimited or permanent storage: files may be deleted by you, by us (during maintenance) or after your account is closed. Make your own backup of valuable models.
When closing your account, you can request through the customer portal that your personal data be anonymized. After a grace period, identifying data is removed or disconnected; legally required records may be retained in anonymized form.
6. Sharing with third parties (processors)
We share personal data only where necessary for our services or where required by law. Third parties process data on our behalf (processors) or as independent controllers (e.g. a payment provider).
6.1 Mollie B.V.
Payment processing. You are redirected to Mollie's secure environment. Printics does not store full payment card details.
Mollie privacy policy.
6.2 PostNL (or another carrier)
Shipping: name, address and contact details required for delivery.
PostNL privacy policy.
6.3 Email (SMTP)
Transactional emails (confirmations, status updates, login links) are sent through our email infrastructure (Google Workspace SMTP). Only the data required to send the relevant email is processed.
6.4 Other
We do not sell personal data. We do not use external CRM systems, advertising networks or third-party analytics services to track visitors. Hosting, database and application run on infrastructure managed by us; customer data is not deliberately placed in generic consumer cloud storage for marketing or profiling purposes.
6.5 Cloudflare Turnstile
Bot detection and abuse prevention on forms. Cloudflare processes technical signals for this purpose as a processor. See the
Turnstile Privacy Addendum.
7. Transfers outside the EEA
We aim to process data within the European Economic Area (EEA). If a (sub)processor processes data outside the EEA, we ensure an appropriate legal basis in accordance with the GDPR (for example an adequacy decision or standard contractual clauses). Contact us if you would like specific information about a particular processing activity.
Cloudflare Turnstile may involve transfers outside the EEA; we use appropriate safeguards through Cloudflare for this purpose (including a data processing agreement and standard contractual clauses where applicable).
8. Cookies and similar technologies
We use no third-party marketing or tracking cookies. We therefore do not display a cookie banner for advertising or analytics purposes.
The following strictly necessary technologies may be used:
Session cookie — to keep you signed in, enable the cart/calculator to function and prevent CSRF attacks;
Security cookie (anti-bot) — anonymous visitor identifier to limit abuse of forms (printics_antibot_vid);
Cloudflare Turnstile — strictly necessary security technology against bots on forms (no marketing or tracking);
localStorage — optional preference for the display theme (light/dark) in your browser; no sale to third parties.
You can block or delete cookies in your browser; some functions (login, ordering, forms) may then not work correctly.
9. Security
We take appropriate technical and organizational measures to protect personal data against loss, misuse, unauthorized access, disclosure or alteration. These measures include encrypted connections (HTTPS), access restrictions on admin environments, login via one-time email links (magic links), optional two-factor authentication (2FA), rate limiting and abuse monitoring.
No method of transmission or storage is 100% secure. If a data breach is likely to pose a risk to your rights and freedoms, we act in accordance with the GDPR notification requirements.
10. Automated decision-making
Our anti-bot measures may result in temporary blocking of forms or — in cases of repeated abuse — parts of the website for a specific IP address or visitor. This is intended for security, not commercial profiling.
Cloudflare Turnstile may deny access to a form or show an additional challenge if bot traffic is suspected; this is not marketing profiling.
In the event of a hard block, if you are a customer, you can use a recovery form to demonstrate that you placed the most recent order (email, order number and postal code). A staff member can also remove blocks manually. You have the right to human intervention and an explanation regarding such measures; contact us via
[email protected].
11. Your rights
Under the GDPR, where applicable, you have the following rights:
Access — to know which data we process about you;
Rectification — to have incorrect data corrected (including through your customer profile);
Erasure — to have data deleted, subject to legal retention obligations;
Restriction — to temporarily restrict processing;
Data portability — to receive data you provided to us on the basis of consent or a contract in a structured, commonly used format;
Objection — to processing based on legitimate interests, subject to our compelling legitimate grounds;
Withdrawal of consent — where processing is based on consent (currently applicable only to a limited extent).
Send your request to
[email protected]
or use the
contact form,
stating your name and email address so that we can identify you. We will respond within one month at the latest (extendable for complex requests in accordance with the GDPR).
For account closure and anonymization, you can also use the function in the customer portal, unless outstanding obligations (active orders, legal retention requirements) prevent this.
12. Complaint to the Dutch Data Protection Authority
Do you believe that we are not handling your personal data correctly? Please contact us first. You also have the right to lodge a complaint with the
Dutch Data Protection Authority.
13. Minors
Our services are not aimed at persons under the age of 16. We do not knowingly process personal data of children without the consent of a parent/guardian. Contact us if you believe we have collected such data.
14. Changes
We may amend this privacy statement, for example when introducing new functionality or following changes in legislation. The current version is always available on this page together with the version date. Where appropriate, we will inform you of material changes (for example via the website or email).
15. Contact
Questions about privacy or exercising your rights?