In line with the General Data Protection Regulation (GDPR)
Version 1.1 · Last updated: 16 July 2026
Also read our
Privacy 2.0
— our approach to privacy in plain language, alongside this formal statement.
We care about your privacy. This privacy statement explains which personal data we process, why we do that, how long we keep data and which rights you have. We are a production company for 3D-printing services — not a data or advertising company. In principle we use personal data only to carry out our services, keep the website secure and meet legal obligations.
Also read our
Privacy 2.0
for our approach to privacy in plain language.
1. Who is responsible?
Printics
(hereafter: “Printics”, “we” or “us”) is the controller for personal data processed via our website, customer portal, email and other channels.
Under the GDPR, Printics is generally not required to appoint a data protection officer. For all privacy questions and requests you can contact
[email protected].
2. Scope
This privacy statement applies to:
visits to and use of our website (including the price calculator, contact form and information pages);
the customer portal (account, orders, messages, uploads);
quote and contact requests;
applications via our vacancies page (details, motivation and CV/attachments);
orders, payment, production and delivery;
communication by email or phone in connection with our services.
The processing of personal data by third parties (for example Mollie when you pay) is also subject to that party’s privacy terms. We refer to those where relevant.
3. Which data do we process?
Depending on your relationship with us, we may process the following categories:
3.1 Identity and contact details
For example: name, email address, phone number, company name (where applicable).
3.2 Account and login details
For a customer account: email address, session data, preferences in your profile, address book (shipping and billing addresses). Login is via a personal one-time login link by email (magic link). Customers who optionally enable two-factor authentication (2FA) also have a hashed password stored.
3.3 Order and invoicing details
Order number, order lines, prices, VAT details, payment status, invoice details, delivery method, track-and-trace information.
3.4 Files and production data
3D model files (STL, OBJ, and so on), attachments to contact or quote requests, print settings, and production and quality data needed to carry out your job.
3.5 Communication
The content of contact messages, quote requests, job applications, messages in the customer portal, email correspondence and any attachments.
3.6 Technical and security data
IP address, browser and device information (user agent), timestamps, server logs, session identifiers, data about failed login attempts, rate limiting, anti-bot challenges and IP blocks in case of abuse.
With Cloudflare Turnstile, technical signals (including IP address, browser/device characteristics and the challenge result) may be processed to tell bots from people.
3.7 Data without an account (guest)
Temporary session data for the cart, calculator uploads and anonymous visitor flows, linked to a technical session or visitor identifier. Without an account we do not build standing customer profiles for marketing.
4. Purposes and legal bases
We process personal data only for the purposes below and on the legal basis from article 6 GDPR stated with them:
Purpose
Legal basis
Performance of a contract (order, production, delivery, customer portal)
Art. 6(1)(b) — performance of a contract
Quotes, contact and customer service
Art. 6(1)(b) (steps prior to a contract) or (f) (legitimate interest: answering questions)
Payment processing via Mollie
Art. 6(1)(b) — performance of a contract
Shipping via PostNL or a similar carrier
Art. 6(1)(b) — performance of a contract
Administration, invoicing and tax (including 7-year retention)
Art. 6(1)(c) — legal obligation
Website security, fraud and abuse prevention (rate limits, anti-bot, IP blocks)
Art. 6(1)(f) — legitimate interest (security of systems and users)
Checks for prohibited or illegal orders (including weapons legislation and Wwft duty of care)
Art. 6(1)(b) (performance) or (c) (statutory retention of remaining records)
Technically necessary cookies and sessions (login, cart, CSRF protection)
Art. 6(1)(f) — legitimate interest / providing the service
No marketing profiles: we do not use your data for targeted advertising, sale to data brokers or profiling for commercial purposes outside our own services. We do not place third-party tracking or marketing cookies (such as Google Analytics or advertising pixels).
5. Retention periods
We do not keep personal data longer than needed for the purpose for which it was collected:
Category
Period
Guest session (calculator, cart without an account)
About 72 hours at most, then automatic cleanup where applicable
Contact or quote messages without an order
As long as needed to handle them; then deletion or anonymisation, unless a statutory retention duty applies
Application data
If rejected: up to 12 months in a talent pool if you choose that, otherwise anonymisation within about 30 days; if hired, in line with the employment relationship
Customer account, orders and production files
For the customer relationship; files may be removed after production — see also § 5.1
Invoice and administrative records
7 years (tax retention duty); anonymised where possible after the customer relationship ends
Payment details (card, account)
Not stored by Printics; processed via Mollie under their policy
Anti-bot and security logs (IP, timestamps)
Temporary; soft blocks for 24 hours at most; logs and completed enforcements are cleaned up periodically
Server logs
A limited period for security and incident analysis (usually a few weeks to a few months)
5.1 3D files — not a storage service
Printics is a print service, not cloud storage for your designs. Files are kept to produce your job and, for your convenience, to remain available in the customer portal. We do not guarantee unlimited or permanent storage: files can be deleted by you, by us (during maintenance) or after your account is closed. Keep your own backup of valuable models.
When closing an account you can ask via the customer portal to anonymise your personal data. After a grace period, identifying data is removed or unlinked; records we must keep by law may be stored in anonymised form.
6. Sharing with third parties (processors)
We share personal data only when that is needed for our services or required by law. Third parties process data on our instructions (processors) or as independent controllers (for example a payment provider).
6.1 Mollie B.V.
Payment processing. You are sent to Mollie’s secure environment. Printics does not store full payment-card details.
Mollie privacy policy.
6.2 PostNL (or another carrier)
Shipping: name, address and contact details needed for delivery.
PostNL privacy policy.
6.3 Email (SMTP)
Transactional emails (confirmations, status, login links) are sent via our email infrastructure (Google Workspace SMTP). Only data needed to send that email is processed.
6.4 Other
We do not sell personal data. We do not use external CRM systems, advertising networks or third-party analytics for visitor tracking. Hosting, database and application run on infrastructure we manage; customer data is not deliberately placed in generic consumer cloud storage for marketing or profiling.
6.5 Cloudflare Turnstile
Bot detection and abuse prevention on forms. Cloudflare processes technical signals for this as a processor. See the
Turnstile Privacy Addendum.
7. Transfers outside the EEA
We aim to process data inside the European Economic Area (EEA). If a processor or sub-processor processes data outside the EEA, we provide an appropriate basis under the GDPR (for example an adequacy decision or standard contractual clauses). Contact us if you want specific information about a particular processing activity.
Cloudflare Turnstile may involve a transfer outside the EEA; we use appropriate safeguards via Cloudflare for that (including a data processing agreement and standard contractual clauses where applicable).
8. Cookies and similar techniques
We do not use third-party marketing or tracking cookies. That is why we do not show a cookie banner for advertising or analytics.
The following strictly necessary techniques may be used:
Session cookie — to stay logged in, to run the cart and calculator, and to prevent CSRF attacks;
Security cookie (anti-bot) — an anonymous visitor identifier to limit abuse of forms (printics_antibot_vid);
Cloudflare Turnstile — a strictly necessary security technique against bots on forms (not marketing or tracking);
localStorage — an optional preference for the display theme (light/dark) in your browser; not sold on to third parties.
You can block or delete cookies in your browser; some functions (logging in, ordering, forms) may then not work correctly.
9. Security
We take appropriate technical and organisational measures to protect personal data against loss, misuse, unauthorised access, disclosure or alteration. That includes encrypted connections (HTTPS), access limits on admin areas, login via one-time email links (magic links), optional two-factor authentication (2FA), rate limiting and monitoring of abuse.
No method of transmission or storage is 100% secure. If a data breach is likely to pose a risk to your rights and freedoms, we act in line with the notification duties in the GDPR.
10. Automated decision-making
Our anti-bot measures can lead to a temporary block of forms or — in case of repeated abuse — of (parts of) the website for a specific IP address or visitor. This is for security, not commercial profiling.
Cloudflare Turnstile can refuse access to a form or show an extra challenge when it suspects bot traffic; this is not marketing profiling.
In case of a hard block you can — if you are a customer — use a recovery form to show that you placed the latest order (email, order number and postcode). A member of staff can also lift blocks manually. You have the right to human intervention and an explanation of such measures; contact
[email protected].
11. Your rights
Under the GDPR you have — where applicable — the following rights:
Access — to know which data we process about you;
Rectification — to have incorrect data corrected (also via your customer profile);
Erasure — to have data deleted, except where the law requires us to keep it;
Restriction — to temporarily limit processing;
Data portability — to receive, in a structured, commonly used format, data you provided to us on the basis of consent or a contract;
Objection — to processing based on legitimate interest, taking account of our compelling grounds;
Withdraw consent — where processing is based on consent (currently of limited application).
Send your request to
[email protected]
or the
contact form,
stating your name and email address so we can identify you. We reply within one month at the latest (extendable for complex requests, in line with the GDPR).
To close an account and anonymise data you can also use the function in the customer portal, unless outstanding obligations (open orders, a statutory retention duty) stand in the way.
12. Complaint to the Dutch Data Protection Authority
Our services are not aimed at people under 16. We do not knowingly process personal data of children without consent of a parent or guardian. Contact us if you think we have collected such data.
14. Changes
We may change this privacy statement, for example when we add functionality or the law changes. The current version is always on this page, with the version date. For material changes we inform you where appropriate (for example via the website or email).
15. Contact
Questions about privacy or exercising your rights?