Perfect Cut

Privacy Notice

Effective

1. Controller and roles

Andreas Ehrhardt, trading as PurePortal, Hohenzollernstraße 17, 72172 Sulz am Neckar, Germany is the controller for account administration, authentication, platform security, billing administration, support, legal compliance and operation of Perfect Cut. Privacy requests can be sent to [email protected] or made by phone at +49 174 7297964.

For personal data that a business customer enters in team content, the customer determines purpose and means and is normally the controller; PurePortal processes that data on the customer’s behalf under the Data Processing Agreement. PurePortal is the controller for its seller, contract and subscription-administration records. Stripe and Sold through Link process Managed Payments data independently for merchant-of-record payment processing, indirect tax, transaction support, fraud prevention, security and legal compliance.

2. Data, purposes and legal bases

2. Data, purposes and legal bases
ActivityData and purposeLegal basis
Website and service deliveryIP address, date, route, device/browser and security/error logs to deliver pages, prevent abuse and diagnose failuresArt. 6(1)(b) where delivery is necessary for a contract with the individual; Art. 6(1)(f) for delivery to business users and secure, reliable operation
Consent-based analyticsConsent choice, page route, limited non-secret navigation/campaign parameters, referrer/campaign, locale/time zone, device/browser, visit and session activity, performance timings, selected product events, client error details and a signed-in user’s pseudonymous internal account ID to understand use, performance and failures; the analytics server uses IP address and user agent for short-lived visitor/session recognitionArt. 6(1)(a) GDPR and Section 25(1) TDDDG; no analytics data is sent before consent
Registration and accountEmail, username, name, company/team, legal acceptance, verification status and account settingsArt. 6(1)(b) where the individual is the customer; Art. 6(1)(f) for B2B user/account administration and proof of terms
Authentication and securityPassword hash, session and one-time-token data, OIDC identifiers/configuration, API-key metadata, IP/security events and audit logsArt. 6(1)(b) where applicable, Art. 6(1)(c) where legally required, and Art. 6(1)(f) to protect accounts, customers and the service
Teams and workMemberships, invitations, permissions, domains, projects, materials, dimensions, calculations, results, imports/exports, quotes, pricing policies, templates, custom fields, avatars and logosArt. 6(1)(b) where the individual is the customer; Art. 6(1)(f) for B2B service administration; Art. 28 GDPR/DPA for customer-controlled personal data
Catalog sharingCatalog ownership, audience, invitations, subscriptions, items, changes and publisher/user identifiers to provide selected or global sharingArt. 6(1)(b) where applicable; Art. 6(1)(f) for B2B delivery and platform integrity; Art. 28 where customer-controlled
BillingCustomer and purchaser identity, plan/seat order, legal acceptance, Stripe customer/subscription/invoice IDs, status, totals, billing location, business name and encrypted webhook payloads; PurePortal does not receive full card details or store the customer tax-ID valueArt. 6(1)(b) where the individual is the customer; Art. 6(1)(c) for commercial/tax records; Art. 6(1)(f) for B2B billing, reconciliation and fraud/security
Support and legal noticesContact details, message, attachments, affected content, correspondence and resolutionArt. 6(1)(b) where applicable, Art. 6(1)(c), and Art. 6(1)(f) to answer requests, establish claims and keep the service lawful

Required account and contract data must be provided to create and operate an account or subscription. Optional profile fields can be left blank. Perfect Cut does not use personal data or analytics for advertising and does not make decisions about people based solely on automated processing within Article 22 GDPR. Cutting optimisation is an automated calculation about material, not a decision about a person.

3. Recipients

  • Authorised users and administrators of the customer’s teams, according to roles and sharing choices.
  • Recipients of catalog invitations and authenticated customers who can access a catalog published to the global library.
  • Hetzner Online GmbH, Industriestraße 25, 91710 Gunzenhausen, Germany, for application, database and server hosting.
  • Cloudflare, Inc., 101 Townsend Street, San Francisco, CA 94107, USA, for authoritative DNS, reverse-proxy delivery, TLS, traffic routing and network security; Cloudflare receives connection and request data and may transiently process proxied content.
  • Zoho Corporation B.V., Beneluxlaan 4B, 3527 HT Utrecht, Netherlands, and approved Zoho affiliates/subprocessors for transactional email.
  • Sold through Link LLC and the applicable Stripe entity identified in Stripe’s privacy notice for Managed Payments, payment processing, indirect tax, receipts and invoices, transaction support, fraud prevention, security and legal duties, acting as independent controllers for those purposes.
  • An identity provider configured by the customer for Enterprise SSO, acting under the customer’s arrangements.
  • Professional advisers, courts or authorities only where necessary to establish claims or comply with law.

4. Current and planned services

4. Current and planned services
StatusServiceProcessing
ActiveHetznerHosts the application, PostgreSQL database, uploaded images and technical logs.
ActiveCloudflareProvides DNS and proxied network delivery/security and processes IP addresses, request headers, routing/security metadata and transmitted content as needed.
ActiveLocal backupsBackup copies are currently stored only on infrastructure controlled by PurePortal; no remote Backblaze copy exists. Copies may contain the database and customer content and are used only for recovery.
ActiveFile importsCSV, JSON, XML, text and supported XLSX content is sent to Perfect Cut and parsed on the Hetzner-hosted application. The application does not retain the raw import file after the request; imported rows and the file name recorded in the project audit trail may remain with the team data.
Planned—not activeBackblaze B2Encrypted remote backups may be added later. Before activation PurePortal must choose the EU region, encrypt before upload, set access/retention/deletion controls, complete the DPA and transfer assessment, test restoration, notify customers and update this notice and the subprocessor list.
Active after consentPurePortal-operated SwetrixReceives page views, session activity, performance timings, selected product events and client error details through swetrix.pureportal.io only after analytics consent. Swetrix does not place its own tracking cookie or use browser storage; session replay is disabled.
Planned—not activeOpenAI APIAI-assisted XLS mapping or similar suggestions may be added later. No spreadsheet, prompt or output is currently sent to OpenAI. Activation requires an OpenAI business/API DPA, a transfer and retention configuration, updated subprocessor notice, minimisation and deletion rules, and an in-product disclosure before a user sends data.

A future AI import flow must identify the data sent, purpose, provider and retention at the point of use; warn that spreadsheets can contain personal or confidential data; require a deliberate user action; and present mappings as AI-generated suggestions for human review before import. PurePortal will not enable model-training opt-in or solely automated decisions about people for this feature. A new purpose or high-risk use requires a fresh GDPR and EU AI Act assessment before release.

5. International transfers

Primary application/database hosting is with Hetzner Online GmbH, which is established in Germany. The selected Hetzner data-centre location is not evidenced by the deployment materials reviewed for this notice and must be confirmed; this notice must be updated before using a location that creates an additional third-country transfer. Cloudflare operates a global network and may process connection, security and request data in the United States and other countries; its DPA uses recognised transfer mechanisms including adequacy frameworks where applicable and EU standard contractual clauses. Stripe and Sold through Link may process Managed Payments data in the locations described in their privacy information using applicable adequacy decisions or safeguards such as standard contractual clauses. Zoho stores European customer email data in EU data centres; limited third-country support or subprocessor access may rely on standard contractual clauses. A customer-selected identity provider processes data in locations chosen by that customer. Planned Backblaze and OpenAI processing is not an active transfer.

6. Cookies and browser storage

Perfect Cut asks before activating Swetrix analytics. No analytics data is sent before acceptance, and future collection stops after withdrawal in Privacy settings. Swetrix itself is cookieless; Perfect Cut stores only the consent decision. Section 25(1) TDDDG and Art. 6(1)(a) GDPR apply to consented analytics, while Section 25(2) TDDDG applies to necessary storage below.

6. Cookies and browser storage
StoragePurposeTypical duration
pc_session (HTTP-only cookie)Keeps an authenticated session and enforces the selected team/security stateConfigured session lifetime; default 7 days, or deleted at logout
NEXT_LOCALE (cookie)Remembers the language selected or used for the service1 year
sidebar_state (cookie)Remembers whether the workspace navigation is open7 days
pc_analytics_consent (cookie)Remembers whether Swetrix analytics was accepted or rejected and enables later withdrawal or change180 days; replaced when the choice changes
pc_sso_flow / pc_sso_link (HTTP-only cookies)Protects and completes an OIDC sign-in or account-link flowA few minutes; removed after the flow
Browser session/history stateTemporarily carries one-time sign-in, registration or pending catalog-invitation state and clears secrets from the address barUntil used, expired or the browser session is cleared
Cloudflare security storage (for example __cf_bm, cf_clearance or _cfuvid, only if the relevant protection is triggered/enabled)Distinguishes legitimate traffic, completes a security challenge or applies rate/security controlsFeature-dependent; Cloudflare controls the duration stated in its cookie documentation
Link and Stripe checkout storageCompletes the user-initiated Managed Payments checkout, prevents fraud and remembers payment choices under Link’s and Stripe’s noticesSet only when checkout, Link order management or the customer portal is opened; duration controlled by Link and Stripe

7. Retention

  • Uncompleted registration verification records expire after 1 day; passwordless links expire after 15 minutes. Expired transient records are deleted during service cleanup.
  • Raw import-file content is processed for preview/import and is not retained by the application after the request. Imported project records and the file name in the project audit trail follow the account/team retention rules below.
  • Account and team data are retained while the account or customer contract is active. Deleting a user account tombstones the live identity, avatar, sign-in data and external identifiers, pseudonymises its audit actor label, removes stored profile values from self-profile audit entries and disables memberships. A pseudonymous internal ID may remain in audit/security or shared business records where needed for integrity, claims or customer continuity.
  • When a team deletion is requested, the team remains available during a 14-day cancellation period and is then permanently deleted, subject to contractual or legal retention duties. PurePortal may retain minimal security and audit evidence to protect the service and establish claims.
  • Encrypted Stripe webhook payloads are normally deleted after 90 days. Subscription, transaction, acceptance and invoice-related records are retained as needed for reconciliation and statutory commercial/tax retention, generally 6 years for business correspondence, 8 years for accounting vouchers and 10 years for books and annual accounts under applicable German rules.
  • Consented Swetrix analytics is retained only for as long as needed to measure use, performance and failures, then deleted or aggregated; changing the preference stops future collection without changing data already lawfully processed.
  • Support and illegal-content notices are retained for the request and as long as necessary for follow-up, legal duties or claims, then deleted or anonymised.
  • After a completed SaaS switch, exportable data is available for the stated retrieval period and then erased as described in the Data Portability and Switching Register, subject to legal retention and segregated backup cycles.
  • Backups are currently local only and are retained only for the rolling recovery window, then overwritten. Account/team erasure reaches remaining copies when that recovery copy is overwritten; statutory records may remain separately restricted.

8. Security

PurePortal uses measures appropriate to the risk, including TLS in transit, one-way password hashing, hashed one-time credentials and API secrets, HTTP-only session cookies, tenant scoping, role-based access, rate limits, validation, audit/security logging, restricted administrative access and encrypted storage of sensitive Stripe webhook payloads. No internet service can guarantee absolute security. Customers must manage users, identity-provider settings, API keys and exports securely.

9. Your rights

Subject to the legal conditions, individuals may request access, correction, deletion, restriction, portability, and information about recipients. They may object to processing based on Art. 6(1)(f) GDPR for reasons arising from their situation. Analytics consent can be withdrawn at any time in Privacy settings for future collection. Requests should identify the account and may require proportionate identity verification. For customer-controlled team content, PurePortal may refer the request to the relevant customer or assist that customer under the DPA.

10. Complaint

A complaint may be lodged with any competent supervisory authority, including the State Commissioner for Data Protection and Freedom of Information Baden-Württemberg (LfDI BW), Heilbronner Straße 35, 70191 Stuttgart, Germany, [email protected]. The right to other administrative or judicial remedies remains unaffected.

11. Updates

This notice is updated when data use, providers or law materially changes. The current version is bundled in Perfect Cut. Material changes affecting an existing account are communicated in the service or by email where required.