Privacy Policy
- Who we are
- What we collect
- Why and on what basis
- Machine control
- Cookies & storage
- Service providers
- Retention
- Your rights
This policy explains what personal data MELD d.o.o. processes when you visit this website or use MeldCNC (the “service”), why we process it, and the rights you have under the EU General Data Protection Regulation (GDPR) and the Slovenian Personal Data Protection Act (ZVOP-2).
1. Who is responsible
The controller of your personal data is:
MELD d.o.o.Legen 38
SI-2383 Šmartno pri Slovenj Gradcu, Slovenia
VAT ID: SI35492031
For any privacy question or request, write to us at the address above. We answer within one month.
2. What we collect
When you visit this website
The website does not use analytics, advertising or tracking tools, and it loads no fonts or scripts from other companies. Like every web server, ours receives your IP address, browser type and the requested page so that it can deliver the page; these technical logs are used only for security and troubleshooting.
When you create an account and use the service
- Account data: your name, email address and a one-way hash of your password (we never store the password itself).
- Your content: projects, uploaded files (SVG, DXF, images, STL, G-code), exported G-code, and your own bits, materials and machine profiles.
- Session data: a random session token, stored only as a hash on our side, with its creation and expiry time.
- Billing data (paid plans): plan, billing period, invoices and the billing address and VAT number you give us. Card details are handled by our payment provider and never reach our servers.
- Support messages you send us, and our replies.
- Technical logs: IP address, time, requested endpoint and error details, to keep the service secure and working.
3. Why we process it, and on what legal basis
| Purpose | Data | Legal basis (GDPR) |
|---|---|---|
| Providing your account, projects, toolpaths and exports | Account data, your content, session data | Contract, Art. 6(1)(b) |
| Billing, invoicing and tax records | Billing data | Contract, Art. 6(1)(b); legal obligation, Art. 6(1)(c) |
| Security, abuse prevention, rate limiting, troubleshooting | Technical logs | Legitimate interest, Art. 6(1)(f) |
| Answering your questions | Support messages, account data | Contract or legitimate interest, Art. 6(1)(b)/(f) |
| Service emails (password, billing, important changes) | Email address | Contract, Art. 6(1)(b) |
We do not sell personal data, do not use it for advertising, and do not use your projects to train machine-learning models.
4. Machine control
When you connect a CNC machine, MeldCNC talks to it directly from your browser through the Web Serial interface. The G-code, positions, settings and messages exchanged with your machine stay on your computer and are not sent to our servers. Your browser asks for your permission before any serial port can be opened, and you can revoke it in the browser’s site settings.
5. Cookies and browser storage
We use only what the service needs to work. Because none of it is used for tracking, no consent banner is required.
| Name | Type | Purpose | Lifetime |
|---|---|---|---|
| meld_session | Cookie (HTTP-only, first party) | Keeps you signed in | Up to 30 days, or until you sign out |
| meldcnc-site-theme | Local storage | Remembers light or dark theme on this website | Until you clear it |
| meldcnc:theme, meldcnc:v1 | Local storage | App theme and feeds-calculator settings | Until you clear it |
| meldcnc:control:v1 | Local storage | Machine-control preferences (baud rate, jog and probe settings) | Until you clear it |
| meldcnc:projects-sort, meldcnc:library-units | Local storage | List sorting and unit preferences | Until you clear it |
| meldcnc.editor.clipboard | Local storage | Copy and paste between projects | Until you clear it |
Local storage stays in your browser and is never sent to us. You can delete it at any time in your browser settings.
6. Service providers and transfers
We use carefully selected providers that process data on our behalf under a data processing agreement (Art. 28 GDPR): hosting and file storage, email delivery, and payment processing. They may only use the data to provide their service to us. Where a provider processes data outside the European Economic Area, we rely on an adequacy decision or the European Commission’s Standard Contractual Clauses. A current list of providers is available on request.
We disclose data to authorities only where the law requires it.
7. How long we keep data
- Account data and your content: while your account exists. After you delete the account we erase it within 30 days, and from backups within a further 60 days.
- Invoices and billing records: as long as Slovenian tax and accounting law requires (currently 10 years).
- Technical logs: up to 30 days, longer only while needed to investigate a specific security incident.
- Support messages: up to 2 years after the conversation ends.
8. Your rights
You have the right to:
- access the personal data we hold about you and receive a copy (Art. 15);
- have inaccurate data corrected (Art. 16) and data erased (Art. 17);
- restrict processing (Art. 18) and object to processing based on legitimate interest (Art. 21);
- receive your data in a portable format (Art. 20) — you can also download your projects and G-code yourself at any time;
- lodge a complaint with a supervisory authority.
In Slovenia the supervisory authority is the Information Commissioner of the Republic of Slovenia (Informacijski pooblaščenec), Dunajska cesta 22, 1000 Ljubljana, www.ip-rs.si. You may also contact the authority in the EU country where you live.
9. Security
Connections are encrypted with TLS. Passwords are stored with a salted, memory-hard hash (scrypt), session tokens only as hashes, and access to production systems is limited to the people who run the service.
10. Children
The service is not intended for children under 16, and we do not knowingly collect their data.
11. Changes to this policy
If we change this policy in a way that matters, we tell account holders by email before the change takes effect. The date at the top always shows the current version.