The content below is prepared in accordance with Regulation (EU) 2016/679 (GDPR) and the Personal Data Protection Act (ZVOP-2).
1. Data controller
The controller of your personal data is Prokon. For all questions regarding the protection of personal data and the exercise of your rights, write to studio@prokon.si.
We have not appointed a dedicated data protection officer (DPO), because this is not legally required for the scope of our processing; for privacy questions use the email address above.
Our role: controller and processor
For account and contact data (registration, inquiries) we act as the data controller. For the content you upload into the workspace — including personal data of third parties, e.g. welders or NDT personnel (name, certificate number and validity) — we act as the processor, processing the data solely on the instructions of your organization (the controller). In that case you are responsible for the lawfulness of the processing and for informing those individuals (Art. 14 GDPR — the type of data and its source); we provide appropriate technical and organizational measures and a data processing agreement on request.
2. What data we process
- Inquiry (contact / cut-on-demand): full name, email, phone (optional), company (optional), the message content and attached files (e.g. DXF drawings with part data).
- User account and organization: email, name, username, organization data (name, code, country) and the content you create — projects, drawings, WPQR/WPS, welder qualifications (EN ISO 9606-1), NDT personnel (EN ISO 9712) and attached certificates (PDF).
- Technical data during use: server logs (IP address, time, request type) needed for security, abuse prevention and troubleshooting.
- Free tools: they run in your browser and do not send your inputs to our server — except when you are signed in and explicitly save the content into a project.
We do not intentionally collect special categories of personal data (e.g. health data).
Providing the data is not a legal obligation, but it is a condition for entering into and performing the contract: without an email and organization data we cannot create an account, and without the inquiry content we cannot respond to it.
3. Purposes of processing and legal bases
| Purpose | Legal basis (GDPR) |
|---|---|
| Responding to an inquiry and preparing a quote / carrying out cutting | performance of a contract or pre-contractual measures (Art. 6(1)(b)) |
| Maintaining the account, storing and processing your documentation | performance of a contract (Art. 6(1)(b)) |
| Service security, abuse prevention, logs, basic operational statistics | legitimate interest (Art. 6(1)(f)) |
| Compliance with legal obligations (e.g. accounting regulations) | legal obligation (Art. 6(1)(c)) |
| Any optional email notifications about the service | consent (Art. 6(1)(a)), which you can withdraw at any time |
We do not sell your data and do not use it for advertising or profiling.
4. Who we share data with (processors)
We do not share data with third parties for their own purposes. To operate the service we use carefully selected contractual processors that process data solely on our instructions and under a data processing agreement (DPA):
| Processor | Purpose | Processing location |
|---|---|---|
| Supabase | database, sign-in, file storage (certificates, drawings) | EU (Frankfurt) |
| Cloudflare | application hosting, network (CDN), security and abuse prevention | EU / global edge network |
| Stripe (when payments are activated) | processing subscription payments | EU / USA (SCC) |
| Email provider (e.g. Resend, when activated) | sending system emails (confirmations, password reset) | EU / USA (SCC) |
We may also disclose data to the competent authorities where required by law. The current list of processors is available on request via studio@prokon.si.
5. Transfers to third countries
Your content data (accounts, projects, documentation) is stored on servers in the EU (Supabase, Frankfurt). Some processors (e.g. Cloudflare) may, due to the global nature of the network, also process data outside the EU; in such cases the transfer is safeguarded by the European Commission's standard contractual clauses (SCC) or another appropriate mechanism under Art. 46 GDPR.
The AI assistant is not yet active. When it becomes available, it will run on infrastructure in the EU; if we were to use a provider outside the EU/EEA for part of the processing (e.g. in a country without an adequacy decision), we will first put in place appropriate safeguards (SCC + a transfer impact assessment) and update this policy accordingly.
We host web fonts locally (on our own domain) and do not use Google Fonts or other external font CDNs — so your IP address is not sent to such third parties when you visit.
6. How long we keep data
- Account and content: for as long as the account is active or until you delete it; after cancellation we delete or anonymize the data within a reasonable period, except where retention is required by law.
- Inquiries from forms: only for as long as needed to handle the matter.
- Accounting documents: for the legally prescribed period (as a rule up to 10 years).
- Security logs: a shorter period, needed for security and troubleshooting.
7. Your rights
In accordance with the GDPR and ZVOP-2 you have the right to:
- access your data and obtain a copy of the processing;
- rectification of inaccurate and completion of incomplete data;
- erasure ("the right to be forgotten") where there is no basis for retention;
- restriction of processing and objection to processing based on legitimate interest;
- data portability in a structured, machine-readable format (export);
- withdrawal of consent where the processing is based on it (withdrawal does not affect the lawfulness of prior processing).
Send your request to studio@prokon.si; we respond within the statutory deadline (as a rule one month). If you believe the processing infringes the regulations, you may lodge a complaint with the supervisory authority — the Information Commissioner of the Republic of Slovenia, Dunajska cesta 22, 1000 Ljubljana, ip-rs.si.
8. Automated decision-making
We do not carry out automated decision-making with legal or similarly significant effects, nor profiling within the meaning of Art. 22 GDPR. The engineering calculations in the tools are an aid; the judgement of the responsible welding coordinator (EN ISO 14731) is authoritative.
9. Security
We use appropriate technical and organizational measures: encrypted transmission (HTTPS), separation of data by organization at the database level (row-level security / RLS), access control and hosting in the EU. Nevertheless, no system is completely secure; in the event of a personal data breach we will notify you in accordance with the law.
10. Changes
We may update this policy (e.g. with new features or processors). We publish material changes on this page with a new date; for important changes we may also notify you by email.
11. Cookies
We use only strictly necessary cookies. Details are in the cookie policy.