Legal

Privacy Policy

Notice on the processing of personal data and images uploaded to the CVCAD platform.

Data controller

The data controller is Luca Benvenuti, Italy, who operates the CVCAD service and determines the purposes and means of the processing described in this notice. You can contact us at the details shown on the site for any request concerning your data.

Data processed

We process: account data (email address, name if provided, login credentials or social provider identifier); uploaded images and generated files; service usage data (conversions performed, credit balance and movements); technical access data (IP address, device and browser type, security logs); the content of any support requests.

Purposes and legal bases

Creation and management of the account, provision of conversions, management of the credit balance and history: performance of a contract. Platform security, prevention of abuse and fraud and technical improvement of the service: legitimate interest. Accounting and tax obligations and responses to authorities: legal obligation. Any promotional communications are sent only with your prior consent, which may be withdrawn at any time.

Recipients of data

Data may be disclosed to: service providers acting as data processors (hosting and database, file storage, image-processing infrastructure, support tools); Paddle.com, as Merchant of Record for the sale of credits, which processes the data necessary for payments, invoicing, taxes and order management in accordance with its own privacy notice; professional advisers (lawyers and accountants); competent authorities where required by law. We do not sell your data and do not use it to train models.

Retention and confidentiality

Uploaded images and generated files are stored in private archives, accessible only through temporary signed links tied to your account, and are automatically deleted 5 days after conversion. Account data and credit movements are kept for as long as the account remains active and, for accounting purposes, for the periods required by law; technical logs are kept for a limited period for security purposes. At the end of these periods the data is deleted or anonymised. Details of the measures adopted, and their limits, are described on the Confidentiality of uploaded files page.

Transfers outside the EEA

Some providers may process data outside the European Economic Area. In that case the transfer takes place on the basis of adequacy decisions or standard contractual clauses approved by the European Commission, with supplementary measures where necessary.

Security

We adopt appropriate technical and organisational measures: encryption in transit, non-public archives, per-user access controls applied at database and storage level, signed and time-limited download links.

Cookies

We use only cookies and local storage that are technically necessary to maintain the login session and essential preferences. We do not use advertising profiling cookies. Checkout may use Paddle's own technical cookies to complete payment.

Data subject rights

You may request at any time access, rectification, erasure, restriction, portability and objection to processing, including deletion of uploaded images and generated files, and withdraw any consent given, by writing to the service's contact details. We respond within one month. You also have the right to lodge a complaint with the Garante per la protezione dei dati personali (the Italian Data Protection Authority).