Madegrain

Privacy policy · DXF Medic

Your working files are processed locally in your browser. When you visit the website, make a purchase, have a licence issued or recovered, or contact us, we process the personal data described below.

1. Controller

Cayan Oyman
Ramsener Straße 43
78239 Rielasingen-Worblingen
Germany
[email protected]

2. Processing of Your Design Data: Does Not Take Place

The DXF Medic application runs entirely on your device as a WebAssembly program. Files you open (DXF, SVG) are processed exclusively in your browser’s memory and are never transferred to us or to third parties. There is no server endpoint that could receive files. Diagnostic reports and repaired files are generated and saved directly on your device.

3. Visiting the Website (Hosting)

The website is served through Cloudflare Pages; purchase confirmation, licence issuance and recovery use Cloudflare Workers. Cloudflare, Inc. processes technically necessary connection data, particularly IP address, time, requested resource and browser information. This is used to deliver and protect the website. The legal basis is our legitimate interest in secure operation under Article 6(1)(f) GDPR.

4. Cookies, Tracking and External Payment Pages

Our own pages do not include advertising networks or social media modules. Fonts, images and video are served with the website. The public purchase confirmation does not require a user account and does not set cookies of its own. External payment pages have their own privacy and cookie notices.

Since 20 September 2026, we count page views, clicks to the app and clicks on the purchase button on the four product landing pages. We store only the day, product, event type, a broad source category (such as search, directory or outreach email) and the total count in Cloudflare D1. The full referring address, IP addresses and personal or device identifiers are not included in these counters. No cookies or browser storage are used for this, and no individual visitor journeys are recorded. Counts are deleted after 90 days. If Global Privacy Control or Do Not Track is enabled in the browser, the page sends no counting events. Technical connection data processed for hosting is described above. The counters help us understand which product pages and contact channels are used; they are not linked to orders.

5. Local Browser Storage (No Tracking)

The application and website store certain settings locally in your browser (localStorage): language preference, colour scheme, the most recently used repair settings and, after a purchase, your licence key so you do not have to enter it again. These data remain on your device, are not transferred to us and serve only the functionality you request (§ 25(2) no. 2 TDDDG; where the GDPR applies: Art. 6(1)(b) GDPR). You can delete them at any time using your browser settings.

6. Offline Use (PWA)

If you install DXF Medic as an app, your browser stores a local copy of the application files on your device (service worker cache) so that the application works without an internet connection. No data are transferred to us in this process either.

7. Purchase and Payment Processing

For purchases through Stripe Managed Payments, Stripe and Sold through Link process the information needed for the purchase, such as email address, payment details and billing country, as independent data controllers. See the Stripe and Link privacy policy. For earlier Gumroad purchases, the Gumroad privacy policy continues to apply.

Orders and licences

We process the purchase email address, purchased product, order and payment identifiers, time, language, price, payment status and delivery status to identify the purchase, issue a licence and enable recovery. Full card numbers and card security codes are not stored in our order database. The legal basis is performance of the contract under Article 6(1)(b) GDPR. The order database uses Cloudflare D1 with EU jurisdiction: its data is stored and database queries are executed within the European Union. This location restriction applies to the database, not to all processing by Cloudflare or other service providers.

Licence email delivery

We use Resend (Plus Five Five, Inc.) as a processor for purchase and recovery emails. Data transmitted includes the recipient address, message content containing the licence or personal recovery link, and information needed for delivery. The sender is [email protected]. Open and click tracking are disabled for these emails. Delivery serves performance of the contract under Article 6(1)(b) GDPR.

Abuse prevention

To protect purchase confirmation and prevent abusive recovery requests, we process connection data, identifiers derived from it or from the requested email address, and time-limited request counters. This supports security and prevents unwanted email delivery. The legal basis is Article 6(1)(f) GDPR. These derived identifiers should not be regarded as anonymous data.

Retention

We retain paid orders and their licence association for as long as necessary for the perpetual major-version-1 licence, its recovery or the handling of claims. We delete data in response to a valid erasure request unless statutory retention obligations or other lawful grounds prevent this. Information that must be retained by law is processed under Article 6(1)(c) GDPR. Incomplete orders that remain pending, have no associated email address and have no delivery record are deleted after 30 days by the regular cleanup process. Security and delivery data is retained only as long as needed for its respective purpose.

Processing outside the EU

Cloudflare and Resend may also process personal data outside the EU, particularly in the United States. The safeguards described by these providers for international transfers include EU Standard Contractual Clauses. See the Cloudflare data processing agreement and the Resend data processing agreement.

Electronic withdrawal

When you use the withdrawal function, we process your name, the contract details you provide, your chosen email address, the declaration and its receipt time. We store the declaration in Cloudflare D1 with EU jurisdiction and send the acknowledgment through Resend to the supplied address. Our support team receives a notification for processing. The legal basis for receipt and acknowledgment is Article 6(1)(c) GDPR in conjunction with section 356a of the German Civil Code (BGB); subsequent contract handling is based on Article 6(1)(b) GDPR. We retain the declaration and delivery records as necessary for processing, statutory obligations or establishing, exercising or defending claims. Limited request counters with derived identifiers are used to prevent abuse. Open and click tracking are disabled.

8. Licence Keys and Redemption

Your licence key is bound to your purchase email address and verified offline in the application. After a Stripe purchase, you receive the offline licence on the confirmation page and by email. When an earlier Gumroad purchase key is first converted through the existing redemption page, it is sent to our licence service and verified with Gumroad. This processes the purchase key and the purchase information required to issue the licence (Article 6(1)(b) GDPR). The issued offline licence is stored on your device. Your work files are not uploaded during these processes.

9. Email Contact

When you email us, we process your email address and the content you provide to handle your request. The legal basis is Article 6(1)(b) GDPR for contract-related inquiries and otherwise Article 6(1)(f) GDPR. Data is deleted when its purpose no longer applies and no statutory retention obligations remain.

10. Your Rights

Under the conditions of the GDPR, you have rights of access, rectification, erasure, restriction of processing, data portability and objection to processing based on Article 6(1)(f) GDPR. You may lodge a complaint with a data protection supervisory authority. For questions about our processing, contact the email address above.

11. Last updated

Last updated 9 September 2026