Privacy policy
What we store about you, why, where it lives and the rights you have.
Draft under completion before commercial launch. The document gets a legal review before real sales begin.
The short version
- We process account, company and order data to deliver and invoice maps. Not for tracking, not for ad profiling.
- Data lives with processors in the EU (Supabase in Stockholm, Render in Frankfurt). Payment and sign-in can involve lawful transfers to the US.
- Only strictly necessary cookies, which is why there is no consent banner. See Cookies.
- You can access, correct and delete your data, and complain to Datatilsynet.
1. Who is responsible
GeoAnvil AS, org. no. 938 139 962, is the data controller. Questions go to post@geoanvil.com.
2. What we process
- Account: name, email and sign-in method (email, Google or Microsoft).
- Company (optional): company name, organisation number and the billing details you provide.
- Orders: project name, the area you drew (coordinates), map, amount and status.
- Plugin devices: a device name and last-used time when you sign in from a CAD plugin, so you can see and revoke access from your account page.
- Payment: handled by Stripe. We store a payment reference and the amount, never card numbers.
- Technical: IP address and timestamps in server logs, for security and debugging. Sign-in may use Cloudflare Turnstile to tell people from bots.
- Plugin usage: when you use the CAD plugin, it reports what happened and how long it took — whether an import succeeded, its error code, how many elements it built, and which Archicad, plugin and operating system versions you run. This is linked to your account so we can spot a problem that hits you specifically and reach out. It never includes your project names, file paths, coordinates or layer names. You can switch it off under Settings in the plugin.
- Visit statistics: page, referring site and approximate country, collected without cookies and without anything that identifies you. See Cookies.
3. Why, and on what legal basis
Delivering and invoicing what you order rests on the contract with you (GDPR art. 6(1)(b)). Security and abuse prevention rest on legitimate interest (art. 6(1)(f)). Keeping accounting records rests on legal obligation (art. 6(1)(c), Norwegian bookkeeping law, five years).
4. Who processes it for us
Supabase (database and sign-in, Stockholm), Render (servers, Frankfurt), Stripe (payment), Resend (transactional email), Cloudflare (network and bot protection) and Umami (cookieless visit statistics). Payment and sign-in providers may transfer data to the US under EU-approved mechanisms.
5. How long we keep it
Account data lives until you delete the account. Order and accounting records are kept five years, as bookkeeping law requires. Server logs rotate on short cycles. Plugin usage events are deleted after 180 days; what survives is anonymous daily totals with no link to you.
6. Your rights
You can see, correct, export and delete your data. Deleting your account from the account page removes everything except what bookkeeping law forces us to keep, and you are offered an export first. Complaints can go to Datatilsynet, the Norwegian Data Protection Authority.
7. Changes
If this policy changes materially, the change is announced on the site before it takes effect.
