Privacy policy

1. Who we are

Pentrical is a trademark of Woodmont Digital, established at Groenhovenweg 85, 2803 DB Gouda, the Netherlands, registered with the Dutch Chamber of Commerce under number 97972495, VAT identification number NL005300877B78. For questions about privacy or to exercise your rights, email [email protected]. We have not appointed a data protection officer; this is not legally required for an organisation of this size with these processing activities.

2. Our role: controller and processor

For the data we need in order to provide and bill the service - account details, payment details and technical log files - we are the controller. This policy concerns that data. For the content customers place in their own environment we are the processor: if that content contains personal data, the customer determines the purpose and means and we merely carry out the processing. Our data processing agreement applies to that, which customers receive on request.

3. What data we process

Account details: name, email address, encrypted stored password, the name of your environment, your role in the team and your preferences for language, display and notifications. Registration details: the moment you accepted the terms, which version, and the IP address at that moment. Usage data: an activity log of which action was performed when and by which user, including IP address and browser type, and the number of failed login attempts. Payment details: name, billing address, country and VAT number insofar as Paddle reports these back to us - we do not see your card or bank details. Content: the documentation, designs and previews you place yourself or synchronise via your own Figma connection. In addition, technical server log files, which may temporarily contain IP addresses and error messages. Your name and email address are required to create an account; without them we cannot provide the service.

4. Purposes and legal bases

To perform the agreement (article 6(1)(b) GDPR) we create your account, enable you to sign in, display your environment, synchronise with Figma and send service emails such as verification, subscription warnings and reminders before deletion. On the basis of a legitimate interest (article 6(1)(f) GDPR) we keep an activity log and record failed login attempts, in order to prevent abuse and investigate incidents; our interest in a secure and traceable platform outweighs the limited intrusion into your privacy here. Billing and retaining our administration are carried out to comply with a legal obligation (article 6(1)(c) GDPR). We do not sell data and do not use it for advertising or profiling.

5. Processors and transfers outside the EEA

Hosting: Hetzner Online GmbH (Germany) - all servers and databases are located within the EU. Email: Brevo, Sendinblue SAS (France). Payments: Paddle.com Market Ltd (United Kingdom) as merchant of record; an adequacy decision of the European Commission applies to the United Kingdom. Fonts: Bunny Fonts, BunnyWay d.o.o. (Slovenia), which sets no cookies and keeps no visitor records. DNS and certificates: Cloudflare. If you connect a Figma file, your Figma access token and the retrieved design data are exchanged with Figma, Inc. in the United States; that transfer relies on the EU-US Data Privacy Framework and, where necessary, on the European Commission standard contractual clauses. Data processing agreements are in place with all our processors. Apart from the above, no transfer takes place outside the European Economic Area.

6. Retention periods

Your data is kept for as long as your account exists. If the trial period expires without a subscription, your environment becomes read-only and is permanently deleted thirty days later - forty-four days after registration in total. If you cancel a paid subscription, your environment remains available read-only for thirty days so you can export, is then closed and retained for a further ninety days, and is permanently deleted no later than one hundred and twenty days after the subscription ends. Technical server log files are kept for fourteen days. The activity log exists for as long as the environment exists and is deleted along with it. Billing records are retained by Paddle as merchant of record; we retain our administration for seven years under the statutory tax retention obligation.

7. Cookies and local storage

Pentrical uses no tracking or advertising cookies and does not measure visitor behaviour. We store only what the service needs to work: a session cookie to keep you signed in, and a security token that prevents form abuse. Visitors to a password-protected documentation environment receive a similar cookie, once they submit the correct password, that remembers which sections have already been unlocked; that cookie contains no personal data and, depending on your choice, remains valid for a browser session or for thirty days. We also store your own settings in your browser - language, theme and display preferences - so you do not have to set them again each visit. No consent is required for these; you can delete them via your browser settings, though signing in - or unlocking protected documentation - will then no longer work. On the billing page, Paddle loads its own script to handle payment; this happens only if you open that page yourself. Our fonts come from Bunny Fonts, which sets no cookies and keeps no visitor records.

8. Your rights

You have the right of access, rectification, erasure, restriction of processing, objection to processing based on a legitimate interest, and data portability. You can change your name and preferences yourself in your profile; to change your email address, for access, for a full export or for deletion of your account, email [email protected]. We respond within one month. If your account is deleted, the content of your environment goes with it - request an export beforehand if you want to keep it. If you are unhappy with how we handle your data, you can lodge a complaint with the Dutch Data Protection Authority (Autoriteit Persoonsgegevens).

9. Security and data breaches

Connections are encrypted with TLS, passwords are stored hashed, and customer environments are strictly separated from one another; that separation is tested automatically on every change. Access to production systems is limited to those who need it. If a data breach occurs that poses a risk to your rights and freedoms, we report it to the Dutch Data Protection Authority within seventy-two hours and inform you without undue delay where the breach affects you. If you think you have found a vulnerability, report it via [email protected].

10. No automated decision-making

We do not take decisions with legal or similarly significant effects based solely on automated processing, and we do not carry out profiling.

11. Changes to this policy

We may amend this privacy policy; the date shown with this policy indicates when that last happened. For material changes we inform account owners by email.