Privacy Policy

Last updated: 5 April 2026

1. Introduction

DXF Manufacturing Ltd ("we", "us", "our") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, store, and protect your personal data when you use RIGHT.CUT.

We are the data controller for the purposes of UK GDPR and the Data Protection Act 2018.

DXF Manufacturing Ltd
Company Number: 12455731
Registered in England and Wales

2. Information We Collect

2.1 Information You Provide

  • Account Information: Email address, password (encrypted)
  • Profile Data: Saved cutting parameters, machine configurations, material settings
  • User Content: Photos of cut edges, notes, quality ratings, tags
  • Communications: Support requests, feedback, correspondence

2.2 Automatically Collected Information

  • Usage Data: Pages visited, features used, time spent, search queries
  • Device Information: Browser type, operating system, device type, IP address
  • Cookies: Session cookies, authentication cookies, preference cookies

2.3 Information from Third Parties

  • Authentication Services: If you use third-party login (future feature)
  • AI Processing: Images sent to Google Gemini AI for analysis

3. How We Use Your Information

We use your data for the following purposes:

3.1 Service Provision (Contractual Basis)

  • Provide access to the RIGHT.CUT platform
  • Store and retrieve your saved parameters
  • Process AI analysis requests
  • Maintain your account and preferences

3.2 Service Improvement (Legitimate Interest)

  • Analyse usage patterns to improve features
  • Develop and train AI models
  • Fix bugs and technical issues
  • Review newly created, saved, and submitted cut profiles to improve the parameter database, recommendations, and profiles offered through the Service
  • Enhance user experience

3.3 Communication (Legitimate Interest)

  • Send service updates and announcements
  • Respond to support requests
  • Notify you of new features

3.4 Legal Compliance (Legal Obligation)

  • Comply with legal requirements
  • Respond to lawful requests from authorities
  • Enforce our terms of service

4. Legal Basis for Processing (UK GDPR)

We process your personal data under the following legal bases:

  • Contract: To provide the Service you have agreed to use
  • Legitimate Interest: To operate, secure, maintain, support, moderate, and improve the Service, including internal review of cut profiles for quality control, troubleshooting, fraud prevention, and service improvement
  • Consent: For optional public community sharing features and any other processing where consent is required
  • Legal Obligation: To comply with UK law

5. Data Sharing and Disclosure

We do not sell your personal data. We may share data with:

5.1 Service Providers

  • Hosting: Vercel (USA) - cloud hosting
  • Database: Supabase (EU/UK region) - data storage
  • AI Processing: Google Gemini AI - image analysis only when you request it

All service providers are contractually required to protect your data and use it only for specified purposes.

5.2 Community Sharing and Internal Review

If you choose to share parameters or cut profiles with the community, the technical profile data may be made visible to other users of the Service. Community-shared profiles are not publicly displayed with your account identity.

We may also review newly created, saved, or submitted cut profiles through internal administrator tools in order to moderate submissions, maintain quality, improve recommendations, improve the parameter database, and develop or refine the profiles and settings offered through the Service. Where possible, this review is carried out without publicly identifying the submitting customer to other users.

5.3 Legal Requirements

We may disclose data if required by law, court order, or to protect our legal rights.

6. International Data Transfers

Your data is primarily stored in EU/UK data centers. Some service providers (e.g., Vercel, Google) may process data in the USA. We ensure adequate safeguards are in place for such transfers, including:

  • Standard Contractual Clauses (SCCs)
  • Adequacy decisions where applicable
  • Certification under recognized frameworks

7. Data Retention

We retain your data as follows:

  • Account Data: Until you delete your account, then erased within 30 days
  • Saved Parameters: Until you delete them, or your account is deleted
  • Community-shared and internally reviewed profile data: Retained for as long as reasonably necessary for operation, moderation, quality control, service improvement, and database maintenance. Where profiles are no longer needed in identifiable form, we may retain de-identified or aggregated technical profile data
  • Usage Logs: 12 months for analytics and troubleshooting
  • Support Communications: 3 years for quality and legal purposes

8. Your Rights (UK GDPR)

You have the following rights:

  • Right of Access: Request a copy of your personal data
  • Right to Rectification: Correct inaccurate or incomplete data
  • Right to Erasure: Request deletion of your data ("right to be forgotten")
  • Right to Restriction: Limit how we process your data
  • Right to Data Portability: Receive your data in a structured, machine-readable format
  • Right to Object: Object to processing based on legitimate interests
  • Right to Withdraw Consent: Withdraw consent for optional features
  • Right to Complain: Lodge a complaint with the Information Commissioner's Office (ICO)

To exercise these rights, contact us at: support@dxfmachinery.com

9. Data Security

We implement appropriate technical and organizational measures to protect your data:

  • Encryption in transit (TLS/SSL)
  • Encryption at rest for sensitive data
  • Password hashing (bcrypt)
  • Regular security audits
  • Access controls and authentication
  • Backup and disaster recovery procedures

However, no system is 100% secure. You are responsible for keeping your account credentials confidential.

10. Cookies

We use the following types of cookies:

  • Essential Cookies: Required for authentication and basic functionality
  • Preference Cookies: Remember your settings and preferences
  • Analytics Cookies: Understand how you use the Service (anonymized)

You can control cookies through your browser settings, but this may affect Service functionality.

11. Children's Privacy

RIGHT.CUT is not intended for users under 18. We do not knowingly collect data from children. If we become aware that we have collected data from a child, we will delete it promptly.

12. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of significant changes via email or a notice in the Service. Continued use after changes constitutes acceptance.

13. Contact Information

For privacy questions or to exercise your rights:

DXF Manufacturing Ltd
Company Number: 12455731
Email: support@dxfmachinery.com

To complain to the UK data protection authority:

Information Commissioner's Office (ICO)
Website: ico.org.uk
Helpline: 0303 123 1113