kavtek

Version 2026-09-01

Privacy Notice — kavtek.eu

1 September 2026


1. Controller

KD18 holdings s.r.o.
Růžová 972/1, Nové Město, 110 00 Praha 1, Czech Republic
IČO: 17745837 · DIČ: CZ17745837
Commercial Register: Municipal Court in Prague, file C 375547
Privacy contact: info@kavtek.eu

We have not appointed a Data Protection Officer; none of the Art. 37(1) GDPR conditions applies to our processing. Requests concerning personal data go to the contact above.

2. What we process

Account and identity. Email; name if provided; password stored only as a salted cryptographic hash; language preference; account status; email-verification, password-reset and session records; and records of which version of which legal document you were shown or accepted, with timestamps.

Requests, quotes and orders. The technical content of what you ask us to make (technology, material, grade, colour, finish, tolerances, parameters, quantity, notes, intended use where stated); quotes with price, currency, validity, and your acceptance or rejection; order status history; production assignment and any problem note; carrier and tracking data; complaints and their resolution.

Model files. Uploaded 3D models (STL, STEP, STP, OBJ, up to 150 MB) and technical properties derived from them. Model files often embody confidential designs and are handled as described in section 6; a file can itself contain personal data in names or notes.

Delivery and billing details — collected when you accept a quote, because that is when they become necessary: recipient name, delivery address, the telephone number carriers require; a billing address if different; for businesses, company name, registration number and VAT ID. The order stores these as given at the time: later account changes do not rewrite an issued document, and address corrections are recorded with the previous version retained, so the history of a shipment or tax document can be established.

Payments and invoices. Order and payment references, amounts, currency, dates, payer information visible in bank records, pro forma documents and tax invoices. Payment is by bank transfer; we operate no card gateway and never see or store card numbers.

Guest submissions. Email and the consent/acknowledgement events given at submission. An unconfirmed guest request, including its uploaded file, is deleted after 7 days; the unconfirmed account is anonymised.

Communications. Messages sent via the contact form or email, with their content and attachments. Contact-form messages are delivered to our mailbox (they do not create a database record) and are covered by this Notice and the mailbox retention below.

Technical and security data. IP address, timestamps and requested URLs in server logs; session identifiers and authentication events; rate-limit and abuse-prevention data. We rate-limit authentication, submission and password-reset endpoints.

Advertising measurement. If you reached us from an advertisement and consented to advertising measurement: the identifier Google attached to that click, stored with your order; and an irreversibly hashed form (SHA-256) of the email address you gave us, sent to Google so that the order can be matched to the click. The address itself is never sent, the hash cannot be turned back into it, and we do not store the hash. See section 9 and the Cookie Notice.

Cookies and analytics — see section 9 and the Cookie Notice.

We do not process special categories of data (Art. 9). The service is intended for adults and businesses; we do not knowingly process children's data. No solely automated decision-making producing legal or similarly significant effects takes place (Art. 22): quotes are prepared by human engineers and order decisions are made by people.

3. Purposes and legal bases

Purpose Legal basis
Receiving and verifying a request (incl. holding an unconfirmed guest file up to 7 days) Art. 6(1)(b) — pre-contractual steps at your request; Art. 6(1)(f) for security
Account operation Art. 6(1)(b)
Review, quoting, manufacturing, delivery, support Art. 6(1)(b)
Determining VAT treatment and totals from your status, destination and VAT ID Art. 6(1)(b); Art. 6(1)(c) where tax law requires
Evidencing contract formation (accepted quote, Terms version, timestamps) Art. 6(1)(b); Art. 6(1)(f) — proving and defending the transaction
Transactional email (confirmation, quote ready, payment received, shipped with tracking, completion, password reset) Art. 6(1)(b); cannot be disabled while needed for an active order
Invoicing, accounting, tax records Art. 6(1)(c) — Act No. 563/1991 Coll.; Act No. 235/2004 Coll.
Complaints and legal claims Art. 6(1)(b), (c), (f) as applicable
Security, abuse prevention, logs Art. 6(1)(f)
Recording consents and document versions Art. 6(1)(c) — Art. 7(1) GDPR requires us to demonstrate them
Marketing email (only if you opt in; none currently sent) Art. 6(1)(a) — withdrawable at any time
Non-essential analytics cookies Consent under § 89(3) of Act No. 127/2005 Coll. and Art. 6(1)(a) GDPR
Advertising measurement: connecting an advertising click to a request or an order Art. 6(1)(a) — consent, given through the cookie banner and withdrawable at any time

Must you provide data? Email and the model file are needed to quote; delivery, billing and (for businesses) tax details are needed to conclude and perform an order. Without them we cannot quote, contract or deliver. Marketing and analytics consent are optional and change nothing about your orders.

4. Recipients

Only where necessary, and only these:

We do not sell personal data. Where you have consented to advertising measurement, we tell Google Ads that a click it sent us later became a request or an order, when it did, and for how much, together with a hashed form of your email address so that the two can be matched. We do not share your name, your address, your model files, or what you asked us to make.

5. International transfers

Our core infrastructure is in Germany (EU).

If you consent to analytics, measurement data is sent to Google's European endpoint (region1.google-analytics.com). For visitors in the EEA the controller for these analytics services is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. Google may onward-transfer data to Google LLC in the United States; such transfers rely on the EU–US Data Privacy Framework and standard contractual clauses. Per-cookie detail is in the Cookie Notice.

Manufacturing partners for orders we currently accept are located in the EU/EEA, Switzerland or the UK; the UK holds an EU adequacy decision.

6. Your model files

Stored in private object storage unreachable from the internet, accessed by the application with credentials scoped to one bucket. Access: you; staff who need the file to quote, produce or handle a claim; the partner manufacturing the part. Used solely for your order — never reused, never published, never used in marketing or case studies without your separate express permission.

7. Retention

Data Kept
Unconfirmed guest request + file 7 days
Account data While the account exists
Model files of completed orders 365 days after completion, then deleted — or earlier at your request
Order, quote and complaint records For the contract and the limitation period for claims
Invoices and tax documents, incl. the billing details on them 10 years (VAT Act); accounting records 5 years — retained even after account deletion (section 8)
Delivery addresses With the order; erased on account deletion
Consent and acceptance records As long as needed to demonstrate compliance and defend claims
Server and security logs 90 days
Contact-form / mailbox correspondence 3 years after the matter closes
Marketing preference Until withdrawn
Consent-record cookies (euconsent-v2, IABGPP_HDR_GppString) ~13 months
Analytics cookies (_ga, _ga_<id>), if you consent 2 years
Advertising cookies (_gcl_aw, _gcl_gb, _gcl_dc), if you consent 90 days
Advertising click identifier on an order With the order; erased on account deletion
Hashed email address Not stored — computed when you submit, sent, discarded

8. Account deletion

Request deletion in your account settings; an administrator reviews and carries out every request, and may postpone it while an order, complaint or payment is active.

Erased: name, email, credentials, uploaded model files, delivery addresses.

Retained: invoices and the billing details on them, for invoiced orders — a tax document is valid only if it identifies its buyer, and Czech law requires it to be kept for ten years. Basis: Art. 6(1)(c); Art. 17(3)(b) GDPR expressly permits refusing erasure where processing is necessary for a legal obligation. Data retained on this ground is access-restricted and deleted when the period ends.

9. Cookies and analytics

Strictly necessary: a session cookie that keeps you signed in, backed by a revocable server-side session, plus the cookies that record your consent decision. These require no consent (§ 89(3) of Act No. 127/2005 Coll.) — storing your refusal necessarily means storing something. They are itemised in the Cookie Notice.

Analytics (optional, consent-first). The public storefront uses Google Analytics 4 deployed through Google Tag Manager, governed by the InMobi consent-management platform:

What happens before you choose. Because the consent platform is delivered through the tag manager, loading it means one request to Google's servers before you have answered — that request is what brings you the banner. No analytics identifier is created, stored or transmitted at that point. We state this rather than claim that no contact occurs at all.

Advertising (optional, consent-first). We advertise on Google. After you consent to advertising storage, Google records which advertising click brought you here, and we report back to Google when such a click later produced a request or an order. The same "Cookie settings" control withdraws it, and refusing changes nothing about browsing, requesting a quote or ordering.

The exact cookies, providers, durations and transfer safeguards are in the Cookie Notice, which is kept synchronised with the deployed configuration.

10. Security

TLS in transit; salted password hashing; server-side revocable sessions; private object storage with narrowly scoped credentials; administrative access restricted to specific network addresses; rate limiting on sensitive endpoints; role-based internal access (engineers see what quoting needs and not delivery addresses; production sees what shipping needs; administrators the commercial record; customers only their own data).

If a breach is likely to risk your rights, we notify the supervisory authority within 72 hours (Art. 33) and you directly where the risk is high (Art. 34).

11. Your rights

Access (the account provides an immediate self-service export in machine-readable form); rectification (addresses on unshipped orders are correctable directly); erasure within the limits of section 8; restriction; portability; objection to legitimate-interest processing; withdrawal of consent at any time without affecting prior processing.

We respond within one month, extendable by two for complex requests with notice. Complaints: Úřad pro ochranu osobních údajů, Pplk. Sochora 27, 170 00 Praha 7 — uoou.gov.cz.

12. Changes

The current version is published with its identifier and date; material changes are announced to registered users by email before taking effect. Consent and acceptance records always reference the version you actually saw.