Data Protection & Privacy
Privacy Policy
Exo2STL is built on a zero-retention philosophy for dental CAD meshes. Uploaded preview files and generated STL files are stored temporarily in high-security, encrypted cloud storage (Cloudflare R2) with a strict 1-hour time-to-live. After 60 minutes, files are permanently and irreversibly purged from our servers. You may also trigger immediate deletion at any moment.
1. Introduction
Exo2STL (“we”, “our”, or “us”) provides an automated web service and API converting Exocad 3D preview HTML documents into binary STL meshes. This Privacy Policy details the types of information we collect, how that data is processed, and our strict safeguards regarding clinical file privacy and personal data protection under the General Data Protection Regulation (GDPR) and the Health Insurance Portability and Accountability Act (HIPAA).
2. Clinical CAD Data & Patient Information (HIPAA / GDPR)
As a technical file formatting utility, Exo2STL does not index, extract, catalog, or aggregate patient identities, patient medical records, or clinical diagnostic data.
- De-Identification Requirement: Users (dental clinicians, labs, and technicians) are required to ensure that files submitted for conversion do not contain unredacted Protected Health Information (PHI) or personal identifiable patient details.
- No Permanent Medical Records: We do not act as an electronic health record (EHR) custodian. Models converted through our pipeline are not archived or retained beyond the temporary 1-hour conversion lifecycle.
- No AI Model Training: Your uploaded 3D meshes, dental scan geometries, and files are never used to train machine learning models or artificial intelligence algorithms.
3. Information We Collect
To provide access to the platform and process payments, we collect minimal personal data:
4. How We Use Your Information
We use collected information solely for:
- Authenticating user sessions and providing access to the Clinical Portal;
- Tracking account conversion credits and processing Stripe checkout sessions;
- Executing algorithmic mesh extraction in secure, stateless serverless worker nodes;
- Defending our infrastructure against denial-of-service attacks, brute force, and abuse.
5. Infrastructure & Subprocessors
We partner with enterprise-grade cloud infrastructure providers that adhere to ISO 27001, SOC 2 Type II, and GDPR compliance standards:
Cloudflare, Inc.
Global edge hosting (Pages), D1 encrypted database, and ephemeral object storage (R2).
Amazon Web Services (AWS)
Stateless Lambda execution environment executing sandboxed mesh extraction.
Stripe, Inc.
PCI-DSS Level 1 certified payment processing for credit purchases.
Google LLC
Optional OAuth 2.0 social identity verification and sign-in provider.
6. Data Retention & Destruction Lifecycle
Our data retention schedule is strictly enforced:
- Uploaded HTML Documents: Automatically deleted via Cloudflare R2 bucket lifecycle rules after 1 hour.
- Generated STL Archives: Automatically deleted via Cloudflare R2 bucket lifecycle rules after 1 hour.
- Manual Purge: Clicking “Purge Cloud Data Now” in the dashboard deletes both the source file and STL archive immediately.
- Account Data: Retained until the user requests account deletion.
8. Your Rights Under GDPR & CCPA
Depending on your location, you hold statutory rights regarding your personal information:
- Right of Access & Portability: You may request a copy of the personal data held about you;
- Right to Rectification: You may update your account details at any time;
- Right to Erasure (“Right to be Forgotten”): You may request complete deletion of your account and related records;
- Right to Object: You may object to data processing based on legitimate interests.
9. Security Safeguards
All communications between your browser, our edge workers, and storage endpoints are encrypted in transit using Transport Layer Security (TLS 1.3). Cloud storage repositories are encrypted at rest using industry-standard AES-256 encryption. We enforce least-privilege IAM credentials across all cloud microservices.
10. Contact Us
If you have questions about this Privacy Policy or wish to exercise your data rights, please contact:
Privacy Office: [email protected]