Privacy Policy
Last updated: September 2026 · Version 2026-09
1. Who we are
NouSynth AIDA is operated by Luca Bottero (sole proprietor) — P.IVA 04063950044, Strada Gandini 6/c, 12042 Bra (CN), Italy — trading as NouSynth™ (“we”, “us”, “our”). We are the data controller for personal data processed through this platform. Contact (PEC): [email protected].
2. What data we collect and why
- Account data (name, email, organisation) — to authenticate you and operate your account.
- Usage data (parts created, AI interactions, session logs) — to deliver and improve the service.
- Technical data (IP address, browser type, device) — for security and fraud prevention.
- Consent records — to demonstrate compliance with GDPR Article 7.
We do not collect data beyond what is necessary for these purposes (data minimisation, GDPR Art. 5(1)(c)).
3. Legal basis for processing
- Contract performance (Art. 6(1)(b)) — processing necessary to provide the service you signed up for.
- Consent (Art. 6(1)(a)) — for any processing beyond service delivery, explicitly obtained at account creation.
- Legitimate interests (Art. 6(1)(f)) — security monitoring, abuse prevention.
- Legal obligation (Art. 6(1)(c)) — where required by EU or member-state law.
4. Your designs, and what we may do with them
A design you make here exists in two forms, and they are governed differently. The full rules are in the Terms of Service, Section 3; this section states the same thing in data-protection terms, because it is the part of our contract most likely to matter to you.
- What you export — STL, STEP, drawing sheets, documents and data files you download — is yours, on every plan, without limitation, for good. We place no restriction on using, modifying, manufacturing, publishing or selling it, and that does not end when your contract does.
- What stays inside the platform — the parametric source code AIDA writes, the parameter set it extracts, previews, checks, measurements, run transcripts and the indexes built from them (together, the “Platform Representation”) — is produced by our systems, belongs to us, and what we may do with it is set by the data tier of your plan.
The data tier is a property of your plan, shown on it in Billing. It takes one of three values — broad, standard or private — and they mean exactly what Terms §3.4 says they mean. In short: the cheaper plans pay partly in data, and the private tier does not.
Where a Platform Representation happens to contain personal data — a name in a title block, an email in a prompt — that data is processed under the same tier. Under the private tier it is never used to train a model, never becomes an example, and is read by a person only where a fault or your own support request requires it.
5. Data sharing
- Within your organisation — data is shared with other members of your tenant according to role-based permissions.
- With other organisations — only for parts you explicitly publish to the Community library (Section 7), or as Terms §3.4 permits for your plan’s data tier.
- Service providers — infrastructure providers (hosting, email delivery) and the AI model providers that run a generation, under data processing agreements (GDPR Art. 28).
- Legal requirements — where compelled by a court order or applicable law. We will notify you unless prohibited.
We do not sell personal data. Ever.
6. Where your data is processed
The platform is hosted in the European Union. Generating a design sends the text and images you provide to AI model providers who may process them outside the EU; those transfers are covered by the European Commission’s Standard Contractual Clauses. Our providers are contractually barred from training their own models on what we send them.
7. Community sharing (optional, off by default)
Your parts are private to your organisation unless you choose to publish one to the Community library. Nothing is shared automatically, and no part is ever published on your behalf. This is separate from the data tier in Section 4: publishing is a decision you take part by part.
When you publish a part, the following becomes visible to every other organisation using the platform:
- The part’s name, description, tags and engineering metadata (for example the standard designation it conforms to).
- Its preview image and 3D geometry, and the downloadable geometry files.
- The name of your organisation, shown as the contributor.
- A count of how many organisations have taken a copy.
The following is never shared, whatever you publish:
- The text of the requests you typed to generate the part.
- Any link to the chat session it came from.
- Any other part, project or assembly in your workspace.
Be aware that where your organisation name identifies an individual — for example a sole trader trading under their own name — publishing a part makes that name public to other organisations on the platform. Consider that before you publish.
Withdrawal: you may unpublish a part at any time, from the part’s sharing dialog. This stops any new copies being taken. Copies that other organisations have already taken are their own records in their own workspace and remain with them — in the same way that withdrawing a book from sale does not recall the copies already sold. We tell you how many copies exist at the moment you withdraw.
Taking a copy of a community part records that you did so, so that contributors can see how widely their work is used and so we can investigate misuse.
8. Data retention
Account data is retained for the duration of your contract plus 12 months, after which it is anonymised or deleted. You may request earlier deletion at any time (see Section 9). Audit logs are retained for up to 5 years to satisfy legal obligations.
Material already incorporated into a trained model or a retrieval corpus under a broad or standard tier is addressed by Terms §3.5, which explains plainly what deletion can and cannot reach.
9. Your rights under GDPR
You have the following rights, exercisable via your Account Settings or by writing to us at the address in Section 1:
- Access — obtain a copy of your personal data (Art. 15).
- Rectification — correct inaccurate data (Art. 16).
- Erasure — request deletion of your account and personal data (Art. 17). Note: parts and assemblies you created belong to your organisation and are retained.
- Portability — receive your data in a machine-readable format (Art. 20).
- Restriction — limit processing in certain circumstances (Art. 18).
- Objection — object to processing based on legitimate interests (Art. 21).
- Withdraw consent — at any time, without affecting prior lawful processing.
You also have the right to lodge a complaint with a supervisory authority — in Italy, the Garante per la protezione dei dati personali — in particular in the EU member state of your habitual residence.
10. Security
We implement appropriate technical and organisational measures including: bcrypt password hashing, AES-256 encryption for sensitive fields, TLS in transit, audit logging, and account lockout policies. No method of transmission is 100% secure; we cannot guarantee absolute security.
11. Children
The platform is not intended for users under 16. We do not knowingly collect data from minors.
12. Changes to this policy
Material changes will be notified to active users by email and require renewed consent at next sign-in. The version number at the top of this page identifies the current policy version stored against your consent record.
13. Language
This document is published in English and Italian. The English text is the authoritative one: where the two differ, the English governs. The law that applies and the courts that hear a dispute are Italian either way.
© 2026 Luca Bottero · NouSynth™