Privacy Policy
- Who we are
- Controller and processor — who is responsible for what
- What we collect
- Why we process it, and our legal basis
- Who else touches the data
- Where the data lives
- How long we keep it
- How it is protected
- A note for shops: telling your team
- Your rights
- Cookies and tracking
- Children
- Changes
- Contact and complaints
1. Who we are
CutterLog is operated by Brehau Softwares. For privacy questions, email contact@cutter-log.com.
2. Controller and processor — who is responsible for what
This distinction matters, and it is worth being clear about:
- For your employees' data — their names, email addresses, and the record of which of them logged which breakage — your organisation is the data controller and we are the processor. You decide what goes in; we process it on your instructions in order to run the service.
- For your account and billing data — the person who signed up, the billing contact, our correspondence with you — we are the controller.
If you need a signed Data Processing Agreement for your own compliance, email us and we will provide one.
3. What we collect
Account and people data
- Member records — name, email address, role (supervisor or operator), and the date the account was created or archived.
- Authentication — email and a password. Passwords are hashed by our authentication provider; we never see or store them in readable form.
- Organisation — your organisation's name, plan and billing status.
- Alert recipient — the one email address you configure to receive stock and breakage alerts.
Operational data you enter
- Tools, machines, assemblies, stock levels, prices, suppliers and settings.
- Consumption and breakage entries — date, tool, machine, quantity, reason, profile, job reference, notes, and which member recorded it.
- Material damage entries — date, profile, reason, quantity, lengths, notes, the member who recorded it, and optionally a photograph of the damaged material.
- Restock history.
Photographs are of material and parts. Please do not photograph people. If a person appears incidentally in an image, that image contains personal data and you as controller are responsible for it.
Technical data
- A log of alert emails sent for your organisation — recipient, type, and whether it succeeded. This backs the sending rate limit and lets us answer "why did I not get an alert".
- Standard server and security logs from our infrastructure providers, including IP addresses, retained for a short period for security and diagnostics.
We do not collect payment card details. When billing is enabled these go directly to our payment processor and never reach our systems.
4. Why we process it, and our legal basis
| What | Why | Legal basis (UK/EU GDPR) |
|---|---|---|
| Member accounts and sign-in | To let people use the service and to attribute entries correctly | Performance of a contract |
| Tool, log and material records | To provide the service you subscribed to | Performance of a contract |
| Alert emails | To notify you of low stock and repeated breakages, as you configured | Performance of a contract |
| Security and error logs | To keep the service secure, available and working | Legitimate interests |
| Billing records | To take payment and meet accounting obligations | Contract and legal obligation |
| Service emails about your account | To tell you about outages, changes and renewals | Legitimate interests |
We do not send marketing email to your team's addresses. If we ever send marketing to a billing contact, it will be with consent and with a working unsubscribe link.
5. Who else touches the data
We use a small number of providers. Each is bound by contract to protect the data.
| Provider | What for | Data involved |
|---|---|---|
| Supabase (and AWS beneath it) | Database, authentication, file storage | All application data, including member names, emails and photographs |
| Netlify | Hosting the website and application front end | Request logs and IP addresses. No application data is stored here. |
| Resend | Sending alert and account emails | Recipient email address and the message content |
| Sentry | Reporting application errors so we can find and fix faults | Technical diagnostics only — what the error was, which screen it happened on, the browser and version, and your organisation's id. No names, email addresses or IP addresses, and no recording of your screen. |
| Google (Google Analytics) | Measuring how the public website is used | Website usage only, and only for visitors who accept analytics cookies. No application data. IP addresses are anonymised. Transfers to the US rely on Google's certification under the EU-US Data Privacy Framework. |
| Stripe | Subscription payments | Billing contact and payment details, handled entirely by them |
We will update this list before adding a new provider that processes personal data. We do not sell or share your data with anyone else, and we do not use it for advertising.
We may disclose data if legally required to, and where we are permitted to tell you, we will.
6. Where the data lives
Your data is stored in our infrastructure provider's EU (Ireland) region. Some of our providers are based in the United States, so data may be transferred outside the UK and EEA. Where that happens, transfers are covered by the UK International Data Transfer Agreement and the EU Standard Contractual Clauses, or another lawful transfer mechanism.
Brehau Softwares is a company established in Brazil. Your data continues to be stored in the EU, but we may access it from Brazil in order to operate and support the service. Brazil is not covered by a UK or EU adequacy decision, so that access relies on the same safeguards — the UK International Data Transfer Agreement and the EU Standard Contractual Clauses.
7. How long we keep it
- While your subscription is active, we keep your data so the service works. History is the product — a breakage log with entries missing is not useful.
- Archived members are not deleted. When you remove someone's access, their account is archived rather than erased, because past log entries reference them and removing the row would leave your history saying an entry was made by nobody. Their name remains attached to the entries they made. Their sign-in stops working immediately.
- After cancellation, your organisation's data is kept for 60 days in a read-only state, then may be permanently deleted.
- Alert send logs are kept for 12 months.
- Billing records are kept for as long as tax law requires, typically 6–7 years.
If you need a specific person's record erased sooner, see section 10 — but note that as controller, that decision and its consequences for your records are yours.
8. How it is protected
- All traffic is encrypted in transit (TLS). Data is encrypted at rest by our infrastructure provider.
- Each organisation's data is isolated at the database level, not merely filtered in the interface. Every record belongs to exactly one organisation, and the database itself refuses cross-organisation access. We test this against the live API with real accounts rather than assuming it.
- Permissions are enforced by the database too: an operator cannot delete inventory or amend past log entries even if they bypass the interface entirely.
- Material damage photographs are held in private storage and served only through short-lived signed links.
- Sessions on shared terminals end when the browser tab is closed.
- Passwords are hashed by our authentication provider. Staff access to production data is limited to what is needed to operate and support the service.
No system is perfectly secure. If a breach affects your data and presents a risk, we will notify you without undue delay and, where required, the relevant supervisory authority within 72 hours.
9. A note for shops: telling your team
CutterLog records the name of the person who made each entry. That is the point — per-operator breakage patterns are how you spot a training need or a setup problem.
It also means the system holds a record of individual employees' activity. In most jurisdictions, you are legally required to tell your employees that this record exists, what it is used for, and how long it is kept — and in some, to carry out an assessment before introducing it. That obligation sits with you as their employer and data controller, not with us.
It is also simply better practice. A team told "this is so we can find out why tools keep breaking" behaves very differently from a team that discovers it is being logged.
10. Your rights
Under UK and EU data protection law, individuals have the right to access their data, to have inaccurate data corrected, to have data erased in some circumstances, to restrict or object to processing, and to data portability. Depending on where you live, similar rights may apply under other laws, including for residents of California and other US states.
Because we are established in Brazil, the Brazilian General Data Protection Law (LGPD, Lei nº 13.709/2018) also governs how we handle personal data. It gives comparable rights — confirmation that we process your data, access to it, correction of what is incomplete or inaccurate, anonymisation or deletion, portability, and information about who we share it with. You can exercise them the same way, using the contact details below.
If you are an employee of a CutterLog customer, please contact your employer first — they control your data and can act on most requests directly in the application. If you cannot reach them, contact us and we will help.
If you are a customer, email contact@cutter-log.com. We will respond within one month.
11. Cookies and tracking
This website uses Google Analytics, and only if you agree to it. Nothing is loaded and no request is made to Google unless you choose "Accept" on the cookie banner. If you decline, or simply ignore the banner, no analytics cookies are set and your visit is not measured.
We use it to see which pages people read before signing up, so we know what is worth explaining better. IP addresses are anonymised, the data is not used for advertising, and we do not sell it. You can change your choice at any time using the Cookie settings link in the footer.
We use no advertising trackers, no session recording, and no cross-site profiling of any kind, whatever your choice above.
The application stores only what it needs to function: your sign-in session (held in the browser tab and discarded when it closes) and your personal display preferences such as dark mode, currency and column choices, held in your browser's local storage. These are strictly necessary or set by you, are not used for tracking, and are not shared.
12. Children
CutterLog is a workplace tool and is not directed at children. We do not knowingly collect data from anyone under 16. Where an apprentice under 16 uses the system as an employee, their data is processed under your organisation's responsibility as employer.
13. Changes
We may update this policy. For material changes we will email your registered address at least 30 days beforehand. The "last updated" date at the top always reflects the current version.
14. Contact and complaints
contact@cutter-log.com
Brehau Softwares
If you are unhappy with how we have handled your data you can complain to your local supervisory authority. In Ireland that is the Data Protection Commission at dataprotection.ie, in the UK the Information Commissioner's Office at ico.org.uk, and in Brazil the Autoridade Nacional de Proteção de Dados at gov.br/anpd. We would appreciate the chance to put it right first.