Privacy Policy
This is a plain-language explanation of what data motordevs collects, why, and what your rights are. The legally binding text is the English version below. If anything is unclear, email [email protected].
1. Who we are
motordevs is electromagnetic engineering software for designing electric machines. The data controller (Greek: υπεύθυνος επεξεργασίας) is currently Giorgos Sakkas, operating as a sole trader in Greece, reachable at [email protected].
Planned change of controller. We intend, in the foreseeable future, to register a Greek single-member private limited company (Ι.Κ.Ε.) and to transfer operation of motordevs to that company. When that happens, the new entity will become the data controller. Before the transfer takes effect we will:
- notify all account holders by email at least 30 days in advance, naming the new entity, its registered office, and its contact details;
- confirm that the new entity has agreed in writing to be bound by privacy terms no less protective than this Privacy Policy in force at the time of transfer;
- give you the option to delete your account before the transfer, with full pro-rated refund of any unused prepaid period and no other detriment.
If you do not delete your account before the transfer date, your account, content, and continued use of the service will be on the basis of the new controller's privacy policy, which we will send you in advance.
2. What we collect and why
2.1 Identity data (Google sign-in)
When you sign in with Google we receive your email address, display name, and profile picture URL. We use these to create your account and address you in the interface. Legal basis: performance of the contract (GDPR Art. 6(1)(b)).
2.2 Designs and computed results
Motor specifications, analysis configurations, and computed results you create or upload. Stored so you can return to them later. You own this content (see Terms § 9). Legal basis: performance of the contract (Art. 6(1)(b)).
2.3 Usage logs
Standard server access logs — IP address, timestamp, the URL or endpoint accessed, request size, response status, and basic browser information from the User-Agent header. We use these logs to:
- (a) operate the service and diagnose errors;
- (b) detect and investigate abuse, attempted intrusion, and misuse of compute quotas;
- (c) measure aggregate load to plan capacity.
Legal basis: GDPR Art. 6(1)(f) — legitimate interests, namely the security and integrity of our service and the prevention of abuse. We have assessed that this processing is necessary, proportionate, and consistent with the reasonable expectations of users of an engineering compute service. You may object to this processing under Art. 21 GDPR (see § 7); we will then weigh your individual circumstances against our interests.
Logs are rotated routinely; entries older than 30 days are purged unless we have a specific reason to retain them (for example, an active abuse investigation), in which case they are kept for as long as that purpose requires.
2.4 Billing data (only if you pay)
Payment cards are handled entirely by Stripe — we never see them. We retain transaction records (amount, date, plan, your VAT number if you provided one) to issue invoices and meet our tax obligations. Legal basis: contract performance and legal obligation (Art. 6(1)(b) and (c)).
3. What we do not do
- No third-party advertising trackers.
- No analytics that follow you across other sites.
- No selling, renting, or sharing of your data with third parties for their own purposes.
- No AI/ML training on your designs or results. Your motor specifications and computed outputs are never used to train any artificial-intelligence model, ours or anyone else's.
4. How we use it
Strictly to deliver the service: authenticate you, store your designs, run computations, deliver results, bill you correctly when applicable, and contact you about your account or material service changes.
5. Where it lives — sub-processors
We use the following data processors. Each is bound by a written data-processing agreement with terms at least as protective as this policy.
| Sub-processor | Purpose | Location | Transfer mechanism |
|---|---|---|---|
| Supabase, Inc. (operating EU instance hosted in Frankfurt) | Authentication, Postgres database, real-time | EU (Frankfurt) | Standard Contractual Clauses (Modules 2 and 3) |
| Cloudflare, Inc. (Pages + R2) | Static site hosting; object storage for design files and results | EU primary; global CDN for static, non-personal assets only | EU-US Data Privacy Framework (active certification) + Standard Contractual Clauses |
| Google LLC (OAuth only) | Sign-in; we receive only email + name + profile picture URL | USA | EU-US Data Privacy Framework (active certification) |
| Stripe Technology Company, Limited (Ireland) — primary EU contracting entity; Stripe Payment Europe, Limited (Ireland) — regulated payments entity; Stripe, Inc. (USA) — group parent and onward processor | Payment processing for paid plans | EU/Ireland for primary processing; USA for some onward processing | EU-US Data Privacy Framework (active certification) + Standard Contractual Clauses |
We will update this list at least 30 days before introducing a new sub-processor that handles personal data, by email to active account holders. If you object to the new sub-processor on reasonable data-protection grounds, you may terminate your account and receive a pro-rated refund of any unused prepaid period before the change takes effect.
Business customers — Data Processing Agreement. If you upload designs or other content that contains personal data of third parties (your employees, contractors, or end clients), motordevs acts as a processor and you act as the controller within the meaning of GDPR Art. 4. The terms of that controller-processor relationship are set out in our Data Processing Agreement, available at motordevs.com/dpa, and are incorporated by reference into the contract you formed when you accepted the Terms of Service.
6. How long we keep it
- Account data — for as long as your account is active, plus a maximum of 30 days in backups after deletion.
- Designs, configurations, and results — same as account data. You can delete individual items at any time.
- Server access logs — rotated routinely; older than 30 days are purged.
- Billing and tax records — five (5) years from the end of the financial year to which they relate, as required by Art. 7 Law 4308/2014 (Greek Accounting Standards) and Arts 13 and 36 Law 5104/2024 (Greek Code of Tax Procedure). This period may extend to twenty (20) years where the tax authorities open an investigation alleging tax evasion in respect of the relevant period (Art. 36(2) Law 5104/2024). The legal basis for this retention is GDPR Art. 6(1)(c) — compliance with a legal obligation.
- Limited records of abuse / suspended accounts — retained as long as necessary to enforce our Terms and prevent recurrence.
7. Your rights under GDPR
You can ask us to:
- show you all the data we hold about you (Art. 15 — right of access);
- correct anything that is wrong (Art. 16);
- delete your account and all associated data (Art. 17 — right to erasure);
- limit how we process your data while you contest it (Art. 18);
- export your designs and results in a portable format (Art. 20 — right to data portability);
- object to processing based on legitimate interest (Art. 21);
- withdraw any specific consent you have given us, at any time, with no detriment to other processing (Art. 7(3)).
Email [email protected]. We respond within 30 days as required by Art. 12(3). We may extend by up to 60 days for complex requests, and will tell you if we do.
You also have the right under Art. 77(1) GDPR to lodge a complaint with a supervisory authority. You may do so with the supervisory authority of the EU/EEA member state of your habitual residence, your place of work, or the place of the alleged infringement.
The Greek supervisory authority is the Hellenic Data Protection Authority — Αρχή Προστασίας Δεδομένων Προσωπικού Χαρακτήρα, Kifisias 1-3, 11523 Athens, phone +30 210 6475600, email [email protected], www.dpa.gr. A list of EU/EEA supervisory authorities is maintained by the European Data Protection Board at edpb.europa.eu.
8. Cookies
We use a single essential cookie set by Supabase to keep you signed in. Under Greek Law 4624/2019 Art. 4 and the ePrivacy Directive, consent is required only for non-essential cookies — and we don't use any. You can clear the session cookie any time from your browser; doing so signs you out.
9. International data transfers
Personal data is processed primarily in the EU (Frankfurt). Where any transfer to a third country occurs (e.g. Stripe in the US), the transfer relies on adequacy decisions or Standard Contractual Clauses approved by the European Commission, supplemented by the EU-US Data Privacy Framework where applicable. We do not transfer your designs, computed results, or any free-text content outside the EU.
10. Children
motordevs is not directed at, and is not intended for use by, any person under 16. We do not knowingly collect personal data from children. If you believe a child has signed up, please contact us and we will delete the account immediately.
11. Security
Communication uses HTTPS in transit. Data at rest is encrypted by our sub-processors using industry standards (AES-256 or equivalent). Passwords never reach us — sign-in goes through Google. We follow the principle of least privilege internally.
No system is perfectly secure. If we discover a personal data breach affecting you, we will notify you and the Hellenic DPA within 72 hours of becoming aware, as required by GDPR Art. 33–34.
12. Changes to this policy
Material changes (new categories of data, new sub-processors, new purposes) will be emailed to all registered users at least 30 days before they take effect. Cosmetic edits (typo fixes, clearer wording) ship without notice.