Privacy Policy
Flexam Technologies GmbH
Version: August 2026 · Effective 15 August 2026
1. Who we are
The controller responsible for the processing described here is:
Flexam Technologies GmbH
Dr.-Karl-Lueger-Platz 5
1010 Vienna
Austria
Email: hello@flexam.tech
Website: https://flexam.tech
2. Scope
This Privacy Policy applies to flexam.tech and its subdomains, including our public website, our account and sign-in system, and our authenticated product applications:
- Flexam Slicer — preparing and slicing models for robotic additive manufacturing
- Flexam Toolpath Editor — reviewing and editing machine code
Not every processing activity described below applies to every product. Where something applies only to a specific product or only when you use a specific feature, we say so.
3. Account and authentication data
To use our authenticated products you need an account. We process the identifier, email address, display name, and group or role assignments held for your account, together with sign-in events and related security records.
We also record that you accepted the Terms of Use and this Privacy Policy, including the version accepted and the time of acceptance.
Legal basis: Art. 6(1)(b) GDPR to provide the account and the product functionality you request, and Art. 6(1)(f) GDPR for the security and integrity of the sign-in process.
4. Product use and technical data
When you use our products we process technical data needed to deliver and operate them, such as IP address, date and time of access, browser and device information, requested pages or endpoints, errors, and performance data. Our applications and infrastructure keep operational logs for this purpose.
Legal basis: Art. 6(1)(b) GDPR to provide the requested functionality, and Art. 6(1)(f) GDPR for security, reliability, abuse prevention, and necessary diagnostics.
5. Cookies and local storage
Our public website uses only storage required for basic functionality and security.
In our product applications, cookies and browser local storage are also used to keep you signed in, to remember interface preferences and the acceptance you have given, and — where the product analytics described in the next section are active — by our analytics provider to recognise a returning session. We do not use advertising or remarketing cookies.
6. Product analytics and session replay
Selected Flexam applications use PostHog, in its EU region, to understand how features are used, to diagnose problems, and to improve the product. We have a data processing agreement in place with PostHog.
Depending on how the product is configured, the data processed through PostHog may include:
- a user or account identifier
- page or screen views
- clicks and product actions
- browser and device data
- network information derived from your IP address
- errors and performance data
- session replay — a reconstruction of your interaction with the application
Session replay records how the application appeared and behaved while you used it. This can include the content visible on screen within the application at that time.
We do not use PostHog for advertising, and we do not use it to train AI models.
How this is presented in each product:
- Flexam Slicer presents the Terms of Use and this Privacy Policy for acceptance before you are redirected to sign in. Analytics start only once that acceptance has been recorded.
- Flexam Toolpath Editor does not have its own username and password sign-in. On first visit it shows a dialog describing this processing; analytics start only once you agree there.
Legal basis: Art. 6(1)(a) GDPR, consent, where this processing relies on consent. You can withdraw your agreement at any time by contacting us at hello@flexam.tech; withdrawal takes effect for future processing.
7. AI-powered features
Some Flexam products offer features powered by large language models. Where you invoke such a feature, the content you submit to it — together with the operational context needed to answer, such as the relevant file or machine-code content — is transmitted to the AI provider configured for that feature and processed to generate a response.
We currently use Google Cloud (Vertex AI) and OpenAI as AI providers for these features. This applies only where an AI-powered feature is enabled and you actively use it.
Legal basis: Art. 6(1)(b) GDPR, to deliver the feature you requested.
8. Files, intermediate data, and generated artifacts
Our products process the files you upload — for example geometry and configuration — along with intermediate data and the artifacts generated from them, such as machine code, toolpaths, previews, and job records. This processing is what delivers the product function you asked for, and the data is stored so you can return to your projects and jobs.
Where you separately opt in, we may also use uploaded data in anonymized or pseudonymized form to improve our software.
Legal basis: Art. 6(1)(b) GDPR for providing the product, and Art. 6(1)(a) GDPR, consent, for any separately opted-in use.
9. Website contact form
When you use the contact form or contact us by email, we process the information you provide, such as your name, company or organization, email address, and message content, in order to respond.
We use Formspree to process messages submitted through the contact form on this website. Formspree acts as a processor and states that its services are hosted on AWS in the United States and that it relies on Standard Contractual Clauses for GDPR-related international transfers. Messages delivered to our business email may be processed through Google Workspace.
We do not use contact form data for advertising, profiling, newsletter automation, or CRM enrichment.
Legal basis: Art. 6(1)(b) GDPR where your request relates to a possible business relationship, and Art. 6(1)(f) GDPR for our legitimate interest in responding to inquiries.
10. Processors we use
We use the following categories of service providers to operate the website and our products:
- hosting and infrastructure providers, for servers, storage, and network delivery
- product analytics and session replay — PostHog (EU region)
- AI model providers — Google Cloud (Vertex AI) and OpenAI, where an AI-powered feature is used
- contact form processing — Formspree
- business email and productivity — Google Workspace
We do not share personal data with third parties for advertising or unrelated commercial purposes, and we do not sell personal data.
11. International transfers
Some of the providers above are established outside the European Economic Area or may process data outside it. Where that is the case, we rely on the transfer mechanisms available under Chapter V of the GDPR, in particular Standard Contractual Clauses, together with the safeguards offered by the provider.
We select EU regions where a provider offers them and it is practical to do so — our PostHog instance runs in the EU region — but we do not claim that every provider stores all data exclusively within the EU.
12. Retention
- Product analytics events: up to 12 months.
- Session recordings: up to 30 days.
- Account and consent records: for as long as the account exists, and afterwards where a legal retention obligation applies.
- Project files, jobs, and generated artifacts: for as long as the account exists or until you delete them.
- Inquiry data: as long as needed to handle the request and the related communication, unless a legal retention obligation requires longer.
- Technical logs: for a limited period necessary for security and operation.
13. Your rights
Under the GDPR you may have the right to request access, correction, deletion, restriction, and data portability, to object to processing based on legitimate interests, and to withdraw consent you have given, with effect for the future.
To exercise your rights, contact us at hello@flexam.tech.
You also have the right to lodge a complaint with a supervisory authority. The competent authority for us is:
Austrian Data Protection Authority
Barichgasse 40-42
1030 Vienna
Austria
https://www.dsb.gv.at
14. Security
Our products are served over encrypted connections, access to the authenticated applications requires sign-in, and access to production systems is limited to the people who need it. We take reasonable technical and organizational measures appropriate to the risk. No system can be guaranteed to be entirely secure.
15. Changes to this policy
We may update this Privacy Policy when our website, our products, or legal requirements change. The current version and its effective date are shown at the top of this page.
16. Legal Notice
Company identification details are set out in our Legal Notice.