WoodMinded Designer
Privacy Policy
Last updated: July 28, 2026
1. Who we are (data controller)
WoodMinded Designer ("WoodMinded", "we", "us") is an online woodworking design application available at woodminded.com and app.woodminded.com. The controller responsible for the processing of personal data described in this policy is:
ELIORA ApS
Vadumvej 16
7860 Spøttrup, Denmark
Company registration (CVR) no.: 43577646
Email: hello@woodminded.com
We have not appointed a statutory Data Protection Officer, as we are not legally required to do so. For any privacy matter, please use the contact details above.
2. Scope of this policy
This policy explains how we collect, use, share, and protect personal data when you visit our website, create an account, and use the WoodMinded Designer application. Because we are established in the European Union, this policy is based on the EU General Data Protection Regulation (GDPR) and applicable Danish data protection law, and it applies regardless of where you access the service from.
3. Data we collect
We collect and process the following categories of personal data:
Account data — the information you provide when registering and managing your account, such as your name (if provided), email address, and authentication credentials (passwords are stored only in hashed form).
Profile and preference data — settings such as your language, measurement units, and other workspace preferences.
Project and design content — the designs, projects, files, and related data you create, upload, or save in the application.
Billing and subscription data — your subscription status, plan, and transaction history. Payments are processed by Stripe; we do not receive or store complete payment-card numbers (see Section 5).
Contact data — your name, email address, selected topic, message, and technical anti-spam information when you use our contact form.
Technical, usage, and log data — information generated automatically when you use the service, such as your IP address, device and browser type, session identifiers, timestamps, error logs, and information about how features are used. This is necessary to operate, secure, and improve the service.
You are not legally obliged to provide your data, but account, billing, and certain technical data are necessary to create an account and use the service. Without them, we cannot provide WoodMinded Designer to you.
4. How we use your data and our legal bases
We process your personal data only where we have a legal basis under Article 6(1) GDPR:
To provide the service and answer requests (Art. 6(1)(b) — performance of a contract): to create and authenticate your account, provide the design workspace, store your projects, generate exports, manage your subscription and billing, and respond to service-related contact requests.
To operate, secure, and improve the service (Art. 6(1)(f) — legitimate interests): to maintain security and prevent abuse, ensure reliability, diagnose errors, and understand feature usage so we can improve the product. Where we rely on legitimate interests, we balance those interests against your rights and freedoms, and you may object as described in Section 11.
To comply with legal obligations (Art. 6(1)(c)): for example to retain accounting and tax records and to respond to lawful requests.
With your consent (Art. 6(1)(a)): where we specifically ask for it, for example for any non-essential communications. You may withdraw consent at any time without affecting processing carried out before withdrawal.
We do not use your personal data for automated decision-making that produces legal or similarly significant effects, and we do not sell your personal data.
5. Payments
Subscription payments are processed by Stripe (Stripe, Inc. and its group companies). When you make a payment, your card and payment details are provided directly to Stripe and processed under Stripe's own terms and privacy policy. WoodMinded Designer does not store complete payment-card details; we receive only limited information such as your subscription status and confirmation of payment. Stripe acts as an independent controller and/or processor for payment data as described in its own documentation.
6. Service providers and recipients
We share personal data only with providers who help us operate the service, and only as necessary. These include:
Hosting and infrastructure: ALL-INKL.COM – Neue Medien Münnich (Germany, EU), which hosts the application and stores account and project data on our behalf as a data processor.
Payment processing: Stripe, as described in Section 5.
Self-hosted analytics: Matomo, operated through our analytics endpoint at zone-seven.de, is used only after you give analytics consent. The analytics data remains under our control.
These providers are bound by contractual data-protection obligations (including data processing agreements where they act as processors) and may only process your data on our instructions or as required by law. We may also disclose data where required by law, court order, or to protect our legal rights.
7. International data transfers
Our hosting provider is located within the EU. Some providers, such as Stripe, may process data outside the European Economic Area (for example in the United States). Where personal data is transferred outside the EEA, we rely on appropriate safeguards recognised under the GDPR, such as the European Commission's Standard Contractual Clauses or an applicable adequacy decision. You may request further information about these safeguards using the contact details in Section 1.
8. Cookies, sessions and analytics
We use essential session cookies to keep you signed in and to protect account actions (for example against cross-site request forgery). These cookies are strictly necessary for the application to function and do not require consent.
With your consent, we use our self-hosted Matomo analytics system to measure page views, referrers, device and browser information, campaign attribution, feature usage, funnel steps, and subscription conversions. For signed-in users, Matomo receives a pseudonymous account identifier such as wm-123 so activity can be connected across sessions and the marketing site and application. We do not send project content, entered text, passwords, contact-form messages, or complete payment-card details to Matomo.
Matomo uses first-party analytics cookies, including identifiers used to distinguish visits and connect actions within a session. Analytics processing is based on your consent under Article 6(1)(a) GDPR. You can refuse analytics without losing access to the service and can change your choice at any time using the “Privacy settings” control displayed on the website and in the application. We do not use advertising cookies or sell analytics data.
9. Data retention
We retain account and project data for as long as your account is active or as needed to provide the service. Raw Matomo visitor data is generally retained for up to 12 months; aggregated reports may be retained for longer. Contact-form messages are generally retained for up to 12 months after the request has been resolved, unless longer retention is necessary for an ongoing contractual or legal matter. If you close your account or request deletion, we delete or anonymise your personal data within a reasonable period, except where we are required to retain certain information to comply with legal obligations (for example, billing and accounting records, which under Danish law are generally kept for up to five years) or to establish, exercise, or defend legal claims. Backup copies are deleted in the ordinary course of our backup cycle.
10. Security
We use reasonable technical and organisational measures to protect personal data against unauthorised access, loss, or misuse, including encrypted transport (TLS), hashed password storage, and access controls. No online service can guarantee absolute security, and you are responsible for keeping your login credentials confidential. In the event of a personal data breach that is likely to result in a risk to your rights, we will notify the competent supervisory authority and, where required, affected users in accordance with the GDPR.
11. Your rights
Subject to the conditions and exceptions in applicable law, you have the right to: request access to your personal data; request rectification of inaccurate data; request erasure ("right to be forgotten"); request restriction of processing; object to processing based on our legitimate interests; receive your data in a portable, machine-readable format (data portability); and withdraw consent at any time where processing is based on consent.
To exercise any of these rights, contact us at hello@woodminded.com. We will respond within the time limits set by the GDPR (generally one month). We may need to verify your identity before acting on a request.
If you believe our processing of your personal data infringes data protection law, you have the right to lodge a complaint with a supervisory authority. In Denmark, this is:
Datatilsynet (Danish Data Protection Agency)
Carl Jacobsens Vej 35, 2500 Valby, Denmark
Phone: +45 33 19 32 00 · Email: dt@datatilsynet.dk
Website: www.datatilsynet.dk
You may also contact the supervisory authority in your own EU/EEA country of residence.
12. Children
WoodMinded Designer is intended for adults and is not directed at children. We do not knowingly collect personal data from children under the age of 16 (or the applicable age of digital consent in your country). If you believe a child has provided us with personal data, please contact us and we will delete it.
13. Changes to this policy
We may update this Privacy Policy from time to time to reflect changes in our service or legal requirements. When we make material changes, we will update the "Last updated" date above and, where appropriate, notify you. Your continued use of the service after an update constitutes acceptance of the revised policy.
14. Contact
For privacy questions or requests, email hello@woodminded.com.