Privacy Notice for the Instant Price Calculator
Last updated: 22 August 2026
1. Controller
The controller within the meaning of the General Data Protection Regulation (GDPR) is:
fexon e.K.
Owner: Christian Fischer
An Der Eisbahn 8
07973 Greiz
Germany
Phone: +49 3661 4555881
Email: info@fexon-blechbearbeitung.de
The full provider identification is available in the legal notice (Impressum).
2. Purposes, Legal Bases and Provision of Data
We process personal data to the extent necessary to provide and secure the calculator, to carry out calculations and requests, to set up a customer account, and to initiate, perform and invoice orders.
We rely in particular on the following legal bases:
- Article 6(1)(b) GDPR: pre-contractual measures and performance of a contract, in particular calculation, request, customer account, order, payment, production and delivery
- Article 6(1)(c) GDPR: compliance with legal obligations, in particular commercial- and tax-law retention and record-keeping obligations
- Article 6(1)(f) GDPR: our legitimate interests in secure and trouble-free operation, in preventing misuse and fraud, in asserting or defending legal claims, and in traceable order processing
- Article 6(1)(a) GDPR: only where we expressly ask for your consent for a separate, voluntary purpose
The fields marked as required in the calculator, the customer account and checkout are necessary for the respective calculation, request or contract. Without this information we cannot provide the requested function or process the order. Your acknowledgement of the privacy notice at checkout is recorded with a timestamp; it is not consent to the data processing required for performing the contract.
3. Hosting and Server Log Data
The calculator runs on a server operated by DigitalOcean, LLC. We have chosen a server location in Germany. DigitalOcean processes the data stored on the server infrastructure on our behalf. Further information is available in DigitalOcean's Data Processing Agreement.
On every visit, the server processes technically necessary connection and log data. This may include in particular the IP address, date and time, the address accessed, the amount of data transferred, the HTTP status, the referrer, and browser and device information. This processing serves to deliver the service, analyse errors, ensure system security, and defend against abusive access. The legal basis is Article 6(1)(f) GDPR.
Server log data is deleted as soon as it is no longer required for operation, error analysis and security. In the event of a specific security incident, affected log data may be retained until the matter is fully resolved and for the purpose of asserting or defending legal claims.
4. Technically Necessary Cookies and Sessions
The calculator uses technically necessary session information to match related requests, maintain login status, secure a shopping cart, and prevent unauthorised access to someone else's calculations or orders. This information is stored in a technically necessary session cookie. Without this cookie, essential functions of the calculator and checkout cannot be used.
For your language choice (German/English) we additionally set the technically necessary cookie lt_lang, which stores only this choice, is valid for one year, is set domain-wide on laserteile-online.eu (and therefore also applies to kalkulator.laserteile-online.eu), and likewise relies on Section 25(2) No. 2 TDDDG (German Telecommunications and Digital Services Data Protection Act).
Storage of, or access to, information on your device takes place, where applicable, on the basis of Section 25(2) No. 2 TDDDG. Any further processing is based, depending on the function, on Article 6(1)(b) or (f) GDPR.
5. Calculations and Uploaded CAD Files
For price calculation, we process the uploaded CAD files and technical drawings, together with the details you enter or that are derived from the files. This includes in particular the file name and file contents, geometry, dimensions, material, material thickness, quantity, requested processing steps, calculation results and technical review notes. For guest use, calculations are additionally secured against unauthorised access and misuse using session and IP data.
The purpose is automated technical evaluation, price calculation, quote preparation and - in the case of an order - production exactly according to the submitted customer data. The legal basis is Article 6(1)(b) GDPR. Security- and record-keeping-related processing is additionally based on Article 6(1)(f) GDPR.
The following retention periods currently apply to CAD files:
- Ordinary uploads without a saved request or order: deleted after 7 days
- Saved requests without an easybill quote: deleted after 30 days
- Requests with an easybill quote created: retained indefinitely, no automatic deletion period
- Files belonging to paid orders: retained for 2 years from the order date; the order file archive is then deleted
Order, invoice and accounting data that we are legally required to retain is not affected by deletion of the file archive. If you submit personal data or confidential information about third parties in your files, you must be authorised to do so and must limit the data to what is necessary for calculation and production.
6. AI Analysis Using Google Gemini
To support technical drawing analysis, we use the Gemini API. For a customer based in Germany, under the intended paid use, the recipient is Google Cloud EMEA Limited, 70 Sir John Rogerson's Quay, Dublin 2, Ireland. Depending on the drawing, image views or document pages, together with necessary accompanying information such as file names and position, material and dimension data, are transmitted to Gemini. The AI helps in particular to read technical details from drawings and to match them to line items.
The legal basis is Article 6(1)(b) GDPR, to the extent the analysis is necessary for the requested calculation or performance of the contract. In addition, we have a legitimate interest in an efficient, low-error technical pre-check under Article 6(1)(f) GDPR.
Production use for users in the European Economic Area is intended exclusively as a Gemini API Paid Service. Under the Gemini API Terms, Google does not use inputs and outputs from Paid Services to improve its products; time-limited logging for abuse detection and to comply with legal obligations may still take place. This may involve temporary processing in countries outside the European Economic Area. Google provides a data processing and international transfer framework for this purpose.
The AI does not make any final decision on the conclusion of the contract or on manufacturability. Before production begins, a member of our staff personally reviews the order and the technical data.
7. Sheet Metal Assistant (Beta)
The Sheet Metal Assistant is a new feature, still under development, for customers who do not have a CAD model of their sheet metal part. You describe the part in words, choose a part type from a catalog, or upload a sketch; from this we create a 3D model, a dimensioned review drawing and a non-binding preliminary calculation. Ordering through the assistant is not possible.
What we record. To assess whether and how this feature helps, we log your path through the assistant: the description you enter, an uploaded sketch, the result of automatic recognition, any dimensions you subsequently change, the part produced and the preliminary calculation. This log is tied to the technical session and contains no information about you personally unless you provide it to us.
Retention. These records, including uploaded sketches and entered descriptions, are deleted six months after they are created. After that, only anonymous monthly statistics remain (number of uses per entry path and part type, and the stage each reached), which no longer allow any link to a person or an individual session.
Requests from the assistant. If you submit the result as a request, we additionally process your email address and - to the extent you voluntarily provide them - your name, company, phone number and message, in order to prepare a quote for you. This information and the associated technical documents are likewise retained for six months; if a quote or an order results from it, the retention periods in Sections 5 and 10 apply instead.
The legal basis for creating the model, drawing and calculation, and for processing your request, is Article 6(1)(b) GDPR (taking steps prior to entering into a contract). The legal basis for logging the usage history is Article 6(1)(f) GDPR; our legitimate interest lies in evaluating and improving a new feature. Section 6 additionally applies to the transmission of an uploaded sketch to the AI.
8. Local GeoIP and Abuse Detection
For abuse detection, to identify conspicuous access patterns, and to enforce usage limits, we process the IP address and derive from it an approximate location, in particular country, region, city or postal code area, as well as indications of known VPN or proxy networks.
This evaluation is carried out exclusively locally on our server using locally stored databases. No customer IP address is transmitted to an external geolocation service for GeoIP or VPN checks. The data is not used for advertising or to create movement profiles. The legal basis is Article 6(1)(f) GDPR; our legitimate interest lies in protecting the calculator from automated or abusive access and in fairly enforcing usage limits.
IP and location data is stored only for as long as necessary for the respective calculation, security check or order, and to address specific cases of misuse. IP addresses of paid orders may be retained together with the order and consent records until the relevant record-keeping or limitation periods expire.
9. Customer Account
When you register a customer account, we process in particular your email address, username, password (stored encrypted), email confirmation status, and technical confirmation and password-reset tokens. If you set up a customer profile, we additionally process the contact, company, billing and delivery address details you provide there.
We use this data to provide the customer account, confirm your email address, secure login and account access, enable a password reset, and match calculations, requests or orders to the correct customer. The legal basis is Article 6(1)(b) GDPR; security measures are additionally based on Article 6(1)(f) GDPR.
Account data is stored until the customer account is deleted. Data that also belongs to an order, invoice or statutory record-keeping obligation may continue to be retained by us, in blocked form, after account deletion for the applicable statutory period.
10. Direct Order and Consent Records
For a direct purchase, we process in particular your name, email address, phone number, customer type, company, VAT identification number, billing and delivery address, ordered line items, prices, tax and shipping data, payment method, payment status, transaction references, IP address, browser information, and the time at which you acknowledged the Terms & Conditions, the right-of-withdrawal notice and this privacy notice.
This processing serves to conclude the contract, carry out the technical review, process payment, production, delivery and customer communication, issue invoices, and provide evidence of properly conducted order processing. The legal bases are Article 6(1)(b), (c) and (f) GDPR.
Order and invoice data is stored in accordance with statutory commercial- and tax-law retention obligations. Accounting vouchers are generally retained for eight years and commercial or business letters for generally six years; these periods generally begin at the end of the relevant calendar year. Where data is additionally required to assert or defend legal claims, it may be retained until the relevant limitation periods expire. For CAD files belonging to paid orders, the two-year period stated above applies instead.
11. Payment Processing via Stripe
For payments by credit card, Klarna, Google Pay and Apple Pay, we use Stripe. The contracting party for the Stripe services is Stripe Payments Europe, Limited, Ireland; for the provision of regulated payment services and for its own statutory purposes, other Stripe entities and involved payment service providers may also be responsible.
The order, contact and transaction data necessary for payment is transmitted to Stripe, in particular the order number, amount, currency, email address, chosen payment method and payment status. You enter payment data such as card or account details directly on the payment page provided by Stripe; it is not stored on our server. Stripe may process the data for payment processing, fraud prevention and to fulfil its own statutory obligations, and may pass it on to banks, card networks or the payment provider you selected.
The legal basis for our transmission is Article 6(1)(b) GDPR; security and fraud-prevention measures are additionally based on Article 6(1)(f) GDPR. Further information is available in Stripe's privacy policy.
12. Payment Processing via PayPal
If you choose PayPal, the order, contact and transaction data necessary for payment is transmitted to PayPal (Europe) S.à r.l. et Cie, S.C.A., 22–24 Boulevard Royal, L-2449 Luxembourg. This includes in particular the order number, amount, currency, payment status, and the account, device and payment data PayPal collects for payment processing and fraud prevention.
PayPal processes some data under its own data protection responsibility and may involve further companies or service providers within and outside the European Economic Area. According to its own statements, PayPal bases intra-group transfers, among other things, on approved binding corporate rules.
The legal basis for our transmission is Article 6(1)(b) GDPR; safeguarding against payment fraud is additionally based on Article 6(1)(f) GDPR. Further information is available in the PayPal Privacy Statement.
13. Invoicing with easybill
To create, manage and send quotes and invoices, we transmit the necessary customer, address, order, line-item, price, tax and payment data to easybill GmbH, Düsselstraße 21, 41564 Kaarst, Germany. easybill processes this data on our behalf. A data processing agreement under Article 28 GDPR is in place for this purpose.
The legal bases are Article 6(1)(b) GDPR for billing under the contract and Article 6(1)(c) GDPR for statutory invoicing and record-keeping obligations. Further information is available in easybill's privacy policy.
14. Email Delivery via Brevo
We send transactional and service messages such as email confirmation, password reset, request, order and payment confirmations, as well as internal notifications, via Brevo. The provider is Sendinblue GmbH, Germany, together with Sendinblue SAS, France. Which entity is the contracting party depends on the agreement applicable to our account.
For this purpose we process in particular the recipient and sender address, subject, message content, sending time, delivery status and technical delivery data. Internal order emails may include the CAD file archive as an attachment, provided its size allows this; otherwise a protected download link is sent instead. Brevo processes this data as a processor. According to the provider, the core infrastructure of the email service is located within the European Union; however, the involvement of sub-processors outside the European Economic Area cannot be fully excluded.
The legal basis is Article 6(1)(b) GDPR, to the extent the message is necessary for registration, a request or performance of the contract. Legally required notices are based on Article 6(1)(c) GDPR; ensuring reliable customer communication and delivery is based on Article 6(1)(f) GDPR. Further information is available in Brevo's privacy policy.
15. Review Request After Delivery
A few days after your order has been delivered, we send you a one-off email asking you to review our business. For this purpose we process your email address, first name, order number, and the delivery time reported by the shipping provider.
The legal basis is Article 6(1)(f) GDPR. Our legitimate interest lies in receiving feedback on services rendered and in advertising our own, similar services to existing customers; in doing so, we comply with the requirements of Section 7(3) UWG (German Act Against Unfair Competition).
You may object to this use of your address at any time, free of charge other than transmission costs at the basic rates. It is sufficient to use the unsubscribe link in the relevant email, or to send an informal message to info@fexon-blechbearbeitung.de. After an objection, we store your email address on a suppression list so that we can permanently honour your objection; the legal basis for this is Article 6(1)(c) GDPR.
Messages required to process your order - order confirmation, invoice and shipping information - are not affected by an objection and will continue to be sent.
The email contains a link to our company profile on Google. Simply receiving the email does not transmit any data to Google. Only when you follow the link do you leave our service; the privacy notices of Google Ireland Limited then apply. A review submitted there is publicly visible.
16. Contacting Us
If you contact us by email or phone, we process the contact and content details you provide, including any attached drawings, in order to answer your enquiry, prepare a quote, or process an existing order. The legal basis is Article 6(1)(b) GDPR for pre-contractual or contractual matters, and Article 6(1)(f) GDPR for other business enquiries.
Enquiry content is deleted once processing is complete and no statutory retention, record-keeping or limitation reasons prevent deletion. Business letters may be subject to statutory retention periods of generally six years.
17. Recipients and Processors
Within fexon e.K., access is limited to those staff members who need the data for calculation, technical review, customer support, production, accounting or IT operations. External recipients receive data only to the extent necessary for hosting, AI analysis, payment, invoicing, email delivery, shipping, legal advice, or compliance with statutory obligations.
Where service providers process data solely on our instructions, they are engaged as processors on the basis of an agreement under Article 28 GDPR. Payment service providers, banks, authorities or other bodies may themselves be responsible for their own statutory duties.
18. Data Transfers to Third Countries
In the case of DigitalOcean, Stripe, PayPal, Google, easybill and Brevo, processing by affiliated companies or sub-processors outside the European Economic Area, in particular in the USA, cannot be fully excluded despite European contractual or server locations. Such transfers take place only where the requirements of Articles 44 et seq. GDPR are met, in particular on the basis of an adequacy decision, approved binding corporate rules, or the European Commission's Standard Contractual Clauses, including any necessary supplementary safeguards.
19. Automated Price Calculation and Human Review
The calculator determines prices automatically based on the uploaded geometry and the chosen production parameters. This calculation alone does not result in a concluded contract. After you place an order, a member of our staff reviews the technical data and the plausibility of the price; the contract is only concluded through a separate order confirmation or by dispatch of the goods. There is therefore no decision based solely on automated processing with legal or similarly significant effects within the meaning of Article 22 GDPR.
20. Your Rights
Subject to the statutory requirements, you have the following rights:
- Access to your processed personal data under Article 15 GDPR
- Rectification of inaccurate data or completion of incomplete data under Article 16 GDPR
- Erasure under Article 17 GDPR, unless statutory retention obligations or other overriding grounds apply
- Restriction of processing under Article 18 GDPR
- Data portability under Article 20 GDPR, to the extent the statutory requirements are met
- Objection to processing based on Article 6(1)(e) or (f) GDPR under Article 21 GDPR
- Withdrawal of consent at any time with effect for the future under Article 7(3) GDPR; this does not affect the lawfulness of processing carried out before the withdrawal
To exercise your rights, a message to info@fexon-blechbearbeitung.de is sufficient. To protect your data, we may ask for reasonable proof of your identity.
21. Right to Lodge a Complaint with a Supervisory Authority
Under Article 77 GDPR, you have the right to lodge a complaint with a data protection supervisory authority. You may contact, in particular, the authority for your place of residence, your workplace, or the place of the alleged infringement. The authority responsible for us is:
Thuringian Commissioner for Data Protection and Freedom of Information (TLfDI)
Häßlerstraße 8
99096 Erfurt, Germany
Phone: +49 361 57-3112900
Email: poststelle@datenschutz.thueringen.de
Website: https://tlfdi.de/
22. Updates to This Privacy Notice
We update this privacy notice whenever the calculator, the service providers we use, or the legal situation change. The version published on this page at any given time is the applicable one.
Provider identification: Impressum (legal notice)