Who we are
Hardwire Electronics Ltd is responsible for the personal information described in this policy. We are a company registered in England and Wales, company number 12091276. Our registered office is Unit 2E, Roxby Road Industrial Estate, Enterprise Way, Winterton, Scunthorpe, DN15 9SU, United Kingdom.
For privacy questions or requests, write to our registered office or email contact@loom3d.co.uk, marking your enquiry “Loom3D privacy”.
This policy covers the Loom3D desktop app, its account and cloud services, the Loom3D website and Technician View. Separate websites, including the Hardwire Electronics shop, have their own privacy information. Acknowledging this policy is not consent to optional error reporting or usage statistics.
Accounts and project information
You need an account to use Loom3D. Account information includes your account identifier, email address, sign-in provider, verification status and authentication records. If you use Google sign-in, we receive the identity information provided for sign-in, which can include your name and profile photo. You can also provide a display name and organisation.
The app stores sign-in information and preferences on your device so you can stay signed in and use supported offline features. Local project files and recovery information remain on your device unless you choose a feature that uploads or shares them. Optional error reporting does not upload your projects.
When you use cloud projects, we process the project content and assets you upload, project identifiers and names, membership and permissions, invitations, edits and revision history, and timestamps. Collaboration also uses temporary presence information to show who is connected. Project owners and authorised collaborators can see information associated with participation and edits.
We may receive your email address from someone inviting you to a project. We use it to manage that invitation and access. If someone includes personal information in an uploaded project or library contribution, we receive it from that contributor. Please only include information you are entitled to share and avoid unnecessary personal or sensitive information.
Shared links and public library contributions
Technician View links allow anyone holding the link to access the published project view. Recipients may forward the link or save information they can access. Revoking a link prevents future access through that link; it does not remove copies already downloaded or otherwise saved.
If you submit a part to the global library, we process the part details, submitted assets, contributor information and moderation records. Published contributions and their author attribution are visible to library users. Attribution can include your display name, organisation and profile photo. If no display name is set, the current service can use your sign-in name or the part of your email address before “@”. Check your profile before publishing.
A contribution may be downloaded into other users’ projects. Removing it from the library cannot automatically remove those copies. Account closure and requests about public attribution are considered separately from preserving other users’ project content.
Website, device storage and support
Our hosting and online services process connection information such as IP addresses, requested resources, browser or client information, timestamps and response status to deliver the service and protect it. These operational records are separate from optional app error reports.
The public marketing pages currently use no analytics or advertising scripts, embedded third-party video players or application-set cookies. Demonstration videos are served from the website, play when selected and do not store playback position. Account sign-in and interactive services are separate from those marketing pages and may use necessary authentication or local storage to provide their functions.
If you contact us, we receive your contact details, message and any attachments you send. Contact links on the marketing website open your email application rather than submitting a website form. Please avoid sending passwords or unrelated project data. External links and Google sign-in are also subject to the relevant provider’s privacy information.
Optional usage statistics
Usage statistics are optional and off by default. With your consent, we collect basic information about app launches, features used and whether imports or exports succeed, together with your app version and general device information. These records do not include your account details, project contents or detailed editing history. You can turn collection off at any time in the app settings without losing access to features.
We keep a record of your choice on your device. Turning usage statistics off stops further collection and removes information waiting to be sent. It does not affect information already received or the lawfulness of earlier collection. This choice is separate from error reporting.
Feedback submitted from the app
You can choose to send feedback, report a problem or suggest a feature. We receive the information and attachments you choose to submit, any reply email you provide, and basic app and device information to help us understand your report. Additional diagnostics and project files are included only if you choose to share them. Nothing is attached automatically.
Feedback and attachments are stored privately. If delivery is unavailable, the app may keep your submission on your device until it can be sent. You can remove an unsent submission; this does not recall information already received.
App updates
Loom3D periodically checks for updates and downloads them when available. Requests reveal your IP address and the update requested to the hosting provider; service records may record these requests. Update requests do not include your sign-in credentials, account details or project content. Downloaded updates and related information are stored on your device. Updates are installed only when you choose to restart the app.
When the app connects to our online services, it includes its version so we can check compatibility.
Optional error reporting
Error reporting is optional and off by default. With your consent, the app automatically sends information about faults to help us investigate and improve reliability. You can turn it off at any time in the app settings without losing access to features.
Error reports include your app version, general device information, the type and timing of the fault, and technical references that help us find and group problems. Temporary identifiers may link reports from the same app session.
Report contents exclude the original error text, account details, email addresses, project contents, personal file locations or copies of computer memory. They are not linked to your account. We do not describe the service as anonymous: temporary session references and connection information can still be personal information.
We keep a record of your reporting choice on your device. Reports may be held on your device temporarily if they cannot be sent immediately.
You can withdraw consent in the same setting at any time. This stops further capture and deletes unsent reports. It cannot recall a report already received, and withdrawal does not affect the lawfulness of earlier processing. Because reports are not indexed by account, an email address alone may not let us identify your reports. We will explain what additional information, if any, could help with a request.
We use separate connection records to protect the reporting services against abuse. These may include information derived from your IP address. They are kept separately from the contents of your error reports and usage statistics.
Essential sign-in, collaboration and security processing continues whether or not you enable optional reporting. The app also keeps limited troubleshooting information on your device to support collaboration; this is separate from optional error reporting.
Why we use information
Under UK data protection law, we use the following bases:
- Providing the service: account access, requested cloud storage, collaboration and requested publication are necessary to perform our agreement with you. Where you use an organisation’s account and are not personally a party to that agreement, we rely on our legitimate interests in delivering the service to that organisation and its authorised users.
- Security and administration: preventing abuse, managing permissions, investigating faults in essential services and maintaining reliable operations serve our legitimate interests in protecting users and the service.
- Support and moderation: responding to enquiries and feedback, investigating reported problems, assessing feature requests and reviewing library submissions serve our legitimate interests in helping users and maintaining a useful, lawful library. Steps you ask us to take before entering an agreement may instead be necessary for that agreement.
- Optional error reports and usage statistics: we rely on your separate consent choices to collect error reports to understand faults and usage events to understand which features are used. Separate abuse-prevention controls protect the reporting service.
- Legal responsibilities: we process information where necessary to meet applicable legal obligations, including responding to valid data protection requests. Establishing or defending legal claims may involve our legitimate interests.
Where we rely on legitimate interests, you can object for reasons relating to your situation. We must consider your rights alongside those interests. Information needed for sign-in or a requested online feature is necessary to provide that feature; optional diagnostic consent is not.
Who receives information and international processing
We use service providers to manage account sign-in, host the website and online services, store information and handle email enquiries. They process the information needed to provide those services. Authorised company personnel and service providers may access information where needed for their work.
Other recipients include collaborators and library users as described above. Information may also be disclosed to professional advisers or authorities where necessary for a legal obligation or to establish, exercise or defend legal claims.
Error reports, usage statistics, feedback and selected attachments are stored in the Netherlands. Other account, support and service information may be processed in other countries. Our providers publish information about safeguards for international processing, including the UK Extension to the EU-US Data Privacy Framework for eligible US transfers and contractual safeguards where applicable. You can read their online service privacy information, data processing terms and email provider privacy information, or contact us for information about the safeguards relevant to your data.
How long information is kept
- Local files: project files are under your control. Signing out or closing an account does not erase your own project files or copies held by collaborators. The app keeps limited troubleshooting information on your device and replaces older records as needed.
- Accounts and cloud content: these are kept to provide your account and the projects or published contributions you choose to maintain. Closure or deletion requests require consideration of project ownership, other members’ access, public contributions and any records needed for security or legal claims. Contact us to request account closure or deletion of personal information.
- Error reports, usage events and in-app feedback: pending items have a seven-day expiry on the device; received items and feedback attachments have a 30-day expiry; separate abuse counters have a two-day expiry. Expired information is removed during scheduled cleanup, which may not happen immediately. Information waiting on your device is cleaned up when the app runs. Any follow-up email correspondence is covered by the support retention criteria below.
- Support correspondence: retention depends on whether the enquiry is resolved, whether related support remains ongoing and whether records are needed for a dispute or legal obligation.
- Operational records: routine service logs are retained for 30 days and required provider audit records for 400 days. Sign-in records, project revisions and recovery information have separate lifecycles; a diagnostic report’s expiry does not delete these separate records.
Our sign-in provider keeps connection IP addresses for a few weeks and removes other account authentication information from its live and backup systems within 180 days after we initiate deletion. Our website hosting provider retains IP data for a few months. These provider-managed periods are separate from the records described above. Further details are available in the provider privacy information.
Deleting an item from a live service may not immediately remove every recovery copy or provider backup. We will explain any applicable retention or legal exception when handling a deletion request. We do not promise that every cloud record is removed immediately when a link is revoked or an account is closed.
Your rights and complaints
Depending on the circumstances, you can ask to access your personal information, correct inaccuracies, erase information, restrict processing, or receive certain information in a portable format. You can object where we rely on legitimate interests and withdraw consent where we rely on consent. These rights have conditions and exceptions.
Email contact@loom3d.co.uk or write to our registered office. We may need proportionate information to confirm your identity and locate the relevant records. We normally respond to rights requests within one month; if a lawful extension applies, we will explain it.
If you are unhappy with how we handle information, please contact us so we can investigate. You also have the right to complain to the Information Commissioner’s Office, the UK data protection regulator. You do not have to contact us before exercising that right.
Changes to this policy
We will update this policy when our services or handling of information change. Material changes will be brought to your attention through an appropriate service notice. Where new processing requires consent, updating this policy alone will not replace that consent.