1. Who we are
MorphoCAD ("we", "our", "us") provides an AI-powered AutoCAD standardization plugin and the associated web platform at morphocad.com. This Privacy Policy explains how we collect, use, and protect your personal data in accordance with the General Data Protection Regulation (GDPR). The data controller is MorphoCAD, based in Torino, Italy. Contact: info@morphocad.com.
2. Data we collect
- - Account data: Email address and encrypted password when you register. If you enable two-factor authentication (2FA), we store the TOTP factor status and hashed recovery codes.
- - Usage data: Number of AI runs, layer templates created, commands used (MORPHO, MORPHOSTYLE, MORPHOCHECK), and feature usage for billing and analytics.
- - Drawing metadata: Layer names and properties (color, linetype, lineweight, visibility status), block names, dimension style names, text style names, file names (for compliance tracking), mapping results, and short text summaries from annotations (common personally identifiable information patterns such as emails and phone numbers are filtered). We do not collect or store DWG file contents, geometry, coordinates, or drawing layouts.
- - Payment data: Billing and payment processing are handled by Paddle.com Market Ltd ("Paddle"), our Merchant of Record. Paddle collects and processes your payment information directly. We do not store credit card numbers, bank details, or other payment credentials on our servers. For details on how Paddle handles your data, see Paddle's Privacy Policy.
- - Session logs: Each run records the number of layers or styles processed, mapping results, and your user ID for analytics and debugging.
- - Local storage: An encrypted authentication token is stored on your computer (using Windows DPAPI encryption) to keep you signed in. No passwords or personal data are stored locally.
- - Admin audit logs: Administrative actions (user management, plan changes, organization updates) are logged with timestamps, action type, and admin user ID for security and compliance.
3. How we use your data
- - To provide and improve the Morpho service
- - To process billing and enforce usage limits
- - To send transactional emails (account confirmation, password reset)
- - To respond to support requests
We do not sell your data to third parties. We do not use your data for advertising.
Legal bases under GDPR
We process your personal data under the following legal bases:
- - Account data (email, password): Contract performance (Art. 6(1)(b) GDPR) - necessary to provide the service you signed up for.
- - Billing data (invoices, transaction records): Legal obligation (Art. 6(1)(c) GDPR) - required for tax and accounting compliance.
- - Usage analytics (conversion counts, feature usage): Legitimate interest (Art. 6(1)(f) GDPR) - to improve the service and monitor system health.
- - Marketing emails: Consent (Art. 6(1)(a) GDPR) - only sent with your explicit opt-in. You may withdraw consent at any time.
4. AI processing
When you run the MORPHO command, layer names, block names, and your template's standard layer names are sent to a third-party AI service via a secure proxy for mapping suggestions. No DWG file contents, geometry, coordinates, or file paths are transmitted. MORPHOSTYLE and MORPHOCHECK do not use AI and do not send data to external services.
5. Data storage
Your data is stored on Supabase infrastructure hosted in the European Union. Layer mappings and Memory data are isolated per account and never shared between organizations.
6. Data retention
We retain your account data for as long as your account is active. Upon account deletion, your personal data, Cloud Memory rules, templates, and style corrections are permanently deleted within 30 days. Admin audit logs may be retained for up to 90 days for security purposes.
7. Your rights (GDPR)
Under GDPR, you have the right to access, correct, or delete your personal data at any time. You may also request a copy of your data or withdraw consent for processing. To exercise these rights, contact us at info@morphocad.com.
8. Third-party service providers
We use third-party service providers in the following categories to operate MorphoCAD:
- - Database hosting and authentication (EU) - stores your account, templates, and Cloud Memory data
- - AI processing (US) - processes layer and style metadata only to generate mapping suggestions. No DWG file contents, geometry, or personal data are sent
- - Payment processing (EU/UK) - handles billing, invoicing, and sales tax as our Merchant of Record
- - Website hosting (US) - serves the MorphoCAD web platform
- - Analytics (US) - website usage analytics, consent-based only
- - Security and rate limiting (EU) - prevents API abuse. Stores only anonymized request counts, no personal data
For a complete list of named subprocessors, contact us at info@morphocad.com.
9. International data transfers
Some of our subprocessors are based in the United States. Transfers of personal data outside the EU/EEA are covered by Standard Contractual Clauses (SCCs) or equivalent safeguards as required by GDPR.
10. Security
We use encryption in transit (TLS) and at rest. Access to production systems is restricted to authorized personnel only. Regular security reviews are conducted to identify and address vulnerabilities.
11. Anonymized platform data
MorphoCAD collects anonymized standardization patterns to improve mapping accuracy across the platform. This may include layer name mappings, style name mappings, mapping decision types, and your organization's country. All data is de-identified: organization, user, and file information is stripped and cannot be linked back to your organization. This data falls outside the scope of personal data under GDPR (Recital 26).
12. Cookies
We use only essential cookies required for authentication and session management. We do not use tracking or advertising cookies.
13. Newsletter and marketing
If you opt in to our newsletter during registration, we may send you product updates, tips, and announcements via email. You can unsubscribe at any time using the link in every email, or by updating your preferences in your account settings. We do not share your email address with third parties for marketing purposes. Legal basis: Consent (Art. 6(1)(a) GDPR).
14. Contact
For any privacy-related questions, contact us at info@morphocad.com or through our contact page.