Legal · Privacy policy

Privacy policy.

What we collect, why we process it, how long we keep it, and who else touches it.

Draft pending legal review. This text describes the intended handling of data and is published for transparency; it is not yet the operative policy, and registration will require acceptance of the reviewed version.

Grate Nesting is operated by Flocra Technologies Private Limited, Chennai, India, which is the controller for the data described here.

What we collect

Account data

Your email address, your name if you provide one, the organisation you belong to, your role within it, and a hashed form of your password. We record when you accepted the current terms and privacy policy, which version you accepted and when, because a checkbox alone is not evidence of agreement.

Content you upload

Cut lists, machine profiles, the results computed from them and the exports generated from those results. This is your commercial geometry, and it is treated as confidential.

Operational data

Sign-in events, usage counters for the run allowance, and records of emails we sent you about your account. Server logs record request metadata for security and diagnosis.

What we do not collect

There is no advertising network, no third-party analytics tag, no tag manager and no tracking cookie on this website. Nothing on these pages profiles you, which is why you are not being asked to dismiss a consent banner.

Why we process it

  • To provide the service you asked for — validating cut lists, running optimisations, returning and exporting results.
  • To operate accounts and organisations, including verification, sign-in and colleague invitations.
  • To enforce the run allowance and protect the service from abuse, since a run consumes real compute.
  • To meet legal and accounting obligations where they apply.

How long we keep it

DataRetained
Account and organisation recordsWhile the account exists
Record of legal-document acceptanceKept as evidence after the account closes
Uploaded cut lists and machine profilesUntil you delete the batch or the account
Results and generated exportsUntil the batch is deleted, then purged with it
Sign-in and security audit recordsA limited period, for security investigation
Email delivery recordsA limited period, to answer whether a message was sent

Deleting a batch purges its stored files as well as its database records. Deleting an account removes the account and its content; anonymised counters that do not identify you may remain.

Who processes it on our behalf

We keep this list short deliberately, and every processor is bound to use the data only to provide the service.

  • Microsoft Azure — hosting, storage and the compute that runs an optimisation.
  • MongoDB Atlas — the application database.
  • Azure Communication Services — transactional email such as address verification and password reset.

We do not sell personal data, and we do not share your uploaded geometry with anyone outside this list.

Cookies

This website sets no cookies. The application at app.gratenesting.com sets cookies that are strictly necessary to keep you signed in and to protect against cross-site request forgery. They are not used for analytics or advertising.

Security

Data is encrypted in transit. Access to production data is restricted and audited, credentials are held in a managed secret store rather than in configuration, and each organisation's data is isolated from every other. If you believe you have found a vulnerability, please contact us before disclosing it publicly.

Your rights

You can ask for a copy of your data, ask for it to be corrected, ask for it to be deleted, or object to a particular use. Write to us using the address on the contact page and we will respond within the period the applicable law requires.

Changes to this policy

Material changes are published as a new version with its own version number and effective date, and require acceptance when you next sign in.