← Back to Homepage

Data Protection & GDPR Policy

How HSAN Studios collects, processes, stores, and protects your personal data

Last updated: 7 April 2026

1. About This Policy

This Data Protection Policy explains how HSAN Studios (trading as "HSAN Studios — a Private Limited Company") processes personal data in connection with the ARC3D™ architectural design software and the website at hsan-studios.com.

This policy is written in accordance with:

By creating an account or using ARC3D™, you acknowledge that you have read and understood this policy.

2. Data Controller

The data controller responsible for your personal data is:

HSAN Studios

45 Merefield Street, Rochdale, OL11 3RH

United Kingdom

Email: support@hsan-studios.com

Website: hsan-studios.com

If you have any questions about how your personal data is handled, please contact us at the above address.

3. Lawful Basis for Processing

Under Article 6 of the UK GDPR, we process personal data on the following lawful bases:

PurposeLawful BasisGDPR Article
Account creation & authentication Performance of a contract Art. 6(1)(b)
Processing payments & purchases Performance of a contract Art. 6(1)(b)
Cloud project storage & sync Performance of a contract Art. 6(1)(b)
Customer support Legitimate interest Art. 6(1)(f)
Security & fraud prevention Legitimate interest Art. 6(1)(f)
Legal compliance (financial records) Legal obligation Art. 6(1)(c)

We do not rely on consent as a lawful basis for any core data processing. Where consent is used (e.g., optional marketing emails in the future), it will be freely given, specific, informed, and withdrawable at any time.

4. Personal Data We Collect

4.1 Account Data

DataPurposeStorage
Full nameAccount profile, correspondenceServer + local
Email addressLogin, email confirmation, supportServer + local
PasswordAuthenticationServer (bcrypt hash), local (SHA-256 hash)
Phone number (optional)Profile, contactServer only
Company name (optional)ProfileServer only
We never store your password in plain text. Server-side passwords are hashed with bcrypt (adaptive cost factor). Local passwords are hashed with SHA-256 via the Web Crypto API.

4.2 Payment Data

DataPurposeStorage
Last 4 digits of card numberDisplay reference onlyServer + local
Card expiry dateDisplay reference onlyServer + local
Cardholder name (hashed)Verification referenceServer + local
PayPal email (if chosen)Payment processingServer + local
Purchase recordsTransaction history, invoicesServer + local
We do not store full card numbers, CVV/CVC codes, or PIN numbers. Actual payment processing is handled by external payment processors (PayPal). We only retain a receipt-level summary.

4.3 Project Data

DataPurposeStorage
Project files (JSON)Saving architectural designsLocal IndexedDB + cloud (if logged in)
Project metadataName, type, description, addressLocal IndexedDB + cloud
Thumbnails (PNG)Project preview imagesLocal IndexedDB + cloud

Project data may contain addresses and client contact details that you enter. This data is only stored for your use and is not accessed by HSAN Studios unless you explicitly share it with us for support purposes.

4.4 Technical Data

We may automatically collect:

We do not use analytics services, advertising trackers, or fingerprinting technologies.

5. How We Use Your Data

We use your personal data exclusively for the following purposes:

We do not:

6. Data Storage & Security

6.1 Local Storage (Your Device)

6.2 Cloud Server

6.3 Security Measures

MeasureImplementation
Encryption in transitHTTPS / TLS for all server communication
Password hashingbcrypt (server), SHA-256 (local)
Authentication tokensJWT with expiration, stored in localStorage
Rate limiting20 auth attempts / 15 min; 100 general requests / 15 min
Security headersHelmet.js (CSP, HSTS, X-Frame-Options, etc.)
CORSRestricted to allowed origins only
Input validationServer-side validation on all endpoints
No raw credentials storedFull card numbers and CVV never stored

7. Cloud Synchronisation

ARC3D™ offers optional cloud synchronisation to allow you to access your projects from any device:

Cloud sync is triggered when you save a project while logged in. You can delete individual cloud projects at any time from the Project Database panel, or delete your entire account (which removes all cloud data) via the Dashboard.

8. Data Sharing & Third Parties

We do not share your personal data with any third parties except in the following limited circumstances:

We do not use:

9. International Data Transfers

Your data is primarily processed and stored in the United Kingdom. If data is transferred outside the UK (e.g., if using a cloud hosting provider with international data centres), we ensure that:

You may contact us for details on the specific safeguards applied to any international transfer.

10. Data Retention

Data CategoryRetention Period
Account dataUntil you delete your account
Cloud project filesUntil you delete the project or your account
Local project filesUntil you clear browser data or delete them
Purchase records6 years from transaction date (HMRC requirement)
Server access logs (IP, timestamp)90 days, then automatically purged
Support correspondence2 years from last contact, or until deletion requested

When you delete your account, all personal data (name, email, password hash, payment methods, cloud projects) is permanently removed from our servers. Purchase records may be retained in anonymised form for financial reporting as required by UK law (HMRC).

11. Your Rights Under UK GDPR

Under the UK GDPR and the Data Protection Act 2018, you have the following rights:

RightDescriptionHow to Exercise
Access (Art. 15) Obtain a copy of all personal data we hold about you Email support@hsan-studios.com or view in your Dashboard
Rectification (Art. 16) Correct inaccurate or incomplete data Update via your Dashboard profile settings
Erasure (Art. 17) Request deletion of your personal data ("right to be forgotten") Delete account via Dashboard "Danger Zone" or email us
Restriction (Art. 18) Request we limit processing of your data Email support@hsan-studios.com
Portability (Art. 20) Receive your data in a structured, machine-readable format Export projects as .ark (JSON) files; email us for account data export
Objection (Art. 21) Object to processing based on legitimate interest Email support@hsan-studios.com
Withdraw consent (Art. 7) Withdraw consent at any time (where consent is the lawful basis) Email support@hsan-studios.com
Response time: We will respond to all data subject requests within one calendar month of receipt, as required by UK GDPR Art. 12(3). If the request is complex, we may extend this by a further two months with notification.

To verify your identity for a data subject request, we may ask you to confirm your email address and provide additional identifying information. We will not charge a fee for reasonable requests.

12. Cookies & Local Storage

ARC3D™ does not use cookies for tracking, advertising, or analytics.

We use the following browser storage mechanisms for essential functionality only:

StoragePurposeType
localStorage: arc3d_auth_tokenJWT session token for authenticated API callsStrictly necessary
localStorage: arc3d_server_urlCustom server URL (if configured)Strictly necessary
localStorage: userSessionCurrent login session dataStrictly necessary
localStorage: cadModelerAutoSaveEmergency auto-save of current projectStrictly necessary
IndexedDB: ARC3D_UserDBLocal user accounts, payment methods, purchasesStrictly necessary
IndexedDB: ARC3D™ProjectsDBSaved project files and thumbnailsStrictly necessary

Under the Privacy and Electronic Communications Regulations 2003 (PECR), strictly necessary storage does not require consent. These storage items are essential for the software to function and are never used for tracking.

13. Children's Data

ARC3D™ is professional architectural design software and is not directed at children under the age of 16.

We do not knowingly collect personal data from anyone under 16. If we become aware that we have inadvertently collected data from a child under 16, we will delete it promptly. If you believe a child has provided us with personal data, please contact support@hsan-studios.com.

14. Data Breach Procedures

In the event of a personal data breach, HSAN Studios will:

  1. Assess the breach within 24 hours of discovery to determine its scope and severity
  2. Notify the ICO within 72 hours of becoming aware of the breach, if it is likely to result in a risk to the rights and freedoms of individuals (UK GDPR Art. 33)
  3. Notify affected individuals without undue delay if the breach is likely to result in a high risk to their rights and freedoms (UK GDPR Art. 34)
  4. Document the breach, its effects, and the remedial actions taken in our internal breach register
  5. Remediate by fixing the vulnerability, rotating affected credentials, and implementing additional safeguards

15. Changes to This Policy

We may update this Data Protection Policy from time to time to reflect changes in our practices, technology, or legal requirements.

We encourage you to review this policy periodically.

16. Complaints & Contact

If you have any questions, concerns, or complaints about how your data is handled, you can contact us:

HSAN Studios — Data Protection

45 Merefield Street, Rochdale, OL11 3RH, United Kingdom

Email: support@hsan-studios.com

Website: hsan-studios.com

If you are not satisfied with our response, you have the right to lodge a complaint with the Information Commissioner's Office (ICO):

Information Commissioner's Office

Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF

Helpline: 0303 123 1113

Website: ico.org.uk