Trust and security
This page summarises where your data lives, who processes it besides us, and what availability commitment we offer — with links to the full privacy policy where the detail lives there instead.
This English text is a translation provided for convenience. The binding version of this page is the Spanish one, available at confsas3d.com/legal/confianza. In the event of any discrepancy between the two, the Spanish version prevails.
1. Sub-processors
Confsas3D does not host its own infrastructure. Your data and uploaded content pass through:
- Google Firebase / Google Cloud: authentication, database (Firestore), file storage and the 3D model processing pipeline.
- Google Gemini: solely to automatically propose the configurable parts of an uploaded model — see §2 of the privacy policy for the full detail.
- Tripo3D: only if you use AI 3D generation. The images you upload to generate a model are sent to this provider, which returns the mesh — see §2 of the privacy policy. If you do not use that feature, nothing is sent to it.
- Stripe: payment processing. We never store a full card number ourselves; it lives exclusively with Stripe.
There are no sub-processors beyond these four. If we add one, this page is updated in the same change — not afterwards.
2. Where the data lives
The database (Firestore) runs in the multi-region location nam5 (United States), replicated automatically across several physical locations by Google Cloud's own infrastructure. We do not currently offer a choice of a European or other specific region.
3. Durability and backups
Firestore replicates every write across physical locations automatically — a property of the managed infrastructure, not something we configure ourselves. That said, we do not currently run an independent scheduled backup regime (for example, a daily export to separate storage with its own retention). It is a real, pending improvement, not something we claim to already have.
4. Availability
We do not publish an SLA with a numeric uptime figure, because we do not run the operation (on-call rotations, 24/7 monitoring, downtime credit agreements) that would make that number sustainable rather than decorative. What is true: the public viewer that shows your configurators to your customers does not depend on you having a session open, or on our own dashboard being available at that instant — it runs on the same managed infrastructure as the rest of the Service.
The one circumstance today where a visitor can fail to see a configurator, outside of an outage on Google's infrastructure, is your plan's monthly delivery quota running out (see the privacy policy §1 "Usage data") — an explicit cost cap, not a failure.
5. Data Processing Agreement (DPA)
If your organisation needs a signed DPA for GDPR compliance or a vendor audit, here is the standard template we use:
Download the Confsas3D DPA (PDF)
It is a standard template, not a custom-negotiated document. If your organisation needs changes to it, write to us at psabater@confsas3d.com.
6. Contact
For any security, privacy or compliance question this page does not answer, write to us at psabater@confsas3d.com.