Protos Labs Pte. Ltd. andits affiliates and subsidiaries ("Protos Labs", "we","us", or "our") respects your privacy and is committed toprotecting your personal data. This Privacy Policy explains how we may collect,use, disclose, process, transfers, retain and safeguard your personal data whenyou visit our website or use our services (“Services”), including signing upfor an account, newsletter, demo, or trial.
Protos Labs respectsand complies with major data protection laws including the Singapore PersonalData Protection Act (PDPA), the European Union's General Data Protection Regulation (GDPR), and for Californian residents, the California Consumer Privacy Act (CCPA/CPRA).
If you are a California resident, please see Section 14 (California Privacy Rights) for additionaldisclosures and rights specific to you under the CCPA/CPRA.
This Privacy Policy applies to:
· Visitors to our website
· Users, customers and their authorized users of our Services
· Individuals whose personal data is processed through the Services on behalf of our customers
This Privacy Policy may not apply where weprocess personal data solely on behalf of our customers as a processor. In suchcases, the relevant customer is responsible for the processing of personal dataand you should refer to their privacy policy.
The personal data we collect depends on howyou interact with us, the Services you use, and the choices you make.
We may collect personal data from various sources and in different ways, including directly from you, automatically through your use of our Services,and from third parties.
We collect thefollowing types of personal data:
· Contact Information: Name, email address, phone number, company name, and job title
· Account Information: Username, password, login history, account balances, payment, payment card data, customer support, return, replacement, subscription, and history of product and services obtained, purchased, and considered, and any otherinformation you provide to us. Do note we use a third-party provider to process payments on our behalf and do not accept payments directly through our Services.
· Technical Data: IP address, browser type, operating system, referral URLs, and usage behavior
· Marketing Data: Preferences, responses to campaigns, and opt-in status
· Cookies & Tracking Data: See Section 7 and our Cookie Policy at www.protoslabs.io/cookie-policy
· Platform Content Data: Text inputs, prompts, queries, and files or documents uploaded by users in the course of using the Protos AI platform ("User Content"). User Content may contain personal data depending on what users choose to submit
· Communication Information:. Information/communications content (audio, video, text), provided in custom messages sent through the forms, recorded in chat messages, to our email addresses, or via phone or other communications details when you interact withProtos Labs
· Clients' Customers' Data: Information submitted by our clients that may include personal dataabout their own customers, depending on how they use our platform
We do not collect biometric data nor geolocation data.
We collect personal data through various means, depending on how you interact with us and use ourServices.
We may collect data:
· Directly from you, including when you complete sign-up forms and contact forms or communicate with us
· Through your use of Protos AI platform, our Services and/or website, including User Content submitted through Protos AI such as text inputs, prompts, queries, and uploaded files
· Automatically, through cookies and tracking technologies (see Section 7), which collect information about your device, browsing behaviour, and interactions with our Services. This may include information such as IP address, device identifiers, pages visited, features used, and interaction patterns
· Communication with our sales and support teams
· From third parties, including serviceproviders, analytics providers, and integration partners, where applicable
Wemay combine information collected from these different sources to provide andimprove our Services. For more information on our use of cookies and trackingtechnologies, please refer to our Cookie Policy.
We process yourpersonal data under the following legal bases:
· Consent: Where you have provided consent, including for sending marketing communications and for non-essential cookies and tracking technologies
· Contractual Necessity: Where processing is necessary to perform a contract with you or to takesteps at your request prior to entering into a contract including to provide access toour platform or respond to your request
· Legitimate Interests: Where processing is necessary for our legitimate interests, including operating and improving our Services, ensuring security, for analytics, fraud prevention, improving user experience and preventing fraud
· Legal Obligation: Where processing is necessary for our legitimate interests, including operating and improving our Services, ensuring security,
Wherewe rely on legitimate interests, you may have the right to object to suchprocessing in certain circumstances.
We use personal data for the following purposes:
· Account Management: To create and manage user accounts, authenticate users, and provide customer support
· Service Provision: To provide, operate, and maintain the Platform, delivering requested Services or trials to you, including processing User Content and generating AI-assisted outputs requested by you
· Communications: To send service-related communications, respond to enquiries, andprovide support. Where permitted, we may also send marketing communications based on your preferences/consent
· Service Improvement andAnalytics: To analyse usage, monitor performance, develop new features, and improve the functionality and user experience of our Services
· Security and FraudPrevention: To protect the security and integrity of ourPlatform, detect and prevent fraud, misuse, and unauthorised access
· Legal and RegulatoryCompliance: To comply with applicable laws, regulations, and legal processes, and to enforce our terms, policies, and legal rights
· Business Operations: To manage our business operations, including internal reporting, audits, and administrative purposes
Where possible, we may use aggregated or anonymised data that does not identify individuals to support analytics and service improvement.
· We may disclose personal data to thefollowing categories of recipients, for the purposes described in this Privacy Policy: Third-party service providers: Third-party vendors who provide services onour behalf, including cloud hosting, analytics, email marketing, customer support (including CRM),communications and security services. Analytics and tracking service providersreceive data only where you have consented via our cookie consent banner.
· AI and large language model (LLM) providers: We use third-party AI/LLM providers to power certain features of Protos AI. User Content, including prompts and uploaded files, may be transmitted to these providers solely for the purpose of delivering the requested service. These providers are contractually designatedas Service Providers and are prohibited from using your data for any purposeother than providing services to us. We maintain data processing agreementswith all such providers.
A full list of cookieswe use, including provider, purpose, and expiry, is available in our Cookie Policy at www.protoslabs.io/cookie-policy.
· Affiliates and partners: Our affiliates, where necessary for internal business operations and service delivery, subject to strict confidentiality and data protection terms
· Professional Advisors: Legal, accounting, audit, and other professional advisors where necessary for business, compliance, or risk management purposes
· Business Transfers: In connection with amerger, acquisition, financing, reorganisation, or sale of all or part of our business or assets, where personal data may be disclosed as part of the transaction, subject to appropriate confidentiality obligations
· Legal authorities: When required to comply with applicable laws, legal process or enforce our legal rights.
We never sell your personal data. We do not share your personal data with third parties for cross-contextual behavioral advertising purposes. However, certain cookies and tracking technologies may involve the sharing of data with analytics or service providers asdescribed in our Cookie Policy.
Personal data may be transferred to, stored, and processed in countries outside your jurisdiction, including Singapore and other countries where we or our service providers operate. These transfers may occur, for example, where our infrastructure, service providers, or affiliates are located in different jurisdictions, or where it is necessary to provide and support our Services.
If your data is transferred outside your jurisdiction (e.g. from the EU to Singapore), we ensure appropriate safeguards are in place that such datais protected in accordance with applicable data protection laws. Thesesafeguards may include:
· Entering into Standard Contractual Clauses (SCCs) or equivalentcontractual arrangements
· Implementing data processing agreements with third parties that impose appropriate data protection obligations
· Ensuring that recipients are subject to legal frameworks or certifications that provide an adequate level of protection, where applicable
Any personal datatransferred across borders will be protected using safeguards that provide alevel of protection equivalent to the data protection requirements of yourjurisdiction.
We use cookies andsimilar technologies to:
· Provide and maintain the functionality of our Services, including authentication and security
· Improve website and platform performance
· Analyze user behavior (where consent has been given)
· Personalize content, user experience and remembering preferences
· Support communications, marketing, and customer engagement activities
Cookie Categories
Some of these technologies are strictly necessary for the operation of our Services, while others are used only with your consent.
Your Cookie Choices
When you first visitour website or platform, a cookie consent banner will ask for your preferences.You may:
· Accept all cookies
· Do Not Sell or Share My Personal Information — opt out of analytics and non-essential cookies
You may change your preference at any time by clicking "Do Not Sell or Share My Personal Information" in the footer of our website or platform. You may also manage cookies directly through your browser settings, though this may affectplatform functionality.
Non-essential cookies(analytics, functional, marketing) will not be loaded until you have accepted via the consent banner.
For more detailed information about the cookies we use, including theirpurposes, providers, and retention periods, please refer to our Cookie Policy.
Depending on your jurisdiction and subject to applicable law, you may have the right to:
· Access the personal data we hold about you
· Correct inaccurate personal data
· Delete your personal data, subject to certain legal exceptions
· Restrict or object to certain processing activities
· Data portability — receive your data in a structured, machine-readable format
· Withdraw consent at any time, without affecting the lawfulness of prior processing
· Opt out of the sale or sharing of your personal information (Californiaresidents — see Section 14)
· Non-discrimination for exercising your privacy rights
To exercise any ofthese rights, please contact our Data Protection Officer at marketing@protoslabs.io with the subject line: ATTENTION DATAPROTECTION OFFICER PROTOS LABS PTE LTD.
We may need to verify your identity before processing your request. Wemay also decline or limit requests where permitted by applicable law, includingwhere fulfilling the request would adversely affect the rights of others or ourlegal obligations.
We retain your personal data only for as long as necessary to fulfill the purposes outlined in this policy including to provide our Services, comply with legal obligations/laws,resolve disputes, and enforce our agreements.
The specific retention period depends on various factors, including:
· The nature and purpose of the personal data
· The duration of your relationship with us and use of our Services
· Legal, regulatory, tax, accounting, or reporting requirements
· The need to establish, exercise,or defend legal claims
In general,
· Account and profile data are retained for as long as your account remains active and for a reasonable period thereafter
· User Content (including prompts and uploaded files) is retained only forthe duration necessary to deliver the requested service and is deleted inaccordance with our standard data retention schedule. Users may request deletion of their User Content at any time by contacting our Data ProtectionOfficer.
· Technical and usage data may be retained for analytics, security, and service improvement purposes, subject to appropriate safeguards
· Communications data may be retained to support customer service, internal records, and compliance requirements
Where personal data is no longer required, we will take reasonable steps to delete, anonymise, or securely dispose of such data, generally within 30 days, except where retention is required or permitted by law.
In certain circumstances, we may retain personal data for longer periods where required or permitted by law, or where necessary for legitimate business purposes such asfraud prevention, security, or legal compliance.
Our services are notdirected to individuals under the age of 16 (or the equivalent minimum age inyour jurisdiction). We do not knowingly collect personal data from children without appropriate parental consent.
If we become aware that we have collected personal data from a child without appropriate consent, we will take reasonable steps to delete such dataas soon as practicable. If you believe that a child has provided us withpersonal data, please contact us.
We implement appropriate technical and organizational measures to protect your personal dataagainst unauthorised access, disclosure, alteration, or destruction.
These measures include,where appropriate, encryption, access controls, authentication mechanisms,monitoring and regular security audits. We are ISO/IEC 27001:2022 certified to ensure the highest standards of controls.
Whilewe take reasonable steps to protect personal data, no system is completely secure, and we cannot guarantee absolute security.
We may update this Privacy Policy periodically to reflect changes in our practices, technologies, legal requirements, or other factors. If we make material changes, we will notify you by email or prominently on our website. Where changes affect how we use cookies or tracking technologies, we will re-seek your consent whererequired.
The updated Privacy Policy will be effective from the date indicated above. We encourage you to review this Privacy Policy periodically to stay informed about how we handle personal data.
You may contact our Data Protection Officer if you have any enquiries or feedback on our personal data protection policies and procedures, or if you wish to make any request, inthe following manner:
· Name of DPO: Simeon Tan
· Contact: marketing@protoslabs.io [TT6]
· Subject: ATTENTION DATA PROTECTION OFFICER PROTOS LABS PTE LTD
This section appliessolely to residents of California and supplements the rest of this Privacy Policy. It is provided pursuant to the California Consumer Privacy Act of 2018 and the California Privacy Rights Act of 2020 (collectively, "CCPA").
Ifyou are a California resident, you have certain rights under the California Consumer Privacy Act (CCPA/CPRA), subject to applicable conditions and limitations. If you are not a California resident these CA Notices and Rights do not apply to you.
Tolearn more about the types of personal information we collect, the sources from which we collect or receive personal information, and the purposes for which we use this information, please refer to paragraph 2, 3 and 5 of our Privacy Policy.
In the preceding 12 months, we have collected the following categories of personal information:
We collect this information from a variety of sources, including: directly from you, from your organization, from our customers andother users, from our business partners and affiliates, from your browser or device when you use our Services, or from third parties that you permit to share information with us. Please see paragraph 3 (How We Collect Your Data) of the Privacy Policy for more information about the sources of personal information we collect.
We do not collect biometric data and geolocation data.
We collect the categories of personal information listed above for the following business or commercial purposes:
· For providing, maintaining, and improving the Protos AI platform
· For account creation, authentication and access control
· For delivering AI-assisted features by transmitting User Content to designated AI or large language model Service Providers
· For analytics and platform performance monitoring (where consent has been given)
· For security, fraud prevention, and legal compliance
· For transactional, service communications and administrative matters
We share personal information with the following categories of Service Providers, solely for business purposes:
· Cloud infrastructure and hosting providers
· Analytics providers (where user consent has been obtained via cookie banner)
· Email and communications providers
· AI and large language model service providers (for processing User Content to deliver platform features)
· Customer relationship management and customer support service providers
All such serviceproviders are contractually required to process personal information only for specified purposes and in accordance with applicable data protection laws.
We do not sell personal information. We do not share personal information with third parties for cross-contextual behavioral advertising. However, certain cookies and tracking technologies may involve the sharing of data with analytics or service providers as described in our Cookie Policy.
When you first visit our website or platform, you will be presented with a cookie consent banner. Non-essential cookies — including analytics and tracking technologies — will not load until you click "Accept."
You may update your preferences and/or opt out at any time by clicking "Do Not Sell or Share My Personal Information" in the footer of our website or platform, or by contacting us directly. Your preference will be stored and respected on all subsequent visits.
Right to Know: You may request disclosure of the categories and specific pieces of personal information wehave collected about you, the categories of sources, our business purposes for collecting it, and the categories of third parties with whom we share it.
Right to Delete: You may request deletion of personal information we hold about you, subject to certain legalexceptions (e.g. information needed to complete a transaction or comply with alegal obligation).
Right to Correct: You may request correction of inaccurate personal information we hold about you.
Right to Opt Out: You may opt out of the sale or sharing of your personal information at any time by clicking "DoNot Sell or Share My Personal Information" in the footer of our website orplatform, or by contacting us directly.
Right to Limit Use of Sensitive Personal Information: You may request that we limit the use of sensitive personal information(such as account credentials) to purposes necessary to provide the services.
Right to Non-Discrimination: We will not discriminate against you for exercising any of your CCPA rights. We will not deny services, charge different prices, or provide a lower quality of service as a result of you exercising these rights.
To exercise any of therights above:
· Email: marketing@protoslabs.io
· Subject line: ATTENTION DATA PROTECTION OFFICER — CCPA REQUEST
We will acknowledgeyour request within 10 business days and respond within 30 calendar days. If we require additional time (up to 90 days total), we will notify you in writing. We may need to verify your identity before processing your request. We will not require you to create an account solely to submit a request.
You may designate anauthorized agent to submit a CCPA request on your behalf, where permitted byapplicable law. We may require written proof of authorization and may require you to verify your identity directly with us before processing the request.
We retain each category of personal information for the period necessary to fulfill the purposes described in this policy, taking into account factors such as the nature of the data, the purposes of processing, and applicable legal or regulatory requirements.
In certain circumstances, we may retain personal information for longer periods where required or permitted by law, including for legal, compliance, or business purposes, after which it is deleted or anonymized.
For more information about our data retention practices, please refer tothe Paragraph 9 (Data Retention) of the Privacy Policy above or contact our DPO using the details provided in thisPrivacy Policy.
Effective Date: 08 April 2026 | Last Updated: 8 April 2026