1. Collection of Information & Buffer Boundaries
When submitting an inquiry to Oh Handy!, we collect your email address (strictly bounded to a maximum of 254 characters in accordance with RFC 5321) and 3D print query details (strictly bounded to a maximum of 3,000 characters, covering print specifications, material preferences, and dimensional requirements). If you affirmatively tick our optional newsletter checkbox, we record your opt-in consent and marketing preference.
Data Minimization Principle: We practice strict data minimization. We do not collect, process, or store financial details, payment card data, government identifiers, or special category data under GDPR Article 9.
2. Lawful Basis under GDPR & UK GDPR
We process personal data under the following distinct lawful bases:
-
Inquiry Processing & Custom Quotes:
Processed under GDPR Art. 6(1)(a) (Explicit Consent via mandatory checkbox confirmation) and GDPR Art. 6(1)(b) (taking pre-contractual steps at your request prior to entering into a custom 3D printing agreement).
-
Mailing List & Product Announcements (Optional — Double Opt-In):
Processed strictly under GDPR Art. 6(1)(a) (Freely Given Consent) and UK PECR Reg. 22. We enforce a Double Opt-In (DOI) protocol: ticking the newsletter box transmits an initial confirmation request to your email, and your subscription is only activated after you click the verification link in that email. This consent is completely decoupled from our quoting service; declining or unticking the mailing list box does not affect your ability to request or receive custom 3D printing quotes.
3. Processing Roles & Authorized Sub-Processors
Oh Handy! acts as the Data Controller (GDPR Art. 4(7)) for personal data collected on this site. To deliver our serverless contact infrastructure and static web application, we engage the following authorized Data Processors & Sub-Processors (GDPR Art. 28):
-
Web3Forms (Form Data Processor):
Processes contact form payloads (email address, query text, IP address for anti-spam) to route inquiries directly to our team. Bound by GDPR DPA & SCCs. Transmissions are strictly relayed to encrypted operational email endpoints with zero persistent cloud database storage or cross-site profiling.
-
Cloudflare (Edge CDN & Security Sub-Processor):
Provides edge SSL/TLS encryption, WAF protection, and static asset caching. Processes transient HTTP connection metadata and IP addresses to maintain perimeter network security.
-
First-Party Typography (Zero-CDN Architecture):
All typography font files (Fredoka, Space Grotesk, Inter) are strictly self-hosted directly on our origin server. Zero external font CDN requests or visitor IP disclosures are made to third-party font servers.
4. Retention & Deletion Schedule
Unconverted quote inquiries and associated message records are retained for a maximum of 30 days post-resolution, after which they are permanently deleted from active systems. For users who subscribe to our optional mailing list, subscription records are retained securely until you unsubscribe or withdraw consent.
5. Your Full Data Rights Under GDPR & UK GDPR
As a data subject under GDPR, you hold the following explicit rights regarding your personal data:
- Right of Access (Art. 15): Request a copy of all personal data we process about you.
- Right to Rectification (Art. 16): Request correction of inaccurate or incomplete personal information.
- Right to Erasure / "Right to be Forgotten" (Art. 17): Request permanent deletion of your data when no longer needed.
- Right to Restriction of Processing (Art. 18): Request temporary suspension of data processing.
- Right to Data Portability (Art. 20): Request transfer of your data in a structured, machine-readable format.
- Right to Object (Art. 21): Object to processing based on legitimate interests at any time.
- Automated Decision-Making & Profiling (Art. 22): Right not to be subject to automated decision-making (Oh Handy! performs zero automated profiling).
- Right to Withdraw Consent (Art. 7(3)): Withdraw consent at any time. For our optional mailing list, you may unsubscribe instantly via the one-click link at the footer of any marketing email, or by emailing privacy@oh-handy.com. For active inquiries, withdrawing consent cancels your pending quote request.
- Right to Lodge a Complaint (Art. 77): File a complaint with a Data Protection Supervisory Authority (such as the UK ICO or your local EU DPA).
To exercise any of your GDPR rights, submit a request through the Contact Hub or email privacy@oh-handy.com. All requests are processed free of charge within 30 days.
6. Cookies & Client-Side Local Storage Disclosure
Under the EU ePrivacy Directive (Article 5(3)) and UK PECR Regulations, Oh Handy! operates on a Zero-Tracking-Cookie Architecture. We do not deploy advertising pixels, third-party marketing beacons, or cross-site tracking cookies.
We strictly utilize HTML5 localStorage for technical operation, user interface preferences, and site security:
Remembers your preferred Light or Dark display theme across visits so you do not have to reselect it. Stored indefinitely on your device until manually cleared.
Records the timestamp of your last contact form submission to enforce our 1-per-hour inquiry rate limit, mitigating spam bots and denial-of-service abuse. Automatically expires after 60 minutes.
Maintains local query count increments when inquiring about catalogued prints to dynamically surface popular models on your screen. This data is strictly local to your browser and is never transmitted to any external server or analytics broker.
Managing Your Local Storage: You can inspect, disable, or delete local storage entries at any time through your browser's Developer Tools (under Application > Local Storage) or via your browser's "Clear Browsing Data / Site Data" settings.
7. Technical Security & Data Protection Measures (GDPR Art. 32)
Pursuant to GDPR Article 32 ("Security of processing"), Oh Handy! implements and maintains comprehensive technical and organizational safeguards to ensure data integrity, confidentiality, and resilience:
-
Content Security Policy (CSP) & Defense-in-Depth:
Strict origin lockdown (
default-src 'self') prevents cross-site scripting (XSS), data exfiltration, and unauthorized external script injection.
-
Clickjacking & UI Redress Protection:
Dual-layer framing prevention combining host-level HTTP headers (
X-Frame-Options: DENY and CSP frame-ancestors 'none') with client-side frame-busting fallback scripts to prevent unauthorized embedding.
-
Transport & Network Protocol Hardening:
Enforced TLS 1.3 edge encryption, MIME-type sniffing suppression (
X-Content-Type-Options: nosniff), restrictive referrer leakage prevention (Referrer-Policy: strict-origin-when-cross-origin), and complete lockdown of device APIs (camera, microphone, geolocation).
-
Input Bounds & Injection Defense:
Strict client- and server-level buffer limits (254-character email cap, 3,000-character message cap), comprehensive HTML sanitization, and CRLF header injection mitigation.
-
Anti-Spam & Rate Limiting Controls:
Automated client-side rate limiting (1 submission per hour per browser) and silent honeypot trap filtering relayed to anti-abuse verification engines.
-
Zero-Persistence Serverless Architecture:
Direct transient encrypted routing of form inquiries without intermediary persistent SQL/NoSQL cloud database storage, eliminating centralized storage breach attack surfaces.