This site runs no analytics and sets no cookies at all. The hosted product sets one cookie, to keep you signed in. We store the account details you give us and the engineering data you put in — parts, bills of material, documents, supplier contacts — on our own server, in Postgres. Card details never reach us: Stripe handles payment. We do not sell anything to anyone, and we do not use your product data to train anything.
If you run TurboPLM on your own hardware, none of this applies to us, because none of your data reaches us. You hold it.
There is no self-service delete button yet. Ask us at office@turboplm.com and a person does it by hand.
Contact us about anything on this page at office@turboplm.com.
Registered address: available on request — write to office@turboplm.com. Company registration number: available on request.
We have not appointed a data protection officer. We are a small company and are not required to have one; questions go to the address above and are answered by a person rather than a function.
Four different things carry the TurboPLM name, and they hold your data very differently. This notice tells you which is which.
| What | Where | Who holds the data |
|---|---|---|
| Marketing site | turboplm.com | Nothing is collected from you here beyond server logs. There are no forms and no trackers. |
| Public demo | demo.turboplm.com | We do. It is a single shared instance and everything in it is visible to every visitor. Do not put real product data in it. |
| Hosted product | saas.turboplm.com | We do. Your organisation gets its own isolated workspace on our server. This is what most of this notice is about. |
| Self-hosted | Your own hardware | You do. The software sends us nothing — there is no telemetry, no licence check and no call home. We have no access and receive no copy. |
This page and the rest of turboplm.com are static files. There is no analytics script, no tag manager, no advertising pixel, no embedded font from anyone else's server and no cookie — which is why you were not asked to accept any. The contact link opens your own email client; nothing is submitted to us through the page.
Our web server keeps ordinary access logs: the IP address the request came from, the time, the URL requested, the response code and the browser's user-agent string. They exist to diagnose faults and to see whether the site is up, they are not joined to anything else, and nobody is profiled from them. Container logs roll at 10 MB with five files kept per service, so a log line survives roughly days to weeks at current traffic rather than indefinitely.
Sign-in to the hosted product is by email address and password. We do not currently offer sign-in through Google or any other identity provider on saas.turboplm.com.
Everything you create in the application: parts and their revisions, bills of material, manufacturing processes, engineering change requests and notices, requirements, projects, quality records, serial and lot records, cost figures, and files you upload — drawings, CAD models, specifications, images. Uploaded files are stored on our server's disk, not in a third-party object store.
Some of that is personal data about other people, because PLM is full of names: supplier and manufacturer contacts, supplier portal users you invite, colleagues you invite by email. You decide what goes in. In data protection terms, for that content you are the controller and we are your processor — we hold it to run the service for you and for no other purpose.
Change control is worthless if nobody can see who changed what, so every successful write through the API is recorded. Each entry holds:
POST /parts/1042/revisions),password, passwordHash, token or
secret replaced by [redacted] before it is written,It does not record IP addresses. It is visible inside the application to signed-in members of your own organisation, and to nobody outside it. It is not pruned: it is the record, and a record with gaps is not one.
Payment is processed by Stripe. Card numbers are entered on Stripe's own
checkout pages and never touch our servers — we could not store them if we wanted to.
What we keep is the Stripe customer and subscription identifiers, the status word Stripe
gives us (active, past_due, canceled and so on) and
the date the paid period ends. Stripe's own
privacy policy is at stripe.com/privacy.
The application sends transactional email only: invitations to join an organisation, and
notifications about work assigned to you. It is sent from
office@turboplm.com through Microsoft 365. There is no marketing list, and
nothing you do in the product subscribes you to one.
The hosted product sets one cookie, turboplm_token. It holds a signed
session token, lasts seven days, is marked HttpOnly so no script can read it,
and is sent only over HTTPS. Without it you cannot stay signed in, which is why there is
no banner asking permission for it — a cookie that is strictly necessary to deliver the
thing you asked for does not need consent.
There are no analytics cookies, no advertising cookies and no third-party cookies anywhere on turboplm.com, demo.turboplm.com or saas.turboplm.com.
The hosted product runs in Docker containers on a server operated by us — the application, the Postgres database and the file storage are all on that one machine, behind a reverse proxy that terminates TLS. Data is not spread across a cloud provider's managed services.
Server location: Ontario, Canada. The hosted service runs on infrastructure we operate there, not on a third-party managed platform.
These are the only third parties that process data for us:
| Who | What for | What they get |
|---|---|---|
| Stripe | Taking payment for the Pro plan | Your billing email and card details, entered directly with them; the name of your organisation |
| Microsoft | Sending invitation and notification email | The recipient's email address and the contents of that email |
| operated by us, in Ontario, Canada | Running the server | Everything stored, at rest on their infrastructure |
Stripe and Microsoft are global companies and may process data outside the country you are in, and both publish their own transfer safeguards. We have not independently verified which mechanism applies to your jurisdiction, and this notice deliberately does not claim one it has not checked — if your procurement process needs that confirmed in writing, ask us and we will get it confirmed rather than guess.
Nobody else. We do not sell data, we do not share it with advertisers, and we do not use your engineering data to train machine learning models — ours or anyone else's.
The database and the uploaded files are dumped to disk on the same server once a day, and those dumps are deleted after 14 days. That is the whole backup arrangement, stated plainly because it matters to two different questions: how much you would lose in a failure, and how long a deletion takes to become total. Data you ask us to delete is gone from the live database immediately and disappears from the last backup within 14 days.
If you are in the UK or the EU you have the right to a copy of your personal data, to have it corrected, to have it deleted, to restrict or object to how it is used, and to complain to your data protection authority. We will honour those rights wherever you are. Write to office@turboplm.com.
We would rather describe how these are handled today than quote a service level we have not built:
Complaints: if you are in the UK or the EEA and you are unhappy with how we have handled your data, you may complain to your national data protection authority. We would rather you told us first, at office@turboplm.com, so we have a chance to put it right.
What is actually in place:
What we do not claim: we hold no SOC 2 report, no ISO 27001 certificate and no third-party security audit, and there is no such thing as a GDPR certification, so nobody honest displays one. We are a small company and this notice describes a small company's arrangements. If your procurement process needs one of those certificates, tell us before you spend time on an evaluation — we would rather say so now than at the end.
The open-source build under the GNU AGPL v3 contains no telemetry, no analytics, no usage reporting and no licence check. It never contacts us. When you run it on your own hardware, you are the controller and the processor: your users' accounts, your product data and your audit log are on your machines, we cannot see them, and nothing in this notice gives us any access. Your obligations to your own users and to the people named in your data are yours.
demo.turboplm.com is one shared instance holding sample data. Accounts created there are read-only, but the email address and name you register with are visible to us, and the instance may be reset without notice. Treat it as a public space: do not enter anything confidential, and do not reuse a password you use elsewhere.
If we change how any of this works, we will change this page and move the date at the top. For a change that materially affects data we already hold for you, we will email the administrators of each organisation rather than rely on you noticing.
office@turboplm.com — for a copy of your data, a correction, a deletion, a security question, or to tell us something on this page is wrong.