Security and data

3D Print Manager Security: EU Hosting, Backups and GDPR

Your stock, costs, orders and customers are your business. Here is where they are kept, who can see them, how they come back if something breaks and how you take them with you, including what we do not do yet.

Every new account starts with 14 days of PRO, no credit card. The FARM plans have their own 14-day trial: a card is required and nothing is charged during the trial.

Your printers3DPM Agent on your computerEU server, CroatiaNightly backup, 14 days
Hosted in the EU (Croatia) GDPR DPA: EU standard clauses Nightly backups Export and delete it yourself Cards only at Stripe

What we keep, and where

DataKept by 3D Print ManagerWhere it is
Your production
Spools, print jobs and costs
Yes
EU server, Optima Hosting, Pula (Croatia)
Orders, customers and teamFARM
Yes
Same EU server, never transferred outside the EEA
Quotes and invoices (PDF)FARM
Yes
EU server, in a folder the web server does not serve to the internet
Backups
Every night, kept 14 days
Same EU hosting, above the public web folder
Never on our servers
Bambu Lab password and sign-in
No
Your computer only, in the operating system's credential store
Card details
No
Stripe
Barcode camera images
No
Your device reads the code and sends no picture

yes no

Prusa (PrusaLink) and Klipper (Moonraker) printers are read by 3DPM Agent on your local network, without a cloud. The data flows one way, into 3D Print Manager: neither the Agent nor Home Assistant lets 3DPM start, stop or send a print.

How it is protected

HTTPS only

The service runs over HTTPS (TLS), and http:// redirects to https://. Session cookies are Secure and HttpOnly: they travel only over HTTPS and page scripts cannot read them.

Passwords

Stored only as a one-way hash (PHP password_hash), so nobody can read them back, including us. A "remember me" sign-in lasts at most 30 days.

Accounts kept apart

Every query is limited to the account the data belongs to, and automated tests try to reach another account's data before every release.

Team rolesFARM

Owner, manager, operator and viewer. A viewer can only read, and permissions are checked on the server. An invitation link is valid for 14 days.

Who has access

Only the owner of dD Tech, bound by confidentiality, has access to the server and the database.

Backups that do not delete

Old print history is trimmed only after a nightly backup has succeeded, so a failed backup never removes anything.

What we don't do yet. There is no two-factor sign-in. The database and the backups are not encrypted separately at rest: they are protected by the hosting account and are never served to the internet. We hold no security certification of our own, and we don't claim one.

Your data, your exit

Export

Your inventory exports to CSV at any time, on every plan: Settings → Import / Export. Customer and order data comes in a machine-readable format within 30 days of a request to info@ddtech.hr.

Deletion

The account owner deletes the account in Settings → Danger Zone, and an active subscription is cancelled with it. The data, PDF quotes and invoices included, is deleted at once and is gone from the backups within 14 days.

Automatic clean-up

Finished print jobs are kept for 90 days, usage history for 400 days and team activity for 90 days; older records are deleted on their own.

Invoices and other records the law makes us keep stay for the statutory period after deletion (Privacy Policy).

Security and data FAQ

Who runs 3D Print Manager, and what if something happens to you?
dD Tech, a sole-proprietor business in Croatia owned by Damir Druško (legal notice). It is one person, so the answers are on paper: your data sits with an EU hosting company, not on our desk; it is backed up every night; you can export it; and a change that materially and negatively affects your access is announced by email at least 30 days ahead, with the right to leave free of charge (Terms of Use).
Can anyone at dD Tech see my data?
Only the owner of dD Tech, who is bound by confidentiality, has access to the server and the database. A working copy of the database for development and testing is kept on the owner's computer in Croatia.
Who else processes my data?
Optima Hosting (Plus Hosting Grupa d.o.o., Pula, Croatia) hosts the servers, database, files, backups and outgoing mail, in the EU. Stripe handles subscription billing, Google Analytics counts visits only after you agree in the cookie banner, Anthropic recognises a filament colour from its colour name and receives no personal data, and Telegram is used only if you connect a chat for notifications. A new sub-processor is announced by email at least 30 days in advance.
Is there a GDPR data processing agreement?
Yes. When you enter your customers' or team's data, you are the controller and dD Tech is the processor. The data processing agreement is the European Commission's standard contractual clauses (Implementing Decision (EU) 2021/915) word for word, with the annexes filled in. It is part of the Terms of Use; a copy signed by us is available on request at info@ddtech.hr.
What happens if there is a data breach?
We tell you by email to your account address without undue delay and no later than 48 hours after we become aware of it.
Is there two-factor sign-in?
Not yet. Passwords are stored only as a one-way hash, a remember-me sign-in lasts at most 30 days, and session cookies travel only over HTTPS.
How do I report a security issue?
Write to info@ddtech.hr. You get an answer from the person who fixes it.

Last updated: 11 October 2026.

Read the documents

See it with your own data

Every new account starts with 14 days of PRO, no credit card. The FARM plans have their own 14-day trial: a card is required and nothing is charged during the trial.