Version 1.0 – 20 Juni 2025

Privacy Policy Nimbus 3D GmbH

About us

This privacy policy (β€œPrivacy Policy”) explains how we process and protect your personal data when you use this website or our services offered via www.nimbus-3D.com (together, β€œour Services”).

The website is operated by Nimbus 3D GmbH, Hofackerstrasse 16, 4132 Muttenz (the "company", the "firm", "we", "our" or "us"). The company is responsible for the data processing described below.

Unless otherwise defined in this privacy policy, the definitions used in this privacy policy have the same meaning as in the Swiss Federal Act on Data Protection ("FADP") or in the EU General Data Protection Regulation ("GDPR").

1 Personal data that we collect

When you use our services, we may collect or receive personal data for a number of purposes related to our business operations. This includes the following:

β€’ Usage and analytics data (e.g., IDs, number of clicks, tracking data)

β€’ Contact details (e.g., name, address, phone number, date of birth)

β€’ Login details (e.g., password, username, session)

β€’ Payment data (e.g., billing information, account information)

β€’ Request details (e.g., details and content of your requests to us)

β€’ Website visitor data (e.g., IP address, log files, device ID)

There is no obligation to provide your personal data. However, please note that our services cannot be provided if you do not supply the necessary data that is essential for fulfilling the contract between you and us.

2 How we collect personal data

We collect information about our users when they use our services, including certain actions on our website.

Direct

β€’ About our website and electronic communication

β€’ If you use our services

β€’ If you provide us with services

β€’ If you correspond with us electronically

β€’ When you browse while using our services, fill out a form, or make a request

Indirect

β€’ Through public sources

β€’ From public records (e.g., commercial registers), news articles, and internet searches

β€’ When our business clients hire us to provide professional services and share personal data with us that they control as part of this assignment

β€’ From external service providers

3 Legal basis and purposes of data processing

Our legal basis for collecting and using the personal data described in this privacy policy depends on the personal data we collect and the specific purposes for which we collect it.

Contract:

To fulfill our (pre-)contractual obligations or to take measures related to a contract with you. In particular:

β€’ To help you with inquiries

β€’ To set up and maintain your account as well as to verify your login details

β€’ In order to provide our services

Consent:

We can rely on the consent you voluntarily gave at the time you provided your personal data. In particular:

β€’ To set optional cookies and similar technologies on your device

β€’ To provide users with news, special offers, newsletters, and general information about the goods and services we offer

Legitimate interests:

We can rely on legitimate interests based on our assessment that the processing is fair and reasonable, and where your interests or fundamental rights and freedoms do not prevail. Specifically:

β€’ To set technically necessary cookies and similar technologies on your device

β€’ To develop new services

β€’ For maintaining and improving our services, as well as to prevent, find, and fix security issues

Need to comply with legal obligations:

To fulfill legal obligations and responsibilities in the public interest. In particular:

β€’ To inform you about changes to our services and our privacy policy

β€’ To comply with the applicable rules and laws

β€’ For the legal enforcement of claims and rights

4 Storage periods

We keep personal data for as long as it’s needed for the purposes it was collected and in line with legal and regulatory requirements or contractual agreements.

After this period, we will delete your personal data or fully anonymize it.

5 Recipients of personal data

We hire third-party companies ("service providers") to help run our services, analyze how they're used, or provide necessary services like payment processing and IT support. These third parties only have access to your personal data as far as needed to get these tasks done.

Types of service providers who can access your personal data:

β€’ Third parties that we involve in the course of providing our services for you, such as consultants, banks and other payment service providers, KYC/AML service providers, as well as postal and courier services

β€’ Other corporate units that are involved in providing our services to you

β€’ Third parties who support us with IT and software solutions

β€’ Third parties who help us gain customer insights and with marketing activities

6 Data transfers to third countries

We and/or our service providers may transfer your personal data to the following places and process it there:

β€’ EU and EEA

β€’ USA

β€’ Switzerland

β€’ India

We can use service providers who are partly located in so-called third countries (outside the European Union or the European Economic Area or Switzerland) or who process personal data there, meaning in countries whose data protection level does not match that of the EU or Switzerland.

We protect your personal data according to our contractual obligations and the applicable data protection laws when we transfer data abroad.

Such protective measures can include:

β€’ The transfer to countries that, according to the Federal Council, provide an adequate level of protection, as well as countries for which there is an adequacy decision by the European Commission

β€’ Use of standard contractual clauses, binding corporate rules, or other standard contractual obligations that ensure adequate data protection

If data is transferred to a third country and there is no adequacy decision or appropriate safeguards, it is possible and there is a risk that authorities in the third country (e.g., intelligence services) may access the transferred data and that enforceability of the data subjects' rights may not be guaranteed.

7 Data sharing

We may disclose your personal data if we believe in good faith that such a measure is necessary:

β€’ To comply with a legal obligation (i.e., when this is legally required or in response to legitimate requests from authorities, such as a court or a government agency)

β€’ To protect the security of the website and defend our rights or property

β€’ To prevent or investigate any possible misconduct related to us

8 Data security

We use appropriate technical and organizational security measures to protect your stored data from manipulation, loss, or unauthorized access by third parties. Our security measures are continuously updated in line with technological developments.

We also take internal data protection very seriously. Our employees and the service providers we commission are obliged to maintain confidentiality and comply with applicable data protection laws. Furthermore, they only have access to personal data to the extent necessary to perform their respective tasks or assignments.

The security of your personal data is important to us, but keep in mind that no method of transmission over the Internet or electronic storage is 100% secure. Even though we strive to protect your personal data with economically reasonable means, we cannot guarantee absolute security. We recommend using antivirus software, a firewall, and other similar software to protect your system.

9 Your rights

You have the following privacy rights. To exercise these rights, you can contact the address mentioned above or send an email to service@nimbus-3D.com. Please note that we may ask you to verify your identity before we respond to such requests in detail.

β€’ Right to information: You have the right to request a copy of your personal data, which we will provide to you in electronic form.

β€’ Right to correction: You have the right to ask us to correct our records if you believe they contain false or incomplete information about you.

β€’ Right to withdraw consent: If you have consented to the processing of your personal data, you have the right to withdraw that consent for the future. This also applies if you want to unsubscribe from marketing messages. Once we receive the notification that you have withdrawn your consent, we will no longer process your data for the purpose(s) you originally agreed to, unless there is another legal basis for processing. To stop receiving emails from us, please click the "Unsubscribe" link in the email you received or contact us at service@nimbus-3D.com.

β€’ Right to deletion: You have the right to request that we delete your personal data if it is no longer needed for the purposes it was collected for or if it has been processed unlawfully.

β€’ Right to restrict processing: You have the right to request the restriction of processing your personal data if you believe the data is inaccurate, the processing is unlawful, or we no longer need the data for the original purpose but cannot delete it due to a legal obligation or because you don't want us to.

β€’ Right to data portability: You have the right to request that we transfer your personal data to another controller in a standard format like Excel, as long as it's data you provided us and we process it based on your consent or to fulfill our contractual obligations.

β€’ Right to object to processing: If the legal basis for processing your personal data is our legitimate interest, you have the right to object to this processing for reasons arising from your particular situation. We will comply with your request unless we have a compelling legal basis for processing that outweighs your interests, or we need to continue processing the personal data for the establishment, exercise, or defense of a legal claim.

β€’ Right to lodge a complaint with a supervisory authority: You have the right to lodge a complaint with a data protection supervisory authority if you believe that the processing of your personal data violates data protection law. In the EU and the EEA, for example, you can exercise this right with a supervisory authority in the member state of your residence, your workplace, or the place of the alleged violation. You can find a list of the relevant authorities at:

https://edpb.europa.eu/about-edpb/about-edpb/members_de.

The responsible supervisory authority in Switzerland is the Federal Data Protection and Information Commissioner, Feldeggweg 1, CH – 3003 Bern, info@edoeb.admin.ch.

10 Cookies

Our services use cookies and similar technologies (together called 'tools'), which are provided either by us or by third parties.

A cookie is a small text file that is stored on your device. Similar technologies include web storage (local/session storage), fingerprints, tags, or pixels. Most browsers are set by default to accept cookies and similar technologies. However, you can usually set your browser to reject cookies or similar technologies, or to only store them with your prior consent. If you refuse cookies or similar technologies, you might not be able to use all of our services without issues.

Below, we have listed the tools we use by category, specifically informing you about the providers of the tools, the storage duration, and their purpose. If personal data is transferred to third countries, we refer to Chapter 6 of our privacy policy, also in terms of the possible risks that might be associated with it.

We use tools that are necessary for operating the website, based on our legitimate interest in making your use of our services more convenient and personalized, and as time-saving as possible. In certain cases, these tools may also be required to fulfill a contract or to carry out pre-contractual measures. In these cases, accessing and storing information on your device is strictly necessary and is done based on the implementation laws of the ePrivacy Directive in EU member states.

We use all other tools, especially those for marketing purposes, based on your consent. In these cases, accessing and storing information on your device requires your approval and happens according to the implementation laws of the EU member states' ePrivacy Directive. If you’ve given your consent to use certain tools, we will also transfer the data processed while using these tools to third countries based on that consent.

11 Social Media and links to third-party apps and websites

Our services include links to websites or apps that are not operated by us. When you click on a third-party link, you will be directed to that third-party's website or app. We have no control over the content, privacy policies, or practices of third-party websites or services.

We maintain online presences on social networks to, among other things, communicate with customers and prospects and provide information about our products and services. If you have an account on the same network, it is possible that the information and media you make available there can be seen by us, for example when we view your profile. Additionally, the social network may, under certain circumstances, allow us to get in touch with you.

As soon as we take personal data into our own systems, we are independently responsible for it. This happens to carry out pre-contractual measures and to fulfill a contract.

Please refer to the privacy policies of the social networks for the legal basis of the data processing they carry out on their own responsibility.

Below is a list of social networks where we have an online presence:

β€’ Facebook: Privacy Policy

β€’ Instagram: Privacy Policy

β€’ LinkedIn: Privacy Policy

β€’ Xing: Privacy Policy

β€’ X: Privacy Policy

β€’ YouTube: Privacy Policy

12 Newsletter

We send newsletters and other notifications by email and through other communication channels, and we can also deliver them with the help of third parties.

Basically, you need to explicitly agree to receive newsletters and other notifications from us, unless this is allowed for other legal reasons. For emails, we use the 'double opt-in' process, meaning you'll get an email with a web link that you need to click to confirm, so that no unauthorized third parties can misuse it. We can log such consents including your IP address, date, and time.

Newsletters and other notifications may contain web links or tracking pixels that record whether a particular newsletter or notification was opened and which web links were clicked (performance measurement). These web links and tracking pixels record the usage of newsletters and other notifications. We use this statistical recording of usage, including success and reach measurement, to offer newsletters and other notifications in an effective, user-friendly, and consistently safe and reliable way based on the reading habits of the recipients.

13 Changes to this privacy policy

We may update our privacy policy from time to time. We therefore recommend that you regularly check this privacy policy for any changes.

Changes to this privacy policy take effect when they are posted on this page.

14 Contact us

If you have any questions about this privacy policy, don't hesitate to get in touch with us:

Nimbus 3D GmbH

Hofackerstrasse 16

4132 Muttenz

E-Mail: service@nimbus-3D.com