MC Studio is a trade name of REVE Media, KVK 88874990, VAT identification number NL004665647B65, with business address Diamantdreef 16, 7828 AW Emmen, the Netherlands.
Export, switching and deletion requests: privacy@mcstudio.io or info@mcstudio.io.
1. Purpose, scope and current capability
This policy explains how to request your data, the retained data structures and formats, known technical limitations, and the switching and deletion rights that apply to MC Studio's services. It supplements the Terms of Service and, where MC Studio processes a Business Customer's personal data on its behalf, the Data Processing Agreement (DPA).
The current request route is contact with MC Studio for administrator assistance. Underlying cloud records and stored files can be retrieved administratively. A complete, validated workspace-export workflow and a documented destination-provider switching interface have not yet been established. Individual file downloads are not equivalent to a complete workspace export. We do not represent source-code recovery features as deployed self-service export functions without deployment confirmation.
The technical information below reflects the review of 14 September 2026. Describing retrievable records or a feasible format does not mean a complete customer package has already been produced and tested. These limitations do not waive or postpone obligations imposed by the GDPR, the EU Data Act, the DPA or other mandatory law, and do not excuse a failure to provide data that we are required to provide.
2. Making a request
Contact privacy@mcstudio.io or info@mcstudio.io and identify the account or workspace and what you need. You may request a copy of retained data, assistance switching to another provider, transfer to your own ICT infrastructure, or deletion. A simple request is sufficient; you do not have to use technical terms or a prescribed form.
We may make proportionate identity and authority checks before disclosing data. A workspace owner, authorised representative and individual exercising personal-data rights may have different entitlements. We will not disclose another person's or another workspace's information without authority. We may ask for the details of an authorised destination provider and agree a secure way to deliver the data.
An export request does not by itself cancel every subscription or request deletion. We will clarify the intended action where necessary. Where the Data Act applies and you choose switching or erasure on termination, the termination rules in section 10 apply.
Do not send passwords, session tokens, OAuth credentials, private links that grant access, a full authentication database or an unfiltered browser-storage dump. If local-only data may matter, tell us before clearing or resetting the relevant browser.
3. Different rights and their deadlines
3.1 GDPR and Controller instructions
An individual's GDPR access, portability or erasure request is separate from a contractual Data Act switching process. When MC Studio is the controller, we act without undue delay and normally within one month of receiving the request. An extension of up to two further months is available only where permitted because of the complexity or number of requests; we explain the extension and reasons within the first month. A refusal or limitation must meet applicable law and be explained with available complaint and remedy information.
When MC Studio acts as processor, the Business Customer's instructions and the DPA govern return or deletion and assistance with individuals' rights. A two-month switching-notice period does not override those instructions or a shorter mandatory deadline.
3.2 Data Act initiation notice
Where Chapter VI of the EU Data Act applies, the maximum contractual notice period before initiation of switching is two months from the switching request. Switching may start earlier by agreement. We will identify the applicable dates in the response and support your exit strategy for the contracted services. This period is not a general waiting period for ordinary file downloads, GDPR requests or subscription cancellation under a separate cancellation right.
3.3 Transition
After the applicable initiation-notice period, switching must proceed without undue delay and within 30 calendar days, except where a lawful extension applies. During the transition, the relevant contract remains applicable. MC Studio will provide reasonable assistance to you and your authorised destination provider, exercise due care to maintain service continuity, communicate known continuity risks and maintain a high level of security during transfer and retrieval.
If the ordinary 30-day transition is technically infeasible, we will notify you within 14 working days of your switching request, explain and substantiate the technical reason and give an alternative transition period of no more than seven months. Ordinary workload does not by itself establish technical infeasibility. The absence of a prepared exporter is not treated by this policy as an automatic entitlement to the maximum extension.
You may extend the transition once for a period you consider more appropriate for your own purposes, as provided by Article 25(5). Tell us through the switching contact route before the current transition ends so the process can be coordinated.
4. Data categories and retained representations
MC Studio must make available all exportable data and digital assets required by applicable law and contract, including relevant input, output and relationship metadata. An incomplete internal tool or inventory is not a contractual exclusion.
The following table records identified data categories and the representations from which an export can be assembled. These are technical extraction formats, not a certified complete export feature. Whether a category contains data depends on what has actually been created, saved and retained. Nested structures must be preserved rather than flattened away. JSON is structured text; CSV is suitable for flat tables but is not a replacement for complete nested design data.
| Data category | Retained structure and extraction representation | Important scope or limitation |
|---|---|---|
| Customers and contacts | Client records, saved project contact fields and contact history; JSON or CSV. | Retained archived clients are included in scope. |
| Projects and project metadata | Project records, status, archive flag, client reference, dates, budget/cost and customer submissions; JSON, with CSV for flat fields. | Nested planning, items, rooms and images must be retained, not lost by flattening. |
| Designs, rooms, cabinets and parts | Cloud design documents and available local documents; proprietary MC Studio JSON. | Browser-only and unsynchronised copies require separate recovery; see section 5. |
| Notes | Saved client, supplier and project notes; text or JSON. | Rich-text notes use a versioned tiptap-json representation in a text field; preserve it alongside any retained plain text. |
| Tasks and checklists | Project tasks/sections and workspace lists/items; JSON or CSV. | Preserve ordering, completion status and parent references; local legacy items may be separate. |
| Measurements and site-visit information | Saved planning/room data, dimensions in design documents, calendar events and associated notes/files. | No universal separate site-visit record or dedicated complete measurement export is established. |
| Photographs, documents and branding images | File metadata, referenced stored bytes and available local image blobs. | Provide files in the form retained by MC Studio; original pre-processing images are not always retained. |
| Workshop and project settings | Workspace settings, relevant profile preferences and calendar/task templates; JSON or CSV. | Some settings are local-only and require device access. |
| Construction methods, materials and cabinet templates | Available cloud or legacy local structured records and design data; JSON, with CSV for suitable flat records. | Applies to customer data and transferable assets, subject to lawful third-party rights. |
| Quotes and offers | Retained legacy or design-embedded offer structures; proprietary nested JSON, or a quote saved as a file. | No separate cloud quotes table or complete quote-export workflow was found in the reviewed implementation. |
| Customer payment and deposit information | Information retained in notes or files can accompany those records. | No dedicated structured customer payment/deposit ledger was established. Project costs, procurement status and MC Studio subscription status are not that ledger. |
| Users, membership and subscription information | Relevant profile, membership and customer-facing entitlement records; allowlisted JSON or CSV. | Scope shared accounts to this workspace and request; exclude credentials and unrelated workspace references. |
| Suppliers, inventory and procurement | Retained supplier, inventory/material and project-procurement records; JSON or CSV. | Keep project, supplier and item relationships. |
| Calendar events and templates | Retained calendar/event and template records; JSON or CSV where suitable. | Data that remains only with Google or another provider is not part of a cloud-database extraction; relevant rights and scope must still be assessed. |
| Other customer-submitted and legacy workshop content | Retained project changes, workshop standards, lessons, skills, tools and hardware libraries; JSON or CSV where suitable. | Local-only collections require separately scoped recovery; private third-party content is not included without authority. |
Relevant customer data held by MC Studio through external services, including support conversations, must also be assessed. It is not automatically excluded just because it is outside Supabase. Data held solely by an independently used third-party service may need to be requested from that provider. We will explain the distinction rather than silently omit a known data location.
This table does not promise a product feature or dataset that has never been supplied, recorded or retained. Nor does it limit a right to other data that applicable law requires us to provide.
5. Important format and recovery limitations
5.1 Editable design format
The identified editable design representation is MC Studio's proprietary JSON-shaped McDocument, stored as JSONB in cloud design records and as structured objects in legacy IndexedDB. The reviewed source uses schema identifier mc-doc/next-0.5. The actual document and its applicable schema/version should remain together; a recovery file may use a versioned draft envelope.
This is not a promise of an editable STEP, DXF or other neutral CAD conversion. No complete neutral editable-design conversion was verified. Cutting lists, prints and manufacturing outputs are not substitutes for the complete editable document. Another product may require conversion to interpret the data. These statements do not remove applicable interoperability duties.
5.2 Images and original files
Files are supplied in the form retained by MC Studio. Non-transformed stored files can be returned unchanged. Some photographs are resized or recompressed before upload; branding images can be cropped, resized and converted to WebP. A filename or extension can remain unchanged even when image bytes were processed. We do not guarantee original resolution or pre-processing originals that were not retained.
5.3 Browser-only and unsynchronised work
Some legacy designs, settings, templates, offers, images or drafts may exist only in a particular browser or device. Cloud extraction alone cannot capture them. Recovery depends on access to that device and on the information still being retained. We must establish the correct workspace scope before collecting local records, because a local store may contain data for more than one workspace.
Please preserve the relevant browser data while recovery is assessed. Do not send all browser storage or authentication information. Cleared, overwritten or otherwise unretained local data cannot be promised as recoverable. These limitations do not shift responsibility for an MC Studio breach to you.
5.4 Archives, history and completeness
Retained archived, locked or read-only data is not excluded solely because the ordinary interface does not display or permit editing of it. Deleted data is a separate case. A current design and revision number do not establish a complete version-history archive. We do not promise reconstruction of deleted or overwritten data that is no longer retained.
We will identify known omissions or limitations in the response. Describing an omission does not make it lawful to withhold information that must be provided.
6. Preparing and delivering data
For a lawful request, MC Studio will establish the relevant workspace and data locations, apply a customer-field allowlist, preserve the relationships needed to understand the data, and arrange secure delivery. Necessary identifiers for clients, projects, designs, suppliers, tasks and files are not stripped merely because they are technical IDs.
A delivery should explain its scope and extraction date, record structures and schema versions, relationships, included files and known omissions. Where files are delivered, a manifest should relate them to their records and parent projects without losing their recorded names. A ZIP can contain structured data, design documents, retained files and a README/manifest; this describes a packaging approach, not an already tested automated product feature or fixed folder-name promise.
We will assess relevant external-service records and browser-only recovery separately rather than calling a database-only extraction complete. No measured normal-workspace turnaround time is currently established; the statutory and contractual deadlines in section 3 still apply.
7. Security exclusions and protected material
We do not deliver an unfiltered database backup, raw authentication tables or a wholesale browser-storage dump. The following categories are withheld only to the extent lawfully outside the data to be provided or necessary to protect security or other people's rights:
- Passwords/hashes, authentication and recovery tokens, session/refresh credentials, invitation and temporary-upload credentials, bearer share-link secrets, OAuth credentials and calendar sync/watch secrets.
- Other customers' data, unrelated workspace references and personal information the requester is not authorised to receive.
- MC Studio source/object code, proprietary algorithms, model weights and protected internal architecture; protected first-party or third-party source assets that are not lawfully transferable as part of the customer's export.
- Internal threat intelligence, fraud/security rules and privileged diagnostic payloads whose disclosure would undermine security or reveal protected internal functioning, and which are not the customer's legally exportable data.
- Internal benchmarking or diagnostic models/metrics that are genuinely outside the customer's exportable data and are not needed to make that data usable.
Ordinary record IDs, the customer's own input/output data and necessary metadata are not excluded merely because they appear in an internal system. Trade-secret exclusions must not impede or delay protected switching rights. Customer outputs containing licensed material remain subject to the relevant licence without automatically being excluded as a whole.
A lawful duty to retain MC Studio's own accounting or legal records is a retention exception, not a reason to deny the customer a copy of data it is entitled to receive. Credentials remain excluded even where a customer asks a destination provider to assist.
8. Export information and interfaces
Our Data Export & Portability page is the location for this policy and current information on retained structures, formats, relevant standards, available methods and limitations. We update that information when the supported structure or method changes. A complete field/schema specification is not represented as having been validated by the technical table alone.
MC Studio does not currently provide a verified complete-workspace self-service export or documented destination-provider portability API. Internal application endpoints and underlying Supabase APIs are not represented as a supported external interface. No customer should be given privileged administrative credentials as a substitute.
Where Article 30(2) of the Data Act applies, MC Studio must make the required open interfaces and sufficient information available equally and free of charge to customers and relevant destination providers. Manual delivery is not represented as satisfying that separate obligation by itself. Applicable interoperability specifications and standards must be respected; where Article 30(5) applies, all exportable data must be provided in a structured, commonly used and machine-readable format.
A later self-service feature will be described when available. Its future development does not suspend existing data-access, switching or interoperability obligations.
9. Retrieval, erasure and other retention periods
After the agreed Data Act transition ends, the relevant exportable data will remain available for retrieval for at least 30 calendar days. A later erasure date may be agreed for a genuine retrieval need, subject to the GDPR, Controller instructions and applicable law. This is not permission to retain customer content for unrelated analytics.
After successful switching and expiry of that retrieval period, or a lawful later period agreed with the customer, MC Studio will erase the exportable data and digital assets generated directly by or relating directly to the customer as required by the Data Act. Narrow records retained to meet mandatory legal obligations remain restricted to those purposes and do not justify keeping the entire workspace. We will not deliberately retain deleted customer data through operational backup reuse contrary to the applicable deletion obligation.
This lifecycle is separate from the ordinary 30-day accidental account-deletion recovery period and up-to-12-month cancellation/downgrade recovery window in the Terms and DPA. A valid earlier erasure request or Controller return/deletion instruction takes priority where required. Merely leaving a subscription does not turn private customer content into MC Studio's analytics data.
Cloud deletion does not guarantee remote erasure of browser-only copies or files you or a destination provider have lawfully received. We will explain the local-data steps relevant to the request without asking you to erase unsynchronised work before it can be recovered. MC Studio remains responsible for processing and deletion under its control.
10. Charges, continuity and termination
MC Studio does not charge a special switching fee, including data-egress charges for the statutory switching process. This commercial policy also applies before the Data Act's prohibition on switching charges takes effect on 12 January 2027. We do not require purchase of a Production Pass or a higher plan merely to exercise statutory data-access or switching rights. Generating a new paid manufacturing output is distinct from returning existing data that the customer is entitled to receive.
Normal subscription fees lawfully due before termination and genuinely separate professional services expressly requested outside statutory assistance remain governed by the Order and mandatory law. No new early-termination penalty is created by this policy. Any valid continuing payment obligation or early-termination charge must have been disclosed before contracting and must comply with applicable law; statutory assistance cannot be relabelled as paid consulting.
Where the Data Act applies, the affected service contract is considered terminated when switching is successfully completed, or at the end of the applicable initiation-notice period when you chose erasure rather than switching. We will notify you of termination. An incomplete internal exporter is not a basis for declaring the switch complete or continuing charges indefinitely. Accrued lawful obligations and rights that survive termination remain unaffected.
11. Provider jurisdictions and governmental access
MC Studio operates under Dutch law and uses third-party infrastructure. The Supabase production project is configured in an EU region. This does not establish that every provider's processing, support or administrative access takes place only in the EU.
Relevant provider identities, ICT-infrastructure jurisdictions and processing locations, roles and international-transfer safeguards are maintained through mcstudio.io/legal/subprocessors. That information must reflect actual account configuration and provider arrangements, not assumptions drawn solely from cookie names.
Where Article 32 of the Data Act applies, MC Studio will take the required technical, organisational and contractual measures against unlawful third-country governmental access to non-personal data held in the Union. This includes assessing the legal basis of a demand, limiting any legally permitted disclosure, seeking the appropriate authority's assessment where required and informing the customer before compliance except where the lawful law-enforcement exception applies. A general description of the actual measures and relevant infrastructure jurisdictions must be available on the linked legal information page under Article 28.
The Privacy Policy and DPA govern personal-data transfers. Google Calendar information remains subject to the specific Limited Use restrictions in the Privacy Policy. A switching request does not authorise unrelated AI training or disclosure of Calendar credentials. Those restrictions do not remove statutory rights to one's data.
12. Cooperation, complaints and updates
MC Studio, the customer and an authorised destination provider must cooperate in good faith to make switching timely and effective. Reasonable security or authority checks must not be used as unnecessary barriers. We will communicate known gaps and work needed rather than imply that a proposed export design is already implemented.
Contact privacy@mcstudio.io or info@mcstudio.io for exports, switching or deletion. You retain any right to contact a competent authority or court without first exhausting MC Studio support. We will update this policy and the linked technical information when the actual supported scope changes; changes do not retrospectively remove accrued or mandatory rights.