This Privacy Policy explains how Intacta collects, uses, and protects personal data when you visit our website, request a product evaluation, or use our AI product-photography platform (the “Service”). We act as the data controller for the personal data described here. Where we process personal data contained in content you upload to the Service on behalf of your business, we act as your processor under our Data Processing Agreement.
1. Who we are & scope
Intacta (operated by [registered company name, address, and registration number]) provides AI-generated product photography for consumer brands. This Policy applies to visitors to our website, people who contact us or request a product evaluation, and authorized users of the Service. Where we handle personal data that appears inside content a business customer uploads, our Data Processing Agreement governs that processing. You can reach us about privacy at privacy@intacta.io.
2. Information we collect
- Account information — your name, business email, company name, role, Account status, and plan. Our authentication provider manages authentication credentials; Intacta does not receive your full password.
- Inputs, prompts & Outputs — product photographs, brand assets, product names, selected scenes, custom instructions and other materials you submit, together with the Generated Images produced for you.
- Billing information — where paid billing is enabled, your plan, billing-cycle dates, transaction status, and customer or subscription identifiers from our payment processor. We do not receive or store full payment-card numbers.
- Usage, provenance & safety data — generation and download history, quota usage, file type, provider, cryptographic hash, Content Credential validation status, audit events, suspected misuse, and reports or correspondence concerning an Output.
- Evaluation & contact data — first and last name, business email, role, company, company website, product category, approximate product count, typical monthly visual need, and the free-text information you submit through our evaluation form or other messages.
- Technical & log data — IP address, browser/device information, request identifiers, timestamps, authentication, security, diagnostic, error, and audit logs.
3. How we use your data
We use personal data to:
- provide, operate, and maintain the Service, and generate images from your Inputs;
- create and manage your account and authenticate users;
- process billing and manage your subscription;
- provide support and respond to your requests;
- attach, validate, preserve, and report technical provenance information that helps identify Outputs as AI-generated;
- secure the Service, detect and prevent abuse, investigate reports, enforce our Terms, and protect people and third-party rights;
- understand usage and improve our Service (without training AI models on your content — see Section 5);
- communicate with you about your account, important changes, and, where permitted, relevant updates; and
- comply with our legal obligations.
4. Legal bases (GDPR)
If you are in the EEA or UK, we process your personal data on these legal bases:
- Performance of a contract — to provide the Service, manage your account, and handle billing.
- Legitimate interests — to secure and improve the Service, maintain AI-output provenance, prevent fraud and misuse, investigate reports, understand usage, establish or defend legal claims, and conduct proportionate business communications, balanced against your rights.
- Consent — for any optional marketing messages or optional tracking we may introduce; you can withdraw consent at any time.
- Legal obligation — to comply with applicable law.
5. Your content & AI processing
To generate images, we send relevant Inputs and instructions to the AI provider that powers the Service so it can produce your Generated Images. The provider may apply automated safety systems and may reject content under its policies. We validate technical provenance information returned with Outputs and store the resulting status and integrity information. Your content is stored in access-controlled cloud storage and delivered through short-lived, signed links.
OpenAI states that data submitted through its API is not used to train its models unless the account holder explicitly opts in. Under OpenAI’s standard API data controls, Inputs and Outputs may be retained in abuse-monitoring logs for up to thirty (30) days, unless different approved data controls apply. OpenAI explains these controls in its API data-usage documentation.
If illegal or abusive use is reported or reasonably suspected, authorized personnel may review relevant Account records, prompts, Inputs, Outputs, and logs only to the extent reasonably necessary to investigate, protect a person, enforce our Terms, or comply with law. We do not use safety review to train AI models.
Intacta does not train its own models on your data. We do not use your Inputs or Generated Images to train models. Our AI providers process content under their applicable enterprise/API terms, as described in our sub-processor disclosures and customer agreements.
6. Sharing & sub-processors
We do not sell your personal data. We share it only with:
- Service providers (sub-processors) that host and power the Service — including cloud hosting and database, AI image generation, payment processing, transactional email, and error monitoring. These are listed on our Sub-processors page.
- Professional advisers, affected service providers, and competent authorities, where reasonably necessary to investigate misuse, protect a person or our rights, establish or defend legal claims, or comply with law.
- A successor entity, in connection with a merger, acquisition, or sale of assets, with notice to you.
7. International transfers
Our Service and data are currently hosted in the United States (Google Cloud), and providers may process data in the locations listed in our sub-processor disclosures. If you are in the EEA or UK, your personal data may therefore be transferred to countries whose laws may differ from yours. Where a restricted international transfer requires a safeguard, the applicable provider agreement or Data Processing Agreement must supply a valid transfer mechanism, which may include an adequacy decision, the European Commission’s Standard Contractual Clauses, the UK International Data Transfer Addendum, and appropriate supplementary measures. You may contact us for information about the mechanism applicable to your data.
8. Data retention
We retain personal data only for as long as needed for the purposes above, taking account of the Account relationship, your deletion choices, security needs, disputes, and mandatory legal, tax, and accounting periods:
- temporary job-specific copies of product references are scheduled for deletion after a completed or failed generation job is finalized;
- product-library assets, Generated Images, project records, and related instructions are retained while your Account is active unless you delete the relevant item sooner;
- after termination, Generated Images are ordinarily available for export for thirty (30) days, unless access must be restricted for legal or safety reasons, and are then deleted or anonymized under our deletion process;
- contract, billing, security, audit, safety-report, and support records are retained only for the period reasonably necessary for the relevant legal, accounting, fraud-prevention, security, dispute, or enforcement purpose; and
- evaluation and sales-enquiry information is retained while we are responding and while a business relationship remains reasonably anticipated, then deleted or anonymized when it is no longer necessary for that purpose.
9. How we protect your data
We use administrative and technical measures to protect personal data, including encryption in transit, access controls, per-customer data isolation, short-lived signed links for images, and locked database rules. No method of storage or transmission is completely secure, but we work to protect your data and will notify you of a personal-data breach where required by law.
10. Your rights
Depending on where you live, you may have the right to access, correct, delete, restrict, or object to our processing of your personal data, to data portability, and to withdraw consent. To exercise these rights, contact privacy@intacta.io. You may also lodge a complaint with your local data-protection authority (in Greece, the Hellenic Data Protection Authority). Where we process personal data on behalf of a business customer, please direct your request to that customer, and we will assist them as their processor.
11. Cookies & analytics
We currently use only storage and similar technologies needed to operate and secure the app, including authentication and account-state storage. We do not currently set optional analytics or advertising cookies. If that changes, we will update this notice and request consent where required. For details, see our Cookie Policy.
12. Children
The Service is intended for businesses and is not directed to children. We do not knowingly collect personal data from children. If you believe a child has provided us personal data, contact us and we will delete it.
13. Changes to this policy
We may update this Privacy Policy from time to time. If we make a material change, we will provide reasonable notice (for example, by email or on our website) and update the “last updated” date above.
14. Contact us
For privacy questions, rights requests, or questions about international-transfer safeguards, contact us at privacy@intacta.io, or write to Intacta, [registered company name and address]. Reports concerning illegal or abusive Outputs should be sent to legal@intacta.io.