Short retention, clear choices
1. Who controls your data
Controller: ILO APPLICATIONS SL, NIF B93663862, EU VAT ID ESB93663862, Málaga, Spain. The registered street address and public privacy mailbox are deployment values that must be verified before paid launch. Company details shows their current status.
2. Data we process
- Source photos, finished images, extraction masks, technical image checks and the choices needed to process the order.
- Email address, locale, consent records, secure-link identifiers and order status.
- Payment status, amount, currency, tax and receipt references received from Stripe; we do not receive your full card number.
- Security and operations data such as IP-derived request information, timestamps, device/browser data, rate-limit events, audit logs and error diagnostics.
- Optional share-page title, selected finished images, download setting, publication/renewal dates and abuse reports.
- Messages you send for a privacy, legal, refund or support request.
3. Why and on what legal basis
- Contract: pre-payment checks you request, checkout, processing, delivery, refinements, recovery and owner controls.
- Consent: an optional public share page and any optional non-essential browser storage or marketing use. You may withdraw consent prospectively.
- Legal obligation: tax, accounting, consumer, fraud-prevention and data-rights records where required.
- Legitimate interests: keeping the service secure, preventing abuse, measuring operational reliability without customer-media analytics, and establishing or defending legal claims, balanced against your rights.
4. Image processing and AI providers
Standard output copies visible dog RGB from the uploaded source into a deterministic composite. Bounded on-host tools detect one dog and dog/person overlap before payment. After verified payment, an approved remote provider may estimate an alpha mask; its colour output is discarded. Approved scene-generation providers may create generic empty portrait settings without customer photos.
We do not use ordinary customer photos to train models, build marketing examples or compare providers. Any separately consented evaluation programme requires its own clear purpose and revocable consent. Automated checks decide whether an image can enter this photo workflow; they do not make a legal or similarly significant decision about you.
5. Recipients and international transfers
We use service providers by category: EU hosting and object storage, payment and tax processing (Stripe), transactional email, security/monitoring, and approved image-processing providers. They receive only the data needed for their task and act under contracts or as independent controllers where their service requires it.
Some providers may process data outside the EEA. Before activation we document the transfer mechanism and safeguards, such as an adequacy decision or Standard Contractual Clauses, plus relevant supplementary measures. The live provider register and configurations must be approved before paid launch; we do not claim that every optional provider is active.
6. Retention and deletion
- Unpaid uploads: no longer than 24 hours, unless you delete sooner.
- Private order photos and results: normally seven days after delivery, unless needed briefly to resolve an active defect, refund or legal claim.
- Optional share-page copies: up to 12 months from publication or renewal; unpublishing hides the page immediately and deletion removes its active assets.
- Image-free order, consent, payment, tax, security and rights-request records: only for the applicable contractual, statutory or claims period.
- Backups and provider-side deletion must follow the verified production retention schedule. The exact maximum backup-removal window is a launch-gate item and must be published once confirmed.
7. Public share pages are different
Creating a share page is optional and separate from the seven-day private workspace. Anyone with its opaque URL can view the selected results, so recipients can copy or redistribute them. Share pages are marked noindex and omitted from our sitemap, but no technical setting can guarantee that a third party will not record or disclose the URL.
Source photos, before/after views, EXIF/GPS, filenames, order identifiers, email and payment data are never part of the public page. The owner-management token is separate from the public URL.
8. Your GDPR rights
Subject to applicable limits, you may ask for access, correction, erasure, restriction, portability, or objection; withdraw consent; and complain to the Spanish Data Protection Agency (AEPD) or your local supervisory authority. You may also ask about transfer safeguards.
Self-service export provides an image-free JSON summary and deletion removes active photos and eligible personal data. Those tools do not narrow your statutory access rights: photos may themselves be personal data, and we assess a verified rights request under the GDPR. We may retain data that the law requires or that is necessary for a legal claim, and will explain this when applicable.
9. Security, children and changes
We use access tokens separated from public share links, encryption in transit, private storage, input validation, least-privilege administration, audit records and bounded retention. No internet service is risk-free; report a suspected privacy or security issue through the verified contact channel.
The service is not directed to children and a person placing an order must be able to enter the contract. We publish material privacy changes before they apply and retain the notice version accepted with an order where required.