1. Data Controller
Cafe Balu Paweł Mioduszewski, Fabryczna 18, 62-300 Września, Polska, NIP PL7891687047, REGON 301958859. Data-protection contact: privacy@artilio.com.
2. Data we process
Account data; profile & company data; billing data (card data handled solely by the payment provider); gallery content (photos/files, EXIF, names, sharing settings); photographer's end-client data (see §9); technical & activity data (logs, IP, device/browser, cookies); gallery-visitor data.
3. Purposes & legal bases (GDPR)
Service & account — Art. 6(1)(b); payments — (b)+(c); security/analytics/claims — (f); marketing/cookies — (a) consent; in-gallery AI features (content search, auto-tagging, cover/quality suggestions) and improving them, incl. training our non-biometric models on photos — (f) legitimate interest (with a right to object / opt out — see §7); accounting/tax — (c).
4. Recipients (categories of processors)
We use the following categories of processors, only as needed to provide the Service:
- An EU-based AI image-processing provider — image embeddings for content search (processing in the EU).
- A US-based AI assistant provider — the in-app assistant; receives only text + gallery/image metadata, never the photos (SCCs/DPF).
- EU-based cloud hosting, file storage and database providers — application hosting, gallery file storage/CDN (EU jurisdiction, encrypted at rest), and database (EU — Frankfurt).
- A payment provider— payments & invoicing.
- An EU-based email provider — transactional email.
We do not sell personal data. The full, named list of subprocessors is provided to our customers (photographers) in-app / on request, under the Data Processing Agreement.
5. Transfers outside the EEA
Most processing is in the EU (gallery files, database, image embeddings, email). Photos never leave the EU. Outside the EEA we transfer only text + metadata to the US-based AI assistant provider and payment data to the payment provider, under SCCs and/or the Data Privacy Framework.
6. Retention
Account data — while the account exists + up to 30 days after deletion; billing/invoices — 5 years from end of tax year; gallery content — until deleted by the user or, after a subscription ends, 14 days, after which it is scheduled for deletion; technical logs — up to 12 months.
7. AI processing of photos
- In-gallery AI features: we use AI for content search, auto-tagging / topic detection, and “best cover” / quality suggestions — computed from photo embeddings and EXIF metadata. Embeddings are produced by an AI provider whose infrastructure and processing are EU-only.
- Improving these features (research, development & model training): to research, develop and improve these non-biometric features, we train and experiment with our own models on real photos (e.g. for aesthetic and quality scoring). We do not use them to build foundation models, do not share photos with third parties for their training, and do not use them to identify individuals. Legal basis: legitimate interest (Art. 6(1)(f)).
- Your control (opt-out): you can turn off AI features and model-improvement at any time in your account settings (Settings → AI features), with separate per-gallery and per-clientoverrides. Turning it off also stops those photos being used for future model research & development and removes derived AI data where feasible.
- Photos never leave the EU.
- AI assistant (in-app): processes only query text + gallery/image metadata — not the photos — via a US-based AI assistant provider, solely to answer you.
- None of this includes biometric identification or face recognition (see §8).
8. Biometric data / face grouping
Artilio offers an optional face grouping feature that groups photos of the same person within a single gallery, to help the photographer organise and select photos. The feature is off by default and must be knowingly turned on by the photographer for a given gallery or account.
Face grouping uses facial-geometry embeddings, which are biometric data under Art. 9 GDPR. Processing takes place in the EU only, on dedicated infrastructure.
Legal basis and role split: the photographer sharing the gallery decides whether to enable this feature and is the controller responsible for obtaining explicit, freely-given consent from the people shown in the photos (Art. 9(2)(a) GDPR) before enabling it, which they confirm in-app via an attestation. We act as the processor: we run face grouping only on the photographer's documented instruction and their consent attestation, under the Data Processing Agreement.
Face embeddings are scoped to that gallery only and are never reused across other galleries or accounts, and are never automatically linked to a name or other identity. This data is deleted when the feature is turned off, when a data subject withdraws consent, or when the gallery is deleted.
9. Photographer as controller
When a photographer shares a gallery, the photographer is a separate controller; we act as a processor under a DPA (in-app / on request).
10. Your rights
Access, rectification, erasure, restriction, portability, objection, withdrawal of consent — privacy@artilio.com. On request, we will disclose the specific identity of the recipients of your data. Complaints: Polish DPA (UODO).
11. Cookies
Necessary (incl. basic preferences such as language), analytics and marketing (with consent — cookie banner). Details and settings: Cookie Policy.
12. Security
SSL/TLS, password hashing, access control, backups, encryption at rest.
13. Changes
Material changes notified by email or in-app.
14. Contact
Cafe Balu Paweł Mioduszewski, Fabryczna 18, 62-300 Września, Polska. Email: privacy@artilio.com.