Privacy Policy

Art Persona · Privacy Policy · v1.0 · Effective 30 July 2026

FieldValue
OperatorGromeFeet OÜ
Company number17348635
Registered officePärnu mnt 12, Kesklinna linnaosa, 10148 Tallinn, Harju maakond
Trading name / brandArt Persona
Websitehttps://art-persona.com
Contact emailinfo@art-persona.com
Support / complaintsinfo@art-persona.com (Monday-Friday, 09:00-17:00 Estonia time, excluding public holidays)
Governing lawEstonia, subject to mandatory consumer protections
Document versionv1.0
Effective date30 July 2026
Who this policy applies to: This policy applies to visitors, customers and identifiable people shown in submitted images. Art Persona processes facial images to create the requested avatar, not to identify a person biometrically across services, and does not intentionally store full payment-card details.

1. Introduction and scope

GromeFeet OÜ is committed to fair, transparent and proportionate processing. This policy applies to visitors, customers, support contacts and people depicted in submitted images. It covers the website, checkout, production of custom avatars, download delivery, complaints and related fraud-prevention activity.

2. Data controller and contact

GromeFeet OÜ is the controller for decisions about customer, website and order data. Privacy questions and data-subject requests may be sent to info@art-persona.com or the registered office. No separate data protection officer has been appointed because the current processing model does not require one; requests are handled under management responsibility.

3. Age position

The Service is intended for adults aged 18 or over. GromeFeet OÜ does not knowingly contract directly with children or invite children to upload images. A parent or legal guardian must place and control an order involving a minor, confirm authority over the image and ensure that the requested Output is appropriate and lawful.

4. Categories of personal data

Data may include identification and contact details, account credentials, order selections, payment references, Customer Materials, generated Outputs, production metadata, device and log data, consent records, support correspondence, fraud indicators and legal-claim information. Full payment-card credentials are handled by the payment provider and are not intentionally stored by GromeFeet OÜ.

CategoryExamplesSourcePurpose
Account and contactName, email, credentials, countryCustomerAccount administration, delivery and communications
Customer Materials and OutputPhotos, prompts, selected style, generated avatar filesCustomer and production workflowCreate, review, deliver and support the custom avatar
Transaction and paymentAmount, currency, provider reference, card brand, partial digits, refund statusCustomer and payment providerAuthorisation, reconciliation, refunds and disputes
Technical and usageIP address, device, browser, logs, cookie choices, access eventsDevice and ServiceSecurity, diagnostics, consent and performance
Support and complianceMessages, complaints, consent evidence, fraud or rights indicatorsCustomer, depicted person, providers or public sourcesSupport, safeguarding, legal compliance and claims

5. Sources of personal data

Most data comes directly from the customer through forms, uploads, checkout and communications. Additional data may come from a payment provider, fraud-prevention service, hosting logs, cookie choices, an authorised representative, a person depicted in an image, or public sources used only to assess a rights, safety or impersonation concern.

Individuals retain the rights and complaint routes provided by applicable data-protection law.

6. How we use personal data

Data is used to create and deliver avatars, administer accounts, take payment, communicate about orders, prevent misuse, secure the Service, honour consent choices, improve reliability, comply with accounting and legal duties, establish or defend claims and respond to rights requests. GromeFeet OÜ does not use uploaded face images to identify people across services or build biometric identity profiles.

7. Lawful bases for processing

Contract is the principal basis for order fulfilment, customer support and delivery. Legal obligation supports tax, accounting and regulatory records. Legitimate interests support proportionate security, fraud prevention, service diagnostics and defence of claims. Consent supports non-essential cookies, optional marketing and any processing that legally requires explicit permission, and may be withdrawn for future processing.

Processing activityLawful basisNotes
Create and deliver an ordered avatarContractNecessary to perform the paid Order and requested revisions
Payment, tax and accounting recordsContract and legal obligationIncludes transaction references but not full card credentials
Security, fraud and abuse preventionLegitimate interests and legal obligation where applicableBalanced against customer rights; high-impact restrictions can receive human review
Non-essential analytics and marketing cookiesConsentNot activated before valid consent where European rules require it
Optional promotional emailConsent or another lawful basis permitted by applicable lawUnsubscribe is available in each marketing message
Legal claims and authority requestsLegal obligation and legitimate interestsLimited to necessary, proportionate information

8. Payments and checkout

The payment provider receives card and authentication information directly through its secure interface. GromeFeet OÜ normally receives the payer name, billing result, tokenised reference, card brand, partial card digits, amount, currency, risk signals and refund status. These records support fulfilment, reconciliation, fraud prevention, customer service and payment disputes.

9. Cookies and similar technologies

Cookies and browser storage are used for security, session continuity, language or preference settings, consent management, analytics and marketing where enabled. Details of categories, providers and retention are contained in the Cookie Policy. Non-essential technology is controlled through the consent interface where required by applicable law.

10. Sharing of personal data

Data may be shared with payment processors, hosting and cloud-storage providers, email and support services, image-processing or artificial-intelligence infrastructure, analytics and consent tools, professional advisers, insurers, auditors, authorities and prospective corporate transaction counterparties. Each recipient receives only the data reasonably needed for its function and is subject to contractual or legal safeguards.

Consent can be withdrawn for future processing without affecting prior lawful processing.

11. International transfers

Some service providers may process data outside Estonia or the European Economic Area. Where the destination does not benefit from an adequacy decision, GromeFeet OÜ uses an approved transfer mechanism such as standard contractual clauses and applies supplementary technical or organisational measures appropriate to the risk. Transfer information may be requested through the privacy contact.

12. Data retention

Customer Materials and working production files are retained only for the production, revision and support period, normally no longer than 30 days after final delivery unless a dispute or explicit storage feature requires longer. Delivered Outputs and account records may be kept while the account remains active. Transaction and accounting data is generally retained for seven years; security logs are normally retained for up to twelve months.

Data categoryRetention periodTrigger / criterion
Raw Customer Materials and working filesNormally up to 30 days after final deliveryLonger only for requested revisions, dispute, security or legal necessity
Delivered Outputs and account libraryWhile the account is active, plus a short closure retrieval periodMay be removed after closure; customer should keep a lawful backup
Transaction, invoice and tax recordsGenerally 7 yearsMeasured from the end of the relevant financial year or longer if legally required
Support correspondenceNormally 3 years after resolutionExtended where needed for an active claim, fraud matter or safeguarding issue
Security and access logsNormally up to 12 monthsShorter where practical; longer only for incident investigation or legal defence
Consent and preference recordsFor the life of the choice plus 3 yearsDemonstrates consent, withdrawal and the notice version shown

13. Data security

Controls include encrypted transport, access restrictions, role separation, strong authentication, logging, backups, vulnerability management, processor due diligence and deletion routines. No system is risk-free, but GromeFeet OÜ assesses incidents and, where legally required, notifies the Estonian Data Protection Inspectorate and affected individuals without undue delay.

14. Your privacy rights

Subject to legal conditions, individuals may request access, correction, deletion, restriction, portability and objection, and may withdraw consent. They may also object to direct marketing and lodge a complaint with the Estonian Data Protection Inspectorate or another competent supervisory authority. Rights can be limited where identity cannot be reasonably verified, another person’s rights would be harmed, or retention is legally required.

15. Marketing communications

Art Persona sends promotional email only with a valid legal basis and includes a functioning unsubscribe method. Transactional messages about an Order are not marketing and may continue where needed to perform the contract. GromeFeet OÜ does not sell personal data and does not use Customer Materials for third-party advertising without separate, specific permission.

Individuals retain the rights and complaint routes provided by applicable data-protection law.

16. Automated decision-making and profiling

Automated tools may flag payment risk, malware, prohibited content or unusual account activity, but Art Persona does not make solely automated decisions that produce legal or similarly significant effects without safeguards required by law. A customer may request human review of a material restriction where the decision was substantially automated.

17. Third-party services and links

Links, payment interfaces and embedded services may be operated by independent controllers with their own notices. GromeFeet OÜ is not responsible for their unrelated processing, but selects processors with regard to security and data-protection capability. Customers should review the notice presented by a payment or external platform before submitting data directly to it.

18. Changes to this policy

This policy may be updated to reflect legal developments, new processors, changed retention or service functions. The effective date identifies the current version. Material changes affecting existing customers will be communicated by a proportionate method, such as an account notice or email, before the new processing begins where law requires advance notice or renewed consent.

19. How to contact us or submit a request

Requests should be concise, identify the relevant order or account and describe the right being exercised. GromeFeet OÜ may ask for proportionate verification and normally responds within one month, subject to lawful extension for complex or multiple requests. Complaints may also be sent to the registered office or raised with the competent supervisory authority.

Schedule 1. Practical Retention Guide

Art Persona applies deletion by data lifecycle rather than by a single blanket date. Production files are short-lived, transaction records follow accounting duties, and evidence linked to a complaint or fraud review is isolated until the matter is resolved. When a lawful hold ends, the ordinary retention rule resumes.

Before delivery: source images and working files remain available to the limited production team and approved processing infrastructure.

After delivery: working files enter the 30-day deletion cycle unless a revision, complaint or lawful hold remains active.

After account closure: hosted Output access ends after the communicated retrieval period; essential transaction and claim records remain segregated.

After a valid erasure request: data not required for contract, accounting, security, rights of others or legal claims is deleted or irreversibly anonymised.

After a provider change: data is exported or deleted under the provider contract and access credentials are revoked.

20. Governing law and mandatory rights

This Privacy Policy is governed by Estonian law and the General Data Protection Regulation, without limiting mandatory rights available under another applicable law. Individuals may complain to the Estonian Data Protection Inspectorate or another competent supervisory authority, and may seek a judicial remedy where provided by law.

Privacy controls in practice

Privacy compliance is implemented through minimisation at upload, purpose-limited processor access, deletion schedules, consent evidence, security review and a documented rights-request channel. Production personnel access only files assigned to the Order, and credentials are revoked when no longer required. Portfolio display, model improvement or promotion requires a separate assessment and, where applicable, specific consent rather than reliance on fulfilment.

Ownership and approval: The named operational owner confirms that the customer-facing rule, production workflow and support script describe the same outcome before publication.

Change control: A material product, provider or checkout change is assessed for legal impact and deployed only after the affected wording, controls and training have been updated.

Customer evidence: Staff rely on the minimum relevant Order, communication, delivery and payment evidence and do not request unrelated identity, image or card information.

Exception handling: An unusual case is escalated to a competent reviewer rather than resolved through an undocumented promise that conflicts with the published terms or mandatory law.

Quality assurance: Sample cases are tested from customer request through final outcome, including the status visible to support and the records needed to explain the decision.

Access control: Systems and provider dashboards use role-based access, strong authentication and prompt removal of credentials when responsibilities change.

Art Persona · Privacy Policy · v1.0 · Effective 30 July 2026. Published on the website; subject to update; the current published version governs.

Cart (0 items)

Create your account