Privacy Notice
pp-v2.01.Controller and contact
VirtualArtist Oskar Lendzion, Niepołomicka 34C/28, 80-180 Gdańsk, Poland, NIP PL5833494394 is the controller for account, website, billing-support and product-operation data described here. Contact [email protected] for privacy requests. No data protection officer has been appointed. We normally respond to rights requests within one month, subject to lawful extensions and identity verification.
2.Data, purposes and legal bases
We process account identifiers, authentication and security records, buyer and transaction data, service settings, brand context, instructions, conversations, uploaded and generated content, publishing tokens and results, consent evidence and support correspondence.
The main bases are performance of the service contract, compliance with tax and other legal duties, consent for optional analytics or marketing storage, and legitimate interests in security, fraud prevention, service diagnostics and legal claims. We assess and limit legitimate-interest processing. Data not needed for a requested function should not be submitted.
3.Automated processing
SMAT sends the minimum context needed for selected text, image, embedding and visual-analysis functions to configured OpenAI or Google services. The active path depends on the feature. There is no active Anthropic fallback. We do not state that provider training is contractually disabled unless a current provider receipt establishes it.
SMAT profiles brand and content signals to provide suggestions and outputs. These product recommendations do not by themselves produce legal or similarly significant effects about a person. Some publishing flows can act on account configuration; therefore this Notice does not promise blanket human review. Selective AI transparency controls are described in the AI Disclosure.
4.Payments, email and social platforms
Stripe receives buyer, payment and transaction data to run checkout, subscriptions, refunds and invoices. Resend receives the email address and confirmation content needed to send transactional messages. Meta receives OAuth credentials, publication content and platform results when a user connects Facebook or Instagram and asks SMAT to publish or synchronize. These providers act under their own terms where they determine processing and as processors where the applicable arrangement says so.
6.Recipients and international transfers
The current product code integrates the providers listed below for the stated functions. A code integration is not proof of a signed data-processing agreement, Data Privacy Framework participation or Standard Contractual Clauses. SMAT must verify current contractual role, location and transfer mechanism before activating a dependent production flow. We do not publish an unverified transfer claim.
7.Retention and security
We keep data only while needed for the account and requested features, applicable legal retention, security, dispute handling and demonstrated consent. Account erasure removes or anonymises data through the service’s registered cleanup paths, except records that must be retained or isolated by law. Provider-side deletion may take the time allowed by the applicable service.
Controls include access restrictions, session security, audit records, encryption in transit, secret management, tenant scoping, safe outbound fetching and incident procedures. No internet service can promise absolute security.
8.Your rights
Where the GDPR applies, you may request access, correction, erasure, restriction, portability and information about processing, and object to legitimate-interest processing. You may withdraw consent at any time without affecting earlier lawful processing. The application provides account export and deletion paths; you may also email [email protected].
You may complain to the competent supervisory authority. For the controller in Poland, this is the President of the Personal Data Protection Office (UODO), ul. Stawki 2, 00-193 Warsaw, uodo.gov.pl.
9.Current product providers and evidence status
The table states only functions verified in the repository. A product integration does not establish whether a provider is a controller, processor or sub-processor. Each dependent production flow remains blocked until the owner retains evidence of the provider’s contractual role and transfer position. Changes that materially affect this Notice require a new document version rather than silently changing the archived version.
| Provider | Verified product function | Data involved | Contractual role / status | Integration evidence |
|---|---|---|---|---|
| OpenAI | Text generation, assistant and selected image processing | Instructions, brand context, generated content and limited telemetry | unverified — dependent production flow blocked | Repository integration verified; contractual and transfer receipt absent |
| Selected image generation, embeddings and visual analysis | Instructions, media, brand context and limited telemetry | unverified — dependent production flow blocked | Repository integration verified; contractual and transfer receipt absent | |
| Stripe | Checkout, subscriptions, refunds and invoices | Buyer, tax, payment and transaction data | unverified — dependent production flow blocked | Repository integration verified; contractual role receipt absent |
| Resend | Transactional and purchase-confirmation email | Recipient address and message content | unverified — dependent production flow blocked | Repository integration verified; contractual and transfer receipt absent |
| Cloudflare | Bot protection and object storage | Network/browser signals and stored media, depending on feature | unverified — dependent production flow blocked | Repository integrations verified; scope-specific contractual receipt absent |
| Meta | Facebook and Instagram connection, publishing and result sync | OAuth token, selected content and platform identifiers | unverified — dependent production flow blocked | Repository integration verified; contractual role receipt absent |