UAML Studio

Legal

Privacy policy

Published from the repository copy of this document, word for word.

Privacy policy

DRAFT — NOT LEGALLY REVIEWED.

Controller: Brandmill, [KvK number], [address], the Netherlands. Contact: [privacy email]. Effective: [date]

This covers personal data we hold as controller — account and billing data. When you put personal data inside a model, we act as processor on your instructions; see data-processing-agreement.md.

What we collect and why

Data Why Lawful basis (GDPR Art. 6) Kept
Name, email, password hash Run your account Contract Account life + [90] days
Billing details, invoices Take payment, meet tax law Contract / legal obligation [7] years (Dutch tax law)
Your models and files Provide the service Contract Until you delete them, then [30] days
Product analytics Improve the product Legitimate interest [14] months
Support messages Answer you Contract / legitimate interest [24] months
Server and security logs Security, abuse, debugging Legitimate interest [90] days

We do not sell personal data, and we do not use your models to train machine-learning models.

Cookies

Strictly necessary cookies (session, security) are set without consent, as the law allows. Analytics cookies are set only with your consent, which you may withdraw at any time at [cookie settings URL].

Who we share it with

Only sub-processors acting on our instructions, listed with their purpose and location at [sub-processor URL]: hosting, payment processing, email delivery, error tracking, product analytics, and the AI model provider used by the AI features.

For transfers outside the EEA we rely on an adequacy decision where one exists, and otherwise on Standard Contractual Clauses with supplementary measures where the transfer risk assessment requires them.

Your rights

Access, rectification, erasure, restriction, portability, objection, and withdrawal of consent. Where processing rests on legitimate interest you may object at any time and we will stop unless we can show compelling grounds.

Write to [privacy email]; we answer within one month. You may complain to the Autoriteit Persoonsgegevens (autoriteitpersoonsgegevens.nl) or to your local supervisory authority.

Security

Encryption in transit and at rest, access on a need-to-know basis, and [audited backups]. No system is perfectly secure; where a breach is likely to risk your rights we notify the supervisory authority within 72 hours and you without undue delay.

Children

Not intended for anyone under 16. We do not knowingly collect their data.

Changes

Material changes are notified by email or in-app at least 30 days ahead.