Privacy Policy

Last updated: October 14, 2024

NexaMind Limited ("we", "us", "our") is committed to protecting your privacy and ensuring that your personal data is handled in accordance with the General Data Protection Regulation (GDPR) and applicable Irish privacy laws. This Privacy Policy outlines how we collect, use, and safeguard your information when you use our AI image generation services, and your rights in relation to your personal data.

 

1. Data We Collect

We collect personal data that you provide directly to us, as well as information collected automatically when you use our services. This includes:

1)  Personal Information: Name, email address, payment information, or any other information you provide when registering for an account or making a purchase.

2)  User-Generated Content: Images, prompts, and other data submitted to our AI image generator.

3)  Automatically Collected Data: Device information, IP address, browser type, operating system, usage patterns, and cookies.

 

2. How We Use Your Data

We may use your personal data for the following purposes:

1)  To provide and maintain our services, including generating images based on your inputs.

2)  To process transactions and send you invoices.

3)  To personalize and improve your experience with our services.

4)  To respond to your inquiries and provide customer support.

5)  To ensure compliance with our legal obligations, including preventing fraudulent activity.

6)  To send you updates, marketing communications, and service-related information if you have consented to receive such communications.

 

3. Legal Basis for Processing

We rely on the following legal bases for processing your personal data under GDPR:

When processing is necessary to provide the services you have requested.

When you have given explicit consent for certain uses of your data (e.g., receiving marketing materials).

For purposes such as improving our services, fraud prevention, and ensuring security.

Where processing is necessary to comply with Irish or EU legal requirements.

 

4. Data Retention

We will retain your personal data for as long as necessary to fulfill the purposes outlined in this policy, or as required by law. When your data is no longer needed, we will securely delete or anonymize it.

 

5. Sharing Your Data

We may share your personal data with third parties under the following circumstances:

1)  We may engage third-party providers to assist with various aspects of our services, such as payment processing, hosting, or analytics. These providers are obligated to protect your data in accordance with GDPR.

2)  We may disclose your information to authorities if required by law, or to protect our rights or the safety of others.

3)  In the event of a merger, acquisition, or sale of assets, your data may be transferred to a new owner.

 

6. International Transfers

As part of providing our services, your personal data may be transferred outside the European Economic Area (EEA). When this happens, we ensure that appropriate safeguards, such as Standard Contractual Clauses (SCCs), are in place to protect your data in line with GDPR requirements.

 

7. Your Rights

Under the GDPR, you have the following rights regarding your personal data:

1)   You can request a copy of the personal data we hold about you.

2)  You have the right to request corrections to inaccurate or incomplete data.

3)  You may request that we delete your personal data under certain conditions.

4)  You can ask us to limit the processing of your personal data.

5)  You can request that we transfer your data to another service provider.

6)  You have the right to object to the processing of your data based on our legitimate interests or for direct marketing purposes.

7)  If we are processing your data based on consent, you can withdraw your consent at any time.

To exercise any of these rights, please contact us at [email protected]. If you make a request, we have one month to respond to you.

 

8. Cookies and Tracking Technologies

We use cookies and similar tracking technologies to enhance your experience on our website. You can control the use of cookies through your browser settings. For more information, please refer to our Cookie Policy.

 

9. Security

We are committed to ensuring the security and confidentiality of your personal data. To protect your information from unauthorized access, alteration, disclosure, or destruction, we have implemented a variety of technical, administrative, and organizational measures, including:

1)  We use industry-standard encryption (e.g., SSL/TLS) to protect your personal data while it is being transmitted over the internet. Additionally, sensitive data, such as payment information, is encrypted at rest to prevent unauthorized access.

2)  We use strict access control mechanisms to ensure that only authorized personnel have access to your personal data. This includes the use of strong passwords, two-factor authentication (2FA), and role-based access controls.

3)  Where applicable, we anonymize or pseudonymize personal data to further protect your identity and minimize the risk of harm in case of a data breach.

4)  Our systems undergo regular security audits and penetration testing to identify and address potential vulnerabilities.

5)  All employees and contractors handling personal data are trained on data privacy and security practices, including GDPR compliance. They are required to adhere to strict internal policies that prevent the mishandling of personal data.

6)  We have a comprehensive data breach response plan in place to quickly identify, contain, and mitigate the impact of any security incidents. In the event of a data breach, we will notify affected individuals and relevant regulatory authorities in accordance with GDPR requirements.

7)  We collect and retain only the minimum amount of personal data necessary to fulfill the purpose for which it was collected. We review and purge data that is no longer needed, ensuring compliance with data retention policies.

8)  We ensure that any third-party service providers or partners who process personal data on our behalf maintain appropriate security measures in line with GDPR standards. Before engaging with third-party providers, we conduct a security assessment to verify their compliance with data protection laws. We also have contractual agreements in place with such providers to ensure that they implement sufficient safeguards for your personal data.

9)  We regularly review and update our security practices to stay ahead of evolving threats. We assess risks associated with new technologies, products, and services before deployment to ensure that your personal data remains protected at all times.

While we take comprehensive measures to protect your personal data, it is also important for you to take steps to protect yourself online. We encourage you to use strong, unique passwords for your account and to ensure that you log out of your account when accessing our services from a shared or public device. Additionally, be cautious of phishing scams and unsolicited communications requesting personal information.

 

10. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. When we do, we will notify you by updating the "Last updated" at the top of this policy. We encourage you to review this policy periodically to stay informed about how we are protecting your information.

 

11. Contact Us

If you have any questions or concerns regarding this Privacy Policy or our data practices, please contact us at:

NexaMind Limited

Address: 77 Lower Camden Street, Dublin, Ireland, D02 XE80

[email protected]

Phone: +371 25200115