Privacy Policy
1. Overview
At ImagR, we take your privacy seriously. This Privacy Policy explains how we collect, use, disclose, and safeguard your personal information when you use our laser image preparation service, website, and related applications.
By using ImagR, you agree to the collection and use of information in accordance with this policy. If you do not agree with our policies and practices, please do not use our services.
2. Data Controller
The data controller responsible for your personal data is:
DesignGecko GmbHStifterstraße 21A
4701 Bad Schallerbach
Austria
Email: [email protected]
3. Data We Collect
3.1 Information You Provide
When you use ImagR, you may provide us with:
- Account information (email address, name) when you create an account
- Payment information processed securely through our payment providers
- Images you upload for processing
- Communication data when you contact our support
3.2 Automatically Collected Information
When you access our services, we automatically collect:
- Device information (browser type, operating system, device type)
- Usage data (pages visited, features used, time spent)
- IP address and approximate location (country/region level)
- Referral source (how you found us)
3.3 Image Data
Images you upload are processed on our servers to provide our service. We do not use your images for any purpose other than providing the requested image preparation service. Uploaded images are automatically deleted according to our data retention policy.
4. Legal Basis for Processing
We process your personal data based on the following legal grounds:
- Contract Performance: Processing necessary to provide our services to you (Art. 6(1)(b) GDPR)
- Legitimate Interests: Processing for fraud prevention, security, and service improvement (Art. 6(1)(f) GDPR)
- Consent: Where you have given explicit consent, such as for marketing communications (Art. 6(1)(a) GDPR)
- Legal Obligation: Processing required to comply with applicable laws (Art. 6(1)(c) GDPR)
5. How We Use Your Data
We use the collected information to:
- Provide, maintain, and improve our image preparation services
- Process your transactions and send related information
- Send technical notices, updates, and support messages
- Respond to your comments, questions, and customer service requests
- Monitor and analyze usage patterns to improve user experience
- Detect, prevent, and address technical issues and fraudulent activity
- Comply with legal obligations
6. Data Sharing & Third Parties
We may share your information with:
6.1 Service Providers
We work with trusted third-party service providers who assist us in operating our service:
- Payment Processing: Stripe and PayPal for secure payment processing
- Cloud Infrastructure: AWS/Google Cloud for hosting and data storage
- Analytics: Google Analytics for usage analysis (anonymized)
- Email Services: Transactional email providers for service communications
6.2 Legal Requirements
We may disclose your information if required by law, court order, or government regulation, or if we believe disclosure is necessary to protect our rights, your safety, or the safety of others.
6.3 Business Transfers
In the event of a merger, acquisition, or sale of assets, your personal data may be transferred. We will provide notice before your data is transferred and becomes subject to a different privacy policy.
8. Data Retention
We retain your personal data only for as long as necessary:
- Account Data: Retained while your account is active and for up to 3 years after deletion for legal compliance
- Uploaded Images: Automatically deleted within 24 hours after processing, or 7 days for premium users
- Payment Records: Retained for 10 years as required by tax law
- Log Data: Retained for up to 90 days for security and debugging purposes
9. Your Rights
Under GDPR and other applicable privacy laws, you have the following rights:
- Right of Access: Request a copy of the personal data we hold about you
- Right to Rectification: Request correction of inaccurate or incomplete data
- Right to Erasure: Request deletion of your personal data ("right to be forgotten")
- Right to Restrict Processing: Request limitation of processing in certain circumstances
- Right to Data Portability: Receive your data in a structured, machine-readable format
- Right to Object: Object to processing based on legitimate interests or direct marketing
- Right to Withdraw Consent: Withdraw consent at any time where processing is based on consent
To exercise any of these rights, please contact us at [email protected]. We will respond to your request within 30 days.
You also have the right to lodge a complaint with a supervisory authority if you believe your data protection rights have been violated.
10. Data Security
We implement appropriate technical and organizational measures to protect your personal data against unauthorized access, alteration, disclosure, or destruction. These measures include:
- Encryption of data in transit (TLS/SSL) and at rest
- Regular security assessments and updates
- Access controls and authentication mechanisms
- Secure data centers with physical security measures
- Employee training on data protection
While we strive to protect your personal data, no method of transmission over the Internet or electronic storage is 100% secure. We cannot guarantee absolute security.
11. International Data Transfers
Your data may be transferred to and processed in countries outside the European Economic Area (EEA). When we transfer data internationally, we ensure appropriate safeguards are in place:
- Standard Contractual Clauses (SCCs) approved by the European Commission
- Transfers to countries with an adequacy decision
- Additional technical and organizational measures where necessary
12. Children's Privacy
Our services are not directed to individuals under the age of 16. We do not knowingly collect personal data from children. If you become aware that a child has provided us with personal data, please contact us, and we will take steps to delete such information.
13. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of any material changes by posting the new policy on this page and updating the "Last updated" date.
For significant changes, we may also send you an email notification. We encourage you to review this Privacy Policy periodically.
14. Contact Us
If you have any questions about this Privacy Policy or our data practices, please contact us:
Data Protection ContactDesignGecko GmbH
Stifterstraße 21A
4701 Bad Schallerbach
Austria
Email: [email protected]
We aim to respond to all inquiries within 30 days.