Privacy Policy
Last updated: 11/18/2025
1. Introduction
At Paintola S.L. ("we," "our," or "us"), we are committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our website Paintola.com and our AI-generated product services.
By using our services, you consent to the data practices described in this policy. We comply with the General Data Protection Regulation (GDPR) and Spanish data protection laws (LOPDGDD).
2. Data Controller
3. Information We Collect
3.1 Personal Information
- Contact Information: Name, email address, phone number
- Account Information: Username, password, profile preferences
- Payment Information: Billing address, payment method details (processed by secure payment providers)
- Shipping Information: Delivery address, shipping preferences
3.2 AI and Content Information
- Prompts and Inputs: Text prompts, images, and parameters used for AI generation
- Generated Content: AI-created images, artworks, and designs
- Usage Data: Generation history, preferences, and interaction patterns
3.3 Technical Information
- Device Information: IP address, browser type, operating system
- Usage Data: Pages visited, time spent, features used
- Cookies and Tracking: As described in our Cookie Policy
4. How We Use Your Information
| Purpose | Legal Basis |
|---|---|
| Provide and maintain our services | Contract performance |
| Process orders and payments | Contract performance |
| Improve AI models and services | Legitimate interests |
| Customer support and communication | Contract performance, Legitimate interests |
| Marketing and promotions (with consent) | Consent |
| Legal compliance and security | Legal obligation, Legitimate interests |
5. AI Data Usage and Training
5.1 Training Data: We may use anonymized prompts and generated content to improve our AI models. Personal information is removed before training.
5.2 Content Storage: Your generated content is stored to provide you with access to your creation history and enable re-ordering.
5.3 Opt-out: You may contact us to exclude your data from AI training, though this does not affect content already used in anonymized training sets.
6. Data Sharing and Disclosure
We may share your information with:
- Service Providers: Payment processors, shipping carriers, cloud hosting providers
- Business Partners: Printing partners for product fulfillment
- Legal Requirements: When required by law or to protect our rights
- Business Transfers: In connection with mergers, acquisitions, or asset sales
All third-party providers are carefully selected and comply with data protection requirements.
7. International Data Transfers
Your data may be transferred to and processed in countries outside the European Economic Area (EEA). We ensure appropriate safeguards are in place, such as:
- EU Standard Contractual Clauses
- Adequacy decisions for recipient countries
- Binding corporate rules for intra-group transfers
8. Data Retention
| Data Type | Retention Period |
|---|---|
| Account information | Until account deletion request |
| Purchase records | 6 years for tax purposes |
| Generated content | Until account deletion or 3 years of inactivity |
| Marketing data | Until consent withdrawal |
| Technical logs | 1 year |
9. Your Data Protection Rights
Under GDPR and Spanish data protection laws, you have the following rights:
10. Cookies and Tracking
We use cookies and similar technologies to:
- Enable essential website functionality
- Remember your preferences and settings
- Analyze website traffic and usage patterns
- Personalize content and advertisements
You can manage your cookie preferences through our Cookie Settings or your browser settings.
11. Data Security
We implement appropriate technical and organizational measures to protect your personal data, including:
- Encryption of data in transit and at rest
- Regular security assessments and updates
- Access controls and authentication mechanisms
- Secure development practices
12. Children's Privacy
Our services are not directed to children under 13 (or 16 in the EU). We do not knowingly collect personal information from children. If we become aware of such collection, we will take steps to delete the information.
13. Changes to This Policy
We may update this Privacy Policy periodically. We will notify you of significant changes by:
- Posting a notice on our website
- Sending an email to registered users
- Updating the "Last updated" date