Home › Privacy Policy

Privacy Policy

Version 1.0 · effective from 1 September 2026

Below we explain what personal data we collect in connection with SnapClick Studio, why and on what legal basis we process it, who we share it with and what rights data subjects have.

1. Data controller

The controller of personal data is DIOVAX Sp. z o.o., seated in Stargard, ul. Metalowa 13, 73-110 Stargard, Poland, KRS 0000613221, VAT no. PL5252657417 (the “Controller”). For data protection matters contact contact@snapclickstudio.online or write to the registered office.

The Controller has not appointed a data protection officer; all data protection requests are handled at the address above.

2. What data we process

  • Contact and registration data — name, e-mail address, phone number, company name, address, VAT number.
  • Account data — login, hashed password, settings, project history.
  • Billing data — invoicing details, payment history, transaction identifiers from the payment operator (we do not process full payment card numbers).
  • Input Materials and Creatives — graphic files and prompts supplied to perform the service.
  • Technical data — IP address, browser information, server and generation job logs.
  • Correspondence — the content of messages sent to the Controller.

3. Purposes and legal bases

PurposeLegal basisRetention
Conclusion and performance of the service contract, Account maintenance Art. 6(1)(b) GDPRterm of the contract
Handling early access applications and commercial correspondence Art. 6(1)(b) and (f) GDPRup to 12 months from last contact
Accounting and tax obligationsArt. 6(1)(c) GDPR5 years from the end of the tax year
Handling complaintsArt. 6(1)(b) and (c) GDPRuntil claims are time-barred
Security and abuse preventionArt. 6(1)(f) GDPRup to 12 months (logs)
Establishing, pursuing or defending claimsArt. 6(1)(f) GDPRuntil claims are time-barred
Newsletter and marketing information (where consent given)Art. 6(1)(a) GDPRuntil consent is withdrawn

Providing data is voluntary but necessary to conclude and perform the contract.

4. Material uploaded by the Customer

Files uploaded to the service are processed solely to generate creatives. They are not used to train or fine-tune artificial intelligence models without the Customer's separate, explicit consent.

Where uploaded material contains personal data controlled by the Customer (for example a person's likeness), the Controller processes it as a processor under a data processing agreement concluded pursuant to Article 28 GDPR. A template is available on request.

Materials and generated creatives are retained for the term of the contract and 30 days thereafter; backups are overwritten within a cycle of no more than 90 days.

5. Recipients of data

Data may be shared only with entities processing it on the Controller's behalf and only as far as necessary to provide the service:

  • cloud infrastructure and compute providers (servers located in the European Union);
  • e-mail and helpdesk providers;
  • payment operators and the accounting office;
  • IT providers maintaining the service;
  • legal advisers, to the extent necessary to pursue or defend claims.

snapclickstudio.online is delivered through the content delivery network of Cloudflare, Inc., which processes the visitor's IP address to secure and serve the site.

6. Transfers outside the EEA

Data is processed within the European Economic Area as a rule. Where the use of an infrastructure provider involves a transfer outside the EEA, it takes place on the basis of a European Commission adequacy decision or standard contractual clauses, together with additional technical safeguards.

7. Your rights

You have the right to: access your data and receive a copy; rectify inaccurate data and complete incomplete data; erase data in the cases set out in Article 17 GDPR; restrict processing; port data processed on the basis of a contract or consent; object to processing based on legitimate interest; and withdraw consent at any time without affecting the lawfulness of processing carried out before withdrawal.

Requests should be sent to contact@snapclickstudio.online. We respond without undue delay and no later than within one month.

You also have the right to lodge a complaint with the President of the Personal Data Protection Office (ul. Stawki 2, 00-193 Warsaw, Poland) or with the supervisory authority in your country of residence.

8. Automated decisions and profiling

The Controller does not take decisions based solely on automated processing that would produce legal effects concerning users or similarly significantly affect them. The artificial intelligence models used in the service process only the content of uploaded images and prompts, not a user profile.

9. Security

The Controller applies technical and organisational measures appropriate to the risk, including transport encryption (TLS), role-based access control, separation of production and test environments, infrastructure monitoring and regular backups. Access to Customer material is limited to authorised staff, to the extent required to maintain the service and handle support requests.

10. Changes to this Policy

This Policy may be updated following changes in law, in the scope of the service or in the technologies used. Material changes are announced by e-mail or through a notice in the service at least 14 days in advance. The current version is always available at this address.

This site only uses files strictly necessary for it to work — no analytics and no advertising trackers. Details in the Cookie Policy.