1. Who Is the Data Controller?
Centyr is the data controller for all personal data collected through the centyr.tech platform. You can contact us regarding any data protection matter at:
- Email: [email protected]
- General support: [email protected]
2. What Personal Data We Collect
We collect the minimum data necessary to provide the Service:
- Account data: email address, name (from OAuth providers such as Google or Apple)
- Authentication data: encrypted session tokens managed via AWS Cognito
- User content: product images you upload for processing (stored temporarily, deleted after 30 days)
- Billing data: payment method details managed exclusively by Stripe, we never store card numbers
- Usage data: job history, upload counts, subscription status
- Technical data: IP address, browser type, request timestamps (for security and fraud prevention)
3. Legal Bases for Processing
We process your personal data on the following legal bases under Art. 6 GDPR:
- Contract (Art. 6(1)(b)): processing necessary to deliver the Service you have subscribed to, including image processing, account management, and billing
- Legitimate interests (Art. 6(1)(f)): security monitoring, fraud prevention, service improvement, and analytics (only aggregated, non-identifying)
- Legal obligation (Art. 6(1)(c)): retention of billing records for 7 years per Italian tax law (D.P.R. 633/1972)
- Consent (Art. 6(1)(a)): used only where explicitly required; you may withdraw consent at any time without affecting prior processing
4. Your GDPR Rights
As a data subject under GDPR, you have the following rights. To exercise any of them, email [email protected]. We will respond within 30 days.
- Right of access (Art. 15)— Request a copy of all personal data we hold about you.
- Right to rectification (Art. 16)— Request correction of inaccurate or incomplete data.
- Right to erasure (Art. 17)— Request deletion of your data ("right to be forgotten"), subject to legal retention obligations.
- Right to data portability (Art. 20)— Receive your data in a structured, machine-readable format (JSON/CSV).
- Right to restriction (Art. 18)— Request that we temporarily stop processing your data while a dispute is resolved.
- Right to object (Art. 21)— Object to processing based on legitimate interests.
- Right not to be subject to automated decisions (Art. 22)— We do not make legally significant automated decisions about you.
If you believe your rights have been violated, you have the right to lodge a complaint with the Italian Data Protection Authority (Garante per la Protezione dei Dati Personali) at garanteprivacy.it, or with the supervisory authority in your country of residence.
5. Data Retention
- Uploaded images (input): automatically deleted after 30 days
- Processed images (output): automatically deleted after 30 days
- Account data: deleted within 30 days of account deletion request
- Billing records: retained for 7 years as required by Italian fiscal law
- Security/access logs: retained for 90 days for fraud prevention
6. Data Transfers Outside the EU
Our primary infrastructure is located in the EU (AWS eu-west-3, Paris). However, some sub-processors may process data outside the EU:
- Stripe (USA): payment processing, covered by EU-US Data Privacy Framework (DPF) and Standard Contractual Clauses (SCCs)
- Vercel (USA): frontend hosting, covered by SCCs
- AWS (EU): infrastructure, data stored in eu-west-3 (Paris)
All international transfers are protected by appropriate safeguards under Art. 46 GDPR.
7. Cookie Policy
Centyr uses only strictly necessary cookies required for the Service to function. We do not use advertising, tracking, or third-party analytics cookies.
| Cookie name | Purpose | Duration | Type |
|---|---|---|---|
| auth_token | Stores your authentication JWT to keep you logged in | Session / 7 days | Strictly necessary |
| user | Caches your basic profile data (name, email) for UI display | Session / 7 days | Strictly necessary |
Because we only use strictly necessary cookies, consent is not technically required under Art. 25 of the Italian Privacy Code (D.Lgs. 196/2003 as amended) and the ePrivacy Directive. We nonetheless display an informational banner on first visit to ensure maximum transparency and comply with the privacy by design principle (GDPR Art. 25).
You can delete these cookies at any time through your browser settings. Doing so will log you out of the Service.
8. Security Measures
We implement appropriate technical and organizational measures to protect your data, including:
- TLS 1.2/1.3 encryption for all data in transit
- AES-256 encryption for data at rest (S3, DynamoDB)
- Access control via AWS IAM with least-privilege policies
- All S3 buckets are private; files accessible only via time-limited presigned URLs
- Cloudflare DDoS protection and WAF
- Regular security reviews
See our Security page for full details.
9. Changes to This Policy
We may update this policy from time to time. Material changes will be communicated by email or via an in-app notice at least 14 days before taking effect. The effective date at the top of this page reflects the date of the latest revision.
10. Contact & Complaints
For any GDPR-related request or question, contact our privacy team at [email protected].
If you are not satisfied with our response, you have the right to lodge a complaint with the Garante per la Protezione dei Dati Personali (Italian DPA) or the supervisory authority in your EU country of residence.