Centyr ("we", "our", or "us") is committed to protecting your personal data and respecting your privacy. This Privacy Policy describes what data we collect, why we collect it, how we use and protect it, and what rights you have over your data, in accordance with the EU General Data Protection Regulation (GDPR).
By using our Service at centyr.tech, you acknowledge that you have read and understood this Privacy Policy.
1. Data Controller
The data controller responsible for processing your personal data is:
For all privacy-related requests, including data subject rights, please contact us at the email above. We will respond within 30 calendar days as required by GDPR Article 12.
2. Personal Data We Collect
We collect only the data necessary to provide the Service ("data minimization", GDPR Art. 5(1)(c)):
Identity and Contact Data
AccountFull name, email address. Collected at registration or retrieved from your OAuth provider (Google, Apple, GitHub) with your consent.
Authentication Data
AccountHashed passwords (managed by AWS Cognito), OAuth tokens, session identifiers, and authentication timestamps. We never store plaintext passwords.
User Content (Images)
ProcessingProduct photos you upload for processing. Stored temporarily on AWS S3 (eu-west-3) and automatically deleted after 30 days. We do not use your images to train AI models.
Usage and Technical Data
ServiceNumber of jobs processed per period, job timestamps, processing durations, API request logs, IP address, browser type, and device information. Used for quota enforcement, debugging, and service improvement.
Billing and Transaction Data
PaymentsSubscription plan, billing history, and a Stripe Customer ID. Full card details are processed exclusively by Stripe and are never transmitted to or stored on our servers.
3. Legal Basis for Processing
We process your personal data on the following legal bases (GDPR Art. 6):
4. How We Use Your Data
- Create and manage your Account
- Authenticate your identity and maintain secure sessions
- Process your uploaded images using our AI pipeline
- Enforce your Subscription quota and plan limits
- Process payments and manage billing via Stripe
- Send transactional emails (email verification, password reset, payment receipts)
- Respond to support requests and communicate about your Account
- Monitor for security incidents, fraud, and Terms of Service violations
- Generate aggregated, anonymized usage statistics to improve the Service
We do not: sell your data, use your images to train AI models, share your data with advertisers, or engage in automated decision-making that produces legal or similarly significant effects.
5. Data Storage, Infrastructure, and International Transfers
Your data is processed and stored on the following infrastructure:
| Sub-processor | Purpose | Location | Safeguard |
|---|---|---|---|
| Amazon Web Services | Storage (S3), database (DynamoDB), compute (ECS), auth (Cognito) | EU (Paris, eu-west-3) | EEA, no transfer |
| Stripe, Inc. | Payment processing | USA / EU | SCCs + EU-US DPF |
| Vercel, Inc. | Web application hosting | USA / EU edge | SCCs |
SCCs = Standard Contractual Clauses (EU Commission Decision 2021/914). DPF = EU-US Data Privacy Framework.
6. Data Retention
7. Your Rights Under GDPR
As a data subject under GDPR Chapter III, you have the following rights:
Right of Access (Art. 15)
Request a copy of all personal data we hold about you.
Right to Rectification (Art. 16)
Correct inaccurate or incomplete personal data.
Right to Erasure (Art. 17)
Request deletion of your data ("right to be forgotten"), subject to legal retention obligations.
Right to Data Portability (Art. 20)
Receive your data in a structured, machine-readable format (JSON/CSV).
Right to Restriction (Art. 18)
Request that we limit processing of your data in certain circumstances.
Right to Object (Art. 21)
Object to processing based on legitimate interest or for direct marketing.
Right to Withdraw Consent (Art. 7(3))
Withdraw consent at any time without affecting prior lawful processing.
Right to Lodge a Complaint (Art. 77)
File a complaint with the Garante per la Protezione dei Dati Personali (Italian DPA) or your local supervisory authority.
For other rights, submit a request to [email protected]. We may ask you to verify your identity before processing the request. We will respond within 30 days and will not charge a fee for reasonable requests.
8. Cookies and Similar Technologies
We use only technically necessary cookies. No advertising or third-party tracking cookies are used.
auth_tokenSessionStores your JWT authentication token to keep you logged in.userSessionStores cached user profile data to avoid redundant API calls.Strictly necessary cookies do not require consent under GDPR Recital 47 and the ePrivacy Directive.
9. Security Measures
We implement appropriate technical and organizational security measures, including:
- TLS 1.2+ encryption for all data in transit
- AES-256 encryption at rest on AWS S3
- Authentication via AWS Cognito with secure password hashing (bcrypt)
- Role-based access controls and principle of least privilege for internal systems
- Automatic expiry and deletion of stored image data after 30 days
- Regular security reviews and dependency updates
In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the competent supervisory authority within 72 hours and affected users without undue delay, as required by GDPR Art. 33-34.
10. Children's Privacy
The Service is not directed to individuals under the age of 16. We do not knowingly collect personal data from children. If we become aware that we have inadvertently collected data from a child, we will delete it promptly. If you believe a child has provided us with personal data, contact us at [email protected].
11. Changes to This Policy
We may update this Privacy Policy from time to time. For material changes, we will provide at least 14 days' notice via email or an in-app notification, with a summary of what has changed. The updated version will be effective as of the date indicated at the top. Your continued use of the Service after that date constitutes acceptance of the changes.
We maintain a change log of material updates to this policy. You may request a copy by contacting us.
12. Contact and Complaints
For any privacy-related questions or to exercise your rights:
Email: [email protected]
Response time: Within 30 days
If you are not satisfied with our response, you have the right to lodge a complaint with the Italian Data Protection Authority:
Garante per la Protezione dei Dati Personali
Piazza Venezia 11, 00187 Roma, Italy