Centyr

Privacy Policy

Version 1.1·Last updated: March 19, 2026
GDPR Compliant. This policy is designed to comply with the EU General Data Protection Regulation (Regulation 2016/679). Our infrastructure is based in the European Union (AWS eu-west-3, Paris).

Centyr ("we", "our", or "us") is committed to protecting your personal data and respecting your privacy. This Privacy Policy describes what data we collect, why we collect it, how we use and protect it, and what rights you have over your data, in accordance with the EU General Data Protection Regulation (GDPR).

By using our Service at centyr.tech, you acknowledge that you have read and understood this Privacy Policy.

1. Data Controller

The data controller responsible for processing your personal data is:

Centyr

Email: [email protected]

Website: centyr.tech

For all privacy-related requests, including data subject rights, please contact us at the email above. We will respond within 30 calendar days as required by GDPR Article 12.

2. Personal Data We Collect

We collect only the data necessary to provide the Service ("data minimization", GDPR Art. 5(1)(c)):

Identity and Contact Data

Account

Full name, email address. Collected at registration or retrieved from your OAuth provider (Google, Apple, GitHub) with your consent.

Authentication Data

Account

Hashed passwords (managed by AWS Cognito), OAuth tokens, session identifiers, and authentication timestamps. We never store plaintext passwords.

User Content (Images)

Processing

Product photos you upload for processing. Stored temporarily on AWS S3 (eu-west-3) and automatically deleted after 30 days. We do not use your images to train AI models.

Usage and Technical Data

Service

Number of jobs processed per period, job timestamps, processing durations, API request logs, IP address, browser type, and device information. Used for quota enforcement, debugging, and service improvement.

Billing and Transaction Data

Payments

Subscription plan, billing history, and a Stripe Customer ID. Full card details are processed exclusively by Stripe and are never transmitted to or stored on our servers.

3. Legal Basis for Processing

We process your personal data on the following legal bases (GDPR Art. 6):

Contract (Art. 6(1)(b))Processing necessary to perform the Service you have subscribed to, including authentication, image processing, quota management, and billing.
Legitimate Interest (Art. 6(1)(f))Security monitoring, fraud prevention, abuse detection, service analytics, and improving the reliability of our infrastructure. We have conducted a Legitimate Interest Assessment (LIA) and concluded our interests do not override your rights and freedoms.
Legal Obligation (Art. 6(1)(c))Retention of billing and transaction records for 7 years to comply with Italian fiscal law (D.P.R. 633/1972) and EU VAT directives.
Consent (Art. 6(1)(a))Marketing communications, product updates, and newsletters, only if you have explicitly opted in. You may withdraw consent at any time.

4. How We Use Your Data

  • Create and manage your Account
  • Authenticate your identity and maintain secure sessions
  • Process your uploaded images using our AI pipeline
  • Enforce your Subscription quota and plan limits
  • Process payments and manage billing via Stripe
  • Send transactional emails (email verification, password reset, payment receipts)
  • Respond to support requests and communicate about your Account
  • Monitor for security incidents, fraud, and Terms of Service violations
  • Generate aggregated, anonymized usage statistics to improve the Service

We do not: sell your data, use your images to train AI models, share your data with advertisers, or engage in automated decision-making that produces legal or similarly significant effects.

5. Data Storage, Infrastructure, and International Transfers

Your data is processed and stored on the following infrastructure:

Sub-processorPurposeLocationSafeguard
Amazon Web ServicesStorage (S3), database (DynamoDB), compute (ECS), auth (Cognito)EU (Paris, eu-west-3)EEA, no transfer
Stripe, Inc.Payment processingUSA / EUSCCs + EU-US DPF
Vercel, Inc.Web application hostingUSA / EU edgeSCCs

SCCs = Standard Contractual Clauses (EU Commission Decision 2021/914). DPF = EU-US Data Privacy Framework.

6. Data Retention

Uploaded images and Outputs30 days from upload date (automatic deletion)
Account data (name, email)Duration of Account + 30 days after deletion request
Usage logs and job metadata90 days for operational purposes
Billing and transaction records7 years (Italian fiscal law requirement)
Security and audit logs12 months
Consent recordsUntil consent is withdrawn + 1 year

7. Your Rights Under GDPR

As a data subject under GDPR Chapter III, you have the following rights:

Right of Access (Art. 15)

Request a copy of all personal data we hold about you.

Right to Rectification (Art. 16)

Correct inaccurate or incomplete personal data.

Right to Erasure (Art. 17)

Request deletion of your data ("right to be forgotten"), subject to legal retention obligations.

Right to Data Portability (Art. 20)

Receive your data in a structured, machine-readable format (JSON/CSV).

Right to Restriction (Art. 18)

Request that we limit processing of your data in certain circumstances.

Right to Object (Art. 21)

Object to processing based on legitimate interest or for direct marketing.

Right to Withdraw Consent (Art. 7(3))

Withdraw consent at any time without affecting prior lawful processing.

Right to Lodge a Complaint (Art. 77)

File a complaint with the Garante per la Protezione dei Dati Personali (Italian DPA) or your local supervisory authority.

Self-service rights: Rights under Art. 17 (erasure) and Art. 20 (portability) can be exercised directly from your account: Dashboard → Settings → Privacy & Data. Your account and all data are deleted immediately, or you can download a complete JSON export of all your data.

For other rights, submit a request to [email protected]. We may ask you to verify your identity before processing the request. We will respond within 30 days and will not charge a fee for reasonable requests.

8. Cookies and Similar Technologies

We use only technically necessary cookies. No advertising or third-party tracking cookies are used.

auth_tokenSessionStores your JWT authentication token to keep you logged in.
userSessionStores cached user profile data to avoid redundant API calls.

Strictly necessary cookies do not require consent under GDPR Recital 47 and the ePrivacy Directive.

9. Security Measures

We implement appropriate technical and organizational security measures, including:

  • TLS 1.2+ encryption for all data in transit
  • AES-256 encryption at rest on AWS S3
  • Authentication via AWS Cognito with secure password hashing (bcrypt)
  • Role-based access controls and principle of least privilege for internal systems
  • Automatic expiry and deletion of stored image data after 30 days
  • Regular security reviews and dependency updates

In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the competent supervisory authority within 72 hours and affected users without undue delay, as required by GDPR Art. 33-34.

10. Children's Privacy

The Service is not directed to individuals under the age of 16. We do not knowingly collect personal data from children. If we become aware that we have inadvertently collected data from a child, we will delete it promptly. If you believe a child has provided us with personal data, contact us at [email protected].

11. Changes to This Policy

We may update this Privacy Policy from time to time. For material changes, we will provide at least 14 days' notice via email or an in-app notification, with a summary of what has changed. The updated version will be effective as of the date indicated at the top. Your continued use of the Service after that date constitutes acceptance of the changes.

We maintain a change log of material updates to this policy. You may request a copy by contacting us.

12. Contact and Complaints

For any privacy-related questions or to exercise your rights:

Email: [email protected]

Response time: Within 30 days

If you are not satisfied with our response, you have the right to lodge a complaint with the Italian Data Protection Authority:

Garante per la Protezione dei Dati Personali

Piazza Venezia 11, 00187 Roma, Italy

www.garanteprivacy.it