This policy explains how Latest Effects processes personal data, under Regulation (EU) 2016/679 (GDPR) and Ley Orgánica 3/2018 on the protection of personal data and the guarantee of digital rights (LOPDGDD).
Controller
- Controller: Latest Effects
- Registered office: pending: registered address
- Tax identification number (NIF): pending: NIF
- Data protection contact: pending: privacy contact email address
- Data protection officer: pending: appointed or not, with contact details
These details must be completed with the operating entity’s real data before the Service is offered commercially.
What we process, why, and on what basis
Account data (name, email address, password hash, language and appearance preferences). Used to create and operate your account. Basis: performance of the contract, article 6.1.b GDPR.
Project content (briefs, prompts, uploaded media, generated media, timelines, exports, comments). Used to provide the workspace, run the operations you ask for and store your work. Basis: performance of the contract.
Billing data (project balance movements, resource plan, invoices, partial card identifiers, tax identification where you invoice as a business). Used to take payment and meet accounting and tax duties. Basis: performance of the contract and legal obligation, articles 6.1.b and 6.1.c GDPR.
Usage and diagnostic data (pages viewed, features used, an anonymous browser identifier, error reports, approximate location derived from IP, device and browser type). Used to keep the Service secure and working and to understand how it is used. Basis: legitimate interest, article 6.1.f GDPR, for strictly necessary security processing. Optional product analytics are based on your consent under article 6.1.a GDPR and article 22.2 LSSI-CE, and remain disabled until you accept them. See the Cookie Policy.
Support correspondence. Used to answer you and to keep a record of the issue. Basis: performance of the contract and legitimate interest.
Marketing email, only where you have opted in. Basis: consent, withdrawable at any time from any message.
What we do not do
We do not use your project content to train artificial intelligence models, neither our own nor those of third parties.
We do not sell personal data. We do not carry out automated decision-making that produces legal effects concerning you or similarly significantly affects you, and we do not profile you for advertising.
Recipients
We share personal data only with providers acting as processors under article 28 GDPR, bound by written contract and by confidentiality:
- Cloud hosting and object storage for the application and your project files.
- Artificial intelligence model providers, which receive the prompt and the input media strictly to execute the operation you requested and return the result.
- Payment processing.
- Error monitoring and product analytics.
- Transactional email delivery.
We also disclose data where a law, a court or a competent authority requires it.
An up-to-date list of processors, with the categories of data and the countries involved, must be published and maintained before the Service is offered commercially.
International transfers
Some providers process data outside the European Economic Area. Where they do, the transfer relies on an adequacy decision of the European Commission or on the standard contractual clauses adopted by the Commission, together with the supplementary measures the transfer assessment identifies. You may request a copy of the safeguards at the contact address above.
Retention
- Account and project data: for as long as the account is open. After closure, project data is deleted within 30 days, except where a longer period is needed to resolve a dispute.
- Billing and invoicing records: six years, under article 30 of the Spanish Commercial Code, and four years for tax purposes under the Ley General Tributaria.
- Diagnostic logs: up to 12 months.
- Support correspondence: up to three years from the last message.
- Consent records: for as long as the processing lasts, plus the limitation period.
Your rights
You may request access to your personal data, its rectification or erasure, the restriction of processing, portability in a structured, commonly used and machine-readable format, and you may object to processing based on our legitimate interest. Where processing rests on consent, you may withdraw it at any time without affecting the lawfulness of processing carried out beforehand.
Write to the data protection contact above. We respond within one month, which may be extended by two further months for complex requests, and we will tell you if it is extended. We may ask for proof of identity where there is reasonable doubt.
If you consider that your rights have not been respected, you may complain to the Spanish data protection authority, the Agencia Española de Protección de Datos (C/ Jorge Juan 6, 28001 Madrid, www.aepd.es), or to the supervisory authority of your country of residence.
Security
We apply technical and organisational measures appropriate to the risk, including encryption in transit and at rest, access control on a need-to-know basis, network isolation of processing workloads, logging, and regular review. No system is perfectly secure. If a breach is likely to result in a high risk to your rights we will notify you, and we will notify the supervisory authority where article 33 GDPR requires it.
Children
The Service is not directed at people under 18. If we learn that we hold the data of a child without the consent required by article 7 LOPDGDD, we delete it.
Changes
We will publish any change here and update the date above. Where a change is significant we will tell you by email or in the application before it takes effect.