Privacy Policy
Last updated: May 21, 2026 • Version 1.1
1. Preamble and Scope of Applicability
Atelier AI Studios, operating at atelieraistudios.com ("Company," "we," "us," or "our"), provides the Atelier platform, APIs, and associated digital services (collectively, the "Services"), including AI-powered product image generation, enhancement, and ecommerce store integration.
This Privacy Policy governs the collection, processing, storage, and protection of personal data for all individuals who access or use our Services. It complies with the following regulatory frameworks:
- CCPA/CPRA — California Consumer Privacy Act and California Privacy Rights Act (United States)
- GDPR — General Data Protection Regulation (European Union)
- UK Data Protection Act 2018 — post-Brexit UK equivalent of GDPR
By accessing or using our Services, you acknowledge that you have read, understood, and agree to the practices described in this Privacy Policy. If you do not agree, you must discontinue use of the Services immediately.
2. Definitions and Interpretation
For the purposes of this Privacy Policy, the following terms have the meanings set out below:
- "Personal Data" means any information relating to an identified or identifiable natural person. An identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, identification number, location data, or online identifier.
- "Data Controller" means the entity that determines the purposes and means of processing Personal Data. Atelier AI Studios acts as a Data Controller with respect to the personal data of its users.
- "Data Processor" means the entity that processes Personal Data on behalf of the Data Controller, in accordance with the Controller's instructions.
- "Processing" means any operation or set of operations performed on Personal Data, including collection, recording, organisation, storage, adaptation, retrieval, use, disclosure, dissemination, restriction, erasure, or destruction.
- "Sub-Processor" means a third-party service provider engaged by us to process Personal Data on our behalf in connection with the provision of our Services.
- "User Content" means product images, catalog data, and other content you upload or transmit through the Services.
- "AI Output" means images or other content generated by our AI models in response to your inputs and instructions.
3. Data Collection and Aggregation
We collect the following categories of Personal Data:
Identity and Contact Data (directly submitted by you):
- Identity data: full name, business name, job title
- Contact information: email address, billing address, phone number (if provided)
- Authentication credentials: encrypted passwords and API keys
- Financial data: partial card details only (last 4 digits of your payment card); full payment card details are never stored on our servers and are processed exclusively by our PCI-DSS compliant payment processor, Stripe
Automatically Collected Technical Data:
- Technical data: IP address, browser type and version, operating system, device type
- Usage metrics: features accessed, actions performed, session duration, error logs
- Device identifiers: hardware model, unique device identifiers where applicable
- Cookies and similar tracking technologies (see Section 10 and our Cookie Policy)
Platform and Content Data:
- Product images and other files you upload for AI processing
- Store configuration and product catalog data from connected ecommerce platforms (Shopify, WooCommerce, Ecwid, and others)
- Product titles, descriptions, and metadata retrieved via platform integrations
- AI-generated output images produced for your account
4. Legal Basis for Processing
We process your Personal Data on the following lawful grounds under applicable data protection law:
- Contractual necessity — processing is required to perform our obligations under the agreement with you, including delivering the Services you have subscribed to
- Legitimate interests — processing is necessary for our legitimate business interests, including fraud prevention, network security, service improvement, and algorithm optimisation, provided those interests are not overridden by your rights and freedoms
- Legal obligation — processing is required to comply with applicable laws, regulations, court orders, or other legal obligations
- Consent — where required by law, we rely on your explicit consent for marketing communications and the use of non-essential cookies and tracking technologies; you may withdraw consent at any time without affecting the lawfulness of prior processing
5. Use and Disclosure of Information
We use the Personal Data we collect for the following purposes:
- Providing, operating, and maintaining the Services
- Processing your image transformations and generating AI output
- Managing your account, authentication, and access control
- Processing payments and managing billing
- Sending transactional communications (receipts, usage notifications, password resets)
- Responding to support requests and enquiries
- Improving and personalising your experience on the platform
- Monitoring usage patterns to detect, investigate, and prevent abuse, fraud, and security incidents
- Training and improving our AI models using only de-identified and aggregated data that cannot be used to identify any individual — we do not use your personally identifiable information or specific uploaded images for model training without your explicit consent
- Complying with applicable legal obligations
We do not sell your Personal Data. We share data only with the following categories of recipients:
- Sub-Processors — cloud infrastructure and service providers (AWS, Microsoft Azure, DigitalOcean), payment processors (Stripe), and analytics platforms (Google Analytics, Microsoft Clarity), each contractually bound by data processing agreements to process data solely on our instructions
- Ecommerce platform integrations — only the minimum data necessary to sync your connected store (Shopify, WooCommerce, Ecwid, or other authorised platforms)
- Legal and regulatory authorities — when required by law, regulation, court order, or to protect our legal rights and the safety of others
- Business transfers — in the event of a merger, acquisition, or sale of all or substantially all of our assets, with prior notice provided to you
6. International Data Transfers
We operate globally and your Personal Data may be transferred to and processed in countries outside your country of residence, including countries that may not provide the same level of data protection as your home jurisdiction.
For users in the European Economic Area (EEA) or United Kingdom, such transfers are subject to appropriate safeguards including:
- Standard Contractual Clauses (SCCs) — approved by the European Commission, incorporated into our Sub-Processor agreements
- UK International Data Transfer Agreements (IDTA) — the UK equivalent mechanism for transfers to countries without UK adequacy decisions
You may request a copy of the relevant safeguards applicable to your data by contacting us through our Help Centre.
7. Data Retention and Minimisation
We retain Personal Data only for as long as necessary for the purposes described in this policy, unless a longer retention period is required or permitted by law:
- Active accounts — account data is retained for the duration of your account relationship with us
- Deleted or terminated accounts — data is archived for approximately 30 days following account closure before permanent deletion, unless we are required by law to retain it for a longer period
- Uploaded images — product images and other User Content are deleted from our servers within 30 days of processing unless your subscription plan specifies otherwise
- Anonymised and aggregated data — data that has been fully de-identified and aggregated may be retained indefinitely for research, analytics, and service improvement purposes, as it no longer constitutes Personal Data
- Financial and transaction records — retained for the periods required by applicable tax and accounting law
8. Rights of the Data Subject
Depending on your location, you have the following rights in relation to your Personal Data:
GDPR Rights (EU/UK users):
- Right of access — request a copy of the Personal Data we hold about you
- Right to rectification — request correction of inaccurate or incomplete Personal Data
- Right to erasure — request deletion of your Personal Data ("right to be forgotten"), subject to applicable legal obligations
- Right to data portability — request your Personal Data in a structured, commonly used, machine-readable format
- Right to restriction — request that we limit the processing of your Personal Data in certain circumstances
- Right to object — object to processing of your Personal Data where we rely on legitimate interests as our lawful basis
- Rights related to automated decision-making — the right not to be subject to solely automated decisions that produce significant legal or similarly significant effects
CCPA/CPRA Rights (California users):
- Right to know what Personal Data is collected, used, disclosed, or sold
- Right to delete Personal Data, subject to certain exceptions
- Right to opt out of the sale or sharing of Personal Data (we do not sell Personal Data)
- Right to correct inaccurate Personal Data
- Right to limit use and disclosure of sensitive Personal Data
- Right to non-discrimination for exercising any of your privacy rights
To exercise any of your rights, please submit a request through our Help Centre. We aim to respond to all verifiable requests within 30 to 45 days. We may need to verify your identity before processing your request.
If you believe we have not adequately addressed your request, EU/UK residents have the right to lodge a complaint with their local supervisory authority (such as the ICO in the UK, or the relevant EU Data Protection Authority).
9. Security Measures
We implement and maintain industry-standard technical and organisational security measures designed to protect your Personal Data against unauthorised access, disclosure, alteration, or destruction:
- Encryption in transit — all data transmitted between your browser and our servers is protected using TLS 1.2 or higher
- Encryption at rest — all stored Personal Data and User Content is encrypted using AES-256
- Access control — role-based access control (RBAC) ensures that internal access to Personal Data is limited to authorised personnel with a legitimate business need
- Authentication — Multi-Factor Authentication (MFA) is enforced for all internal systems with access to personal data
- Vulnerability management — we conduct regular vulnerability scanning and penetration testing to identify and remediate security risks
- Incident response — we maintain a data breach response plan and will notify affected users and relevant authorities in accordance with applicable legal requirements
No method of transmission over the internet or electronic storage is 100% secure. While we apply commercially reasonable safeguards, we cannot guarantee absolute security of your data.
10. Cookies and Tracking Technologies
We use cookies and similar technologies (including pixels and local storage) to enable platform functionality, analyse usage patterns, and store your preferences. The categories of cookies we use include:
- Strictly necessary cookies — essential for the platform to function; cannot be disabled
- Performance and analytics cookies — help us understand how users interact with our Services (e.g. Google Analytics, Microsoft Clarity)
- Functional cookies — remember your preferences and settings to personalise your experience
- Targeting cookies — used to deliver relevant content and measure the effectiveness of our marketing
You can control cookie preferences through our cookie consent banner or your browser settings. Disabling certain cookies may affect the functionality of the Services. For full details, please review our Cookie Policy.
11. Children's Privacy
Our Services are designed exclusively for business users and are not directed to individuals under the age of 18. We do not knowingly collect Personal Data from children under the age of 13 (or 16 in jurisdictions where a higher age threshold applies under applicable law).
If we become aware that we have inadvertently collected Personal Data from a child below the applicable age threshold, we will take immediate steps to delete such data from our systems. If you believe we may have collected data from a child, please notify us through our Help Centre.
12. Amendments to This Policy
We reserve the right to update or modify this Privacy Policy at any time. Where we make material changes to how we process your Personal Data, we will notify you by email or via a prominent notice within the platform dashboard. The "Last Updated" date at the top of this page reflects the date on which the current version became effective.
Your continued use of the Services following notification of material changes constitutes your acceptance of the updated Privacy Policy. If you do not agree to the updated terms, you must discontinue use of the Services.
13. Contact and Dispute Resolution
If you have questions, concerns, or requests relating to this Privacy Policy or our handling of your Personal Data, please contact our Privacy team through our Help Centre.
For unresolved disputes concerning our privacy practices, EU/UK residents may escalate to their applicable supervisory authority. California residents may contact the California Privacy Protection Agency (CPPA). We are committed to working with you and the relevant authorities to resolve any concerns promptly.
Governing law for privacy-related disputes is as follows: California law applies for US users; the laws of England and Wales apply for UK users; and EU Member State law applies for EEA users, consistent with the user's jurisdiction, without regard to conflict-of-law principles.
14. Incorporation and Relationship to Terms of Service
This Privacy Policy is incorporated into and forms part of our Terms and Conditions, which govern your use of the Services. By agreeing to our Terms and Conditions, you also agree to the practices described in this Privacy Policy.
In the event of any conflict between this Privacy Policy and the Terms and Conditions with respect to the processing of Personal Data, this Privacy Policy shall prevail. All other matters not addressed by this Privacy Policy — including liability limitations, dispute resolution, and service terms — are governed by our Terms and Conditions.