Legal

Privacy policy

What we keep, why, for how long, and where it goes. No detours.

Last updated: · Version 1.3

The short version

To make your portraits we need photos of your pet and your email address. Those photos go to our AI supplier, and that processing takes place outside the European Economic Area. You give explicit consent for this when you order. We use your photos only to make your portraits. They are deleted as soon as your portraits are delivered. The temporary AI model trained on them is deleted 14 days after delivery, once your do-over window has closed. We never sell anything on, and we never use your photos for another customer.

1. Who processes your data

DigiPaws is the controller for the processing of your personal data.

Trading nameDigiPaws
Legal entityExplain Academy (eenmanszaak), Dennis Snoeijers
AddressRaadhuisstraat 24, 4698 AK Oud-Vossemeer, Nederland
Chamber of Commerce (KvK)42094488
VAT numberNL005489137B37
Emailinfo@getdigipaws.com
Websitegetdigipaws.com

We are established in the Netherlands and we apply the EU General Data Protection Regulation (GDPR) to every customer, wherever you live. We have not appointed a data protection officer; a business of this size is not required to. You can reach us about anything at the email address above.

2. What we collect

DataWhat forLegal basis
Photos of your pet (2 to 20; 8 or more recommended) Training a model that recognizes your specific pet, and generating the portraits you ordered. Performance of the contract (Art. 6(1)(b) GDPR)
Your email address Confirming your order, delivering your portraits, and telling you if something goes wrong. Performance of the contract
Your pet's name and any notes Making the email personal and taking any particulars into account. Optional. Performance of the contract
Payment data Handling your payment. We never see or store your card or account number — that happens entirely inside Stripe. We only receive the amount, the currency, the payment status and a reference. Performance of the contract and statutory bookkeeping duty
Consent record (timestamp, IP address, browser type at the moment you tick the boxes) Being able to demonstrate that and when you agreed to the terms and to processing outside the EEA. Legal obligation and legitimate interest (evidence)
Technical server logs Security and troubleshooting. Kept automatically by our hosting provider. Legitimate interest (Art. 6(1)(f) GDPR)

We do not ask for your postal address, phone number or date of birth. We do not profile you, and we make no automated decisions about you that produce legal effects.

3. Transfers outside the European Economic Area

Four companies process data for us, and all four process it at least in part outside the European Economic Area. That matters: countries outside the EEA do not automatically offer the protection the GDPR requires, and governments there may have broader access to data under their own laws than is usual in the EU. Three of the four are American companies covered by an EU adequacy decision. The fourth is not covered by it, and we say below which one that is and what covers it instead.

Three are certified under the EU-U.S. Data Privacy Framework. The Framework is an adequacy decision of the European Commission (10 July 2023, under Art. 45 GDPR): the Commission has judged that a certified American organisation offers protection essentially equivalent to the GDPR, so transferring to one needs no further safeguard from us. Certification is public and checkable, and we looked each of these up on the U.S. Department of Commerce's official list at dataprivacyframework.gov rather than taking anyone's word for it.

  • Netlify, Inc. — hosting and storage. Active on the EU-U.S. Framework, the Swiss-U.S. Framework and the UK Extension, for non-HR data.
  • Stripe, LLC — payment processing. Active on all three, for both HR and non-HR data.
  • Resend — sending our emails. Active on the EU-U.S. Framework and the UK Extension, for non-HR data. Its listing currently reads “Active — Re-certification under Review”, which is the annual renewal running its course; the certification stays active throughout. Resend also processes in the eu-west-1 region, which is inside the EU, so in practice your email address and the contents of your emails stay in Europe.

This is the part we do not dance around

Astria.ai does not appear on the Data Privacy Framework list at all — not as active, not as inactive. And it is the supplier that receives the thing you most care about: your pet's photos.

Astria's own privacy statement says it relies on the European Commission's Standard Contractual Clauses for transfers out of the EEA. Those clauses are a recognised safeguard under Art. 46(2)(c) GDPR. We have asked Astria for those clauses and for a processing agreement, and we have not received them yet. So we are going on their published statement, not on a document we have read.

That is why we ask for your explicit consent to this transfer when you order, with its own separate checkbox. That consent is the legal basis we rely on for it (Art. 49(1)(a) GDPR). Without it we cannot fulfil the order, because no portraits can be produced.

You may withdraw your consent at any time by emailing info@getdigipaws.com. Withdrawal works going forward: it does not undo processing that has already happened. If you withdraw before production has started, we cancel the order and refund you in full.

When the Standard Contractual Clauses and the processing agreement reach us, we will update this section and say so here.

4. Who we share your data with

Only with parties needed to fulfil your order. We never sell your data and we never share it for advertising.

PartyWhat they receiveWhat forLocation and safeguard
Astria.ai Your pet's photos and a technical instruction with the chosen style Training the model and generating the portraits Outside the EEA. Not on the Data Privacy Framework list — Standard Contractual Clauses per their own statement, plus your explicit consent. See section 3.
Stripe, LLC Your email address and your payment details Processing the payment EU and United States. EU-U.S. Data Privacy Framework
Resend Your email address and the contents of the email with your portraits Sending our emails EU (eu-west-1). Also certified under the EU-U.S. Data Privacy Framework
Netlify, Inc. Technical logs and the temporary storage of your photos and order data Hosting the website and the storage EU and United States. EU-U.S. Data Privacy Framework

We may also share data where we are legally required to, for example on a lawful order from a competent authority.

5. How long we keep your data

DataRetention period
Photos you uploadDeleted as soon as your portraits are delivered.
The AI model trained on your photosDeleted 14 days after delivery. To make your portraits, our AI supplier trains a temporary model on your photos. It is kept only so we can honour your two free do-overs, and is deleted at the end of that 14-day window.
Photos from an order that was never paid for24 hours, then deleted automatically.
Generated portraits and their download links30 days. So do save your portraits in good time.
Your email address and order data30 days after delivery in our order system.
Invoicing and payment records7 years, because Dutch tax law requires it.
Consent recordAs long as needed to demonstrate that consent was given, and no longer than the payment records.

Deletion is automatic; no human being is involved who could forget.

6. How we protect your data

  • Every connection to the site is encrypted (HTTPS).
  • Your photos sit in private storage, reachable only through a unique, unguessable link tied to your order.
  • Those links appear nowhere on the site and are blocked from search engines and AI indexes.
  • Payment details never touch our own systems.
  • Access to the order system is limited to those who need it to fulfil the order.

7. Your rights

Under the GDPR you have the right to:

  • access your data;
  • have it corrected if something is wrong;
  • have it erased;
  • restrict the processing;
  • object to processing based on legitimate interest;
  • receive your data in a common file format (data portability);
  • withdraw consent you have given, including consent to processing outside the EEA.

Email info@getdigipaws.com and include your order number. We respond within 30 days. Erasure is usually immediate, unless we are legally required to keep the data for our accounts.

If you are unhappy with how we handle your data you can lodge a complaint with the Dutch Data Protection Authority, or with the supervisory authority in your own country. We would of course rather hear it from you first.

8. Cookies and measurement

This site sets no tracking cookies and no advertising cookies. There is no Google Analytics, no Meta pixel and no other tracking software. That is also why you see no cookie banner: none is needed. We do count visits, using Netlify Analytics: it reads our server’s own request logs, sets nothing on your device, and cannot follow you to any other website. When we delete an order, we keep a tally of it: the day it was placed, the style and campaign it came from, and whether it was paid. These totals contain no name, email address or order number, and cannot be traced back to you.

During checkout, Stripe may set functional and security cookies on its own payment page to prevent fraud. Stripe's privacy policy applies there.

9. Children

Our service is not aimed at children under 16. If you are under 16, please order with the permission of a parent or guardian.

10. Changes

If anything material changes in how we handle data, we update this policy and put a new date at the top. For significant changes affecting an order you have already placed, we email you about it.

Read the terms and conditions too