PRIVACY POLICY
HOW WE PROCESS PERSONAL DATA

 

Last updated: July 11, 2026

This Privacy Policy explains how Proxima Pictures ("Company," "we," "us," or "our") collects, uses, stores, shares, and protects personal data when you use https://www.proxima.art/ and our AI image, video, studio, account, credit, subscription, and community services (the "Services").

If you are located in the European Union, including Germany, this Privacy Policy is intended to provide information required under the General Data Protection Regulation ("GDPR") and other applicable data protection laws.

You can contact us at sales@proximai.art. If we designate a separate data protection contact or representative in the future, we will publish the details on this page.

 

1. CONTROLLER

For the Services, Proxima Pictures is the controller of personal data unless a separate agreement or notice states otherwise.

Controller contact: Proxima Pictures, email: sales@proximai.art.

Where legally required, additional company registration, address, representative, or data protection officer details will be provided in our Impressum and related legal notices.

2. PERSONAL DATA WE COLLECT

We process only the personal data that is reasonably needed to provide, secure, improve, bill, moderate, and support the Services.

  • Account data: username, email address, password hash, account settings, language, subscription status, roles, login history, and authentication data.
  • Payment and credit data: plan, purchase history, credit transactions, billing status, refunds, chargebacks, tax-related information, and payment processor transaction references. We do not store full card details unless a payment provider expressly makes limited tokenized data available to us.
  • Content and generation data: prompts, uploaded images or files, generated outputs, model selections, seeds, settings, generation logs, moderation signals, metadata, and related history.
  • Usage and technical data: IP address, device and browser information, cookies, session identifiers, pages viewed, requests, logs, approximate location derived from IP, error reports, and security events.
  • Communications: support requests, emails, feedback, complaints, legal requests, and correspondence with us.
  • Public or community data: profile information, public galleries, comments, likes, published prompts or outputs, and other content you choose to make public.
3. WHY WE PROCESS PERSONAL DATA

We process personal data for the following purposes and legal bases under the GDPR:

  • Providing the Services: to create accounts, authenticate users, process generations, store outputs, manage credits and subscriptions, and provide support. Legal basis: performance of a contract or steps prior to a contract.
  • Payments and accounting: to process purchases, subscriptions, refunds, tax records, invoices, fraud checks, and financial reporting. Legal basis: performance of a contract, legal obligation, and legitimate interests.
  • Security and abuse prevention: to detect fraud, account abuse, cyber threats, scraping, credit abuse, illegal content, and violations of our Terms. Legal basis: legitimate interests and legal obligations.
  • Content moderation and legal compliance: to enforce our Terms, comply with legal requests, protect minors, respond to notices, and prevent unlawful use. Legal basis: legal obligation and legitimate interests.
  • Service improvement: to debug, measure performance, improve features, evaluate model quality, and develop safer tools. Legal basis: legitimate interests or consent where required.
  • Marketing and service messages: to send transactional notices, policy updates, billing notices, and, where permitted, marketing communications. Legal basis: contract, legitimate interests, or consent depending on the message.
  • Cookies and analytics: to remember preferences, keep sessions secure, measure usage, and improve the Services. Legal basis: consent where required and legitimate interests for strictly necessary cookies.
4. AI-SPECIFIC DATA PRACTICES

Because our Services use AI systems, content may be processed by our own infrastructure and by third-party model or infrastructure providers that help generate, edit, upscale, moderate, store, or deliver outputs.

Prompts, uploads, generated content, and related metadata may contain personal data. You must not upload personal data, biometric data, confidential information, third-party images, or likenesses unless you have a lawful basis and all required rights and consents.

Where we provide settings to opt out of model training, product improvement, public display, or similar optional processing, we will honor those settings from the time they are applied, subject to technical, contractual, legal, security, and backup limitations.

Generated outputs may be reviewed automatically and, where necessary, manually for safety, abuse prevention, support, legal compliance, or Terms enforcement.

5. COOKIES AND SIMILAR TECHNOLOGIES

We use cookies, local storage, pixels, logs, and similar technologies to operate the Services, keep users signed in, prevent fraud, remember preferences, process payments, and understand usage.

Strictly necessary cookies may be used without consent where permitted by law. Optional analytics, advertising, or similar cookies will be used only where we have a valid legal basis, including consent where required. More detail is provided in our Cookie Policy.

6. SHARING PERSONAL DATA

We do not sell personal data. We may share personal data only where reasonably necessary for the Services or where legally required.

  • Service providers: hosting, databases, storage, payment processors, email providers, analytics providers, security vendors, support tools, model providers, CDN providers, and other processors acting on our instructions.
  • Payment partners: payment processors, banks, card networks, anti-fraud services, and tax or accounting providers.
  • AI and infrastructure partners: model, GPU, moderation, storage, queue, logging, and content processing providers used to deliver the Services.
  • Legal and safety recipients: courts, regulators, law enforcement, rights holders, advisors, insurers, or affected users where required or permitted by law.
  • Business transfers: parties involved in a merger, acquisition, financing, restructuring, or sale of assets, subject to appropriate confidentiality and legal safeguards.
  • Public sharing: other users or visitors may see content that you choose to publish publicly.
7. INTERNATIONAL TRANSFERS

Some providers may process personal data outside your country, including outside the European Economic Area. Where this happens, we use appropriate safeguards required by the GDPR, such as adequacy decisions, Standard Contractual Clauses, transfer impact assessments, supplementary measures, or another lawful transfer mechanism.

8. RETENTION

We keep personal data only as long as reasonably necessary for the purposes described in this Privacy Policy, unless a longer retention period is required or permitted by law.

  • Account data: generally kept while your account exists and for a reasonable period afterward for security, legal, accounting, and dispute purposes.
  • Generation content and history: kept while needed to provide history, galleries, support, moderation, security, and service operation, unless deleted earlier through available settings or legal requests.
  • Payment and accounting data: kept for statutory accounting, tax, chargeback, and audit periods.
  • Security logs: kept for a limited period needed to protect the Services, investigate abuse, and defend legal claims.
  • Support and legal records: kept while needed to resolve requests, enforce rights, comply with law, and document decisions.

When data is no longer needed, we delete, anonymize, or restrict it where appropriate.

9. YOUR GDPR RIGHTS

If the GDPR applies to you, you may have the right to request access, correction, deletion, restriction, portability, objection to processing based on legitimate interests, and withdrawal of consent where processing is based on consent.

You can contact us at sales@proximai.art to exercise your rights. We may need to verify your identity and may refuse or limit a request where permitted by law, for example to protect other users, comply with legal obligations, preserve evidence, prevent abuse, or maintain security.

You also have the right to lodge a complaint with a data protection supervisory authority, including in the EU member state where you live, work, or believe an infringement occurred.

10. CHILDREN AND MINORS

The Services are intended for users who are at least 13 years old. Users under 18 may use the Services only with the consent and supervision of a parent or legal guardian. We do not knowingly collect personal data from children below the applicable minimum age without required consent.

11. SECURITY

We use technical and organizational measures designed to protect personal data against unauthorized access, loss, misuse, alteration, and disclosure. No online service can be guaranteed completely secure. You are responsible for using a strong password, keeping credentials confidential, and notifying us if you suspect unauthorized access.

12. CHANGES TO THIS PRIVACY POLICY

We may update this Privacy Policy when our Services, providers, legal obligations, or data practices change. We will post the updated version on this page and, where required, notify registered users of material changes.

13. CONTACT

For privacy questions, rights requests, or complaints, contact us at sales@proximai.art. Please include enough information for us to understand and verify your request.