Data Protection Overview
At CreativAI, we are committed to protecting your personal data and respecting your privacy rights. This Privacy Policy explains how we collect, use, process, and safeguard your information when you interact with our platform, services, and applications. Our dedicated Data Protection Team ensures full compliance with the General Data Protection Regulation (GDPR), the California Consumer Privacy Act (CCPA), and other applicable privacy laws worldwide.
Data Controller Information
CreativAI serves as the data controller for personal data collected through our services. Our Data Protection Officer (DPO) and specialized privacy team monitor all data processing activities to ensure compliance with international privacy standards. You can contact our Data Protection Team at privacy@creativai.com for any privacy-related inquiries or to exercise your data protection rights.
Information We Collect
Account and Profile Data
When you create an account, we collect your name, email address, chosen username, and authentication credentials. For premium services, we may collect billing information and payment details processed through secure, PCI-DSS compliant payment processors.
Usage and Analytics Data
We automatically collect information about your interaction with our services, including IP addresses, browser type, device information, page views, feature usage patterns, and performance metrics. This data helps us improve our services and provide personalized experiences.
Communication Data
We process communications you send to us, including support tickets, feedback, and correspondence with our team. This may include email content, chat logs, and any attachments you provide for support purposes.
Legal Basis for Processing
We process your personal data based on the following legal grounds under GDPR: (1) Contractual necessity for service provision, (2) Legitimate interests in improving our services and preventing fraud, (3) Legal compliance with applicable regulations, and (4) Your explicit consent for specific processing activities. You may withdraw consent at any time where processing is based on consent.
How We Use Your Data
- Service delivery and account management
- Platform security and fraud prevention
- Customer support and technical assistance
- Service improvement and feature development
- Legal compliance and regulatory reporting
- Marketing communications (with your consent)
Data Sharing and Third Parties
We do not sell your personal data. We may share data with trusted service providers who assist in delivering our services, including cloud hosting providers, payment processors, and analytics services. All third-party processors are bound by strict data processing agreements and must comply with applicable privacy laws. We may also disclose data when required by law or to protect our legitimate interests.
Data Security Measures
We implement industry-standard security measures including end-to-end encryption, secure data transmission (TLS 1.3), access controls, regular security audits, and employee privacy training. Our infrastructure follows ISO 27001 security standards and undergoes regular penetration testing. We maintain incident response procedures and will notify relevant authorities and affected individuals of any data breaches as required by law.
Data Retention
We retain personal data only as long as necessary for the purposes outlined in this policy or as required by law. Account data is retained while your account is active and for up to 2 years after account deletion. Usage data is typically retained for 3 years for analytics purposes. You can request earlier deletion of your data subject to legal and operational requirements.
Your Privacy Rights
- Access: Request copies of your personal data
- Rectification: Correct inaccurate or incomplete data
- Erasure: Request deletion of your personal data
- Portability: Receive your data in a structured format
- Restriction: Limit how we process your data
- Objection: Object to processing based on legitimate interests
- Complaint: Lodge complaints with supervisory authorities
International Data Transfers
Your data may be processed in countries outside your residence, including the United States and European Union. We ensure adequate protection through Standard Contractual Clauses, adequacy decisions, or other approved transfer mechanisms. All international transfers comply with applicable data protection laws.
Contact Our Privacy Team
For privacy-related questions, data protection requests, or to report privacy concerns, contact our dedicated Data Protection Team at privacy@creativai.com. Our team includes certified data protection professionals and legal experts who respond to inquiries within 72 hours and fulfill data subject requests within 30 days as required by GDPR.