1. Data Controller
The controller of your personal data is:
2. Categories of Personal Data
We collect and process the following categories of personal data:
- IP Address: Used for credit tracking and security purposes
- Device Information: Browser type and user agent for service compatibility
- User Content: Images you upload and prompts you provide for generation
- Usage Data: Interaction patterns with the service
3. Purposes and Legal Basis
We process your data for the following purposes:
Service Provision
Legal basis: Performance of contract (Art. 6(1)(b) GDPR)
Credit Tracking
Legal basis: Legitimate interests (Art. 6(1)(f) GDPR)
Security and Fraud Prevention
Legal basis: Legitimate interests (Art. 6(1)(f) GDPR)
4. Special Category Data
When you upload images containing faces, we may process biometric data:
- Facial images are processed solely for image generation purposes
- Legal basis: Explicit consent (Art. 9(2)(a) GDPR)
- We do not use facial data for identification or AI training
5. Data Recipients
We share your data with the following third parties:
- Fal.ai: AI image generation processor
- Google Gemini: AI image analysis processor
- Cloudflare: Hosting, CDN, and storage provider
We do not sell your personal data to third parties.
6. International Data Transfers
Your data may be transferred to countries outside the EU/EEA:
- Fal.ai (USA) - Standard Contractual Clauses
- Google (USA) - EU-US Data Privacy Framework
- Cloudflare (global) - Standard Contractual Clauses
7. Data Retention
We retain your data for the following periods:
- IP/credit data: Duration of service use plus legal retention requirements
- Generated images: Stored in cloud storage until you delete them
- Local data (history, settings): Stored in your browser until you clear it
8. Your Rights
Under GDPR, you have the following rights:
- Right of Access: Request a copy of your personal data
- Right to Rectification: Request correction of inaccurate data
- Right to Erasure: Request deletion of your data
- Right to Restriction: Request limitation of data processing
- Right to Data Portability: Receive your data in a portable format
- Right to Object: Object to processing based on legitimate interests
- Right to Withdraw Consent: Withdraw consent at any time where processing is based on consent
- Right to Lodge a Complaint: File a complaint with the supervisory authority (UODO)
9. Security Measures
We implement appropriate security measures to protect your data:
- HTTPS encryption for all data transmission
- Cloudflare security protection
- Access controls and monitoring
10. Cookies and Storage
We use the following storage technologies:
- Essential cookies only (no consent required)
- localStorage for settings and history (stays in your browser)
- No third-party tracking cookies
11. Children's Privacy
Our service is not intended for children under 16 years of age. We do not knowingly collect personal data from children.
12. AI Disclosure
In compliance with the EU AI Act:
- Images are processed using AI systems (Fal.ai, Google Gemini)
- No automated decision-making with legal effects is performed
- AI-generated content is provided as-is without guarantees of accuracy
13. Contact and Complaints
For any privacy-related questions or to exercise your rights:
Email: hello@wondel.ai
Data Protection Authority (Poland):
Urząd Ochrony Danych Osobowych
ul. Stawki 2, 00-193 Warsaw, Poland
https://uodo.gov.pl
EU Online Dispute Resolution:
https://ec.europa.eu/consumers/odr