Legal · GDPR
Privacy Policy
Last updated: 21 April 2026
LayerAxon ("we", "us", "our") is the data controller for personal data processed through LayerAxon Studio (the "Service"). We are committed to processing personal data lawfully, fairly, and transparently in accordance with the UK General Data Protection Regulation ("UK GDPR"), the Data Protection Act 2018, and, where applicable, the EU GDPR.
1. Data We Collect
- Account data: name, email address, country, preferred language, hashed password, account role and tier.
- Authentication data: session tokens, two-factor secrets (when enabled), optional OAuth identifiers (e.g., Google).
- Usage data: credits balance, jobs you submit, prompts, generated outputs, support tickets, feedback submissions.
- Device & technical data: IP address, user agent, device fingerprint (hashed), timestamps.
- Billing data (if applicable): handled by our payment processor (Stripe). We do not store full card numbers.
2. How & Why We Use Your Data
- To provide the Service (Art. 6(1)(b) UK GDPR — performance of contract): creating your account, processing generations, delivering credits, customer support.
- To secure the Service (Art. 6(1)(f) — legitimate interests): preventing fraud, abuse, multi-account creation, and DDoS attacks.
- To improve the Service (Art. 6(1)(f) — legitimate interests): aggregate usage analytics, debugging, model performance evaluation.
- To communicate with you (Art. 6(1)(b) and 6(1)(a) — consent for marketing): transactional emails, security alerts, optional product updates.
- To comply with legal obligations (Art. 6(1)(c)): responding to lawful requests from authorities, financial record-keeping.
3. AI Model Training
We do not use your prompts or generated outputs to train third-party foundation models. Generation requests are forwarded to our AI processing partners under terms that prohibit such training on customer data. Where we operate models we host ourselves, we may use anonymised, aggregated metadata to improve quality — never identifiable prompts or outputs without your explicit consent.
4. Sharing & Sub-processors
We rely on the following categories of sub-processors:
- Cloud infrastructure (storage and inference hosting);
- AI model providers (third-party generation partners);
- Email delivery (transactional-email provider — when configured);
- Payments (a PCI-compliant payment processor — when configured);
- Analytics & error monitoring as introduced from time to time.
We do not sell your personal data and we do not share it with advertisers.
5. International Data Transfers
Some of our sub-processors operate outside the UK and EEA. Where personal data is transferred internationally, we rely on appropriate safeguards such as the UK International Data Transfer Agreement, the EU Standard Contractual Clauses, or adequacy decisions.
6. Data Retention
- Account data: retained while your account is active and for up to 12 months after closure (for fraud prevention and tax records);
- Generated outputs: retained until you delete them or close your account;
- Server logs: typically 30–90 days;
- Backups: rotated according to our backup schedule (typically up to 90 days).
7. Your Rights Under UK GDPR
You have the right to:
- Access the personal data we hold about you;
- Request rectification of inaccurate data;
- Request erasure ("right to be forgotten") in certain circumstances;
- Restrict or object to certain processing;
- Receive your data in a portable format;
- Withdraw consent at any time (without affecting prior lawful processing);
- Lodge a complaint with the UK Information Commissioner's Office (ICO) at ico.org.uk.
To exercise these rights, email [email protected]. We will respond within one month.
8. Cookies & Local Storage
We use a minimal set of strictly-necessary cookies and browser local storage to keep you logged in, remember your language and theme preferences, and protect against abuse. We do not use third-party advertising cookies. A detailed cookie list is available on request.
9. Security
We employ industry-standard technical and organisational measures, including TLS in transit, password hashing with scrypt, scoped session tokens, optional two-factor authentication, rate-limiting, a Web Application Firewall, and least-privilege access controls. No system is perfectly secure — please use a strong, unique password and enable two-factor authentication.
10. Children
The Service is not directed to children under 16. We do not knowingly collect personal data from children. If you believe a child has provided us with data, please contact us so we can delete it.
11. Changes to This Policy
We may update this Policy from time to time. The "Last updated" date above reflects the most recent revision. Material changes will be communicated through the Service or by email.
12. Contact
Data Protection enquiries: [email protected].
Postal address: LayerAxon, United Kingdom (full registered address available on request).
Note: This document is provided as a starting template for an AI SaaS startup operating in the UK and does not constitute legal advice. Please have it reviewed by qualified counsel before relying on it in production.
