Privacy policy
Rules for processing personal data, security, and user rights on Pixlinker.
Pixlinker privacy policy
This document explains what data we process, the legal bases we rely on, how long we retain data, and what rights users have. The policy also covers security, analytics, AI tools, and cooperation with technology partners.
1. Data controller
1.1. The controller of personal data is Tomasz Dąbrowski, operating the Pixlinker service, address: ul. Pana Tadeusza 16/28, 39-200 Dębica, Poland, e-mail: contact@pixlinker.com.
1.2. The controller is responsible for compliance with GDPR and applicable national laws.
2. Purposes and scope of processing
2.1. We process data to provide the service, maintain accounts, deliver social and technical features, and ensure platform security.
2.2. The scope of data may include, among others: account data, profile data, content published by the user, transaction data, communication data, and technical data.
2.3. Data may also be used to handle reports, prevent abuse, improve service quality, and produce service performance statistics.
2.4. Processing may concern data related to the account and public profile, portfolio, landing page, listings, messages, comments, reviews, ratings, interactions, rankings, XP, badges, challenges, contests, voting, jury activity, violation reports, and dispute handling.
2.5. Data may also be processed in connection with payments, subscriptions, credits, chargebacks, settlements, security, logs, IP addresses, abuse prevention, and the operation of AI tools and automated content analysis.
3. Legal bases (GDPR)
3.1. GDPR Article 6(1)(b): performance of a contract for the provision of electronic services.
3.2. GDPR Article 6(1)(c): compliance with legal obligations binding on the controller.
3.3. GDPR Article 6(1)(f): the controller's legitimate interests, including security, claims handling, and service quality improvement.
3.4. GDPR Article 6(1)(a): user consent, where required by law.
4. Hosting and technology partners
4.1. Data may be processed by external providers of hosting, e-mail, CDN, security, and analytics services acting as processors.
4.2. The controller selects technology partners with data security and legal compliance in mind.
4.3. Providers process data only to the extent necessary to deliver services for Pixlinker.
4.4. Data and materials may be stored temporarily in cache systems, CDN infrastructure, and security systems used to speed up and protect the service.
4.5. If a given feature is enabled, Pixlinker may use external providers of image analysis, security, anti-spam, anti-fraud, or moderation technology.
4.6. Data may be shared with such providers only to the extent needed for feature operation, content classification, 18+ content detection, tagging, security, diagnostics, or report handling.
5. E-mail, notifications, and communication
5.1. The service may send e-mails related to account operation, security, access reset, feature changes, and system information.
5.2. The service includes a technical and operational notification system related to account operation and user activity.
5.3. Communication data may be processed to the extent necessary to ensure service continuity, security, and report handling.
5.4. This also applies to private messages, comments, reviews, ratings, reports, system notifications, and other forms of user communication and activity available within the service.
6. Security logs, IP, and technical data
6.1. For service security, system logs may be processed, including among others: IP address, session identifiers, timestamps, and device/browser information.
6.2. Technical data is used, among others, to detect abuse, protect accounts, diagnose errors, and ensure service stability.
6.3. Technical and operational data may also be used to detect community manipulation, payment abuse, spam, attempts to bypass blocks, and other actions threatening the safety of the service or its users.
7. Photos, EXIF, and metadata
7.1. Published image files may contain metadata (e.g., EXIF), which may be processed technically as part of service operation.
7.2. To optimize and present content, photos may be converted, scaled, and prepared in different technical variants.
7.3. The user is responsible for what information is contained in published files and metadata.
8. Cookies and analytics
8.1. The service uses cookies and similar technologies to maintain sessions, security, and user convenience.
8.2. The service is prepared for optional analytics and marketing tools, but they will be enabled only after implementation and after the required user consent has been obtained.
8.3. Details about cookies are available in the document Cookie policy.
9. AI and automated moderation
9.1. For moderation and security purposes, the service may use AI tools, including automated content analysis and material classification.
9.2. Analysis may include, among others, detecting violations, marking 18+ content, and limiting visibility of content that requires additional review.
9.3. Automated decisions may be supplemented or corrected by a moderator.
9.4. Automated or mixed analysis may affect content visibility, 18+ markings, safety, tagging, classification, or moderation decisions, which may be corrected manually where needed.
9.5. AI or image analysis tools do not have to operate exclusively locally; where an external provider is used, data is shared only to the extent necessary to support the relevant feature.
10. Data retention and deletion
10.1. We retain data for the period necessary to fulfill processing purposes and legal obligations.
10.2. Data may be deleted or anonymized after use of services ends, taking into account periods necessary for security and claims.
10.3. Some data may be retained longer where required by law or by the controller's legitimate interest.
10.4. Data may temporarily appear in automatically generated backups to ensure service continuity and security.
- Account, public profile, portfolio, landing page, and listing data are generally retained while the account exists or until removed in accordance with service features.
- Billing and payment data is retained for the period required by accounting or tax laws, or as needed to defend claims.
- Security logs, IP addresses, and technical data are retained for a limited time needed for security, diagnostics, abuse prevention, and pursuing claims.
- Violation reports, appeals, and disputes are retained for the time needed to handle the matter, ensure safety, and defend claims.
- Messages and communication are retained while the account operates or until removed in accordance with service features, unless longer retention is needed for security, reports, or claims.
- Backups are retained until overwritten or removed in accordance with the backup cycle.
- Marketing or newsletter data is retained until consent is withdrawn or the user unsubscribes, if such functionality is used.
11. User rights
11.1. The user has the right to: access data, rectify data, erase data, restrict processing, data portability, and object to processing.
11.2. The user may withdraw consent if processing is based on consent.
11.3. The user has the right to lodge a complaint with the competent supervisory authority for personal data protection.
11.4. In Poland, this authority is the President of the Personal Data Protection Office (PUODO).
12. Contact
12.1. For matters related to data protection, write to contact@pixlinker.com and add “GDPR” in the subject.
12.2. A request should include data that allows user identification and a precise description of the request.
