Privacy Policy
Effective date:
1. Controller
Vixel AS, Storgata 9, 2815 Gjøvik, Norway, org. nr. NO 914 457 726 (“Vixel”), is the controller for personal data relating to accounts, billing and use of Vrex Visual (the “Service”).
For material the Customer brings into the Service — designs, images, descriptions and the output generated from them (“Content”) — the Customer is the controller, and Vixel acts as processor on the Customer’s instructions.
Requests concerning personal data may be submitted through the contact form in the application (account menu → Contact) or in writing to the address above.
2. Processing of Content
Vixel processes Content solely to provide the Service: to store it, to generate the images and clips the Customer requests, and to display it to the Customer’s organization.
Generation is performed by AI models operated by Vixel’s providers. A generation request comprises the Customer’s description, the images attached to the request (the base image and any reference images) and the project context the Customer has elected to include (the project description and the project’s general area). Account data is not included in generation requests.
Neither Vixel nor its providers use Content to train or improve AI models; Vixel’s providers are contractually bound accordingly. Content may incidentally contain personal data; where a provider processes Content outside the EEA, the transfer is governed by the EU Standard Contractual Clauses (“SCCs”) or the EU–US Data Privacy Framework (“DPF”). The Customer is responsible for the lawfulness of the Content it uploads.
3. Categories of personal data
- Account data — name, company, work email address and, where provided, a profile picture. Stored in the EEA (Frankfurt). Used for authentication, billing and service communication, through the processors engaged for those purposes. Not included in generation requests.
- Content — as defined in section 1, including derived files used for display.
- Project location — optional. The general area of a project, at the precision the Customer chooses, used solely to reflect the character of that area (climate, light, vegetation, surroundings) in generated output.
- Guest contact data — email addresses of persons the Customer invites to a topic.
- Billing data — plan and status, a payment-provider customer reference and a credit ledger. Card details are processed by the payment provider and do not reach Vixel’s systems.
- Usage records — per-generation technical records without image content, used to operate and price the Service.
- Feedback — where submitted: the message, any screenshot and a snapshot of the application state, used to reproduce the reported issue; processed by Vixel only.
- Server logs — standard logs for security and operations.
4. Purposes and legal bases
- Provision of the Service (generation, storage, billing, support) — performance of a contract, GDPR Art. 6(1)(b).
- Security, abuse prevention and service improvement (rate limiting, logs, aggregated telemetry) — legitimate interests, Art. 6(1)(f).
- Accounting and tax records — legal obligation, Art. 6(1)(c).
5. Recipients and international transfers
| Category of recipient | Location | Transfer safeguard |
|---|---|---|
| Hosting and database | EEA (Frankfurt) | Not applicable (EEA) |
| File storage | EEA (Western Europe) | Not applicable (EEA) |
| AI model providers | May process outside the EEA | SCCs / DPF |
| Authentication, payments, service email, location lookup | EEA and USA | SCCs / DPF |
The list of processors, including contracting entities and transfer mechanisms, is available on request through the contact form in the application. Vixel gives notice of changes.
6. Retention
Content and account data are retained until deleted by the Customer or until the account is deleted. Individual images and generations can be deleted in the application; an organization owner can delete the entire account, which erases the organization’s records and files. Residual copies in encrypted backups expire after a limited period. Usage records and server logs are retained for a limited period for security and operations and then deleted or aggregated.
7. Data subject rights
Data subjects have the rights of access, rectification, erasure, restriction, portability and objection under the GDPR, exercisable through the channels in section 1. Complaints may be lodged with the Norwegian Data Protection Authority (Datatilsynet) or another competent supervisory authority.
8. Cookies and local storage
The application uses a session credential and minimal browser storage for convenience. It uses no advertising cookies or cross-site tracking. The marketing website may use cookieless, privacy-preserving analytics.
9. Security
Data is encrypted in transit. Files are held in private storage and accessed through short-lived signed links. Each organization’s data is segregated at the database level. Further information for IT review is available in the application (Vrex Academy → Compliance → IT & Security).
10. Changes
Updates to this policy are published on this page; material changes are notified to account holders by email.