GDPR Compliance Notice
For users located within the European Economic Area (EEA) and the United Kingdom, faceshell.ai adheres to the General Data Protection Regulation (GDPR) (EU) 2016/679 regarding the collection, use, and retention of personal information, especially concerning sensitive personal data.
Legal Basis for Processing Personal Data
We process your personal data based on the following legal grounds as outlined in the GDPR:
- Consent: We explicitly obtain your consent for processing your personal data, particularly sensitive categories of personal data like facial images, which are essential for our core service.
- Contractual Necessity: Processing is necessary for the performance of a contract to which you are a party (e.g., fulfilling your order for a custom silicone face) or in order to take steps at your request prior to entering into a contract.
- Legal Obligation: Where processing is necessary for compliance with a legal obligation to which we are subject.
- Legitimate Interests: Where processing is necessary for the purposes of the legitimate interests pursued by us or by a third party, except where such interests are overridden by your interests or fundamental rights and freedoms (e.g., improving our services, ensuring security).
Special Categories of Personal Data
Our service involves the processing of highly sensitive personal data, specifically **biometric data** (facial images) which is considered a special category of personal data under GDPR. We only process this data with your explicit consent, for the specific purpose of creating your customized silicone face.
Your Data Protection Rights Under GDPR
If you are a resident of the EEA or UK, you have significant data protection rights. We aim to take reasonable steps to allow you to exercise these rights:
- The Right to Access: You have the right to request copies of your personal data.
- The Right to Rectification: You have the right to request that we correct any information you believe is inaccurate or complete information you believe is incomplete.
- The Right to Erasure (Right to be Forgotten): You have the right to request that we erase your personal data, under certain conditions (e.g., when the data is no longer necessary for the purposes for which it was collected).
- The Right to Restrict Processing: You have the right to request that we restrict the processing of your personal data, under certain conditions (e.g., if you contest the accuracy of the data).
- The Right to Object to Processing: You have the right to object to our processing of your personal data, under certain conditions, particularly if processing is based on legitimate interests or for direct marketing.
- The Right to Data Portability: You have the right to request that we transfer the data that we have collected to another organization, or directly to you, under certain conditions.
- The Right to Withdraw Consent: You also have the right to withdraw your consent at any time where faceshell.ai relied on your consent to process your personal information, especially for sensitive data. Withdrawal of consent will not affect the lawfulness of processing based on consent before its withdrawal.
If you make a request, we have one month to respond to you. If you would like to exercise any of these rights, please contact us at info@faceshell.ai.
International Data Transfers
Your information, including Personal Data, may be transferred to — and maintained on — computers located outside of your state, province, country or other governmental jurisdiction where the data protection laws may differ than those from your jurisdiction.
When transferring your personal data outside the EEA/UK, we will ensure that appropriate safeguards are in place, such as relying on adequacy decisions, standard contractual clauses, or other lawful mechanisms as required by GDPR, to ensure your data receives a level of protection equivalent to that under GDPR.
Supervisory Authority
If you are an EEA or UK resident and have concerns about our processing of your personal data, you have the right to lodge a complaint with your local data protection supervisory authority.
Contact Us
If you have any questions about this GDPR Compliance Notice or our data processing activities, please contact us at info@faceshell.ai.