Privacy Policy
How we handle your personal data at VISUAILS — in plain English, aligned with the EU General Data Protection Regulation (GDPR).
1. Who we are
VISUAILS is an AI-assisted, human-reviewed product-visuals service based in Enschede, the Netherlands.
We have two roles, and this policy covers one of them. For your own data — your name, your company details, your messages, your invoice — VISUAILS is the controller, and that is what this policy is about. For the material you upload, to the extent there are people in it (in practice the worn shot we ask for so the fit is right), the person in that photo is your data subject and we process the image solely on your instruction. There we are the processor and you are the controller, and that relationship has its own document: the Data Processing Agreement.
That split is not cosmetic. It decides who a data subject should turn to, and who reports a breach to the regulator. This page used to claim we were the controller for everything in it; for the worn shot that was not right, and it was corrected in August 2026.
VISUAILS is the trading name of Lucas Snuverink.
Vaarwerkhorst 17, 7531 HK Enschede, the Netherlands
KVK 99742993 · VAT NL005407575B96 · [email protected]
This is our registered and postal address. It is not a visiting address: there is no reception and we do not receive visitors there. All contact goes through email, and post arrives.
- Trading name: VISUAILS
- Location: Enschede, Netherlands
- Chamber of Commerce (KVK): 99742993
- VAT number: NL005407575B96
- Email: [email protected]
- WhatsApp: +31 6 25436130
2. What data we collect
We only collect what we need to produce your visuals and run our business. Depending on how you use VISUAILS, this may include:
- Product photos and images you upload — the source material we use to create your visuals. If there is a person in them, that image is covered by the Data Processing Agreement rather than by this policy — see §1.
- Contact and business details — your name, brand or company name, email address, phone number, and (where relevant) your VAT number for invoicing.
- Message and brief content — the notes, instructions and correspondence you send us by form, email or WhatsApp.
- Payment data — handled by our payment provider. We do not store full card details on our own systems; we receive confirmation of payment and the information needed to issue an invoice.
- Basic technical data — limited information needed to host and secure the website. See our Cookie Policy for details.
- A launch notice, if you asked for one — on a page for a service that is still in build, a separate tick box lets you ask to be emailed when it can be ordered. Ticking it is optional and never a condition of getting an answer; if you leave it, your address is used only to reply to you.
3. Why we use your data
We use your personal data to:
- Produce and deliver the product visuals you order.
- Communicate with you about your brief, order, revisions and delivery.
- Issue invoices and meet our tax and accounting obligations.
- Respond to your questions and support requests.
- Send you one email when a service you asked to be notified about can be ordered — only if you ticked that box, once, and never as a newsletter.
- Maintain, secure and improve our service.
4. Legal bases for processing
Under the GDPR, we rely on the following legal bases:
- Performance of a contract — to deliver the visuals you order and manage your order.
- Consent — for anything optional, such as non-essential analytics cookies and the launch notice described in section 2. You can withdraw consent at any time; one email to us is enough.
- Legitimate interests — to keep our service secure, prevent misuse and improve what we offer, balanced against your rights.
- Legal obligation — to retain invoicing and tax records as required by Dutch and EU law.
5. Processors and third parties
To run VISUAILS we work with a small number of service providers who process data on our behalf, under agreements that require them to protect it. Named, because "an AI provider" tells you nothing you can check:
- Freepik Company, S.L.U. (Málaga, Spain) — the platform on which your visuals are generated.
- Mollie B.V. (Amsterdam, the Netherlands) — payments. We never see or store full card details.
- Cloudflare, Inc. (United States, with storage in the EU) — hosting the site, storing files and order data.
- Resend (United States) — sending email.
Your material is not used to train AI models. That is not our hope, it is what the platform we generate on undertakes in its own terms: "Under no circumstances will we use your images or voices, or those of third parties that you upload to our platform, to train or improve our artificial intelligence models or those of third-party providers" — and that images you upload are deleted immediately after the visual has been generated from them. We do not use your material for our own portfolio or for advertising either, unless you give us separate permission per order.
Which model, we do not say. The platform above offers a large number of models from different makers and we use whatever gives the best result at the time — as the AI model industry improves, so does what we can deliver. Which one that is, is part of how we do our work. What matters for your data is who receives it, and that is named above and does not change when we switch models.
We do not sell your personal data, and we do not share it for third-party advertising.
Reviews are a separate matter: if you choose to leave one on Google or Trustpilot, you are dealing with that platform under its own terms, and we only see what you publish there.
6. How long we keep your data
We keep your data only as long as it is needed. Three of those periods are fixed, because they are the three that affect you directly:
- Source material — the product photos and files you upload are deleted 90 days after your order closes. If you need us to keep them longer, ask us in writing before then and we will agree it with you.
- Delivered visuals — your finished visuals stay in VISUAILS Studio to download for 90 days from delivery; after that they are removed there. We may keep a copy in our own archive, but that is not a guarantee, so keep your own copy. Still need older images, get in touch and we check whether they are still with us.
- Your order link — the private link you download from works for 90 days after your order closes, then it stops. The same 90 days as the visuals themselves: a link that opens your files should not sit live in an inbox forever. If you need the files after it expires, email us and we will send a new link.
Correspondence about an order is kept for as long as it is useful for that order and any follow-up. Invoicing and tax records are kept for as long as Dutch and EU law requires. When data is no longer needed, we delete or anonymise it.
7. Your GDPR rights
As a data subject in the EU, you have the right to:
- Access — request a copy of the personal data we hold about you.
- Rectification — ask us to correct inaccurate or incomplete data.
- Erasure — ask us to delete your data, where no legal obligation requires us to keep it.
- Portability — receive your data in a structured, commonly used format.
- Restriction and objection — ask us to limit or stop certain processing.
- Withdraw consent — at any time, where processing is based on consent.
To exercise any of these rights, email us at [email protected]. You also have the right to lodge a complaint with the Dutch supervisory authority, the Autoriteit Persoonsgegevens (autoriteitpersoonsgegevens.nl).
8. International transfers
Most of it stays inside the European Economic Area. Generation happens with a party in Spain, and payments with a party in the Netherlands. Two providers are established in the United States — Cloudflare and Resend — and for those the transfer rests on the European Commission’s Standard Contractual Clauses (Art. 46(2)(c) GDPR), which we have in place with both. Cloudflare stores our files and order data in the EU.
Where the generation platform passes material on to a model provider outside the EEA, that platform concludes Standard Contractual Clauses of its own. The full chain, with each party’s country and basis, is in §8 of the Data Processing Agreement — one list, kept current, because that is what the GDPR asks of us when we change providers.
9. Security
We use appropriate technical and organisational measures to protect your data, including access controls, encrypted connections and limiting who can access your files. No system is completely secure, but we work to keep your data safe and to respond quickly if anything goes wrong.
Your order lives at a private web address we email you. There is no account and no password — the address itself is the key. That means anyone you forward it to can open your files, so treat it the way you would treat a key. Here is exactly how it is protected:
- It cannot be guessed. The address carries 256 bits of randomness from a cryptographic random number generator. It is not a sequence, not your order number, and nothing derived from your details, so there is no next one to count up to.
- We do not store it. Our database holds only a one-way SHA-256 fingerprint of the address, never the address itself. It cannot be read back out of our systems — not by us, and not by anyone who obtained a copy of the database.
- It stays out of other people’s records. Pages at that address ask search engines not to index, follow or archive them, send no referrer to any site you click through to, and are not stored by shared caches.
- It cannot be attacked by volume. We rate-limit requests to it, so guessing at scale fails before it starts.
- It ends, and it can be replaced. The address stops working 90 days after your order closes (see §6). If it ever goes somewhere it should not have, tell us: we retire that address and issue you a new one, and the old one stops working immediately.
10. How to contact us
If you have any questions about this policy or how we handle your data, contact us at [email protected] or via WhatsApp on +31 6 25436130. We aim to respond promptly.
Questions about your data?
We’re happy to explain anything in this policy. Reach out and we’ll get back to you.