Arteriya – Privacy Policy
Effective date: to be set on publication
Version: 3.1 (draft – pending legal review)
Supersedes: Privacy Policy v3.0 of 1 August 2026; section 10 (Privacy notice), section 11 (Cookies and local storage) and section 12 (Artificial intelligence) of the Arteriya User Agreement v2.0; and all previously published Privacy Policy and Cookie Policy documents.
This version is not yet in force. Version 3.0 of 1 August 2026 continues to apply until an effective date is set above. Version 3.1 makes two changes: it records that we no longer create face-recognition templates (section 5), and it prepares the Policy for users in the European Economic Area (sections 1.1, 9, 10 and 11.4).
This Policy explains what personal data we process, why, on what legal basis, who else sees it, and what you can do about it. It is the complete privacy notice for Arteriya.
It sits alongside the Terms of Service, which governs your use of the service, and the Operator details page, which carries the statutory identification of the operator. Together those three documents replace the single User Agreement published on 27 July 2026.
Table of contents
- Who we are, and who is responsible
- What we collect
- Why we process it, and on what basis
- Automated decisions
- Face data – read this section
- Image metadata, and why GPS matters
- Emergency contacts
- Who else sees your data
- Your rights
- Where your data goes
- Artificial intelligence and your data
- The provenance ledger
- Cookies and local storage
- How long we keep things
- Security
- Changes to this Policy
- How to contact us
1. Who we are, and who is responsible
Arteriya is a professional network for creative practitioners – photographers, models, make-up artists, stylists, retouchers, creative directors and others who work together on creative projects. The service is operated by a private entrepreneur registered in Ukraine.
The controller of personal data is that operator, identified on the Operator details page and contactable at privacy@arteriya.pro. Contact is by email only – we do not accept postal correspondence, and no request needs to be sent on paper to be valid. The person responsible for personal data protection under Article 24(2) of the Law of Ukraine "On Personal Data Protection" is the operator personally.
In this Policy, "we", "us" and "our" mean that operator. "You" and "your" mean you – whether you hold an Arteriya account or simply appear in a photograph someone else uploaded.
1.1 If you are in the European Economic Area
We have no establishment in the European Union. The GDPR still applies to us under its Article 3(2)(a), because we offer the service to people in the EEA, and we treat it as applying to everything described in this Policy.
Because we are outside the EU, Article 27 of the GDPR requires us to designate a representative in the Union: a contact point you and supervisory authorities can address on any data-protection matter, with the same effect as addressing us directly. That representative is:
Anton Chubarov
Avenida de la Tramuntana 14, Portal D, Piso 1, Puerta 3
46540 El Puig de Santa Maria
Valencia, Spain
privacy@arteriya.pro
Email is the channel we prefer, and the one that reaches us soonest. Paper post to that address is accepted and is no less valid, only slower – so if a deadline is running, write. Callers are not received in person there: the address is a private home, not an office, and there is nothing at it that email or post cannot do.
The same person is also our legal representative under Article 13 of the Digital Services Act; both designations are set out on the Operator details page.
The representative is an additional route to us, never the only one. You may exercise every right in section 9 by writing to privacy@arteriya.pro, exactly as before.
We have not appointed a Data Protection Officer, and are not required to; the reasoning is on the Operator details page.
2. What we collect
You give us:
| Data | Notes |
|---|---|
| Email address, authentication credentials | via Firebase Authentication |
| Display name, nickname, username | |
| Legal name, citizenship | optional; used for verification and credits |
| City and country | |
| Profile: biography, avatar, primary role, social links, website | |
| Working areas | geographic coordinates and radius that you place on a map |
| Emergency contact: name, telephone, relationship | a third party's data – see section 7 |
| Photographs and the metadata inside them | see section 6 |
| Projects, participations, credits, applications, messages | |
| Rate cards and availability |
We generate or observe:
| Data | Notes |
|---|---|
| IP address and browser user-agent | on provenance verification requests (section 12), and transiently for rate limiting |
| Image analysis | colour, tonal, sharpness and composition metrics |
| Numerical embeddings of your images | for search, style matching and recommendations |
| Captions and tags | machine-generated descriptions of your images |
| Adult-content scores | per image |
| Face data | see section 5 |
| Creative fingerprint | a machine-written description of your style |
| Server logs | correlation identifiers, request paths, timings – retained 7 days |
We do not collect your date of birth other than as required to confirm you are 18, do not collect your telephone number, and do not operate any behavioural analytics or advertising tracking.
3. Why we process it, and on what basis
| Purpose | Basis (Ukraine) | Basis (GDPR, where applicable) |
|---|---|---|
| Creating and running your account; delivering the service | performance of the contract | Art. 6(1)(b) |
| Storing and displaying your portfolio; generating derivatives | performance of the contract | Art. 6(1)(b) |
| Projects, participations, credits, casting | performance of the contract | Art. 6(1)(b) |
| Search, discovery ranking, style matching, recommendations | legitimate interest in a functioning service | Art. 6(1)(f) |
| Automatic captioning and tagging | legitimate interest | Art. 6(1)(f) |
| Content moderation and adult-content classification | legitimate interest in a lawful, safe service | Art. 6(1)(f) |
| Face detection (position only – no recognition template) | legitimate interest in usable image layouts | Art. 6(1)(f); see section 5 |
| Security, abuse prevention, rate limiting | legitimate interest | Art. 6(1)(f) |
| Provenance verification and the theft ledger | legitimate interest in evidencing image theft | Art. 6(1)(f) |
| Safety check-ins and escalation | performance of the contract | Art. 6(1)(b) / (f) |
| Transactional email | performance of the contract | Art. 6(1)(b) |
| Retaining removed content as evidence | legitimate interest; legal claims | Art. 6(1)(f); Art. 9(2)(f) |
Where we rely on legitimate interests, you may object at any time – write to us and we will stop unless we have compelling grounds that override your interests.
4. Automated decisions
Adult-content classification is automated and can cause an image to be blurred or withheld from public surfaces before any person has looked at it. Permanent removal and account termination are decided by a human being, with a recorded justification (section 7.1 of the Terms of Service).
If an automated decision affects you, you may ask for human review under the appeals procedure in section 7.4 of the Terms of Service.
5. Face data – read this section
When you upload a photograph, our systems detect where faces appear in it. For each detected face we store:
- a bounding box and five facial landmark points (eyes, nose, mouth corners), used to crop images intelligently so faces are not cut off in grid layouts;
- a cropped image of the face, stored in our object storage.
That is the complete list. These records are deleted when the underlying image is deleted.
We want to be direct about three things.
First, this data is generated for everyone depicted in an uploaded photograph – not only account holders. If you are a model photographed by an Arteriya user, face data about you may exist on our systems even though you have never used the service and never agreed to anything. You can require its deletion under section 9 of this Policy and section 5.3 of the Terms of Service, and we will comply.
Second, we do not create face templates. A face template – also called a face embedding or a faceprint – is a numerical code derived from an individual's facial geometry, capable of determining whether two photographs show the same person. That is biometric data: sensitive personal data under Ukrainian law, and, where it is used to identify someone uniquely, special-category data under Article 9 of the GDPR, for which the ordinary legal bases are not sufficient. We do not generate one, do not store one, and operate no system capable of recognising a person from their face. Recording that a face is present at a particular position in an image singles nobody out and is not Article 9 data.
Earlier versions of our image pipeline did compute a face template, together with an estimated age and gender, for every detected face. We have removed that capability. From the effective date of this version of the Policy, those fields do not exist in our systems, and every template and attribute estimate previously computed has been deleted.
Third, we do not use face data to identify anyone, to build a searchable index of people, or to match faces across accounts, and we do not disclose it to anyone. Its only operational use is layout cropping.
If you do not want face data generated from images you appear in, contact us and we will delete it and exclude you.
6. Image metadata, and why GPS matters
Digital photographs carry embedded metadata (EXIF): camera and lens, exposure settings, timestamps and – often – the GPS coordinates of where the photograph was taken.
What we do with it:
- The original file you upload is stored unchanged, with all its metadata intact, in our private storage. It is never served publicly.
- We extract camera settings and, where present, GPS coordinates into our database, and show them to you on your own image's analytics page. Only you can see them. They are not returned by any public endpoint and not shown to other users.
- The display versions we generate and serve – every size shown anywhere on the service – contain no EXIF metadata and no GPS coordinates. Anyone downloading an image from Arteriya gets no location data from it.
⚠️ You should still be careful. Ukraine is at war, and metadata you never look at can reveal where you were standing. Before uploading, consider stripping GPS from photographs taken near military, infrastructure or defence-industry locations – and read section 6.3 of the Terms of Service on Article 114-2 of the Criminal Code. We provide a means to remove this metadata; you are responsible for what your files contain.
7. Emergency contacts
If you use the safety features you may give us the name and telephone number of an emergency contact. That person's data is personal data about them, not about you.
You warrant that you have their permission and have told them why you provided their details.
In accordance with Article 12(2) of the Law of Ukraine "On Personal Data Protection", we will notify that person that we hold their details, why, and how to have them removed. They can require deletion at any time by writing to us, and we will comply without affecting your account.
We use these details only to try to reach that person if you miss a safety check-in. We never use them for marketing.
8. Who else sees your data
We do not sell, rent or trade your personal data. We do not share it with anyone for their own purposes, for marketing or for advertising. We run no advertising on Arteriya and no third-party tracking.
We do use service providers who process data strictly on our instructions, under contract:
| Provider | Purpose | Location |
|---|---|---|
| Google Firebase | authentication | United States |
| Oracle Cloud Infrastructure | image and file storage | European Union (Frankfurt) |
| Redis Cloud | caching, rate limiting | European Union |
| Neo4j Aura | collaboration graph | European Union |
| Zoho (ZeptoMail, Zoho Mail) | transactional email delivery | European Union (EU data centre) |
| Self-hosted infrastructure | primary database, messaging, image processing, monitoring | operated by us |
Our machine-learning models – image analysis, embeddings, captioning, tagging, adult-content classification, face processing and creative fingerprints – run on infrastructure we control, on model weights we hold. Your photographs are not sent to any third-party artificial-intelligence provider.
We will also disclose data where we are legally required to, or where it is necessary to protect someone's life or safety, or to establish or defend legal claims.
9. Your rights
Under Article 8 of the Law of Ukraine "On Personal Data Protection" you have the right to:
- know who holds your data, where it is, and for what purpose;
- know to whom it has been disclosed;
- access your data – we respond within 30 calendar days;
- have inaccurate data corrected;
- have your data deleted;
- object to processing, and to restrict it;
- protection against decisions taken solely by automated means;
- complain to the Verkhovna Rada of Ukraine Commissioner for Human Rights, or to a court.
If the GDPR applies to processing about you, you additionally have the rights of access, rectification, erasure, restriction, portability and objection under Articles 15–22, and the right to complain to a supervisory authority.
Which supervisory authority. If you are in the EEA, you may complain to the authority of the Member State where you live, where you work, or where the thing you are complaining about happened. For users in Spain that is the Agencia Española de Protección de Datos (AEPD), C/ Jorge Juan 6, 28001 Madrid, https://www.aepd.es. Because we have no EU establishment, the GDPR's one-stop-shop does not apply to us and there is no "lead" authority you must go through – your own national authority is competent. The full list of authorities and the Ukrainian Commissioner's address are on the Operator details page.
We do not charge for any of this, and we do not make you justify it. We answer within 30 calendar days (one month under the GDPR), and if a request is genuinely complex we may extend that by two further months, telling you why within the first month.
These rights belong to anyone whose data we hold – including people depicted in photographs who have never used Arteriya.
Two related routes are set out in the Terms of Service and are available to you whether or not you hold an account:
- Removal of an image you appear in – section 5.3 of the Terms of Service. We remove it without requiring you to prove the absence of consent.
- Account deletion and data export – section 12 of the Terms of Service, which also lists what necessarily survives deletion and why.
To exercise any of them, write to privacy@arteriya.pro.
10. Where your data goes
Our service providers are located outside Ukraine, principally in the European Union and the United States. The table in section 8 says which is where.
Under Ukrainian law, transfers are made under Article 29 of the Law of Ukraine "On Personal Data Protection" – to states providing adequate protection of personal data – and, where required, on the basis of your consent to the transfer, which you give when you accept the Terms of Service.
10.1 If you are in the EEA
Two different things happen, and they are governed differently.
Your data reaching us in Ukraine is not a "transfer". When you type your details into Arteriya, you disclose them to us directly. Under the European Data Protection Board's Guidelines 05/2021, data a data subject provides directly to a controller in a third country is not a Chapter V transfer, because there is no EEA-based exporter making it available to us. So the absence of an EU adequacy decision for Ukraine – and there is none – does not stand in the way of your using Arteriya.
Our onward disclosures to processors are transfers, and Chapter V governs them. Where we send your data to a provider outside the EEA:
| Destination | Safeguard |
|---|---|
| United States (Firebase) | EU–US Data Privacy Framework where the recipient is certified; otherwise the Commission's Standard Contractual Clauses (Decision 2021/914), with a transfer impact assessment |
| European Union (Oracle Cloud Frankfurt, Redis Cloud, Neo4j Aura, Zoho EU) | no transfer – the data stays in the EEA |
| Ukraine (our own servers and the operator) | Standard Contractual Clauses, controller-to-processor, where the processing is carried out on our behalf by anyone other than the operator personally |
You may request a copy of the safeguards in place by writing to privacy@arteriya.pro.
A frank word about Ukraine. Ukraine is at war. Our servers, our operator and our records sit in a country under martial law, where the authorities have broader powers than in peacetime. We hold no data we consider attractive to a state actor, we have never received a state access request, and we would tell you if the law let us. But you should weigh that before uploading anything whose exposure would harm you.
11. Artificial intelligence and your data
We use machine learning extensively. Here is exactly what runs and what it does.
11.1 What the systems do
| System | What it does |
|---|---|
| Image analysis | measures colour, tone, sharpness, composition; extracts EXIF |
| Style embeddings | a numerical representation of visual style, for similarity matching |
| Search embeddings | a numerical representation of content, for semantic search |
| Captioning | writes short descriptions of images |
| Tagging | assigns taxonomy tags |
| Adult-content classification | scores images for adult content and flags them for review |
| Face detection | locates faces and five landmark points, for layout cropping. No recognition templates, no age or gender estimates (section 5) |
| Creative fingerprint | writes a short description of your creative style from your portfolio |
11.2 AI-generated text
Descriptions, captions, tags and creative fingerprints are generated by machines and may be inaccurate. Where such text is shown, it is labelled. You can edit or override tags on your own images.
11.3 We do not train generative AI on your work
Your content is never used to train generative image or text models – ours or anyone else's. We do not license your work to third parties for AI training. Your photographs are not transmitted to any third-party AI provider; every model we run operates on infrastructure we control.
We do use your content, and signals derived from it, to operate and improve the systems in section 11.1 – search, matching, tagging and moderation. These are classification and retrieval systems; they do not generate images and cannot reproduce your work.
You may object to this use under section 3.
The invisible watermark embedded in display versions of your images is described in section 13 of the Terms of Service; the data recorded when someone uses the resulting verification tool is described in section 12 below.
11.4 The EU AI Act
The transparency rules in Article 50 of Regulation (EU) 2024/1689 (the AI Act) have applied since 2 August 2026. Two of them are relevant to us, and we meet both:
- Machine-generated text is labelled as such wherever it is shown – captions, tags and creative fingerprints all carry a marker in the interface, so you are never left to guess whether a person or a model wrote a description of your work (section 11.2).
- We operate no system that requires an additional disclosure. We run no chatbot or other AI system you interact with directly, we generate no synthetic images, audio or video, we produce no deepfakes, and we run no emotion recognition and no biometric categorisation – the last two follow from having removed face recognition entirely (section 5).
None of the systems in section 11.1 is a high-risk AI system within the meaning of Annex III. Face detection that locates a face without identifying or categorising anyone is not biometric identification, and adult-content classification scores an image, not a person.
12. The provenance ledger
Arteriya embeds an invisible watermark into the display versions of uploaded images (see section 13 of the Terms of Service), and offers a public tool at /verify that checks whether a given image originated on Arteriya.
When someone submits an image to that tool, the image itself is never stored – it is decoded in memory and discarded.
If the check produces a positive match, we record the match together with the submitter's IP address and browser user-agent, so that patterns of image theft can be evidenced and the endpoint protected from abuse. Where no match is found, nothing is recorded. This is explained on the page before submission. These records are retained for 12 months.
13. Cookies and local storage
We use the minimum necessary. We run no analytics cookies, no advertising cookies, and no third-party tracking of any kind.
| Name | Type | Purpose | Duration |
|---|---|---|---|
artplatform_session | cookie | tells the app you are signed in, so pages route correctly | session |
artplatform_admin | cookie | routes administrators to the admin interface | session |
locale | cookie | remembers whether you chose English or Ukrainian | 1 year |
firebase:authUser:… | local storage | your sign-in token, so you stay signed in | until sign-out |
| Firebase internal keys | local storage / IndexedDB | authentication library internals | managed by the library |
All of these are strictly necessary to provide a service you have asked for, so we do not ask for consent to them. You can clear them in your browser, but you will be signed out and some preferences will reset.
If we ever introduce analytics or advertising, we will ask for your consent first, through a banner that lets you refuse as easily as accept, and we will update this section before doing so.
14. How long we keep things
| Data | Retention |
|---|---|
| Account and profile data | while your account is open |
| Your content | until you delete it, then up to 90 days in caches and backups |
| Face data | deleted with the image it came from |
| Server logs | 7 days |
| Provenance ledger records | 12 months |
| Removed content and moderation records | 12 months, as evidence and to allow appeals |
| Derived signals from removed content (scores, embeddings, labels – no images) | up to 3 years, to improve moderation accuracy |
| Suspected child sexual abuse material | handled solely under the process in section 6.3 of the Terms of Service; never retained for any other purpose and never used to develop our systems |
| Acceptance records for the Terms of Service and this Policy | for the limitation period |
| Records required by tax law | as required by Ukrainian law |
15. Security
We use encrypted connections, private storage buckets, access controls and structured audit logging. No system is perfectly secure. If a breach occurs that is likely to put your rights at risk, we will tell you.
16. Changes to this Policy
We may update this Policy. When we do, we change the version number and the effective date at the top.
- For minor changes – clarifications, corrections, new provider names – we publish the new version and note the change.
- For material changes – anything affecting how we use your data – we notify you and ask you to accept the new version.
Every published version is archived. Ask us for any past version.
Language. This Policy is published in Ukrainian and in English, at the same address and with the same version number and effective date. If you are located in Ukraine, the Ukrainian version is the authoritative text; if you are located elsewhere, including the EEA, the English version is. Where the two differ in meaning, the version authoritative for you prevails. This rule changed in version 3.1, and matches section 16.2 of the Terms of Service.
17. How to contact us
| For | Contact |
|---|---|
| Data protection, access, deletion, objection | privacy@arteriya.pro |
| Removal of an image you appear in | privacy@arteriya.pro |
| Anything else, and general enquiries | support@arteriya.pro |
| Legal notices and disputes | legal@arteriya.pro |
Operator name and place of registration, and our representative in the European Union: see the Operator details page.
You may complain about how we handle personal data to the Verkhovna Rada of Ukraine Commissioner for Human Rights, 01008, Kyiv, vul. Instytutska 21/8, or – if you are in the EEA – to your own national supervisory authority, which for Spain is the Agencia Española de Protección de Datos. See section 9.
Thank you for reading this. We have tried to write it in plain language rather than legal boilerplate, because a policy nobody can read protects nobody.