We use cookies

    We use cookies to ensure the best experience on our site. Essential cookies are always active, but you can choose whether to accept analytics and marketing cookies.

    Privacy Policy

    Record of Processing Activities

    Record of Processing Activities (RoPA) - in accordance with GDPR Art. 30

    Data Controller

    Company: MP Merlin Limited

    Address: 97 Wordsworth Road, M27 9SJ, Swinton, UK

    Contact email:support@upvinti.com

    Personal Data Processing Activities

    Processing activity Purpose of processing Legal basis Data subjects Data categories Data recipients Retention period International transfers
    🔐 Account registration Providing online service Art. 6(1)(b) GDPR - performance of contract Service users Name, email, password (hash) Supabase (database hosting) Until account deletion UK/EU (Standard Contractual Clauses)
    🖼️ Image processing Providing AI service (generation, enhancement) Art. 6(1)(b) GDPR - performance of contract Service users Product photos, clothing images Google AI (Gemini), Lovable AI, Supabase Storage Max. 50 recent generations / until deletion USA, UK/EU (Standard Contractual Clauses)
    💳 Payment processing Transaction and subscription processing Art. 6(1)(b) GDPR - performance of contract, Art. 6(1)(c) - legal obligation Paying customers Payment data (Stripe), transaction history Stripe (payment processor) According to tax requirements (min. 7 years) USA (Standard Contractual Clauses)
    📧 Newsletter and marketing Sending newsletter and marketing communications Art. 6(1)(a) GDPR - user consent Newsletter subscribers Email, consent date Resend (email service) Until consent withdrawal USA (Standard Contractual Clauses)
    📊 Analytics cookies Traffic analysis and UX optimization Art. 6(1)(a) GDPR - user consent Website visitors IP address, device type, browser Lovable Analytics According to cookie settings None
    👤 Custom AI models AI service personalization (custom models) Art. 6(1)(b) GDPR - performance of contract Users with custom models Person photos, physical description (age, height, body type) Supabase Storage, Google AI (portrait generation) Until model or account deletion UK/EU, USA (Standard Contractual Clauses)
    🛡️ Device Fingerprinting (Fraud Prevention) Protection against fraud, multi-account abuse, promo code abuse Art. 6(1)(f) GDPR - legitimate interest All users Device hash, browser, OS, screen resolution, timezone Supabase (internal database) 12 months from last activity UK/EU (Standard Contractual Clauses)

    Data protection contact

    For questions regarding personal data processing, contact us:

    support@upvinti.com

    Related documents

    Full data protection information can be found in:

    Privacy Policy

    Last updated: 26 November 2025