Privacy Policy
This Privacy Policy describes how Visatech S.R.L ("Beinfer", the "Company", "we", "us" or "our") collects, uses and discloses personal data when you visit beinfer.com or use any product or service offered under the Beinfer name (together, the "Services"). Visatech S.R.L is the data controller responsible for your personal data.
Controller and contact
Visatech S.R.L
Via del Lauro 9, Milan, Italy - 20121
Registration No: MI - 2631753 · VAT No: IT 11929140967
Email: support@beinfer.com
Privacy requests, including requests to exercise the rights described in Section 8, should be sent to the address above with "Privacy" in the subject line.
1. Data we collect
What we collect depends on which Services you use. Across the portfolio, the categories are:
- Account data: name, email address, mobile number, profile photo, language and country preferences, and the credentials you use to sign in.
- Technical data: IP address, device identifiers and characteristics, operating system, browser, app version, crash reports and general usage logs.
- Usage data: the features you use, the time and frequency of use, in-game progress and settings, lesson progress in learning products, and interactions with our communications.
- Content data:
- Inputs: text prompts, questions, source images (including images containing faces), source videos, audio and other material you submit to an AI feature;
- Outputs: the images, videos, text, audio and reports generated for you by the Services.
- Face data: facial images you voluntarily upload to AI photo and video features. Section 2 describes how face data is handled.
- Payment data: purchase history, subscription status, transaction identifiers and the last digits and type of a payment card. Full card numbers are handled by our payment processors and never stored by us.
- Communications: the content of support requests and other messages you send us.
- Marketing data: where you arrived from an advertisement, the campaign, network and creative that referred you, so that we can measure our own campaigns.
We do not collect special categories of personal data (such as health data) unless a specific feature requires it and you have given explicit consent. Yoga and wellbeing tutorials do not require you to provide any health information.
2. Face data collection and use
What face data we collect
AI photo and video features in our products may process photographs and video frames that contain human faces when you upload them as an input. Typical features include portrait and headshot generation, hairstyle and outfit try-on, multi-angle views, stylisation, relighting, skin enhancement, image expansion and inpainting, and animating a still portrait into a short clip.
How we use face data
Face data is used only to generate the output you requested: to render your likeness in the requested style, pose, setting or edit, and to produce the resulting image or video. We do not use face data for facial recognition, identity verification, user tracking or advertising, and we do not build biometric templates that identify you across sessions or products.
Where face data is processed
Depending on the model you select, your images are processed either on infrastructure we control or by trusted third-party AI model providers under data protection agreements that limit processing to generating your requested output and require deletion after processing. Uploaded images and generated outputs are stored on cloud infrastructure that maintains industry-standard security certifications.
Retention of face data
Uploaded images and generated outputs stay in your account until you delete them. You can delete any upload or output at any time from inside the product; deletion removes the data from our storage systems. If you delete your account, all associated face data and outputs are permanently deleted within 30 days.
Your rights regarding face data
You may at any time access your face data, request its immediate deletion, withdraw consent to its processing, or receive a copy in a portable format. To exercise these rights, use the in-product controls or write to support@beinfer.com.
3. How we use data and our legal bases
We process personal data for the following purposes and on the following legal bases under the EU General Data Protection Regulation (GDPR):
- To provide the Services you have requested, including processing Inputs to generate Outputs, saving your progress and delivering purchases (performance of a contract, Art. 6(1)(b)).
- To manage accounts, billing and support (performance of a contract, Art. 6(1)(b); legal obligation for tax and accounting records, Art. 6(1)(c)).
- To secure the Services, prevent fraud and abuse, enforce our Terms and protect users (legitimate interests, Art. 6(1)(f)).
- To improve the Services using aggregated and de-identified usage data (legitimate interests, Art. 6(1)(f)).
- To measure our own advertising across the networks on which we promote our products (consent where required for non-essential cookies and SDKs, Art. 6(1)(a); otherwise legitimate interests, Art. 6(1)(f)).
- To send service messages about changes, security and billing (performance of a contract and legal obligation).
- To send marketing messages about Beinfer products where you have opted in; you can opt out at any time (consent, Art. 6(1)(a)).
- To comply with law and respond to lawful requests from authorities (legal obligation, Art. 6(1)(c)).
We do not use your Inputs or Outputs to train AI models unless a product explicitly asks for and receives your consent. We do not sell personal data.
5. International transfers
Some of our providers process data outside the European Economic Area. Where they do, we rely on an adequacy decision of the European Commission or on Standard Contractual Clauses together with additional safeguards where necessary. You may request a copy of the relevant safeguards at support@beinfer.com.
6. Data retention
We keep personal data only for as long as needed for the purposes described above:
- Account data: for the life of the account and up to 30 days after deletion, except where a longer period is required by law.
- Inputs and Outputs, including face data: until you delete them or your account, then removed within 30 days.
- Transaction records: for the period required by Italian tax and accounting law (generally ten years).
- Technical logs: typically up to 12 months, unless needed longer for security investigations.
- Support correspondence: up to 24 months after the matter is closed.
7. Data security
We apply technical and organisational measures appropriate to the risk, including encryption in transit, access controls, logging and least-privilege access for staff. No method of transmission or storage is completely secure; if we become aware of a personal data breach that is likely to affect your rights, we will notify you and the competent authority as required by law.
8. Your rights
Subject to the conditions set by law, you have the right to:
- access the personal data we hold about you and receive a copy;
- rectify inaccurate or incomplete data;
- erase your data ("right to be forgotten");
- restrict or object to processing, including processing based on legitimate interests and any direct marketing;
- receive your data in a portable, machine-readable format;
- withdraw consent at any time, without affecting the lawfulness of processing before withdrawal;
- lodge a complaint with a supervisory authority. In Italy this is the Garante per la protezione dei dati personali (garanteprivacy.it); you may also complain to the authority of the EU country where you live or work.
To exercise any right, write to support@beinfer.com. We will respond within one month, extendable by two further months for complex requests, and may ask you to verify your identity.
10. Children's privacy
Paid Beinfer Services are not directed at children under 16, and AI generation features are not available to children under 16 (or the higher age set by local law). Where a product is suitable for younger users, its marketplace listing and product-specific terms state the applicable age rating, and we collect only the data needed to run the product. If we learn that we have collected personal data from a child without the required consent, we will delete it promptly.
11. Changes to this Policy
We may update this Privacy Policy from time to time. The "Last updated" date identifies the current version. Material changes will be announced by email or by a notice inside the affected product before they take effect.
12. Contact us
If you have any question or concern about this Policy or about how your data is handled, write to support@beinfer.com or to the registered office below.