GDPR & CCPA Compliance Notice
Understanding your data privacy rights and how PrimeStyleAI protects your personal information.
This GDPR & CCPA Compliance Notice explains how PrimeStyleAI complies with the General Data Protection Regulation (GDPR), the California Consumer Privacy Act (CCPA), and the California Privacy Rights Act (CPRA).
Note: This notice supplements our Privacy Policy, Terms of Service, Cookie Policy, Refund & Cancellation Policy, and Pricing Policy.
1. Who This Notice Applies To
This GDPR & CCPA Compliance Notice applies to the following individuals:
GDPR Coverage
Residents of the European Economic Area (EEA), the United Kingdom, and Switzerland are protected under the General Data Protection Regulation (GDPR).
If you are located in any of these regions, you have specific rights regarding the collection, use, and processing of your personal data.
CCPA / CPRA Coverage
California residents are protected under the California Consumer Privacy Act (CCPA), as amended by the California Privacy Rights Act (CPRA).
If you are a California resident, you have specific rights regarding the collection, sale, and disclosure of your personal information.
2. Data Controller Information
The data controller responsible for your personal data is:
Company Details
Business Name: PrimeStyleAI
Websites: myaifitting.com & primestyleai.com
Location: Laguna Niguel, California, USA
Email: Support@PrimeStyleAI.com
Phone: +1 (949) 364-4449
3. Categories of Personal Data We Collect
We may collect the following categories of personal data depending on how you interact with our services:
Data Categories
Identifiers: Name, email address, phone number, account username
Account Credentials: Hashed passwords, authentication tokens
Uploaded Images: Photos you upload for virtual try-on and AI styling features
Usage Data: Interaction logs, feature usage, session data, preferences
Device Information: IP address, browser type, operating system, device identifiers
Payment Metadata: Transaction IDs, billing information (processed by third-party payment processors; we do not store full payment card details)
Sensitive Information
We do not intentionally collect sensitive personal information (e.g., racial or ethnic origin, health data, biometric data) unless specifically required to provide the services you have requested.
4. Purposes and Legal Bases for Processing (GDPR)
Under the GDPR, we process your personal data based on the following legal bases:
Legal Bases
Contractual Necessity: Processing necessary to perform a contract with you, such as providing AI styling services, managing your account, and fulfilling token or membership purchases.
Legitimate Interests: Processing necessary for our legitimate business interests, such as improving our services, preventing fraud, and ensuring platform security, provided these interests do not override your fundamental rights.
Consent: Where you have given explicit consent for specific processing activities, such as receiving marketing communications or using optional AI features. You may withdraw consent at any time.
Legal Obligation: Processing necessary to comply with applicable laws and regulations, such as tax reporting and responding to lawful requests from authorities.
Withdrawing Consent
Where processing is based on consent, you have the right to withdraw your consent at any time. Withdrawal of consent does not affect the lawfulness of processing carried out before the withdrawal.
5. Your Rights Under GDPR
If you are located in the EEA, UK, or Switzerland, you have the following rights regarding your personal data:
GDPR Rights
Right of Access: You have the right to request a copy of the personal data we hold about you.
Right to Rectification: You have the right to request correction of inaccurate or incomplete personal data.
Right to Erasure (Right to be Forgotten): You have the right to request deletion of your personal data under certain circumstances.
Right to Restrict Processing: You have the right to request that we limit how we use your personal data.
Right to Object: You have the right to object to the processing of your personal data for certain purposes, including direct marketing.
Right to Data Portability: You have the right to receive your personal data in a structured, commonly used, and machine-readable format.
Right to Withdraw Consent: Where processing is based on consent, you may withdraw it at any time without affecting the lawfulness of prior processing.
Right to Lodge a Complaint: You have the right to lodge a complaint with a supervisory authority in your jurisdiction if you believe your data protection rights have been violated.
6. Your Rights Under CCPA / CPRA
If you are a California resident, you have the following rights under the CCPA and CPRA:
CCPA / CPRA Rights
Right to Know: You have the right to know what personal information we collect, use, disclose, and sell about you.
Right to Access: You have the right to request access to the specific pieces of personal information we have collected about you.
Right to Delete: You have the right to request deletion of your personal information, subject to certain exceptions.
Right to Correct: You have the right to request correction of inaccurate personal information.
Right to Opt Out of Sale or Sharing: You have the right to opt out of the sale or sharing of your personal information for cross-context behavioral advertising.
Right to Limit Use of Sensitive Personal Information: You have the right to limit the use and disclosure of your sensitive personal information.
Right to Non-Discrimination: You have the right not to be discriminated against for exercising your privacy rights.
Important Disclosure
We do not sell personal information as defined by the CCPA/CPRA. We do not share personal information for cross-context behavioral advertising purposes.
7. How to Exercise Your Rights
To exercise any of the rights described in this notice, you may contact us using the following methods:
Email: Support@PrimeStyleAI.com
Phone: +1 (949) 364-4449
We will respond to your request within the timeframes required by applicable law (generally within 30 days for GDPR and 45 days for CCPA/CPRA).
We may need to verify your identity before processing your request to ensure the security of your personal data. Verification may include confirming your email address, account information, or other identifying details.
8. Authorized Agents (California Residents)
If you are a California resident, you may designate an authorized agent to submit a request on your behalf.
To do so, you must provide the authorized agent with written permission to act on your behalf, and we may require you to verify your identity directly with us.
Proof of authorization (such as a signed written authorization or power of attorney) must be submitted with the request.
9. Data Retention
We retain your personal data only for as long as necessary to fulfill the purposes for which it was collected, including:
Providing and maintaining our services
Complying with legal obligations (e.g., tax, accounting, regulatory requirements)
Resolving disputes and enforcing our agreements
When personal data is no longer needed, we will securely delete or anonymize it in accordance with our data retention policies and applicable law.
10. International Data Transfers
Your personal data may be transferred to and processed in countries outside of your country of residence, including the United States.
Where we transfer personal data outside of the EEA, UK, or Switzerland, we ensure appropriate safeguards are in place, including:
Transfer Safeguards
Standard Contractual Clauses (SCCs): We use EU-approved standard contractual clauses to protect your data during international transfers.
Adequacy Decisions: Where the European Commission or relevant authority has determined that a country provides an adequate level of data protection, we may rely on that determination.
11. Automated Decision-Making & Profiling
We may use automated decision-making and profiling in connection with our AI-powered styling and virtual try-on features.
How We Use Automated Processing
Our AI tools generate personalized outfit visualizations and style recommendations based on your uploaded images, preferences, and usage patterns.
These automated processes are designed to enhance your experience and do not produce legal effects or similarly significant effects on you.
You have the right to request human review of any automated decision that significantly affects you. To request a review, contact us at Support@PrimeStyleAI.com.
12. Security Measures
We implement appropriate technical and organizational measures to protect your personal data against unauthorized access, alteration, disclosure, or destruction. These measures include:
Our Security Practices
Encryption: Data is encrypted in transit (TLS/SSL) and at rest where applicable.
Access Controls: Access to personal data is restricted to authorized personnel on a need-to-know basis.
Secure Cloud Infrastructure: We use reputable cloud service providers with industry-standard security certifications.
No Absolute Guarantee: While we strive to protect your personal data, no method of transmission over the Internet or electronic storage is 100% secure. We cannot guarantee absolute security.
13. Updates to This Notice
We may update this GDPR & CCPA Compliance Notice from time to time to reflect changes in our practices, legal requirements, or applicable regulations.
The "Last Updated" date at the top of this notice indicates the most current version. We encourage you to review this notice periodically.
Your continued use of our services after any updates become effective constitutes your acknowledgment of the updated notice.
14. Contact Information
If you have questions, concerns, or requests regarding this GDPR & CCPA Compliance Notice or our data practices, please contact us:
Business Name: PrimeStyleAI
Location: Laguna Niguel, California, USA
Email: Support@PrimeStyleAI.com
Phone: +1 (949) 364-4449
Need Help?
If you have questions about your data privacy rights or this compliance notice, please contact us:
PrimeStyleAI
Support@PrimeStyleAI.com
+1 (949) 364-4449
Laguna Niguel, California, USA
Response Time: We aim to respond to all data privacy requests within the timeframes required by applicable law (30 days for GDPR, 45 days for CCPA/CPRA).