1. Who is responsible
Pacyra is operated by Nymiva, a sole trader established in Belgium, which is the data controller for account, support and commercial data. Privacy requests can be sent to support@pacyra.com.
2. Data that stays on your device
Source photographs, pixels, filenames, EXIF data, thumbnails, value maps, edge maps, adaptive geometry, painterly patches, projector images, calibrations and exported files are processed in browser memory. Object URLs, workers and buffers are released when you clear the guide, replace the photo or close the tab. Generated guides are not saved as account data.
Ordering a printed canvas is the one exception to that, and adding a canvas to your cart is the act that starts it. The line above that button says what pressing it does, nothing is drawn or uploaded before it is pressed, and the moment you press it is recorded on the order. On that press the browser draws two files from the guide you already have, the print file that goes on the canvas and your coloured painting guide, and uploads those two files to private storage. Both are drawn from the simplified shapes, numbers and palette of the guide rather than copied from the photograph, so they carry none of its pixels, its filename or its camera data, although a simplified picture of the same subject is of course visible in them. Only the print file goes any further than that storage, to the printing partner when the order is paid for. The painting guide stays there for you to download. The photograph itself is never uploaded, and neither Pacyra nor the printing partner ever receives it. Section 5 says who then sees the two files, and section 6 says how long they are kept.
Do not send private source photographs to support. Pacyra cannot retrieve a guide that existed only in your browser tab.
3. Data we process
Depending on the features used, we process account ID, email, profile name, timezone, consent choices, authentication events, plan, quota counters, photo passes, the credit ledger, Stripe identifiers and status, purchase amount and currency, non-image preset settings, support messages and limited structured logs.
For abuse prevention, request rates are counted against a salted one-way hash of the network address. The raw address is not kept in those counters, and the counters expire automatically. A bot-protection check by Cloudflare Turnstile runs on sign-in, registration, checkout, contact and photo unlock requests.
A printed canvas order adds the order itself and what is needed to make it and post it. That means the canvas ordered, the destination country, the amounts charged, the delivery name, address and telephone number that Stripe collects at the till, the two files described in section 2, and the record of the order moving through review, production and delivery.
- We do not store card details. Stripe handles payment information.
- A photo pass stores a random pass ID and a non-reconstructive hash of the photo file. It never stores the photograph or artwork geometry.
- Analytics, when enabled, excludes image subjects, palettes, canvas dimensions, region counts and projector coordinates.
4. Purposes and legal bases
Account and purchase processing is necessary to provide the service and perform a contract. Security, abuse prevention, service reliability and limited operational measurement rely on legitimate interests where applicable. Optional analytics, advertising and marketing run only after the required consent. Legal retention may be required for financial records.
5. Service providers
Supabase provides authentication and the account database, hosted in the European Union. Stripe provides checkout, billing, receipts and tax handling. Cloudflare provides hosting, content delivery, bot protection, message queues and cookieless visit counting. Resend delivers transactional email. Google provides advertising through AdSense on the public pages, and never in the studio. Supabase, Stripe, Cloudflare, Resend and Google each process data under a data-processing agreement, and none of them ever receives your photographs. Only the two providers named next ever receive artwork, and only for a printed canvas you asked us to have made.
Two more names appear for printed canvas orders and for nothing else. The first is Cloudflare again, whose R2 storage holds the print file and the painting guide in a private bucket that has no public address, under the same agreement as the rest of what Cloudflare does for us. Your own download of the guide is checked against your account, and the only other people who see the print file are the reviewer who checks it prints well and the printer who makes the canvas.
The second is PrintKK, which manufactures the canvas and posts it. When an order has passed review and is sent for production, PrintKK receives the print file, the delivery name and address, the telephone number where you gave one, the email address the order was placed with, and the order's own reference number, because a parcel and its tracking cannot be addressed or traced without them. PrintKK never receives your source photograph, your card or payment details, or anything else about your account. PrintKK prints in the United States, Hong Kong and Japan, so sending an order there is a transfer outside the European Economic Area. It is made under Article 49(1)(b) of the GDPR, which permits a transfer that is necessary to perform the contract you asked for, and it carries only what that one canvas needs. We do not claim standard contractual clauses for that transfer, and this notice says so rather than implying a safeguard that is not in place. PrintKK is a manufacturer we buy from rather than a hosting, payment or email provider, and whether the terms we buy on amount to a data-processing agreement in the sense Article 28 of the GDPR means is being settled before printed canvases go on sale. Saying that is better than implying an agreement we cannot point to.
Google gathers advertising consent itself, through the certified consent message it requires of publishers in Europe, so its tag loads on pages that can carry advertising in order to ask the question, and no advertisement is served before it has been answered. Nothing loads at all on a page that carries no advertising, or for a Pro subscriber. When it does run, Google receives the ordinary information any website visit reveals to an embedded provider, such as your network address, your browser and the page being viewed, together with any advertising cookies you have consented to. It never receives your photograph, the guide made from it, its palette, its region counts or its canvas size. Pro subscribers are never shown advertising, so nothing about their browsing reaches Google through Pacyra.
6. Retention
Profile and preset data remains while the account is active. Records of sent transactional emails and processed payment events are deleted after 90 days. Closed support requests are deleted after 12 months. Rate-limit counters expire within hours.
A printed canvas order keeps its print file and its painting guide in private storage until 90 days after the order is delivered, and a scheduled job then removes them from the bucket. That job runs hourly rather than instantly, and where an individual file refuses to delete the failure is recorded so it can be finished by hand, so a file can outlive its window by a short period. An order that is started and never paid for loses its files sooner, after 48 hours, or after 30 days where a payment page was opened and a slow payment method could still settle. That 90 days is an operational setting rather than a fixed term, and this notice is updated if it changes. An order under a legal hold, which happens where a dispute, an investigation or a legal obligation requires the records to be kept, is left out of all of that until the hold is lifted. The order record itself, its delivery address and its financial entries follow the accounting retention described below.
The append-only financial ledger is retained for the statutory accounting period that applies in Belgium, typically seven years, even after account deletion. When you delete your account, the profile is anonymised, the sign-in email is released so it can be used again, and the retained ledger no longer links to a usable identity.
7. Your choices and rights
The account page provides marketing consent controls and immediate account deletion. Ask us at support@pacyra.com for a structured copy of your data and we will prepare it by hand and send it to you, within one month and normally within a few days. Under the GDPR you may also request access, correction, deletion, restriction, portability or objection at that address, and you may complain to a supervisory authority. For Belgium that is the Data Protection Authority (Gegevensbeschermingsautoriteit).
8. Wherever you are
Pacyra is sold worldwide and this notice applies to everyone who uses it. It is written to the General Data Protection Regulation, which sets the strictest standard we are aware of, and we apply that standard to every account rather than only to those in Europe. We do not ask where you live before answering a request.
That means the choices described above are yours wherever you are. You can see what is held about you, take a structured copy of it, correct it, withdraw a consent you have given, object to processing that relies on legitimate interests, and delete your account outright. Deletion is immediate and lives on the account page, so it never waits on us. A copy of your data is prepared by hand when you ask for it, which is slower but is answered within the month the law allows and usually within a few days.
We do not sell personal data for money. Advertising may be personalised where you have allowed it, through the consent tools described above, and Google presents and honours the equivalent controls to visitors in United States jurisdictions that require them, including the signals some browsers send on a visitor's behalf.
Some national laws impose additional duties once a business reaches a certain size, and the California Consumer Privacy Act is the best known of them. Pacyra is run by a sole trader and is far below every revenue and volume threshold those laws set, so they do not currently apply to it. If that changes we will say so here rather than quietly rely on it, and in the meantime the rights above are available to you regardless.
9. Security and international transfers
Pacyra uses encrypted transport, least-privilege database policies with row-level isolation between accounts, signed payment webhooks, rate limits and server-side authorisation for every purchase and export decision. No internet service is risk-free. Where a provider processes limited data outside the European Economic Area, the transfer relies on that provider’s European data-processing terms, including standard contractual clauses. Advertising through Google involves processing in the United States on that basis, which is one reason it is asked for separately and never assumed.
The printing partner in section 5 is the deliberate exception to that sentence. Sending a canvas to be made in the United States, Hong Kong or Japan is necessary to perform the order you placed, and that necessity is what the transfer rests on rather than standard contractual clauses. It carries the print file and the delivery details and nothing else, and it happens only for an order you asked for.
10. Children and classrooms
The commercial service is not directed at children acting independently. Schools and facilitators must determine an appropriate legal basis, obtain required permissions and avoid entering unnecessary personal data.
11. Changes and contact
Material changes will be dated and communicated where required. Use the contact page for privacy requests once the final operator details are published.