Privacy Policy

Snap Matrix · Privacy Policy · v1.0 · effective 29 July 2026

FieldValue
OperatorTrexadoc OÜ
Company number17367549
Registered officeHarju maakond, Tallinn, Kesklinna linnaosa, Pärnu mnt 20, 10141, Estonia
Trading name / brandSnap Matrix
Websitehttps://snap-matrix.com
Contact emailinfo@snap-matrix.com
Support / complaintsinfo@snap-matrix.com
Governing lawLaws of the Republic of Estonia
Document versionv1.0
Effective date29 July 2026
Important: Trexadoc OÜ is the controller for personal data processed through Snap Matrix, except where a payment, authentication or other provider acts as an independent controller. We process only the data reasonably needed to operate the account-based AI image service, comply with law, secure payments and respond to users.
Who this policy applies to: This policy applies to visitors, registered users, purchasers, people who contact support, and individuals whose images or other personal data are submitted by a user. A user who uploads information about another person must have a lawful basis and must respect that person’s rights.

1. Introduction and scope

1.1 This Privacy Policy explains how Trexadoc OÜ collects, uses, discloses, stores and protects personal data in connection with snap-matrix.com, registered Accounts, one-off Token Pack purchases, generated digital photo content, customer support and related security operations.

1.2 It applies to information obtained directly from you, automatically from devices and interactions, from the Payment Provider and security partners, and from another user who lawfully submits your image or other information to the Service.

1.3 The Privacy Policy should be read with the Cookie Policy and the other Snap Matrix customer documents. It does not govern an external service that determines its own purposes and means of processing, even where that service is linked from the website.

2. Data controller and contact

2.1 Trexadoc OÜ, company number 17367549, is the controller for personal data used to operate Snap Matrix. Its registered office is Harju maakond, Tallinn, Kesklinna linnaosa, Pärnu mnt 20, 10141, Estonia.

2.2 Questions, rights requests and privacy complaints should be sent to info@snap-matrix.com. The same address serves as the operational privacy contact. We may request proportionate information to verify identity and prevent disclosure to an unauthorised person.

2.3 Payment providers, banks, identity services and certain platform operators may act as independent controllers for processing they determine, such as payment authorisation, anti-fraud scoring or regulatory reporting. Their notices apply to that separate processing.

3. Age position

3.1 Snap Matrix is intended only for people aged 18 or older. We do not knowingly offer Accounts or Token Packs to children and do not knowingly process a child’s image for account-holder purposes without an adequate lawful basis.

3.2 Users must not upload images of minors for sexualised, exploitative, deceptive or otherwise harmful purposes. Where an ordinary lawful family or creative use could involve a minor, the user must have parental authority or another valid legal basis and must apply heightened care.

3.3 If we learn that a person below the minimum age created an Account or that personal data was submitted unlawfully, we may suspend processing, restrict the material, request evidence of authority and delete data where retention is not required.

4. Categories of personal data

4.1 We process account and identity data, transaction data, technical and usage data, User Content, Generated Content, support communications, consent records and security information. The table below describes the principal categories and their ordinary sources.

4.2 We do not need a physical shipping address because the Service supplies digital products. A billing country, postcode or address may nevertheless be processed by the Payment Provider or passed to us in limited form for tax, authentication, fraud prevention or invoice requirements.

4.3 Uploads may contain faces, names, locations or other personal data. The Service is not designed for government identifiers, full payment-card data, medical records, passwords, authentication secrets or other information whose disclosure would create disproportionate risk.

CategoryExamplesSourcePurpose
Account dataName or display name, email, account ID, settings, login eventsYou; authentication serviceCreate and administer the Account; communicate; secure access
Transaction dataOrder ID, amount, currency, Token Pack, payment status, descriptor, refundsYou; Payment ProviderAuthorise and reconcile purchases; fulfil Orders; accounting; disputes
User ContentPrompts, uploaded images, style references, instructions and feedbackYou or an authorised userPerform requested generation; moderation; support; rights management
Generated ContentOutput images, thumbnails, generation parameters and delivery statusService operationDeliver results; maintain history; investigate quality or abuse issues
Technical dataIP address, device/browser details, timestamps, logs, cookie identifiersDevice and website interactionSecurity, troubleshooting, rate control, analytics with consent where required
Support dataMessages, screenshots, Order references, complaint and resolution historyYou; support channelsRespond, investigate, document outcomes and improve service quality
Compliance dataAge or identity check result, fraud indicators, sanctions or abuse flagsYou; providers; internal controlsPrevent fraud and harm; meet legal duties; enforce policies

5. Sources of personal data

5.1 Most personal data is provided when you register, purchase a Token Pack, submit a prompt or image, download content, choose settings, communicate with us or exercise a right.

5.2 We receive transaction confirmations, risk indicators and limited billing information from the Payment Provider and, where relevant, authentication or fraud-prevention vendors. We do not receive the full card number, card verification value or online banking credentials through the normal hosted checkout flow.

5.3 Technical information is generated when the browser or device communicates with the Service. Essential logs are collected to establish sessions, prevent attacks, diagnose failures, record fulfilment and preserve evidence of consent or account activity.

5.4 Another user may submit an image or other information concerning you. That user is responsible for having a lawful basis. We may contact the submitting user, restrict processing or respond to a rights request where an identifiable person raises a substantiated concern.

6. How we use personal data

6.1 We use personal data to register and authenticate users, maintain Token balances, accept and fulfil Orders, process generation requests, store or display results, provide support, issue refunds and communicate operational notices.

6.2 We use account, device, transaction and content signals to prevent unauthorised payments, detect compromised Accounts, enforce generation limits, moderate prohibited content, investigate abuse, protect systems and preserve evidence needed for disputes.

6.3 We use records to meet tax, accounting, consumer-protection, data-protection and lawful disclosure obligations. We may establish, exercise or defend legal claims, including responding to payment retrievals and chargebacks.

6.4 With the consent required by law, we may use analytics or marketing technologies to understand campaign performance and improve the website. We do not sell Token-buyer lists or disclose User Content for unrelated third-party advertising.

7. Lawful bases for processing

7.1 Under the General Data Protection Regulation, each processing activity must have a lawful basis. Contract is used where processing is objectively necessary to open an Account, fulfil a purchase or supply the requested digital service.

7.2 Legal obligation applies to accounting, tax, regulatory and valid authority requests. Legitimate interests support proportionate security, fraud prevention, service reliability, claim handling and limited internal improvement where those interests are not overridden by individual rights.

7.3 Consent is used for non-essential cookies, optional marketing and any processing that cannot appropriately rely on another basis. Consent can be withdrawn for future processing without affecting processing already carried out lawfully.

7.4 Where User Content contains special-category data, the submitting user must have an additional condition for processing. Snap Matrix does not invite special-category data and may reject or delete it when it is not necessary for a supported, lawful use.

Processing activityLawful basisNotes
Account registration and authenticationContractNecessary to create secure access and maintain entitlements
Token Pack purchase and fulfilmentContract; legal obligationOrder processing, delivery, invoicing and accounting requirements
Prompt and image processingContractLimited to performing the requested generation and related support
Fraud, abuse and security controlsLegitimate interests; legal obligation where applicableProtect users, payments, infrastructure and legal claims
Customer support and complaintsContract; legitimate interests; legal obligationResolve service issues and preserve a fair complaint record
Non-essential analyticsConsentActivated only after valid consent where required
Direct marketingConsent or permitted soft opt-inEvery marketing message provides an unsubscribe route
Rights requests and regulatory cooperationLegal obligationVerify and respond under applicable law

8. Payments and checkout

8.1 Payment details are entered into the checkout environment made available by the Payment Provider. The provider processes card or alternative-payment credentials, performs authentication and communicates the authorisation result to us.

8.2 We normally receive the payer name where supplied, billing country or postcode, Order amount, currency, payment method type, masked account details, transaction identifier, risk result, status, refund status and dispute information. These records support fulfilment and reconciliation.

8.3 The Payment Provider may use device, identity and transaction information for fraud prevention, strong customer authentication, legal compliance and network rules under its own privacy notice. We share only information reasonably required to request payment, identify the Order and prevent misuse.

8.4 Do not send full card information through email or support chat. If such information is received unexpectedly, we will restrict access and remove it where reasonably possible while retaining only what is required to document the incident.

9. Cookies and similar technologies

9.1 The website uses strictly necessary technologies for sessions, authentication, security, checkout continuity, load distribution and consent choices. These technologies are required for the requested service and do not depend on advertising consent.

9.2 Preference, analytics and marketing technologies are used only in accordance with the consent rules applicable to the visitor. The consent interface allows categories to be accepted or rejected and records the choice for a defined period.

9.3 The Cookie Policy provides the current category table, technology inventory, typical durations and controls. Browser deletion may remove a preference and cause the consent interface to appear again.

10. Sharing of personal data

10.1 We disclose personal data to service providers that perform payment processing, cloud hosting, content delivery, artificial-intelligence inference, authentication, security, fraud prevention, analytics, consent management, email delivery and customer support under contractual and confidentiality controls.

10.2 Information may be disclosed to banks, card networks, payment institutions and fraud-prevention participants where needed to authorise a transaction, process a refund, answer a retrieval, contest a chargeback or investigate unauthorised activity.

10.3 We may disclose information to professional advisers, auditors, insurers, competent authorities or courts where necessary for legal compliance, protection of rights or a legal claim. Requests are assessed for validity, scope and proportionality.

10.4 If the business or Service is reorganised, financed, sold or transferred, relevant data may be disclosed under confidentiality and transferred with the affected operation. Users will be informed where law requires notice or a new choice.

11. International transfers

11.1 Some providers may process personal data outside Estonia or the European Economic Area. A transfer is made only where a recognised adequacy decision, approved standard contractual clauses or another valid safeguard is available, unless a specific legal derogation applies.

11.2 We consider the destination, data type, purpose, recipient safeguards, access controls and legal environment. Additional measures may include encryption in transit, restricted administrative access, pseudonymous identifiers and minimisation of content retained by a provider.

11.3 A user may request information about the relevant safeguard and a copy of its material terms, subject to protection of confidential and security-sensitive information.

12. Data retention

12.1 We retain personal data for no longer than reasonably necessary for the purpose collected, including performance of the contract, security, complaint handling, tax and accounting obligations, and establishment or defence of legal claims.

12.2 Retention starts from the event shown in the table. A record may be kept longer where a dispute, legal hold, authority request or continuing security investigation requires it. When the reason ends, the record returns to the ordinary deletion schedule.

12.3 Deletion from active systems may be followed by limited retention in encrypted backups until the backup cycle expires. Backup copies are isolated from ordinary use and restored only for continuity or incident recovery.

Data categoryRetention periodTrigger / criterion
Account profile and settingsAccount life plus 3 yearsClosure or last account activity, for support and claim defence
Transaction, invoice and refund records7 years after the relevant financial yearEstonian accounting and tax record period
Token ledger and fulfilment evidence7 years after transactionReconciliation, consumer claims and payment disputes
Prompts, uploads and generated filesUp to 12 months after creation unless deleted soonerUser access, support and service continuity; longer only for an active dispute or abuse case
Security and access logsUp to 13 monthsDetection, investigation and prevention of security incidents
Support tickets and complaints3 years after closure of the matterQuality assurance and legal claim period
Consent records5 years after withdrawal or replacementDemonstrate the consent presented and choice recorded
Marketing suppression recordUntil objection is withdrawn or no longer neededPrevent further marketing to an opted-out address

13. Data security

13.1 We apply technical and organisational measures proportionate to the data and risk, including encrypted transport, access controls, credential protection, environment separation, monitoring, backups, supplier controls and procedures for security incidents.

13.2 No internet service can guarantee absolute security. Users must protect their email and Account credentials, use secure devices, avoid sharing access, review unusual notifications and report suspected compromise promptly.

13.3 Access to User Content and transaction records is limited to personnel and providers with a role-based need. Sensitive support material should be minimised, and staff access may be logged and reviewed.

13.4 Where a personal-data breach creates a risk to individuals, we assess containment, notification to the Estonian Data Protection Inspectorate within the applicable period, and communication to affected individuals where the risk is high.

14. Your privacy rights

14.1 Subject to applicable conditions, you may request access to personal data, correction of inaccurate data, deletion, restriction, portability of data supplied under contract or consent, and objection to processing based on legitimate interests or direct marketing.

14.2 You may withdraw consent at any time through available settings or by contacting us. Withdrawal does not invalidate earlier processing. Some features may cease where the requested processing is objectively necessary to provide them.

14.3 A request should identify the Account, the right exercised and the relevant data. We may ask for reasonable verification and clarification, especially where User Content concerns more than one person or disclosure could affect another person’s rights.

14.4 We respond without undue delay and ordinarily within one month. That period may be extended by up to two further months for a complex or numerous request, in which case we will explain the extension within the first month.

14.5 You may complain to the Estonian Data Protection Inspectorate or another competent supervisory authority, particularly in the country of habitual residence, work or the alleged infringement. Court remedies remain available.

15. Marketing communications

15.1 Operational messages about security, Orders, refunds, policy changes or Account status are not marketing and may be sent where necessary to perform the contract or comply with law.

15.2 Promotional email is sent only with consent or another lawful basis permitted for existing customers. Each message identifies the sender and includes an effective unsubscribe mechanism.

15.3 An unsubscribe request stops future promotional messages within a reasonable period but does not remove transaction records or prevent essential service communications. We retain a minimal suppression record to respect the choice.

16. Automated decision-making and profiling

16.1 Automated tools may assess payment risk, device anomalies, generation requests, rate limits and prohibited-content signals. They may delay an Order, request additional authentication, block a prompt or flag an Account for review.

16.2 We do not intend to make decisions producing legal or similarly significant effects solely by automated means where the General Data Protection Regulation restricts that practice. A Payment Provider may make its own authorisation or fraud decision under its notice.

16.3 Where a decision materially restricts access and a review is appropriate, you may contact support, explain the circumstances and provide relevant information. We may uphold the restriction where necessary for law, security or protection of third-party rights.

17. Third-party services and links

17.1 The Service may link to payment, authentication, social, storage or other external services. A link does not mean that Trexadoc OÜ controls the external service’s processing, security or content.

17.2 Review the external privacy notice before providing data. Where an external provider acts on our instructions, we remain responsible for selecting and contracting that processor; where it acts independently, it is responsible for its own processing.

17.3 Do not use an external sharing feature for Generated Content containing another person’s data unless you have authority and have considered the destination service’s visibility and retention settings.

18. Changes to this policy

18.1 We may update this policy to reflect changes in law, providers, technology, data uses or user rights. The version and effective date identify the current text.

18.2 Material changes are communicated through the website, Account or email where appropriate. If a new purpose requires consent, we will seek consent before relying on it.

18.3 Earlier versions may be retained for accountability. The current published version governs processing from its effective date, while the legality of earlier processing is assessed under the notice and law applicable at that time.

19. How to contact us or submit a request

19.1 Send privacy requests to info@snap-matrix.com and state “Privacy Request” in the subject. Include the Account email, the right requested and enough detail to locate the data, but do not send passwords, authentication codes or full payment-card data.

19.2 Written notices may also be addressed to Trexadoc OÜ at Harju maakond, Tallinn, Kesklinna linnaosa, Pärnu mnt 20, 10141, Estonia. We may respond electronically unless another method is required or reasonably requested.

19.3 If the request concerns an image uploaded by another user, describe the image, where it appears and the basis of your concern. We may need to balance access, expression, contractual and third-party rights before deciding the appropriate action.

20. Schedule 1 – Practical Retention Guide

20.1 Closing an Account removes ordinary access but does not immediately erase every record. Transaction and invoice data remain for the seven-year accounting period, while support, security and claim records follow the periods stated above.

20.2 Deleting a generated image from the Account removes it from ordinary display and begins deletion from active storage. A limited copy may remain temporarily in backup or be preserved for an active abuse, payment or rights investigation.

20.3 Withdrawing marketing consent stops promotional use; it does not cancel an Order or delete necessary transaction data. Withdrawing optional cookie consent prevents future activation of those categories and can also remove non-essential identifiers from the browser.

20.4 A verified rights request is tracked to completion. The response identifies action taken, data withheld under a lawful exception, recipients notified where required, and the route for complaint if the user disagrees.

Snap Matrix · Privacy Policy · v1.0 · effective 29 July 2026. This version applies from the effective date and supersedes earlier versions for future use.

Prev
Next
cart (0 items)