This Privacy Policy explains how Threadmind AI Limited (“Threadmind AI”, “we”, “us”, “our”), the operator of the ViZO Studio platform (“ViZO”, the “Service”) at www.vizostudio.ai, collects and uses personal data, and your rights under UK data protection law.
We are the data controller for the personal data described in this policy except where we act as a processor on a customer’s behalf (see clause 6).
Company: Threadmind AI Limited, registered in England and Wales, company number 17218646.
Registered office: Xeinadin South East Limited, Office 5, Rayleigh Road, Hutton, Brentwood, Essex, England, CM13 1AB.
Privacy contact / data protection enquiries: support@vizostudio.ai
General/sales contact: sales@vizostudio.ai; support: support@vizostudio.ai
ICO registration number: [ICO REGISTRATION NUMBER].
We process personal data in accordance with the UK GDPR, the Data Protection Act 2018 (“DPA 2018”), and the Privacy and Electronic Communications Regulations (“PECR”).
This policy applies to: (a) visitors to our website; (b) customers and their authorised users who register for and use the Service; and (c) individuals depicted in content processed through the Service, including any person who is the subject of a Digital Twin. Where you are our customer and you upload content containing other people’s personal data, please read clause 6, which explains our respective roles.
We collect the following categories of personal data:
(a) Account and contact data — name, business email, employer/brand, job title, username, password (stored in hashed form), and preferences.
(b) Billing and payment data — billing name and address, VAT details, and payment-method details (card details are handled by our payment processor; we do not store full card numbers).
(c) Input Content — the garments, product images, flat-lays, ghost-mannequin and on-model shots, prompts, briefs and references you upload. Input Content may contain images of real people, which is personal data.
(d) Digital Twin data — facial and bodily imagery of a real, identifiable individual (you or a member of your own staff). This may include biometric data, which is special category data under UK GDPR Article 9 (see clause 8).
(e) Output — the images (1K, 2K or 4K imagery) and video and other creative assets generated for you.
(f) Usage, technical and device data — IP address, device and browser type, operating system, pages viewed, actions taken, timestamps, and diagnostic/log data.
(g) Cookies and browser-storage data — see clause 9.
(h) Contact-form and enquiry data — the name, email, company and message you submit through our website contact form (processed via a third-party form provider — see clauses 9 and 10).
(i) Communications and marketing data — your contact details, marketing preferences, and records of your communications with us.
We collect personal data: (a) directly from you when you register, subscribe, upload content, contact us or use the Service; (b) automatically through cookies, browser storage and server logs; and (c) from third parties such as our payment processor.
We process personal data only where we have a lawful basis under UK GDPR Article 6 (and, for special category data, a condition under Article 9 — see clause 8).
| Purpose | Data used | Lawful basis (UK GDPR) |
|---|---|---|
| Create/administer account; provide Service; generate Output | Account, Input Content, Output, usage | Contract (Art. 6(1)(b)) |
| Process payments, billing, collect fees | Billing/payment data | Contract; legal obligation for tax records (Art. 6(1)(c)) |
| Respond to enquiries and support; contact form | Account, contact-form data, communications | Contract and/or legitimate interests (Art. 6(1)(f)) |
| Secure the Service; prevent fraud/abuse; moderation | Account, usage, Input Content/Output | Legitimate interests; legal obligation where reporting required |
| Improve the Service using anonymised data only (we do NOT train AI models on customer content — clause 7) | Aggregated, de-identified data | Legitimate interests (Art. 6(1)(f)) |
| Operate/improve via aggregated, anonymous data | Aggregated/de-identified data | Legitimate interests (Art. 6(1)(f)) |
| Create and process a Digital Twin | Digital Twin / biometric data | Contract + explicit consent of subject (Art. 9(2)(a)) |
| Service messages (billing, security, changes) | Account, contact data | Contract / legitimate interests |
| Marketing (where permitted) | Contact, marketing data | Consent or legitimate interests, subject to PECR and opt-out |
| Website analytics, ad measurement and remarketing (Google Analytics & Google Ads) | Usage/technical data, online identifiers and cookie IDs | Consent (Art. 6(1)(a)); consent under PECR for the cookies |
| Comply with law; establish/defend claims | Any relevant data | Legal obligation; legitimate interests |
For website data, account, billing, usage and contact-form data, we act as a controller. For personal data contained within your Input Content and any Digital Twin, you (the customer) are the controller, and we act as your processor, processing it on your documented instructions. Our processor obligations (UK GDPR Article 28) are set out in our Terms of Service and any separate Data Processing Agreement. As controller, you are responsible for having a lawful basis and any necessary consents for the people depicted in your uploads and Digital Twins.
We do not use your Input Content or Output to train our AI models. Developing and training our AI models does not rely on your content.
We may use aggregated, de-identified and anonymous data — which does not identify you, any individual, or your content — to operate, secure, analyse and improve the Service. Our use of anonymous data does not affect your ownership of the Output under our Terms of Service.
The Digital Twin feature creates a synthetic likeness of a real, identifiable individual — restricted under our Terms to yourself or a member of your own staff (aged 18+). This processing may involve biometric data, which is special category data under UK GDPR Article 9.
Conditions for processing. We rely on an Article 6 basis (performance of our contract with the customer) and, separately, on the explicit consent of the individual depicted under Article 9(2)(a). Explicit consent must be a clear, specific, freely given, opt-in statement that identifies the nature of the special category data and is separate from other consents.
Customer responsibility. As controller of the Digital Twin subject’s data, the customer is responsible for obtaining and recording that explicit consent before a Digital Twin is created, and for not using the feature on anyone other than themselves or consenting staff.
Withdrawal and erasure. The individual may withdraw consent at any time; on withdrawal, the customer must stop using and, where practicable, delete the relevant Output, and may request erasure of the underlying data.
DPIA and safeguards. Because this is potentially high-risk processing of biometric/special category data, we will carry out a Data Protection Impact Assessment (DPIA) and maintain an appropriate policy document where required and apply heightened security to this data.
We do not sell personal data. We share it only with:
(a) Service providers / sub-processors, under contract and only as needed, including: Tom & Co. Ltd. (company no. 07557895), a UK-based provider that builds, hosts and operates the ViZO platform (app); Cloudflare, Inc., which hosts the ViZO marketing website (United States); Stripe Payments UK Ltd, which processes subscription payments (United Kingdom); Web3Forms, which receives the name, email, company and message you submit through the website contact form (United States); Microsoft (Microsoft 365 / Microsoft Ireland Operations Ltd.), which hosts our email (European Union); and Google (Google Ireland Ltd., Ireland, and Google LLC, United States), which provides the Google Analytics and Google Ads cookies described in clause 9 — set only with your consent — to measure website traffic and advertising performance and to deliver remarketing.
(b) Professional advisers (lawyers, accountants, auditors) under confidentiality.
(c) Authorities, regulators or law enforcement where required by law, or to report unlawful content (for example, CSAM).
(d) A buyer or successor in connection with a merger, acquisition or sale of assets, under appropriate confidentiality.
A current list of sub-processors is available on request.
Some recipients are located outside the UK — in particular Cloudflare, Inc., Web3Forms and Google LLC (United States), and Microsoft 365 and Google Ireland Ltd. (European Union). Where we transfer personal data outside the UK, we use an appropriate safeguard, such as transfer to a country covered by UK adequacy regulations, the UK International Data Transfer Agreement (IDTA), or the UK Addendum to the EU Standard Contractual Clauses, together with any necessary supplementary measures. You can ask us for details of the safeguard used.
We keep personal data only as long as necessary for the purposes above, then delete or anonymise it.
| Data | Typical retention |
|---|---|
| Account data | Life of the account, then e.g. 12 months after closure unless longer required |
| Billing/tax records | 6 years (UK tax/accounting requirements) |
| Input Content & Output on the Platform | Life of account or per plan; deleted a reasonable period after closure (export first — you own your Output) |
| Digital Twin data | Only while consent is valid and the twin is in use; deleted promptly on withdrawal/erasure |
| Contact-form enquiries | e.g. 24 months from last contact |
| Usage/log data | e.g. 12–24 months |
| Marketing data | Until you opt out, then suppression-list only |
We implement appropriate technical and organisational measures to protect personal data, including encryption in transit, access controls, and least-privilege access. Special category data (Digital Twins) is subject to heightened safeguards. No system is completely secure; we will notify you and/or the ICO of a personal data breach where required by law.
Under UK GDPR you have the right to: access your data; request rectification; request erasure; restrict processing; data portability; object to processing (including to legitimate-interests processing and to direct marketing); and withdraw consent at any time where we rely on consent (including Digital Twin consent). You also have rights regarding automated decision-making (see clause 15).
To exercise any right, contact support@vizostudio.ai. We will respond within one month (extendable for complex requests). Where the personal data sits inside a customer’s account as Input Content or a Digital Twin (so the customer is controller), we will refer your request to that customer and assist them as their processor.
You have the right to complain to the Information Commissioner’s Office (ICO) — ico.org.uk, helpline 0303 123 1113 — though we ask that you contact us first so we can help.
We do not make decisions producing legal or similarly significant effects about you based solely on automated processing. The Service generates images from your inputs; this is content generation, not automated decision-making about individuals.
The Service is intended for businesses and users aged 18 or over. It is not directed at children, and we do not knowingly collect children’s personal data. The Digital Twin feature must not be used to depict anyone under 18.
We may update this policy from time to time. We will post the updated version with a new “Last updated” date and, for material changes, give reasonable notice (for example, by email or in-product notice).
For any privacy question, request or complaint: Threadmind AI Limited — Xeinadin South East Limited, Office 5, Rayleigh Road, Hutton, Brentwood, Essex, England, CM13 1AB. — support@vizostudio.ai. You may also complain to the ICO at ico.org.uk.