hum8le.io

Legal

Privacy Policy

This policy explains what personal data hum8le.io processes, why we process it and how long we keep it.

Last updated 1 August 2026

01

Who we are

hum8le.io operates an enterprise material visualization platform for furniture manufacturers, architects and design studios. We act as the data controller for account data and as a data processor for imagery you upload for transformation.

Privacy questions can be sent through the contact page at any time.

02

Data we collect

Account data: first name, last name, email address and a hashed password. Order data: number of credits purchased, currency, promo code, chosen payment method and payment status. We never store full bank or card numbers.

Project data: images, material samples and metadata you upload in order to generate transformations, together with the outputs produced from them.

Technical data: IP address, browser type, device type and pages visited, collected through essential and optional cookies.

03

Why we process it

To create and secure your account, to fulfil credit orders and issue invoices, to run the transformations you request, to provide support, to detect abuse and fraud and to comply with accounting and tax obligations.

04

Legal bases

Performance of a contract for account and order data, legitimate interest for security and service improvement, consent for optional analytics cookies and marketing messages, and legal obligation for financial records.

05

Retention

Account data is retained while your account is active and for 12 months afterwards. Uploaded imagery and generated outputs are retained for 24 months unless you delete them earlier. Invoices and payment records are retained for the statutory period required by applicable accounting law.

06

Sharing and subprocessors

We share data only with subprocessors necessary to run the service: cloud hosting and GPU rendering infrastructure, email delivery, and payment and banking providers. All subprocessors are bound by written data processing agreements. We never sell personal data.

07

International transfers

Where data is processed outside the European Economic Area, transfers are covered by Standard Contractual Clauses together with supplementary technical measures such as encryption in transit and at rest.

08

Your rights

You may request access, rectification, erasure, restriction, portability or object to processing, and you may withdraw consent at any time. Requests are answered within 30 days. You also have the right to lodge a complaint with your local supervisory authority.

09

Security

Access to production systems is restricted and logged, passwords are stored hashed, and data is encrypted in transit and at rest. We review access rights and infrastructure configuration on a recurring schedule.

10

Changes to this policy

Material changes are announced by email to account holders and reflected in the "last updated" date at the top of this page.

Begin

See Every MaterialBefore It's Built