1. Controller and scope
Niklas Koeder, operating Visutta, is the controller for account, website, billing, security and service-administration data. Contact support@visutta.com. Service address: [STREET, NUMBER, POSTCODE, CITY, GERMANY — TO BE COMPLETED]. The legal form, telephone and applicable registration details remain placeholders in the Legal Notice.
This notice covers the website, Studio and Pro interfaces, applications, generation, billing, collaboration and support. A business customer can be a separate controller for personal data it places in a workspace; where Visutta acts solely on that customer's instructions, the applicable processing agreement governs that processor relationship. This notice does not replace an Article 28 agreement.
Competent lead/regional supervisory authority: [TO BE IDENTIFIED FROM THE CONFIRMED ESTABLISHMENT]. You can still complain to a supervisory authority in your habitual residence, place of work or the place of an alleged infringement. Contact support for privacy requests and any applicable data-protection-officer contact.
2. Personal data we process
Account and authentication data
Name or display name, email address, password hash, account identifier, Google sign-in identifier if used, authentication method, session identifiers and token-verification data, session timestamps, IP address, user agent, and security events. We record the Terms version you accept, the Privacy Policy version you acknowledge, the time and method, and email-verification status.
Project and Customer Content
Scripts, prompts, production notes, project memory, reference images, video and audio, generated output, edits, timelines, comments, model settings, file metadata, workspace membership, and collaboration history. This material can contain personal data about you or other people.
Optional camera, microphone and motion features
Virtual-camera tracking uses camera frames and available motion information when you start the feature and grant the required browser permissions. The tracking engine derives camera position, orientation, field of view and tracking status; Visutta relays pose, timing, scene state and commands between paired devices. Pairing and transport state currently expire after 30 minutes unless refreshed. Saved takes and uploaded recordings become project content. Microphone recordings are captured after you choose recording; submitting a voice recording uploads it for the requested workflow. Stop the feature or revoke browser permission to stop further capture.
AI job and usage data
Selected models and providers, request settings, references, job and prediction identifiers, queue state, timestamps, status and error events, output metadata, credit estimates, reservations, settlements, refunds, provider cost, and technical traces needed to operate and debug a job.
Billing and plan data
Plan, billing interval, credit balance and events, team pool and limits, Stripe customer, checkout, subscription, and transaction identifiers, invoice status and PDF links, invoice-email delivery records, tax and billing information returned by the payment provider, and fraud or chargeback information. Visutta does not normally receive full card numbers or card security codes.
Communications and support
Emails, support requests, feedback, cancellation and withdrawal declarations, immutable receipt timestamps, delivery/retry records, legal or rights requests, attached material, and the records needed to investigate and respond.
Referrals and workspace administration
Referral code, referring and referred account identifiers, attribution time, eligibility, first qualifying subscription and one-time credit reward status. Team owners can create managed accounts and set role permissions; we process those details, invitations, memberships and shared usage records. Referral attribution does not give the referrer access to your prompts, media or payment-card details.
Website and device data
Requested path, request ID, IP address, user agent, response status and timing, rate-limit events, site-gate status, interface preferences, locally cached drafts, and other data stored on your device as described below.
3. Sources of data
- directly from you when you register, upload, prompt, edit, pay, or contact us;
- from team owners, administrators, and collaborators who invite or mention you;
- from Google when you choose Google sign-in;
- from Stripe when you start, change, or cancel a paid plan or purchase credits;
- from AI providers when they return job status, output, moderation, or error data;
- automatically from browsers, applications, servers, security controls, and infrastructure.
4. Purposes and legal bases
| Purpose | Typical data | Legal basis under GDPR |
|---|---|---|
| Provide accounts, workspaces, generation, storage, collaboration, export, and support | Account, Customer Content, project, job, and communication data | Art. 6(1)(b) for a contracting individual; Art. 6(1)(f) for necessary business-contact administration, or the customer's instructions where we are a processor |
| Process plans, credits, invoices, refunds, and accounting | Billing, plan, wallet, and transaction data | Contract, Art. 6(1)(b), and legal obligations, Art. 6(1)(c) |
| Protect users, tenants, media, providers, and infrastructure | Sessions, IP, device, logs, abuse and security events | Legitimate interests in secure and reliable operation, Art. 6(1)(f), and legal obligations where applicable |
| Debug failures, improve reliability, measure usage and unit economics | Job status, errors, model settings, cost and performance metrics | Contract and legitimate interests in operating and improving the Service, Art. 6(1)(b) and (f) |
| Handle legal claims, rights requests, takedowns, and compliance | Account, content, communications, logs, and claim records | Legal obligations and legitimate interests, Art. 6(1)(c) and (f) |
| Optionally remember a referral for 30 days | Referral code stored in an optional cookie | Consent, Art. 6(1)(a), which can be withdrawn prospectively |
| Attribute a referral and prevent duplicate or abusive rewards | Referral/account links, qualifying purchase and reward records | Art. 6(1)(f), our legitimate interest in operating a limited, auditable referral programme; optional device persistence separately requires consent |
Account email, authentication information and explicit Terms acceptance are needed to create an account. Requested prompts or references are needed for the selected generation; billing information is needed for a purchase and applicable tax duties. You can omit optional profile details, Google sign-in and referral persistence. Refusing those optional choices does not prevent ordinary password signup.
A contract with an uploader is not automatically a legal basis for processing every depicted person's data. Such processing requires its own lawful basis and, for special-category data, a relevant Article 9 condition. We assess our own controller obligations separately from the customer's duties.
Where we rely on legitimate interests, we consider necessity, your reasonable expectations, impact, and available safeguards. You may object as described in the rights section.
5. AI and provider processing
To perform a requested generation or director task, Visutta sends the prompt, selected references, requested settings, and necessary technical metadata to the provider used by that model. A linear or director pipeline may send different stages to different providers. Job history records the selected model, settings and references; it is not a promise that every internal provider-processing step is visible.
Visutta does not use Customer Content to train a Visutta-owned general-purpose model. External providers process submitted material under their API or business terms and configured data controls. Their retention and use can differ, so do not submit secrets or personal data that are not necessary for the requested output.
Signing in with Google is optional. Its sign-in interface is loaded after you choose it, and Google supplies the verified account identifier and profile information used for sign-in. Provider brand names below identify integrations; the contracted legal entities, processing countries and provider retention settings still require verification in our supplier register.
| Provider or category | Use in Visutta | Data typically sent |
|---|---|---|
| OpenAI | Director language processing and image generation | Prompts, scripts, references, settings, and request metadata |
| Optional sign-in and selected image models | Sign-in credential, or prompts, references, and model settings | |
| ByteDance / BytePlus ARK | Seedream image and Seedance video generation | Prompts, image or video references, media settings, and task metadata |
| Kling / Kuaishou, including Replicate when that route is selected | Selected video generation models | Prompts, frames, settings, and task metadata |
| MiniMax | Hailuo video generation and optional prompt expansion | Prompt, selected frames/references, settings and task metadata |
| Visutta processing workers, including configured LTX models | Generation within the configured infrastructure; a model author is not automatically a recipient of your data | Prompt, selected keyframes, settings and task metadata |
| ElevenLabs | Speech, voice design, and consented voice cloning | Text, voice settings, language, and voice samples where requested |
| Configured music provider | Music generation | Lyrics or prompt, style, title, settings, and task metadata |
6. Recipients and disclosure
We disclose personal data only where needed to:
- use the AI and authentication providers described above;
- process payment through Stripe;
- host compute, PostgreSQL/Redis data and backups with our infrastructure providers [CONTRACTED ENTITIES AND LOCATIONS TO BE COMPLETED], use Cloudflare/R2 for object storage and delivery, and IONOS/configured email services for transactional messages;
- deliver protected media through Cloudflare;
- make shared content and team usage visible to the team owner and authorized members according to their permissions. Independent personal workspaces remain separate; owner-created managed accounts operate only inside their team;
- obtain professional legal, accounting, security, or technical support under confidentiality;
- comply with law, protect rights and safety, or establish and defend legal claims;
- complete a corporate transaction subject to appropriate safeguards.
We do not sell personal data and do not use third-party behavioral advertising analytics in the current pre-release website.
7. International transfers
Model, authentication, payment and infrastructure providers may process data outside the EEA, including through international support and subprocessors. The destination depends on the contracted entity, API route and region. Provider brands alone do not establish where processing occurs.
Transfers requiring a Chapter V GDPR safeguard must have a valid mechanism, such as an applicable adequacy decision or Standard Contractual Clauses with the necessary assessment and supplementary measures. We do not treat accepting these Terms or acknowledging this notice as consent to unrestricted transfers.
Outstanding disclosure: [FOR EACH PROVIDER: CONTRACTED ENTITY, COUNTRIES, PROCESSOR/CONTROLLER ROLE, ACTUAL TRANSFER BASIS AND SAFEGUARD ACCESS — TO BE COMPLETED]. The supplier-contract review remains incomplete. Contact support for information or copies of applicable safeguards with protected details redacted; this draft does not certify that every provider's contractual arrangement has been verified.
8. Retention
We retain personal data only for as long as needed for the purpose, contract, security, legal obligation, or claim. We use the following criteria and current operational defaults:
- Account and workspace data: while the account or workspace is active and afterward only as needed to complete deletion, resolve disputes, prevent fraud, or meet legal obligations.
- Projects and media: until deleted through available controls or an account-deletion request is completed, subject to shared workspace rights, legal holds, and rolling backups.
- Sessions: the account session cookie currently has a maximum age of 30 days; browser sessions also expire after seven days of inactivity under the current policy and may be revoked earlier. Email-verification challenges ordinarily expire after ten minutes. Server-side security records can remain longer where needed to investigate abuse.
- Generation and pipeline records: retained to show job state, references, output, billing, and trace history. Duration depends on ongoing project use, billing evidence and any unresolved provider or support issue. An available 90-day pipeline-pruning default is not a guaranteed deletion deadline for all job data.
- Temporary voice-clone uploads: removed from the private temporary job directory after the job succeeds or fails. A saved voice identity or output remains until deleted or otherwise no longer needed.
- Billing and tax records: retained for the periods required by applicable commercial and tax law. Under ordinary German rules, invoices and accounting vouchers are generally kept for eight years from the end of the relevant year, books for ten years and business correspondence for six; exceptions or proceedings can require longer retention. These duties do not justify keeping all creative media for those periods.
- Backups and logs: operational and release backups can outlast live deletion. A maximum rotation/deletion schedule and log retention remain [TO BE CONFIRMED]; no fixed automatic purge is promised here. Restored data must remain subject to recorded deletion requests. Retention must be limited to a documented need, including specific legal holds.
- Legal declarations and assent: retained as necessary to evidence the contract, statutory duties and associated claims, with restricted access. Withdrawal of optional cookie consent does not erase a necessary record of a valid referral reward or prior consent.
- Optional referral cookie: up to 30 days, or until you remove it below. In-memory referral context is limited to the current page session unless you opt in to persistence.
10. Security
Visutta uses layered controls including TLS at the edge, protected origin services, account and tenant authorization, rate limits, durable job state, server-side provider credentials, signed media URLs, private object storage, database transaction controls, backups, and operational monitoring.
No system is completely secure. Protect your credentials, use only trusted devices, remove former collaborators promptly, and report suspected account compromise or a vulnerability to support. Do not send provider keys or passwords in prompts or support screenshots.
11. Your data-protection rights
Subject to the legal requirements and exceptions, you may have the right to:
- access personal data and obtain a copy;
- correct inaccurate or incomplete data;
- request deletion or restriction;
- receive certain data in a portable format;
- object to processing based on legitimate interests or direct marketing;
- withdraw consent prospectively where processing relies on consent;
- complain to a competent data-protection supervisory authority.
Send a request to support@visutta.com. We may ask for information needed to verify identity, protect other users, and locate the relevant account or workspace. We respond without undue delay and ordinarily within one month. If complexity or number of requests permits an extension of up to two further months, we tell you within the first month and explain why. Requests are normally free, subject to the narrow statutory exceptions. A team member may also need to contact the team or business controller for data that organization controls.
12. Automated decisions and moderation
Creative generation and Director suggestions are intended to assist human creative choices. Automated provider moderation, rate limits, credit checks and security rules can reject or pause requests and flag accounts. Inputs can include prompts, reference media, usage and technical security signals; the consequence can be a blocked generation or restricted access.
You can contact support to contest a restriction, provide your view and request human review. We do not use the creative tools to make employment, credit or similarly consequential decisions about people. If a particular automated account decision falls within Article 22 GDPR, its additional requirements and safeguards apply; calling a system a creative tool does not exclude those obligations.
13. Children and sensitive data
The Service is not intended for people under 18. If you believe a minor created an account or submitted personal data, contact support.
Prompts, reference media, or voice samples may reveal sensitive or special category data. Submit such data only where necessary, lawful, and supported by an appropriate legal basis. Visutta does not use voice samples for biometric authentication; a voice-cloning feature still requires authority and consent for the voice being cloned.
14. Personal data about other people
If you upload or generate material about another person, you are responsible for having a lawful basis and providing any required notice. This includes actors, employees, customers, collaborators, voice talent, depicted persons, and people appearing incidentally in source footage.
Where we obtain personal data indirectly as a controller, we remain responsible for Article 14 information duties and any properly assessed exception. Information is generally due within one month, at first communication, or before first disclosure, as applicable. If you are depicted in uploaded material, contact support with enough information to locate it; you do not need an account to exercise your rights.
Do not use Visutta to clone a voice, imitate a likeness, create intimate content, or make a consequential decision about a person without the rights, consent, and legal authority required for that use.
15. Changes and contact
We may update this Policy when the Service, providers, laws, or processing practices change. We will post the updated date and provide additional notice for material changes where required. A privacy notice describes processing; continued use is not treated as consent where the law requires a separate affirmative choice.
Privacy and data-protection requests: support@visutta.com.