Privacy Policy
How PEWIT Labs collects, uses and protects personal data across our site and plugins.
Template notice. This document is a starting point, not legal advice. Bracketed [PLACEHOLDERS] must be completed with the registered details of PEWIT Labs and reviewed by a qualified lawyer (GDPR / UOKiK in Poland; EU VAT and ePrivacy) before publication.
Last updated: [EFFECTIVEDATE]_
This Privacy Policy explains how [COMPANY_LEGAL_NAME] ("PEWIT Labs", "we") processes personal data in connection with pewitlabs.com and our products, including AI Media Toolkit. We act as the data controller for the data described below. For business customers we also offer a Data Processing Addendum (/legal/dpa).
1. Controller and contact
[COMPANY_LEGAL_NAME], [COMPANY_ADDRESS], [COMPANY_COUNTRY]. Contact: [COMPANY_EMAIL].
2. What data we process and why
| Data | Purpose | Legal basis (GDPR) |
|---|---|---|
| Account & contact data (name, email) | Account, licensing, support | Contract (Art. 6(1)(b)) |
| Purchase data (via Freemius) | Billing, taxes, invoices, refunds | Contract / legal obligation |
| Website/site technical data (URL, plugin/PHP/WP version, IP, logs) | Licensing, updates, security, diagnostics | Legitimate interest (Art. 6(1)(f)) |
| Support messages | Responding to requests | Contract / legitimate interest |
| Cookies & analytics (if consented) | Site analytics, marketing | Consent (Art. 6(1)(a)) |
We do not sell personal data.
3. AI image processing (important)
AI Media Toolkit sends your images to OpenAI to generate metadata (ALT, title, caption, description). There are two modes:
- BYOK (your own OpenAI key): images are sent directly from your WordPress site to OpenAI using your API key and under your OpenAI account/terms. We do not receive those images.
- Managed credits (optional): images pass through our AIMT Cloud proxy and then to OpenAI. We process them only to generate metadata and to meter credit usage; we do not use your images to train models.
Do not send images containing personal or sensitive data that you are not allowed to share with a US-based AI provider. You are responsible for the lawful basis to process images you upload.
4. Subprocessors / recipients
- Freemius, Inc. — checkout, licensing, billing (Merchant of Record).
- OpenAI — AI generation of metadata from images.
- Hosting / infrastructure provider — website and (for managed mode) AIMT Cloud.
- Analytics — only after cookie consent.
Links to their policies are provided on request and in /legal/dpa.
5. International transfers
Some providers (e.g. OpenAI, and possibly hosting/analytics) are located in the United States. Transfers outside the EEA rely on appropriate safeguards such as Standard Contractual Clauses (SCCs) and/or applicable adequacy frameworks.
6. Retention
We keep account and transaction data as long as needed for the relationship and to meet legal (e.g. tax) obligations. Technical/diagnostic logs are kept for a limited period. Managed-mode images are processed transiently and not retained beyond what is needed to return the result and meter usage.
7. Your rights
You have the right to access, rectification, erasure, restriction, portability and objection, and to withdraw consent at any time. You may lodge a complaint with your supervisory authority (in Poland: Prezes UODO). To exercise rights, contact [COMPANY_EMAIL].
8. Cookies
See our Cookie Policy (/legal/cookies). Non-essential cookies load only after consent.
9. Changes
We may update this Policy; material changes will be posted here with a new "Last updated" date.