Privacy Policy
Last Updated: August 17, 2026
At IrisArt AI (accessible from https://irisartai.com), the privacy of our visitors is of paramount importance. This Privacy Policy document outlines the types of personal information that is collected, recorded, and processed by this website, as well as how you can exercise your rights in compliance with the General Data Protection Regulation (EU) 2016/679 (GDPR) and the Spanish Organic Law 3/2018 (LOPDGDD).
1. Data Controller
- Controller / Legal Owner: Antonio Costilla
- Identification Number (NIF/DNI): 18960986Q
- Location: Spain
- Website: https://irisartai.com
- Contact Email: activing@gmail.com
2. Personal Data We Collect and Why We Collect It
A. Contact and Newsletter Forms
When you submit a query or subscribe to our newsletter via forms on our website:
- Data collected: Name, email address, IP address, and any details you provide in your message.
- Purpose: To manage your inquiries, provide customer support, and, where explicit consent is given, send periodic newsletters, updates, and artistic/prompt resources.
- Legal Basis: Your explicit, unambiguous consent (Article 6.1.a GDPR). You may withdraw this consent at any time.
B. Comments
When visitors leave comments on the site, we collect the data shown in the comments form, as well as the visitor’s IP address and browser user agent string to facilitate spam detection.
An anonymized string created from your email address (also known as a hash) may be provided to the Gravatar service to verify usage. The Gravatar service Privacy Policy is available at: https://automattic.com/privacy/. Upon approval of your comment, your profile picture becomes publicly visible in the context of your comment.
C. Media
If you upload images to the website, please avoid uploading files with embedded location data (EXIF GPS) included. Visitors to the website can download and extract any location data from images hosted on the site.
D. Cookies
- Comment Cookies: If you leave a comment, you may opt-in to saving your name, email address, and website in cookies for your convenience, lasting for one year.
- Authentication & Session Cookies: If you visit our login page, a temporary cookie is set to verify browser compatibility (discarded upon closing). When logging in, cookies are set to store credentials and screen display preferences (lasting between two days and two weeks if “Remember Me” is selected).
- Editor Cookies: If you edit or publish an article, an additional cookie containing no personal data indicates the post ID and expires after 1 day.
For full details on how we use cookies and how to manage them, please refer to our Cookie Policy.
E. Embedded Content from Other Websites
Articles on this site may include embedded content (e.g., videos, images, social media posts). Embedded content from third-party websites behaves in the exact same manner as if the visitor had visited the external website directly.
These external websites may collect data about you, utilize cookies, embed additional third-party tracking mechanisms, and monitor your interaction with that content, particularly if you hold an active account and are logged into that service.
3. Legal Basis for Processing
We process your personal data exclusively under the following legal bases:
- Consent (Art. 6.1.a GDPR): For handling subscriptions, newsletters, contact inquiries, and optional cookies.
- Legitimate Interest (Art. 6.1.f GDPR): To ensure website security, prevent fraud, and run automated anti-spam protections.
- Legal Compliance (Art. 6.1.c GDPR): When required to fulfill applicable statutory obligations.
4. Data Recipients and Third-Party Processors
We do not sell, rent, or trade your personal data. We only share data with service providers necessary for our operations under strict confidentiality and GDPR-compliant processing agreements:
- Web Hosting Provider: Infrastructure and hosting services.
- Email & Newsletter Service Providers: For managing mailing lists and newsletter distribution.
- Automated Spam Detection Services: Visitor comments and form submissions may be analyzed via automated filters to prevent spam and abuse.
- Public Authorities: Only when strictly required by applicable law or judicial mandate.
If data is processed outside the European Economic Area (EEA), we ensure adequate data protection safeguards (such as Standard Contractual Clauses approved by the European Commission).
5. Data Retention Periods
- Contact and Newsletter Data: Retained as long as the relationship is maintained or until you request its deletion / unsubscribe from our communications.
- Comments and Metadata: Retained indefinitely to automatically recognize and approve follow-up comments rather than holding them in moderation.
- Registered User Accounts: User profiles are stored until the account is deleted. Users can access, edit, or delete their profile information at any time (except modifying their username).
6. Your Rights Under GDPR
Under European data protection laws, you retain the following rights regarding your personal data:
- Right of Access: Request confirmation of whether we process your data and obtain a copy.
- Right to Rectification: Request correction of inaccurate or incomplete data.
- Right to Erasure (“Right to be Forgotten”): Request deletion of your personal data when it is no longer necessary for the original collection purpose.
- Right to Restriction of Processing: Request temporary restriction of processing under certain conditions.
- Right to Data Portability: Receive your data in a structured, commonly used, machine-readable format.
- Right to Object: Object to data processing based on legitimate interests or direct marketing.
- Right to Withdraw Consent: Withdraw previously granted consent at any time without affecting the lawfulness of prior processing.
How to Exercise Your Rights
To exercise any of these rights, send an email to activing@gmail.com indicating the subject “Data Protection / Exercise of Rights” and attaching proof of identity (such as a copy of your ID/passport).
You also retain the right to lodge a complaint with the competent supervisory authority, notably the Agencia Española de Protección de Datos (AEPD) at www.aepd.es if you believe your data has been handled improperly.
7. Security of Your Data
We employ appropriate technical and organizational measures (including SSL/TLS encryption protocols) to protect your personal data against accidental loss, unauthorized access, misuse, or alteration.
8. Updates to This Policy
We may update this Privacy Policy periodically to reflect changes in our operational practices or legal requirements. Any modifications will be posted on this page with an updated revision date.