Legal
Privacy Policy
Last updated: Aug 5, 2026
How Lignique collects, uses, stores, shares, protects, and deletes personal data and creative content.
Effective date: 5 August 2026 · Version: 1.2 · Owner: Jayadevan Premnath, sole proprietor carrying on business as Lignique Studios.
IMPORTANT NOTICE — Lignique is intended only for people aged 18 or over. Prompts, instructions, reference images, character sheets, locks, and related settings may be transmitted to authorised AI service providers to perform generation or editing. Do not upload another person's personal data, face, likeness, or confidential material unless you have lawful authority.
Privacy at a glance
- Legal operator: Jayadevan Premnath, sole proprietor carrying on business as Lignique Studios, is the data fiduciary or controller for Lignique's own processing described here.
- Creative ownership: You retain the rights you hold in your Inputs. Lignique receives only the limited licence stated in the Terms to provide, secure, support, and lawfully operate the Services.
- AI processing: Creative Inputs may be routed to authorised AI providers. Lignique does not itself use User Content or Outputs to train or fine-tune a foundation model, has not opted customer API content into provider training, and will not do so without an updated notice and any legally required consent.
- Browser and cloud split: Some workspace information may remain only in your browser or device; account, security, usage, billing, and operational records may be processed in cloud systems.
- No data brokerage or behavioural advertising: Lignique does not sell personal data for money, share it for cross-context behavioural advertising, or use it for targeted advertising.
- Synthetic-content transparency: Covered AI-generated or manipulated Outputs will carry required visible labels and technical provenance. Lignique will not enable removal of a mandatory label or identifier.
- Your choices: Depending on the law, you may request access, correction, deletion, portability, objection, restriction, consent withdrawal, human review, or appeal; manage cookies; and complain without discrimination.
1. Scope, identity, and territorial offering
This Privacy Policy applies to the public website at https://lignique.com, the hosted Lignique web application at https://app.lignique.com, support channels, Account services, subscription and Credit functions, and other online services that link to this Policy (together, the Platform).
It does not govern a separately distributed desktop application or downloadable software supplied under a distinct licence and privacy notice. It also does not govern third-party websites or services that Lignique does not control.
For personal data processed for Lignique's own purposes, Jayadevan Premnath, carrying on business as Lignique Studios, acts as the Data Fiduciary under applicable Indian law and as the controller, business, or equivalent under other applicable privacy laws. Where a future Organisation Account uses Lignique to process personal data on its behalf, the organisation may be the controller and Lignique may act as its processor under additional terms or a data-processing agreement.
Paid availability may be limited to countries shown at checkout. Accessing the Platform from another country does not itself mean Lignique targets or offers paid Services there. When Lignique affirmatively offers Services in a jurisdiction, this Policy is supplemented by non-waivable local requirements.
2. Core privacy commitments
- Purpose limitation: Personal data is used only for the disclosed service, security, billing, support, compliance, and improvement purposes, or a compatible purpose permitted by law.
- Data minimisation: Lignique seeks information reasonably necessary for an Account, operation, transaction, safety control, or support request.
- No hidden model training: Lignique does not use User Content or Outputs to train a proprietary or foundation model without a new notice and any legally required consent.
- No sale or targeted advertising: Personal data is not sold for money, shared for cross-context behavioural advertising, or used to create advertising profiles.
- Security and accountability: Lignique uses proportionate safeguards, access controls, logging, provider diligence, and incident handling appropriate to the nature and risk of the data.
- User control: Lignique provides request and grievance channels and does not discriminate against a person for exercising a privacy right.
3. Personal data Lignique processes
The exact information depends on the features used.
| Category | Examples | Main purposes |
|---|---|---|
| Account and contact | Name or display name, email, Account identifier, verification status, country or region where supplied, preferences, communication settings | Registration, authentication, notices, support, rights requests |
| Authentication and security | Password hash or credentials handled by the authentication service, session and refresh tokens, login timestamps, IP address, device and browser signals, security events | Secure access, fraud and abuse prevention, incident investigation |
| Creative Inputs | Prompts, instructions, scripts, reference images, character sheets, style boards, continuity locks, backgrounds, props, presets, parameters, filenames, project labels | Generation, editing, continuity, export, moderation, support |
| Outputs and provenance | Generated or edited images, previews, identifiers, timestamps, dimensions, quality tier, settings, safety labels, technical provenance | Deliver Outputs, maintain history, prevent abuse, resolve failures, meet transparency duties |
| Usage and operations | Routes and operations used, Credit quotes and debits, counters, status codes, latency, errors, model or provider route, concurrency signals, diagnostic metadata | Service delivery, metering, debugging, capacity, security, reconciliation |
| Payments and commerce | Plan, amount, currency, taxes, billing country, order and transaction identifiers, payment status, refund or dispute state, limited payment-method details returned by the Payment Provider | Checkout, receipts, Credits, renewals, refunds, tax, accounting |
| Support and grievances | Messages, attachments, complaint facts, authority to act, resolution notes, and call or meeting details if recorded with notice | Respond, investigate, preserve evidence, comply with law |
| Website and analytics | Cookie or device identifiers, page views, approximate region, acquisition source, browser and device characteristics, interactions, performance information | Essential operation, consent management, reliability, privacy-configured analytics |
IMPORTANT — Sensitive data: Account login credentials and information allowing access to an Account can be sensitive personal information under some laws. Creative content may also incidentally reveal a face, ethnicity, religion, health condition, sexuality, citizenship, or another sensitive characteristic. Lignique does not require government identifiers, financial-account credentials, precise geolocation, health records, or biometric identity templates for ordinary use. Do not upload sensitive data unless it is necessary, lawful, and authorised. Lignique does not intentionally perform biometric identification.
4. Sources of personal data
- Directly from you: When you register, create or edit content, configure continuity tools, purchase, contact support, file a grievance, or exercise a right.
- Automatically from the Platform: Through authentication, server logs, security controls, Credit ledgers, browser storage, cookies, and consented analytics.
- From service providers: Payment status, authentication events, cloud or AI results, delivery events, security alerts, and support records.
- From an authorised person: For example, an Account administrator or authorised agent, if those functions are supported.
- From lawful public or official sources: Only where reasonably necessary for fraud prevention, legal compliance, sanctions screening, or dispute resolution.
5. Purposes, legal bases, and consequences
Where EU, UK, or similar law applies, the table identifies the principal legal bases. Under Indian law, Lignique relies on consent or another lawful use to the extent applicable. Elsewhere, Lignique uses equivalent grounds recognised by law.
| Purpose | Legal basis where applicable | If data is not provided |
|---|---|---|
| Create and operate the Account; provide generation, editing, storage, export, and continuity tools | Contract; steps requested before contract; consent where specifically required | The Account or requested feature may not work |
| Process prompts, images, locks, and parameters through authorised AI and cloud providers | Contract; consent where specifically required | The requested generation or edit cannot be performed |
| Measure Credits, enforce quotas, prevent duplicate debits, reconcile operations | Contract; legitimate interests in accurate accounting and fraud prevention | Paid or metered operations cannot be supplied reliably |
| Process payments, renewals, taxes, refunds, disputes | Contract; legal obligations; legitimate interests in fraud prevention and claim defence | A purchase or refund may not be completed |
| Secure the Platform, moderate prohibited content, investigate abuse, preserve evidence | Legitimate interests; legal obligations; protection of users and rights | Access may be restricted if security cannot be maintained |
| Provide support, resolve grievances, send operational and legal notices | Contract; legal obligations; legitimate interests in support and compliance | Lignique may be unable to resolve the request |
| Use non-essential analytics | Consent where required; otherwise legitimate interests after balancing | No loss of core Service if consent is refused |
| Send marketing | Consent or another locally permitted basis; each message includes an opt-out | No marketing is sent if consent is required and not given |
| Create aggregated or de-identified statistics | Legitimate interests in improvement, provided the data is not used to identify a person | No material consequence to the user |
When processing is based on consent, you may withdraw it through the available setting or by contacting Lignique. Withdrawal does not affect processing already lawfully completed. If the data is necessary to provide a requested feature, withdrawal may mean the feature or Account can no longer be provided.
Where Indian data-protection notice rules apply, Lignique will also present a concise, standalone, purpose-specific notice at or before the relevant point of collection. That notice will identify the data and purpose, how to withdraw consent and exercise rights, and how to complain. This long-form Policy does not replace a just-in-time notice where one is legally required.
6. AI processing, moderation, and provenance
6.1 AI service providers
To generate or edit visual content, Lignique may transmit the minimum reasonably necessary prompt, instruction, reference image, continuity-lock information, dimensions, quality setting, and related parameters to an authorised AI provider. OpenAI's API is a current provider for supported operations. A materially different provider or purpose will be identified through an updated provider notice before use where required.
Lignique does not itself train or fine-tune a foundation model on User Content or Outputs and has not opted customer API content into provider model training. OpenAI states that API data is not used to train or improve its models unless the API customer expressly opts in. By default, OpenAI abuse-monitoring logs may include prompts, images, Outputs, and related metadata and may be retained for up to 30 days, or longer where law or harm prevention requires; some API features may also retain application state. Retention varies by endpoint and account configuration. Lignique therefore does not promise immediate deletion or zero retention from every provider system and will update this notice before opting customer content into training or materially changing the provider purpose.
6.2 Automated safety controls and human review
Automated systems may screen prompts, references, uploads, or Outputs; reject an operation; apply a label; enforce a usage limit; or flag an event for review. These controls are used to prevent unlawful or prohibited content, fraud, abuse, security incidents, and circumvention. Lignique does not use this processing to make credit, employment, housing, insurance, health, or similarly significant eligibility decisions about a person.
If an automated control materially restricts an Account or lawful operation, the user may request human review through the grievance channel, subject to security, legal, and technical limits.
6.3 Mandatory synthetic-content labels and provenance
For an Output within an applicable definition of synthetically generated or manipulated information, Lignique will:
- Display a prominent, easily noticeable label identifying the content as synthetically generated or manipulated.
- Embed permanent metadata or another appropriate technical provenance mechanism, to the extent technically feasible, including a unique identifier that can identify the Lignique computer resource used for the operation where required.
- Mark AI-generated or manipulated output in a machine-readable and detectable format where applicable law, including an applicable EU AI transparency rule, requires it.
- Not enable modification, suppression, or removal of a mandatory visible label, permanent metadata, or unique identifier.
Users must not remove, obscure, or suppress a mandatory label or provenance mechanism. Provenance indicates generation or alteration; it does not guarantee that an Output is accurate, authentic, original, copyrightable, or non-infringing.
7. Browser, device, and cloud storage
Lignique uses a hybrid architecture. Account registration, authentication, security records, usage counters, billing records, and operational logs may be stored in cloud systems. Project history, continuity locks, reference selections, settings, recent Outputs, and related workspace information may be stored locally in browser technologies such as localStorage, sessionStorage, IndexedDB, caches, or device files. A feature may also allow deliberate cloud saving.
- Local-only information may not follow the user to another browser or device and may be lost if browser data is cleared, private browsing is used, the application is reset, or local software is removed.
- On a shared device, sign out and clear local workspace data where appropriate. Local data may remain accessible to another person using the same browser profile.
- Deleting cloud data does not delete independent local copies. Clearing local data does not delete cloud Account, billing, security, or legal records.
- The interface will distinguish a local-only item from a cloud-saved item where that distinction is material to user control.
8. Cookies, analytics, and privacy signals
Lignique uses or may use the following technologies. The live cookie preference centre will show the current cookie or storage identifiers, provider, purpose, and duration.
| Category | Purpose and examples | Choice or legal basis | Retention standard |
|---|---|---|---|
| Strictly necessary | Authentication, session security, load balancing, fraud prevention, consent records, essential preferences | Required to provide the requested Service; no advertising use | Session or the shortest operational period; consent records retained as legal proof |
| Functional | Interface preferences and user-selected local workspace state | User request or consent where required | Until cleared, changed, or no longer needed |
| Analytics | Google Analytics audience, device, acquisition, page-performance, and approximate-region information | Disabled until consent where prior consent is required | User and event data configured for no more than 14 months |
| Marketing or targeted advertising | Not used at the effective date | Would require a new notice and valid choice before activation | Not applicable |
Non-essential analytics will not be activated before consent where law requires prior consent. Rejecting analytics will not block core Service. Advertising personalisation and Google Signals will remain disabled unless Lignique first provides a new notice and legally valid choice.
Lignique will honour a Global Privacy Control or other legally recognised opt-out preference signal as an opt-out of sale, sharing, or targeted advertising where applicable. Because Lignique does not presently engage in those activities, the signal does not change essential processing. The Platform does not respond to non-standardised Do Not Track signals.
9. When personal data is disclosed
Lignique does not disclose personal data for another company's independent marketing. It may disclose the minimum necessary data to:
- Cloud, website, and infrastructure providers to host the public website, application, databases, security controls, and files.
- AI and moderation providers to process prompts, reference images, settings, and Outputs for requested generation, editing, safety, and abuse-prevention functions.
- Analytics providers for privacy-configured measurement and site performance after any required consent.
- Payment Providers or merchants of record to process payment credentials and return transaction, tax, subscription, dispute, and refund information. Lignique does not ordinarily receive a complete payment-card number or security code.
- Authentication, email, support, and security vendors to verify Accounts, deliver communications, manage support, detect abuse, and respond to incidents.
- Professional advisers and insurers where reasonably necessary and subject to confidentiality duties.
- Courts, regulators, law-enforcement bodies, victims, or authorised persons when required or permitted by valid legal process, to protect rights or safety, or to comply with intermediary and synthetic-content duties.
- A successor in a business transaction subject to confidentiality, due diligence, notice, and continued protection.
Service providers are required by contract or binding terms to process data for limited purposes, protect it appropriately, and assist with deletion, security, and rights requests where required. A material new recipient category or materially different purpose will be disclosed before the change takes effect where required.
9.1 Payment Provider as independent controller
The Payment Provider or merchant of record identified at checkout may independently determine how payment credentials, tax information, fraud signals, and statutory transaction records are processed. Its privacy notice applies to that independent processing. Lignique remains controller of the Account, Service, Credit ledger, support, and records it determines to collect. The live checkout must identify the final provider before payment is activated.
10. International processing and transfers
Lignique is established in India and uses providers that may process information in India, the United States, and other countries. Those countries may have different data-protection laws.
Where the EU GDPR, UK GDPR, or another transfer law applies, Lignique will use an approved transfer mechanism when required, such as an adequacy decision, standard contractual clauses, the UK International Data Transfer Agreement or Addendum, and supplementary technical or organisational measures. Transfers from India will comply with any restriction or requirement notified under applicable Indian law. A user may request information about an applicable safeguard, subject to lawful redaction of confidential terms.
11. Retention and deletion
Lignique keeps personal data only for as long as reasonably necessary for a disclosed purpose, contractual or security need, or legal requirement. A legal hold, unresolved dispute, fraud or security investigation, statutory preservation duty, provider constraint, or protected backup cycle may require longer retention. Data may be irreversibly de-identified instead of deleted where lawful.
| Record | Retention standard |
|---|---|
| Browser or device workspace | Until the user clears it, the browser or device removes it, or a Lignique control removes it. Lignique may be unable to delete copies on a device it does not control. |
| Account and registration | While active, then at least 180 days after cancellation or withdrawal where Indian intermediary rules apply; longer only for security, legal, tax, dispute, or suppression needs. |
| Transient prompt or reference payload held by Lignique | Normally no longer than 30 days unless deliberately saved, required for support or safety review, or subject to legal hold. Provider retention follows the endpoint, contract, configuration, and law. |
| Saved cloud projects and Outputs | Until deleted by the user or Account closure, then removed from active user-facing systems without undue delay. Protected backups expire on the documented backup cycle; immediate overwrite in every environment is not guaranteed. |
| Usage and security logs | Normally up to 12 months. Records tied to abuse, fraud, an incident, or dispute may be kept up to 24 months or longer if lawfully required. |
| Consent, policy acceptance, and renewal proof | At least 3 years after the relevant contract ends, or longer where required to prove consent, comply with renewal law, or defend a claim. |
| Payment, refund, tax, and accounting records | For the period required by tax, accounting, foreign-exchange, anti-fraud, and consumer law; generally up to 8 financial years after the transaction. |
| Support and ordinary complaints | Normally 3 years after closure, unless a shorter period is sufficient or a longer period is required for a legal claim. |
| Removed or disabled content and associated records | At least 180 days where Indian intermediary rules apply, and longer if required by a court or authorised government agency. |
| Google Analytics user and event data | Configured for no more than 14 months; aggregated reports that no longer identify a user may be kept longer. |
Deletion requests apply to data Lignique controls. Providers will be instructed to delete or cease processing where required and technically available. Some data may remain for payment records, fraud prevention, legal claims, statutory preservation, or binding orders. A minimal suppression record may be retained to honour an opt-out or prevent improper re-registration.
12. Security and incident response
Lignique applies safeguards proportionate to the size and risk of the Platform. These may include encrypted transport, encryption at rest where supported, password hashing, least-privilege access, environment separation, authentication controls, rate and concurrency limits, logging, input validation, moderation, backups, dependency and provider review, and documented incident handling.
No internet service can guarantee absolute security. Users must protect credentials, use a unique password, keep the registered email secure, sign out on shared devices, and promptly report suspected compromise. If a personal-data breach creates a legally reportable risk, Lignique will notify the competent authority and affected individuals within the time and manner required by law.
13. Rights and choices
Subject to Applicable Law, proportionate verification, and lawful exceptions, a person may have the following rights. Lignique intends to honour these core requests even when a particular law does not yet apply, to the extent technically feasible and consistent with legal obligations.
| Right | What it means |
|---|---|
| Access or know | Ask whether Lignique processes personal data and receive categories, sources, purposes, recipients, retention information, and specific data where required |
| Correction or completion | Correct inaccurate information and complete or update incomplete information |
| Deletion or erasure | Request deletion, subject to contract, security, tax, claim, fraud, and statutory-retention exceptions |
| Portability | Receive eligible data in a structured, commonly used, machine-readable format where required and technically feasible |
| Withdraw consent | Withdraw consent as easily as it was given without affecting prior lawful processing |
| Object or restrict | Object to or request restriction of legitimate-interest processing, direct marketing, or another recognised ground |
| Opt out | Opt out of sale, sharing, targeted advertising, or qualifying profiling. Lignique does not presently engage in those activities |
| Limit sensitive-data use | Limit use or disclosure of sensitive personal information where a law provides the right and the processing is outside permitted purposes |
| Human review or appeal | Request review of a materially adverse automated safety or access decision and appeal a denied privacy request where applicable |
| Nominate | Under applicable Indian law, nominate another person to exercise specified rights in the event of death or incapacity |
| Complain | Complain to Lignique and, where applicable, a regulator or statutory body without retaliation |
13.1 Request process
- Send a request from the registered email where possible to JayadevanPremnath@lignique.com with the subject Privacy Request.
- Identify the right and the Account, transaction, project, Output, or device concerned.
- Complete proportionate verification. Lignique will not request more information than reasonably necessary or use verification data for another purpose.
- Lignique will acknowledge the request promptly and aims to respond within 30 days. Where another deadline or extension applies, Lignique will explain it. If the CCPA applies, receipt will be confirmed within 10 business days and a substantive response provided within 45 calendar days, subject to a lawful extension.
- An authorised agent must provide evidence of authority and may be required to support identity verification.
Lignique may deny or limit a request if identity cannot reasonably be verified, the request is manifestly unfounded or excessive, an exception applies, or compliance would prejudice another person's rights. The response will explain the principal reason and available appeal where required.
14. Grievance, illegal-content, and takedown process
The Grievance Officer and complaint mechanism are published in the Contact section. A complaint concerning privacy, Account access, unlawful content, impersonation, non-consensual imagery, synthetic content, or another Platform matter should identify the relevant URL or content, Output or generation identifier, Account, reason, and authority to act.
Where the Indian intermediary rules apply, Lignique will acknowledge a complaint within 24 hours and resolve it within 7 days, subject to any shorter mandatory period. A qualifying complaint about material exposing a private area, depicting nudity or a sexual act, or impersonating an individual in electronic form, including an artificially morphed image, will be handled under the applicable expedited process, which currently requires reasonable and practicable removal or disabling of access within 2 hours. Certain other unlawful-content complaints currently require resolution within 36 hours. Court or authorised government orders will be handled within the applicable statutory deadline.
Lignique may preserve removed content and associated records for at least 180 days where required. A complainant or affected user may use the statutory appeal or Grievance Appellate Committee route where applicable. These timelines do not replace a shorter obligation under another law.
15. Regional privacy notices
15.1 India
To the extent the Digital Personal Data Protection Act, 2023 and Digital Personal Data Protection Rules, 2025 are in force and apply, Lignique will provide clear purpose-specific notice, obtain valid consent where required, enable comparable withdrawal, maintain reasonable security safeguards, notify reportable breaches, erase data when the purpose and legal retention end, and support applicable access, correction, erasure, grievance, and nomination rights. As at the effective date, the Act and Rules are subject to phased commencement and their core private-sector processing and individual-rights provisions are not all yet operative. Lignique adopts those protections in advance where practicable. Until superseded, and wherever separately applicable, the Information Technology Act, 2000 and the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011 may also apply.
Indian intermediary duties may separately require Account-registration retention, preservation of removed content, a published Grievance Officer, accelerated complaint handling, cooperation with lawful orders, and synthetic-content transparency. Section 14 and Section 6.3 address those duties at policy level.
15.2 California and other US states
If a US state privacy law applies, residents may exercise the rights described above, including access, correction, deletion, portability, opt-out, sensitive-data limitation where applicable, non-discrimination, and appeal. Lignique does not sell personal information, share it for cross-context behavioural advertising, use it for targeted advertising, or provide a financial incentive in exchange for personal information. Subscription discounts and promotional Credits are based on the purchase or promotion, not the value of personal data.
Appendix A is a Notice at Collection for the California categories reasonably expected at the effective date. Point-of-collection interfaces will link to this Policy or provide a concise notice before collection when required.
15.3 EEA, United Kingdom, and Switzerland
Where EU, UK, or Swiss data-protection law applies, a person may exercise access, rectification, erasure, restriction, objection, portability, consent withdrawal, and complaint rights and request information about transfer safeguards.
Lignique is established in India and does not currently maintain an EU or UK establishment. If a local representative becomes legally required for targeted operations, representative details will be published before that offering proceeds. If the EU AI Act applies to an offered function, Lignique will implement applicable provider and deployer transparency measures, including machine-readable marking and deepfake disclosure where required.
16. Children and age restriction
The Platform is intended only for persons aged 18 or over. Lignique does not knowingly offer the Platform to children or knowingly collect personal data from a person under 18. A person who cannot lawfully form the contract must not register or use the Platform. If Lignique learns that it collected a child's data contrary to this restriction, it will restrict the Account and delete the data unless preservation is legally required. A parent, guardian, or affected person may report the matter through the grievance channel.
17. Third-party personal data and likenesses
If a user uploads or describes another person, the user must have a lawful basis, permission, licence, or other authority and must ensure the processing is fair and not misleading. A user must not misuse a real person's likeness, voice, biometric characteristics, identity, private information, or confidential material. Lignique may request evidence, reject an operation, remove or disable access, preserve records, or report the matter when required by law.
18. Changes to this Policy
Each version states its effective date and version number. Lignique may update this Policy for product, provider, security, commercial, or legal changes. A material change will be notified by email, through the Platform, or another appropriate channel before it takes effect when reasonably practicable. New consent will be obtained where required. Earlier versions may be retained for audit and proof of notice.
Contact and grievance redressal
Lignique Studios is owned and operated by Jayadevan Premnath, sole proprietor carrying on business under the trade name Lignique Studios.
| Item | Details |
|---|---|
| Legal business and data fiduciary or controller | Jayadevan Premnath, sole proprietor carrying on business as Lignique Studios |
| Principal address | 4/238, Komalapuram, Alappuzha, Kerala 688006, India |
| GSTIN | 32AWQPJ4353D1ZO |
| Grievance Officer and privacy contact | Jayadevan Premnath |
| Email and complaint mechanism | JayadevanPremnath@lignique.com |
| Business telephone | +91 7736470963 |
| Website | https://lignique.com |
| Policy URL | https://lignique.com/privacy |
Include the registered email, a description of the request, and relevant Account, transaction, project, Output, generation, URL, or complaint identifier. Do not send passwords, full payment-card numbers, or identity documents unless specifically requested through a secure channel.
A person may complain to the competent authority where the law provides that right. Relevant routes may include the Data Protection Board of India, the California Privacy Protection Agency, the UK Information Commissioner's Office, or the competent EEA or Swiss authority. Contacting Lignique first is encouraged for prompt investigation but is not required where law provides a direct complaint right.
Appendix A — US and California Notice at Collection
This Appendix applies if and to the extent the CCPA or another comparable law applies. It also provides transparency regardless of statutory threshold. The table describes categories Lignique reasonably expects to collect, the purposes, service-provider disclosures, and the retention period or criteria.
| Statutory category | Examples and collected status | Business purposes and disclosures | Retention period or criteria |
|---|---|---|---|
| Identifiers | Yes: name, email, Account ID, IP address, device IDs | Account, authentication, support, security, billing; cloud, auth, payment, email, support, security providers | Account identifiers: active term plus at least 180 days where required; security identifiers normally up to 12 months, longer for incidents |
| Customer records and commercial information | Yes: contact details, plan, purchases, Credits, transactions, refunds | Commerce, tax, receipts, ledger, disputes; Payment Provider, accounting, advisers | Transaction and tax records generally up to 8 financial years; consent proof at least 3 years after contract |
| Internet or network activity | Yes: logs, routes, device and browser, interactions, analytics | Service operation, analytics, fraud, security; cloud, analytics, security providers | Operational and security logs normally up to 12 months; analytics user or event data no more than 14 months |
| Approximate geolocation | Yes: approximate region inferred from IP or supplied at checkout; no ordinary precise geolocation | Localisation, fraud, tax, analytics; cloud, payment, analytics, security providers | Kept with relevant transaction, security log, or analytics record under the applicable schedule |
| Audio, electronic, visual, or similar information | Yes when submitted or generated: images, references, Outputs, support attachments | Requested creative processing, continuity, moderation, support; AI, cloud, moderation, support providers | Transient payload normally no more than 30 days; saved content until deletion or Account closure, subject to backup and legal holds |
| Professional or employment information | Not requested; may be included by a user | User-directed creative or support context; providers needed for the requested operation | Same period as the content or support record containing it |
| Protected classifications | Not requested; may be incidentally visible or described in user content | Requested processing, safety, support; providers needed for the operation | Same period as the content containing it; users are asked not to upload unnecessary sensitive data |
| Inferences | Limited workflow, safety, and reliability parameters; no advertising profile | Continuity, abuse prevention, reliability, feature performance; AI, cloud, security providers | Normally tied to project or operational record under the relevant schedule |
| Sensitive personal information | Yes: Account login credentials or access tokens; may appear incidentally in creative content. No ordinary precise geolocation, financial credentials, or biometric identification | Secure Account access, requested creative processing, security, legal compliance; providers necessary for those purposes | Credentials while needed for Account and session security; incidental content under the content schedule; no retention for inferring sensitive traits |
Sold or shared: None. Lignique has not sold personal information for money or shared it for cross-context behavioural advertising in the preceding 12 months. Lignique has not knowingly sold or shared personal information of a person under 16. Lignique does not use or disclose sensitive personal information to infer characteristics or for purposes outside those reasonably necessary to provide, secure, and comply with the Service.
Appendix B — Current provider snapshot
| Provider or category | Purpose | Data involved | Typical processing location |
|---|---|---|---|
| Hostinger and WordPress website services | Public website hosting and content management | Website requests, technical logs, submitted forms where enabled | Provider infrastructure locations |
| Amazon Web Services | Application cloud hosting and infrastructure | Account, security, operational, and content data required by the Service | Regions selected by Lignique and AWS architecture |
| OpenAI API | AI generation, editing, and related safety processing for supported operations | Prompts, reference images, settings, Outputs, operation metadata | United States and other locations under provider terms and safeguards |
| Google Analytics and Search Console | Website and search performance analytics | Cookie or device identifiers, usage, approximate region, technical and search-performance data | Global Google infrastructure with available regional controls |
| Payment Provider or merchant of record identified at checkout | Payments, taxes, subscriptions, refunds, disputes | Payment, billing, transaction, tax, limited Account data | As disclosed by the selected provider |
This snapshot does not mean every provider receives data for every operation. Authentication, email, support, and security providers receive only the minimum data needed for their function and must be identified in the live provider notice. Lignique may replace a provider with an equivalent service after due diligence, contractual protection, transfer review, and any required notice. The live notice and checkout must identify the final payment, authentication, email, support, and security providers before those functions are activated.