Effective 28 June 2026
| Field | Value |
| Operator | Company name |
| Company number | Company number |
| Registered office | address |
| Trading name / brand | Picwave |
| Website | https://pic-wave.com |
| Contact email | info@pic-wave.com |
| Data controller contact / DPO | info@pic-wave.com |
| Governing law | Laws of the Republic of Estonia; GDPR (EU) 2016/679 |
| Document version | v1.0 |
| Effective date | 28 June 2026 |
| Who this policy applies to: This Privacy Policy applies to all individuals who visit the Picwave website at pic-wave.com, register an Account, purchase Digital Images, purchase Token Packs, use the Generate Module, or otherwise interact with Picwave’s products and services. It does not apply to third-party websites linked from our platform. |
| Important: Picwave is committed to protecting your privacy and handling your personal data responsibly under the EU General Data Protection Regulation (GDPR). This Policy explains what data we collect, why, how long we keep it, and your rights. We collect only data necessary to provide the Service. Card data is handled by our payment service provider — not stored on our servers. |
1. Introduction & Scope
1.1 Company name (“Picwave”, “we”, “us”, “our”) is the data controller of personal data collected through the Service at pic-wave.com. This Privacy Policy describes how we collect, use, store, share, and protect your personal data, and sets out your rights under the General Data Protection Regulation (EU) 2016/679 (“GDPR”) and applicable Estonian data protection law.
1.2 This Policy covers all personal data collected through: (a) your use of the Picwave website and platform; (b) registration and management of your Account; (c) purchases of Digital Images and Token Packs; (d) use of the Generate Module; (e) customer support and communications; and (f) cookies and similar tracking technologies, which are addressed in detail in our Cookie Policy.
1.3 We may update this Policy from time to time. Material changes will be notified to you by email or by a prominent notice on the website. The current version is always available at pic-wave.com. The date of the most recent update is shown in the header of this document.
2. Data Controller & Contact
2.1 The data controller for all personal data processed through the Service is:
Company name | Trading as: Picwave
address
Company no. Company number | Email: info@pic-wave.com
2.2 There is no designated Data Protection Officer (DPO) required for Picwave at its current scale of processing. All data-protection enquiries, subject-access requests, and privacy complaints should be addressed to: info@pic-wave.com, clearly marked “Privacy / Data Request” in the subject line.
2.3 You may also contact the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon) at https://www.aki.ee for information about your data-protection rights or to lodge a complaint.
3. Age Position
3.1 The Service is intended for users who are at least 18 years of age. We do not knowingly collect personal data from children under the age of 18 without the express consent of a parent or legal guardian.
3.2 If you are under 18, you may only use the Service with the knowledge and supervision of a parent or guardian. Purchases made by minors must be authorised by a parent or guardian who accepts responsibility for the transaction.
3.3 If we become aware that we have inadvertently collected personal data from a child under 18 without appropriate consent, we will delete that data promptly. If you believe a minor’s data has been submitted without proper consent, please contact us at info@pic-wave.com.
4. Categories of Personal Data
The following table summarises the categories of personal data we collect, examples of specific data types, how we obtain them, and the primary purposes for which we use them.
| Category | Examples | Source | Purpose |
| Account data | Name, email address, password (hashed), account creation date | Provided by you at registration | Account management, authentication, communications |
| Transaction and order data | Order number, product purchased, quantity, price, currency, purchase date, Token balance | Generated at checkout | Order fulfilment, payment processing, accounting, dispute resolution |
| Payment metadata | Payment method type (e.g. card), last four digits, transaction reference, PSP transaction ID | PSP-supplied metadata (not full card data) | Fraud prevention, order verification, reconciliation; full card data handled by PSP only |
| Technical and usage data | IP address, browser type, device type, operating system, pages visited, session duration, generate module usage logs | Collected automatically via website analytics and server logs | Service operation, security, performance optimisation, fraud detection |
| Support and communications data | Content of support emails, contact form submissions, support ticket records | Provided by you | Customer support, complaint resolution, quality assurance |
| Prompt data | Text prompts submitted to the Generate Module | Provided by you | Image generation, safety monitoring, service improvement |
| Cookie and tracking data | Cookie identifiers, consent records, analytics identifiers | Collected automatically | Analytics, user preferences, cookie consent management — see Cookie Policy |
5. Sources of Personal Data
5.1 Directly from you: the majority of personal data we hold is provided directly by you when you register an Account, make a purchase, use the Generate Module, or contact our support team.
5.2 Automatically from your device: technical and usage data is collected automatically when you access the Service through standard server logs and analytics tools. This includes your IP address, browser details, and usage patterns.
5.3 From our payment service provider: our PSP provides us with transaction references and payment metadata to confirm successful or failed payments. We do not receive full card numbers from our PSP.
5.4 From analytics providers: we use third-party analytics services (such as web analytics tools) to understand how the Service is used in aggregate. These providers may set cookies as described in our Cookie Policy.
6. How We Use Personal Data
6.1 Picwave uses your personal data for the following primary purposes:
- Providing the Service: creating and managing your Account; processing Token and Digital Image purchases; delivering download links; crediting Token balances; operating the Generate Module; sending transactional emails (order confirmations, delivery notifications).
- Security and fraud prevention: detecting and preventing fraudulent payments, account hijacking, prompt abuse, and other security threats; maintaining logs for investigation and legal compliance.
- Customer support: responding to enquiries, resolving complaints, processing refund or dispute requests.
- Legal compliance: fulfilling obligations under Estonian, EU, and applicable international law, including VAT/tax records, accounting obligations, and data-subject rights requests.
- Service improvement: analysing usage patterns (in aggregated or anonymised form where possible) to improve the Service, the Generate Module, and the Shop catalogue.
- Marketing communications: where you have given explicit consent, sending promotional emails about new collections, Token promotions, or platform features. You may withdraw consent at any time.
7. Lawful Bases for Processing
Under GDPR, each processing activity requires a lawful basis. The table below sets out the lawful basis for each main category of processing.
| Processing activity | Lawful basis | Notes |
| Account registration and management | Contract (Art. 6(1)(b)) | Necessary to perform the services you have contracted for |
| Processing Token and Digital Image purchases | Contract (Art. 6(1)(b)) | Necessary to fulfil your order |
| Sending order confirmations and delivery notifications | Contract (Art. 6(1)(b)) | Transactional communications required to deliver the product |
| Tax and accounting records | Legal obligation (Art. 6(1)(c)) | Estonian and EU tax, VAT, and accounting law requirements |
| Fraud prevention and security monitoring | Legitimate interests (Art. 6(1)(f)) | Protecting Picwave and its users from fraud, abuse, and security threats; interests not overridden by user rights |
| Prompt safety monitoring and logging | Legitimate interests (Art. 6(1)(f)) | Preventing generation of harmful content; maintaining platform integrity |
| Analytics and service improvement | Legitimate interests (Art. 6(1)(f)) | Understanding how the Service is used to improve it; aggregated/anonymised data minimises privacy impact |
| Non-essential cookies and analytics tracking | Consent (Art. 6(1)(a)) | Prior consent collected via cookie banner; withdrawal available at any time via cookie settings |
| Marketing and promotional emails | Consent (Art. 6(1)(a)) | Sent only where you have opted in; unsubscribe mechanism provided in every email |
| Responding to support and complaints | Contract / Legitimate interests | Necessary to resolve your enquiry or our obligations arising from it |
| Compliance with legal requests (law enforcement, courts) | Legal obligation (Art. 6(1)(c)) | Processing required by applicable law or court order |
8. Payments & Checkout
8.1 Picwave uses an authorised, PCI-DSS compliant payment service provider (“PSP”) to handle all card transactions. When you enter your card details at checkout, that information is submitted directly to the PSP’s secure environment and is not transmitted to or stored on Picwave’s servers.
8.2 Picwave receives from the PSP only: a transaction reference number; confirmation of success or failure; the card type (e.g. Visa, Mastercard); and the last four digits of the card for your reference in your order history.
8.3 Where required by law (e.g. under EU Strong Customer Authentication rules), the PSP may require additional verification steps (such as 3-D Secure) before completing a transaction. These processes are managed entirely by the PSP.
8.4 Picwave retains transaction metadata for accounting, legal compliance, and dispute resolution purposes in accordance with the Retention Schedule in Schedule 1 below.
9. Cookies & Similar Technologies
9.1 Picwave uses cookies and similar tracking technologies on the Service. A full description of the cookies we use, their purposes, durations, and the consent mechanism is set out in our Cookie Policy at pic-wave.com.
9.2 In summary: strictly necessary cookies are used without consent (as they are essential for the website to function); all other cookies — including analytics, functional, and marketing cookies — require your prior consent, collected via our cookie consent banner. You can withdraw or modify your consent at any time through the cookie settings on the website or your browser settings.
10. Sharing of Personal Data
10.1 Picwave does not sell, rent, or trade your personal data. We share personal data only in the following limited circumstances:
- Payment service provider: to process your transactions. The PSP acts as an independent data controller for its own processing and is subject to its own privacy policy and PCI-DSS obligations.
- Analytics and measurement providers: to help us understand website usage. These providers process data on our behalf as data processors and are bound by data processing agreements.
- Hosting and infrastructure providers: our website and platform are hosted on cloud infrastructure. Hosting providers process data on our behalf and are bound by contractual obligations to protect it.
- Translation services: TranslatePress, as a WordPress plugin, may process page content to provide the Turkish-language version of the site. It does not process personal data entered by users.
- Legal and regulatory bodies: where required by law, court order, or regulatory authority (such as the Estonian Data Protection Inspectorate or tax authorities), we may disclose data as required.
- Business transfers: in the event of a merger, acquisition, or sale of Picwave or its assets, personal data may be transferred to the successor entity, subject to equivalent privacy protections.
11. International Transfers
11.1 Company name is established in Estonia (EU/EEA). When personal data is processed by service providers located outside the EEA, we ensure that appropriate safeguards are in place, as required by Chapter V of the GDPR.
11.2 Where transfers occur to countries without an EU adequacy decision, we rely on: (a) Standard Contractual Clauses (SCCs) adopted by the European Commission; or (b) other approved transfer mechanisms.
11.3 Specific providers and their transfer locations are listed below to the extent known:
- Payment service provider: may operate in the USA or other non-EEA jurisdictions; SCCs or equivalent safeguards apply.
- Analytics providers (e.g. Google Analytics, if used): may process data in the USA; subject to Google’s privacy terms and applicable transfer mechanisms.
- Cloud hosting provider: hosting location to be confirmed; appropriate safeguards applied.
11.4 You may request further information about specific international transfer mechanisms by contacting us at info@pic-wave.com.
12. Data Retention
12.1 We retain personal data only for as long as necessary for the purposes for which it was collected, or as required by law. The following table provides our retention schedule.
| Data category | Retention period | Trigger / criterion |
| Account data (name, email, password hash) | Duration of account + 2 years | Closure of Account; extended period for legal claims |
| Transaction and order records (order details, amounts, product) | 7 years from transaction date | Estonian accounting and tax law retention requirement |
| Payment metadata (last four digits, transaction reference) | 7 years from transaction date | Accounting and dispute resolution; required by financial regulation |
| Token balance records | Duration of account or until balance consumed | Account closure or exhaustion of balance; 7 years for audit trail |
| Support and communications records | 3 years from closure of support ticket | Resolution of disputes and quality assurance |
| Prompt data (Generate Module inputs) | 90 days from generation date | Safety monitoring and technical debugging; anonymised thereafter |
| Server logs and technical data | 12 months on a rolling basis | Security monitoring and incident investigation |
| Cookie consent records | 3 years from consent date | GDPR accountability obligation; evidence of valid consent |
| Marketing consent records | Until withdrawal of consent + 3 years | Accountability; evidence of valid consent for marketing sends |
| Data retained for legal proceedings | Duration of proceedings + applicable limitation period | Legal obligation; legitimate interest in defending claims |
13. Data Security
13.1 Picwave implements appropriate technical and organisational security measures designed to protect your personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure, or access. These include: encrypted transmission (TLS/HTTPS); hashed storage of passwords (not stored in plain text); access controls limiting data access to authorised personnel; regular security reviews of our platform and data practices; and contractual security obligations on our data processors.
13.2 Despite these measures, no system is entirely immune from security risks. We will notify you and the relevant supervisory authority of any personal data breach where required by law (within 72 hours of becoming aware of a qualifying breach, as required by GDPR Article 33).
13.3 You are responsible for maintaining the security of your Account credentials. We will never ask you for your password by email or phone.
14. Your Privacy Rights
14.1 As a data subject under GDPR, you have the following rights in respect of your personal data:
- Right of access (Art. 15): to obtain confirmation of whether we hold data about you and to receive a copy of that data.
- Right to rectification (Art. 16): to have inaccurate or incomplete data corrected or completed.
- Right to erasure / ‘right to be forgotten’ (Art. 17): to request deletion of your data where it is no longer necessary for the purpose for which it was collected, you withdraw consent (where consent is the basis), or other GDPR grounds apply.
- Right to restriction of processing (Art. 18): to request that we limit our processing of your data in certain circumstances.
- Right to data portability (Art. 20): to receive your data in a structured, commonly used, machine-readable format and to transmit it to another controller.
- Right to object (Art. 21): to object to processing based on legitimate interests or direct marketing.
- Rights regarding automated decision-making (Art. 22): to not be subject to solely automated decisions that produce legal or similarly significant effects, unless permitted by law.
- Right to withdraw consent: where processing is based on consent, to withdraw that consent at any time without affecting the lawfulness of prior processing.
- Right to lodge a complaint: with the Estonian Data Protection Inspectorate (https://www.aki.ee) or the supervisory authority in your country of residence.
14.2 To exercise any of these rights, contact us at info@pic-wave.com, marking your request “Privacy / Data Request”. We will respond within 30 days. We may request proof of identity to verify your request. In complex or multiple requests, the response period may be extended by up to two further months, with notification.
15. Marketing Communications
15.1 We will only send you marketing or promotional emails if you have explicitly consented to receive them (opt-in). You can withdraw your consent at any time by clicking the “unsubscribe” link in any marketing email or by contacting us at info@pic-wave.com.
15.2 Transactional emails (order confirmations, account notifications, delivery notices, password reset emails) are not marketing communications and will be sent regardless of marketing preferences, as they are necessary for the performance of your contract with us.
15.3 We will not share your email address with third parties for their own marketing purposes.
16. Automated Decision-Making & Profiling
16.1 Picwave uses automated processes to assist with fraud detection and order review. These processes analyse transaction signals (such as velocity, card details, and IP address) to identify potentially fraudulent activity. Where an automated process flags a transaction, it is subject to manual review before any final decision (such as blocking an order) is taken.
16.2 Picwave does not use fully automated decision-making that produces legal or similarly significant effects on users without human oversight.
16.3 Picwave does not engage in systematic profiling of users for targeted advertising purposes. Analytics data is used only to understand aggregate usage patterns and improve the Service.
17. Third-Party Services & Links
17.1 The Service may contain links to third-party websites or embed third-party services (for example, payment processing interfaces or analytics tools). Picwave is not responsible for the privacy practices, content, or data handling of these third parties. We encourage you to review the privacy policies of any third-party services you access through the Service.
17.2 Third-party cookies set by embedded services are described in our Cookie Policy.
18. Changes to this Policy
18.1 Picwave may update this Privacy Policy from time to time to reflect changes in law, our practices, or the Service. The updated date shown in the document header indicates when the Policy was last revised.
18.2 Material changes — those that significantly affect your rights or our practices — will be communicated to you by email at least 14 days before they take effect. For non-material changes (such as clarifications or contact detail updates), the updated Policy will be posted on the website and the version date will be updated.
18.3 Your continued use of the Service after the effective date of an updated Policy constitutes acceptance of the updated Policy. If you do not accept the changes, you should stop using the Service and contact us to close your Account.
19. How to Contact Us / Submit a Request
19.1 For any privacy-related matter — including subject access requests, data deletion, consent withdrawal, or general queries — please contact:
Company name | Privacy Team | info@pic-wave.com
Subject line: “Privacy / Data Request” or “Data Subject Request”
19.2 We will acknowledge your request promptly and respond in full within 30 days. For complex or multiple requests, we may extend this by up to a further two months, with prior notification.
19.3 If you are not satisfied with our response, you have the right to complain to:
- The Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon): https://www.aki.ee / info@aki.ee
- The supervisory authority of your EU country of residence (if different from Estonia).
- The European Data Protection Board: https://edpb.europa.eu
Schedule 1 — Practical Retention Guide
This Schedule provides a quick-reference summary of how long Picwave keeps your data, and what that means for you.
What data does Picwave hold about me?
If you have an Account: your email address, purchase history, Token balance, and prompt logs (for 90 days). If you have contacted support: the content of those communications for 3 years. Financial records relating to your purchases are kept for 7 years as required by accounting law.
When is my data deleted?
Most account data is deleted 2 years after Account closure. Financial records (transaction amounts, dates, references) must be retained for 7 years regardless of Account status. Prompt data is deleted after 90 days. Server logs roll after 12 months.
How do I request deletion of my data?
Email info@pic-wave.com with subject “Erasure Request” and your Account email address. We will confirm what data can be deleted immediately, what is subject to legal retention obligations (and therefore cannot be deleted early), and when deletion will be completed.
What if I want a copy of my data?
Email info@pic-wave.com with subject “Subject Access Request” and your Account email. We will provide a copy of all personal data we hold about you within 30 days, in a commonly used electronic format.
Can Picwave keep my data after I close my Account?
Yes, where required by law. Financial transaction records must be kept for 7 years under Estonian accounting law. All other data subject to that legal obligation will be deleted as soon as the retention period expires. Data kept solely for legal compliance is not used for any other purpose.
Picwave · Privacy Policy · v1.0 · Effective 28 June 2026. Published at pic-wave.com. This document is subject to update; the current published version governs. Operated by Company name, address. Company no. Company number.