1. Who we are
Gigilau (“Gigilau”, “we”, “us”) operates the Gigilau AI platform at gigilau.com, which provides AI text, image, voice and code generation. For the purposes of the EU General Data Protection Regulation (GDPR) and the UK GDPR, Gigilau is the data controller for the personal data described in this policy.
You can reach our data protection contact at [email protected].
2. What data we collect
We collect only what we need to run the service:
- Account data — name, email address, password hash, and the plan you are on.
- Billing data — company name, billing address and VAT number. Card details are handled by our payment processor and never touch Gigilau servers.
- Prompts and generated content — the text, images, audio and code you create with Gigilau AI, stored so you can find your work again.
- Uploads — reference images, documents or audio you provide to a Gigilau AI tool.
- Usage data — which features you use and how often, generation counts, and error logs.
- Technical data — IP address, browser type, device type, and approximate location derived from IP.
- Communications — messages you send us through the contact form or by email.
3. How we use your data
We process personal data on these legal bases:
- Performance of a contract — to create and maintain your account, run Gigilau AI generations, store your projects, and take payment.
- Legitimate interests — to keep the platform secure, prevent abuse and fraud, debug problems, and understand aggregate product usage.
- Consent — for analytics cookies and for marketing email. You can withdraw consent at any time without affecting anything you did before.
- Legal obligation — to keep accounting records and to respond to lawful requests.
We do not train Gigilau AI models on your prompts, uploads or generated output. Your content is processed to produce your result and then stored for you — not folded into a training set. Where a Gigilau AI feature is served by a third-party model provider, we use zero-retention API terms that prohibit training on your data.
4. Cookies
Gigilau uses a small number of cookies and similar technologies. The banner you saw on your first visit lets you accept or decline the non-essential ones, and your choice is stored in your browser.
- Strictly necessary — session and authentication cookies, CSRF protection, and the record of your cookie choice. These cannot be switched off because the site does not work without them.
- Analytics — privacy-focused, aggregated statistics about page visits and feature use. Set only if you press Accept.
- Preferences — remembering interface settings such as your last-used Gigilau AI tool.
We do not use advertising or cross-site tracking cookies. You can clear stored choices at any time through your browser settings, and the banner will reappear on your next visit.
5. Third parties we share data with
We share data only with processors who help us run the service, each under a written data processing agreement:
- Cloud hosting and storage providers in the EU and the United States.
- Payment processing for subscriptions and invoicing.
- Model inference providers for certain Gigilau AI features, under zero-retention, no-training terms.
- Email delivery for transactional messages such as password resets.
- Customer support tooling for handling your tickets.
We never sell personal data. Where data leaves the European Economic Area, transfers are covered by the European Commission’s Standard Contractual Clauses together with supplementary technical measures.
6. How long we keep it
- Account data — for as long as your account is open, then deleted within 30 days of closure.
- Prompts and generated content — until you delete them, or 30 days after account closure.
- Uploads — 90 days after the generation they were used for, unless you saved them to a project.
- Billing records — seven years, because tax law requires it.
- Security and error logs — 12 months.
7. Your rights
Under the GDPR you can ask us to:
- give you a copy of the personal data we hold about you (access and portability);
- correct data that is wrong or incomplete (rectification);
- delete your data (erasure);
- restrict or object to certain processing;
- withdraw a consent you previously gave.
Write to [email protected] and we will respond within 30 days. If you are unhappy with our answer you may complain to your national data protection authority.
8. Security
Data is encrypted in transit with TLS 1.3 and at rest with AES-256. Access to production systems requires multi-factor authentication and is limited to staff who need it, with access logged. We run regular third-party penetration tests and will notify affected users and the relevant supervisory authority within 72 hours of becoming aware of a qualifying personal data breach.
9. Children
Gigilau is not intended for children. You must be at least 16 years old to create a Gigilau account, or older where your country sets a higher age of digital consent. If we learn that we have collected data from a child below that age, we delete it.
10. Changes to this policy
We may update this policy as the Gigilau AI platform changes. Material changes are announced by email and on this page at least 14 days before they take effect. The date at the top of the page always shows the current version.