Privacy Policy

Last updated: May 1, 2026

Tamo Design sp. z o.o. ('Tamo Design', 'we', 'us') respects your privacy. This Privacy Policy explains what personal data we collect when you use tamo-design.com and our services, why we collect it, how we use it, and your rights under the EU General Data Protection Regulation (GDPR) and other applicable laws.

1. Data controller

The data controller is Tamo Design sp. z o.o., Al. Zwycięstwa 220, 81-547 Gdynia, Poland. You can reach our privacy team at [email protected].

2. What data we collect

We collect: (a) account data — name, email, password hash, billing country; (b) billing data — masked card details processed by our PSP, invoices, VAT identifiers; (c) content data — URLs you submit, generated ads, prompts, uploads; (d) usage data — IP address, device, browser, pages viewed, feature events; (e) communications — support tickets, chat transcripts, surveys.

3. Why we use it (legal bases)

We process data to (i) provide the service (contract performance), (ii) bill, prevent fraud and comply with tax law (legal obligation), (iii) improve and secure the product, send service messages, and market similar features to existing customers (legitimate interests), and (iv) send marketing to prospects and place non-essential cookies (consent).

4. How long we keep it

Account and content data are kept while your account is active and for up to 90 days after deletion. Invoices are kept 5 years for tax compliance. Server logs are kept up to 12 months. Marketing data is kept until you unsubscribe.

5. Sharing and sub-processors

We share data with processors that help us run the service: cloud hosting, payment processors, email delivery, analytics, AI inference providers, and customer support tooling. A current list is available on request. All sub-processors are bound by data-processing agreements and, where applicable, EU Standard Contractual Clauses.

6. International transfers

Some sub-processors are located outside the EEA. We rely on adequacy decisions, EU Standard Contractual Clauses and supplementary safeguards to protect your data when it leaves the EEA.

7. Your rights

You have the right to access, rectify, erase, restrict or port your personal data, to object to processing based on legitimate interests, and to withdraw consent at any time. You can exercise these rights by emailing [email protected]. You also have the right to lodge a complaint with the Polish Personal Data Protection Office (UODO).

8. Security

We protect your data with TLS in transit, encryption at rest, role-based access, audit logging, and regular security reviews. No system is perfectly secure — please use a strong, unique password and enable any available account-security features.

9. Children

The service is not intended for users under 16. We do not knowingly collect data from children.

10. Changes

We may update this policy from time to time. We will notify you of material changes by email or in-app notice at least 14 days before they take effect.

Questions about this policy? Contact us at [email protected].