Privacy Policy
Last updated: May 1, 2026
Tamo Design sp. z o.o. ('Tamo Design', 'we', 'us') respects your privacy. This Privacy Policy explains what personal data we collect when you use tamo-design.com and our services, why we collect it, how we use it, and your rights under the EU General Data Protection Regulation (GDPR) and other applicable laws.
1. Data controller
The data controller is Tamo Design sp. z o.o., Al. Zwycięstwa 220, 81-547 Gdynia, Poland. You can reach our privacy team at [email protected].
2. What data we collect
We collect: (a) account data — name, email, password hash, billing country; (b) billing data — masked card details processed by our PSP, invoices, VAT identifiers; (c) content data — URLs you submit, generated ads, prompts, uploads; (d) usage data — IP address, device, browser, pages viewed, feature events; (e) communications — support tickets, chat transcripts, surveys.
3. Why we use it (legal bases)
We process data to (i) provide the service (contract performance), (ii) bill, prevent fraud and comply with tax law (legal obligation), (iii) improve and secure the product, send service messages, and market similar features to existing customers (legitimate interests), and (iv) send marketing to prospects and place non-essential cookies (consent).
4. How long we keep it
Account and content data are kept while your account is active and for up to 90 days after deletion. Invoices are kept 5 years for tax compliance. Server logs are kept up to 12 months. Marketing data is kept until you unsubscribe.
5. Sharing and sub-processors
We share data with processors that help us run the service: cloud hosting, payment processors, email delivery, analytics, AI inference providers, and customer support tooling. A current list is available on request. All sub-processors are bound by data-processing agreements and, where applicable, EU Standard Contractual Clauses.
6. International transfers
Some sub-processors are located outside the EEA. We rely on adequacy decisions, EU Standard Contractual Clauses and supplementary safeguards to protect your data when it leaves the EEA.
7. Your rights
You have the right to access, rectify, erase, restrict or port your personal data, to object to processing based on legitimate interests, and to withdraw consent at any time. You can exercise these rights by emailing [email protected]. You also have the right to lodge a complaint with the Polish Personal Data Protection Office (UODO).
8. Security
We protect your data with TLS in transit, encryption at rest, role-based access, audit logging, and regular security reviews. No system is perfectly secure — please use a strong, unique password and enable any available account-security features.
9. Children
The service is not intended for users under 16. We do not knowingly collect data from children.
10. Changes
We may update this policy from time to time. We will notify you of material changes by email or in-app notice at least 14 days before they take effect.