1. Introduction

ENTRYRISE S.R.L., operating as LogoLabs ("we", "us", or "our"), is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our website and AI-powered logo design services.

We comply with the General Data Protection Regulation (GDPR) and Romanian data protection laws.

2. Data Controller

The data controller responsible for your personal data is:

  • Company: ENTRYRISE S.R.L.
  • Address: Bucovina, Bl. D 18, Sc. A, Et. 0, Ap. 2, 725300 Gura Humorului, Suceava, Romania
  • Tax ID (CIF): 43541700
  • Trade Register: J33/46/2021
  • Privacy Contact: [email protected]

As a small business with fewer than 250 employees, we are not required to appoint a Data Protection Officer. For all privacy inquiries, please contact [email protected].

3. Information We Collect

3.1 Information You Provide

  • Account Information: Name, email address
  • Business Information: Business name, industry, brand requirements, target audience, style preferences, color preferences
  • Billing Information: Billing address, country, VAT number (if applicable)
  • Communication: Messages, feedback, revision requests, and conversation history during the design process
  • Uploaded Content: Any images or files you upload for reference

3.2 Information Collected Automatically

  • Device Information: Browser type, operating system, device type
  • Usage Data: Pages visited, time spent, actions taken
  • Session Data: Form progress, conversation history during onboarding (stored locally in your browser and synced to our servers)
  • Referral Data: How you found us (referrer URL, UTM parameters)

3.3 Information from Third Parties

  • Payment Processor: We receive payment confirmation and billing details from Stripe (we do not receive or store your full card details)

4. How We Use Your Information

We use your personal data for the following purposes:

  • Service Delivery: To process orders, generate logos using AI, and deliver files
  • AI Processing: To send your brand requirements to our AI providers for logo generation (see Section 6)
  • Communication: To send order updates, respond to inquiries, and provide support
  • Billing: To process payments and generate invoices
  • Legal Compliance: To comply with legal obligations including tax requirements
  • Service Improvement: To analyze usage patterns and improve our services
  • Session Recovery: To allow you to resume incomplete orders

5. Legal Basis for Processing (GDPR)

We process your personal data based on:

  • Contract Performance: Processing necessary to fulfill our service agreement with you (generating logos, delivering files, processing payments)
  • Legal Obligation: Processing required by law (tax records, invoicing, 7-year retention for accounting)
  • Legitimate Interest: Service improvement, fraud prevention, security, and internal analytics
  • Consent: Marketing communications (where applicable)

6. AI Data Processing

Important: Our logo design service uses artificial intelligence. Here's how your data is processed:

6.1 What Data is Sent to AI Providers

  • Business name and description
  • Industry and target audience
  • Style preferences and color choices
  • Revision feedback and conversation history
  • Uploaded reference images (if any)

6.2 Our AI Provider

We use OpenRouter API (operated by OpenRouter Inc., USA) to access AI models for conversation and logo generation. OpenRouter acts as a data processor under our instructions.

6.3 AI Training

Your data is NOT used to train AI models. The AI providers we use have confirmed that data submitted through their APIs is not used for model training. Your brand information and generated logos remain confidential.

7. Data Sharing and Third-Party Processors

We share your information with the following categories of recipients:

We may also share data with:

  • Legal Requirements: When required by law, court order, or governmental authority
  • Business Transfers: In connection with a merger, acquisition, or sale of assets (you will be notified)

We do not sell your personal data to third parties.

8. International Data Transfers

Your data may be transferred to and processed in countries outside the European Economic Area (EEA), specifically the United States (for Stripe and OpenRouter). When this occurs, we ensure appropriate safeguards are in place:

  • Standard Contractual Clauses (SCCs): EU-approved contractual terms that bind recipients to protect your data
  • EU-US Data Privacy Framework: For US companies certified under the framework (such as Stripe)

You can request a copy of the safeguards in place by contacting [email protected].

9. Data Retention

We retain your personal data for the following periods:

  • Account Data: Until you request deletion, plus 30-day grace period
  • Order Data: 7 years from order date (legal/tax requirements under Romanian law)
  • Conversation History: Retained with order data for support purposes
  • Incomplete Sessions: 30 days after abandonment, then automatically deleted
  • Communication Records: 3 years after the last interaction
  • Marketing Preferences: Until you withdraw consent

10. Your Rights (GDPR)

Under the GDPR, you have the following rights:

  • Right to Access: Request a copy of your personal data
  • Right to Rectification: Request correction of inaccurate data
  • Right to Erasure: Request deletion of your data ("right to be forgotten")
  • Right to Restriction: Request limitation of processing
  • Right to Data Portability: Receive your data in a structured format
  • Right to Object: Object to certain processing activities
  • Right to Withdraw Consent: Where processing is based on consent

To exercise these rights, visit your account settings dashboard or contact us at [email protected]. We will respond within 30 days. For complex requests, we may extend this by an additional 60 days (we will inform you if this is necessary).

11. Data Security

We implement appropriate technical and organizational measures to protect your personal data, including:

  • Encryption of data in transit (TLS/SSL)
  • Secure password hashing (bcrypt)
  • Access controls and authentication
  • Regular security assessments
  • UUID-based identifiers (non-sequential)

12. Cookies and Local Storage

We use cookies and browser local storage. Local storage is used to save your form progress so you can resume incomplete orders. This data stays in your browser until you complete or abandon the order.

For detailed information, please see our Cookie Policy.

13. Children's Privacy

Our Service is not intended for children under 16 years of age. We do not knowingly collect personal data from children. If you believe we have collected data from a child, please contact us immediately at [email protected].

14. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of any material changes by posting the new policy on this page and updating the "Last updated" date. For significant changes, we may also notify you by email.

15. Supervisory Authority

If you are not satisfied with our response to a privacy concern, you have the right to lodge a complaint with:

  • Romanian Supervisory Authority: Autoritatea Nationala de Supraveghere a Prelucrarii Datelor cu Caracter Personal (ANSPDCP) - www.dataprotection.ro
  • Your Local Authority: You may also contact the data protection authority in your country of residence

16. Contact Us

For questions about this Privacy Policy or your personal data:

  • Email: [email protected]
  • Company: ENTRYRISE S.R.L.
  • Address: Bucovina, Bl. D 18, Sc. A, Et. 0, Ap. 2, 725300 Gura Humorului, Suceava, Romania