Legal

Privacy Policy

This page explains what personal data BE3D sp. z o.o. collects when you buy credits and generate apparel designs, why we need it, how long we keep it and the choices you have. It is maintained by BE3D sp. z o.o. and written to be read, not skimmed past.

Last updated 4 August 2026

01

Who we are

BE3D sp. z o.o. operates this website and the credit-based design platform behind it. For the purposes of the GDPR and the UK GDPR we are the data controller for the account, billing and design data described below.

You can reach our privacy team at [email protected], by phone on +48 17 852 52 45, or by post at BE3D sp. z o.o., Józefa Ignacego Kraszewskiego 2/14, 35-016 Rzeszów, Poland; we answer privacy requests within 30 days.

02

Data we collect

Account data: first name, last name, email address and a hashed password, all supplied by you at checkout.

Order data: credit quantity, currency, promotional code, chosen payment method, order status and timestamps. For bank transfers we also process the payment reference that appears on the incoming transfer.

Design data: the prompts, reference uploads and generated files associated with your account, so you can re-download production files later.

Technical data: IP address, browser and device type, and pages visited — used for security, fraud prevention and aggregate traffic statistics.

03

Why we process it

To perform our contract with you: creating your account, allocating credits, running the design services you spend credits on and delivering files.

To meet legal obligations: retaining invoices and tax records for the periods required by accounting law.

For our legitimate interests: preventing abuse of the platform, securing accounts and improving service quality. You can object to processing based on legitimate interests at any time.

04

Payments and bank transfers

Bank transfer is currently the only active payment method. When you place an order we email our banking details and a unique reference to the address on your account; we never ask for your card numbers or online banking credentials.

Card, PayPal and Stripe payments are not yet enabled. When they launch, card data will be handled directly by the payment provider and never stored on our servers.

05

Sharing and processors

We share data only with service providers that help us run the platform — hosting, email delivery, error monitoring and accounting — each bound by a data processing agreement and permitted to use the data only on our instructions.

We do not sell personal data and we do not share it with advertising networks.

06

International transfers

Where a processor operates outside the European Economic Area, transfers are covered by the European Commission's Standard Contractual Clauses together with supplementary technical measures such as encryption in transit and at rest.

07

Retention

Account and design data are kept while your account is open and for 12 months after you close it, so that accidental deletions can be reversed. Invoices and payment records are retained for the statutory period, typically up to 10 years.

Technical logs are kept for 90 days.

08

Your rights

You have the right to access, correct, delete, restrict and port your data, to object to certain processing, and to withdraw consent where consent is the legal basis. Exercising any of these rights is free of charge.

If you believe we have handled your data incorrectly you may also lodge a complaint with your national data protection authority.

09

Security

Passwords are stored only as salted hashes, traffic is encrypted with TLS, and access to production data is limited to the small number of staff who need it. Suspected incidents are investigated immediately and, where required, reported to the relevant authority within 72 hours.

10

Changes to this policy

When we make material changes we update the date at the top of this page and notify account holders by email before the change takes effect.

Questions about this document? Contact our team.