Privacy Policy
This Privacy Policy explains how Bamboe VOF (“Timagine”, “we”, “us”) processes personal data when you use the Timagine service. We are the data controller for the personal data described below. We process personal data in line with the EU General Data Protection Regulation (GDPR).
1. Who we are
Bamboe VOF, Merendreedorp 75, 9850 Deinze, Belgium. VAT BE 0711.718.494. For any privacy question, contact kasper@timagine.app.
2. What data we process
- Account & identity — your name, email address, and organisation membership, handled through our authentication provider.
- Content you upload — 3D renders, photos, material samples, and project information, plus the AI images generated from them. These may incidentally contain personal data (for example a customer’s home interior).
- Billing data — plan, credit balance, and the customer and subscription identifiers from our payment provider. We do not store full card details; payments are handled by Stripe.
- Usage & technical data — log data, approximate location from IP, device/browser information, and error reports used to run, secure, and improve the Service.
3. Why we process it, and our legal bases
- To provide the Service (accounts, uploads, generating outputs, billing) — performance of our contract with you (Art. 6(1)(b)).
- To secure and improve the Service, prevent abuse and fraud, and monitor errors — our legitimate interests (Art. 6(1)(f)).
- To meet legal obligations, such as keeping accounting and invoice records — legal obligation (Art. 6(1)(c)).
- Non-essential cookies, where used — your consent (Art. 6(1)(a)). See our Cookie Policy.
4. Sub-processors and recipients
We share personal data with the service providers we use to run Timagine. Each is bound by a data-processing agreement and processes data only on our instructions:
| Provider | Purpose | Region |
|---|---|---|
| Clerk | Authentication & account management | United States |
| Supabase | Database & file storage | EU (Frankfurt) |
| Stripe | Payments & invoicing | EU / United States |
| kie.ai | AI image generation (processes your uploads) | Outside the EEA |
| AI analysis of material samples | EU / United States | |
| Inngest | Background job orchestration | United States |
| Sentry | Error monitoring | EU (Frankfurt) |
| Vercel | Application hosting & CDN | United States / global edge |
To generate Outputs, the content you upload is sent to the AI providers above. We do not sell your personal data, and we do not use Your Content to train our own or third parties’ models.
5. International transfers
Some providers are located outside the European Economic Area (notably in the United States). Where data is transferred outside the EEA, we rely on appropriate safeguards such as the European Commission’s Standard Contractual Clauses or an adequacy decision.
6. How long we keep data
We keep account and content data while your account is active and for as long as needed to provide the Service. When you close your account, we delete or anonymise your content within a reasonable period, except where we must keep certain records longer to comply with the law (for example, invoices are retained for the statutory accounting period, which in Belgium is generally seven years).
7. Your rights
Subject to the conditions in the GDPR, you have the right to access, rectify, erase, restrict, and port your personal data, and to object to certain processing. Where processing is based on consent, you can withdraw it at any time. To exercise these rights, email kasper@timagine.app.
You also have the right to lodge a complaint with the Belgian Data Protection Authority (Gegevensbeschermingsautoriteit / Autorité de protection des données), Drukpersstraat 35, 1000 Brussels — dataprotectionauthority.be.
8. When we act as your processor
When you upload content that contains personal data of your own clients, you are the controller of that data and we act as your processor. We process it only to provide the Service to you. A data-processing agreement (DPA) is available on request at kasper@timagine.app.
9. Security
We apply appropriate technical and organisational measures to protect personal data, including access controls, tenant isolation, encryption in transit, and storage of core data in the EU. No system is perfectly secure, but we work to keep your data safe.
10. Changes to this policy
We may update this Privacy Policy from time to time. We will update the date above and, for material changes, take reasonable steps to notify you.