PRIVACY POLICY

for the Neurogen service (neurogen.pro)
Martekings OY (Business ID: 3327882-6)
Työpajankatu 17 A 207, 00580 Helsinki, Finland

Last updated: July 23, 2025

1. GENERAL PROVISIONS

1.1. This Privacy Policy (hereinafter "Policy") is compiled in accordance with the requirements of the EU General Data Protection Regulation (GDPR) and Finnish personal data protection legislation, and defines the procedure for processing personal data and measures to ensure the security of personal data undertaken by Martekings OY (hereinafter "Controller", "Service").

1.2. The Controller considers compliance with the rights and freedoms of individuals in the processing of their personal data, including protection of the right to privacy, as its most important goal and condition for carrying out its activities.

1.3. This Policy applies to all information that the Controller may obtain about Users of the Neurogen service, available at neurogen.pro, including mobile applications, Telegram bot and API.

1.4. Use of the Neurogen service means unconditional consent of the User to this Policy and the personal data processing conditions specified herein.

2. KEY DEFINITIONS

2.1. Personal Data — any information relating directly or indirectly to an identified or identifiable User of the Neurogen service.
2.2. User/Data Subject — any natural or legal person using the Neurogen service.
2.3. Processing of Personal Data — any operation or set of operations performed on personal data, including collection, recording, organization, structuring, storage, adaptation, retrieval, use, disclosure, transmission, anonymization, blocking, deletion, destruction.
2.4. User Images — photographs and other images uploaded by Users for creating personalized content and training neural network models.
2.5. Anonymization of Personal Data — actions resulting in the impossibility of determining the ownership of personal data to a specific User.

3. CATEGORIES OF PROCESSED PERSONAL DATA

Data Category Data Composition Method of Collection
Mandatory Data • Full name
• Email address
• Phone number
• Payment details (card number, expiry date, CVC code)
Provided by User during registration and payment for services
Technical Data • IP address
• Browser and device data
• Cookies
• Service usage data
Collected automatically when using the service
User Images • Face photos and other images
• EXIF data of uploaded images
• Photo metadata
Uploaded by User for LoRA model creation and content generation
Content Data • Created images and videos
• Edited photos
• Posts in the service's social network
• Comments and interactions
Created when using service functionality

4. PURPOSES AND LEGAL BASIS FOR PROCESSING

Processing Purpose Legal Basis (GDPR) Data Categories
Providing access to service functionality Performance of contract (Art. 6(1)(b)) All data categories
Creating personalized LoRA models Consent (Art. 6(1)(a)) User images
Payment processing and billing Performance of contract (Art. 6(1)(b)) Mandatory data
Technical support and security Legitimate interests (Art. 6(1)(f)) Technical data
Service and algorithm improvement Legitimate interests (Art. 6(1)(f)) Anonymized data
Social network content moderation Performance of contract (Art. 6(1)(b)) Content data
Compliance with legal obligations Legal obligation (Art. 6(1)(c)) All data categories

5. OBTAINING CONSENT FOR PROCESSING

5.1. General consent is obtained by one of the following methods:

5.2. Consent for image upload is obtained when:

6. DATA PROCESSING AND RETENTION PERIODS

Data Category Retention Period Basis
User account data Duration of contractual relationship + 3 years Account recovery possibility and dispute resolution
User images Duration of contractual relationship + 1 year LoRA model functionality and content creation
Payment data As required by Finnish tax legislation (up to 6 years) Tax legislation compliance
Technical logs 12 months Security and technical support
User content 14 days from last access + subscription period Terms of service provision
Anonymized data Until processing purposes are achieved Service algorithm improvement

7. DISCLOSURE OF PERSONAL DATA TO THIRD PARTIES

7.1. User personal data may be transferred to the following categories of recipients:

7.1.1. Payment Systems

7.1.2. Cloud Providers

7.1.3. Government Authorities

7.2. International data transfers are carried out in accordance with GDPR Chapter V requirements when appropriate legal safeguards are in place.

7.3. The Controller enters into data processing agreements with recipients ensuring personal data protection in accordance with EU and Finnish legislation requirements.

8. PERSONAL DATA PROTECTION MEASURES

8.1. Organizational measures:

8.2. Technical measures:

8.3. Legal measures:

9. DATA SUBJECT RIGHTS

9.1. Users have the following rights under GDPR:

9.1.1. Right to Information

9.1.2. Right to Rectification and Erasure

9.1.3. Right to Withdraw Consent

9.1.4. Right to Portability

9.1.5. Right to Object and Lodge Complaints

10. EXERCISING YOUR RIGHTS

10.1. To exercise your rights, Users may:

10.2. The request should contain:

10.3. Request processing times:

11. COOKIES AND SIMILAR TECHNOLOGIES

11.1. The Service uses the following technologies:

11.2. Users can manage cookies through browser settings, however disabling essential cookies may limit service functionality.

11.3. Consent for non-essential cookies is obtained through cookie banners and can be withdrawn at any time through cookie settings.

12. DATA BREACH NOTIFICATION

12.1. In case of personal data breach, the Controller will:

13. CHANGES TO PRIVACY POLICY

13.1. The Controller has the right to make changes to this Policy unilaterally.

13.2. Changes take effect from the moment of posting the new version of the Policy on neurogen.pro.

13.3. Continued use of the service after changes means agreement with the new version of the Policy.

13.4. For significant changes, Users are notified by email at least 7 days before the changes take effect.

14. INTERNATIONAL TRANSFERS

14.1. Personal data may be transferred to countries outside the EU/EEA only when:

14.2. Current international transfers include cloud storage providers in the US under Standard Contractual Clauses with additional safeguards.

15. CONTACT INFORMATION

Data Controller:

Martekings OY

Supervisory Authority:

Finnish Data Protection Authority (Tietosuojavaltuutetun toimisto)