Legal
Privacy Policy
Effective July 30, 2026
1. Application and controller
Application: VivaCreo
Website: https://vivacreo.com
Operator and controller: REexcellent GmbH
VivaCreo is the AI creative application available at https://vivacreo.com. REexcellent GmbH operates the application and is the controller for the processing described in this policy.
Ottweilerstraße 1581737 München
Germany
Email: help@vivacreo.com
2. Website delivery and security logs
When you request a page, the server receives IP address, date and time, requested resource, response status, transferred bytes, referrer where supplied, and browser/device headers. We process these data to deliver the site, maintain availability, prevent abuse, rate-limit requests and investigate security incidents under Article 6(1)(b) GDPR where necessary to provide requested access and Article 6(1)(f) GDPR for our legitimate interests in secure and reliable operations. Hosting and project files are provided through Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Germany.
Data-centre location: Germany. The main application server, database and project-controlled media storage are hosted in Germany.
3. Accounts and authentication
For email registration we process name, chosen VivaCreo username, email address, password hash, verification and login timestamps, account status, locale, currency, timezone, preferences, sessions and security events. The legal basis is performance of the user contract and pre-contract steps (Article 6(1)(b) GDPR), security interests (Article 6(1)(f)) and legal duties where applicable (Article 6(1)(c)).
If you choose “Continue with Google”, VivaCreo receives the Google account identifier, verified email address, display name and optional avatar URL from Google Ireland Limited and applicable Google group companies. We request only the basic authentication scopes needed to create, link and authenticate your VivaCreo account. Google also processes the redirect and authentication request under its own privacy terms. Google sign-in is optional; you can register with email and password instead.
Google user data
VivaCreo uses Google user data only to create or link your account, authenticate sign-ins, display basic account information and protect the account against abuse. The Google identifier, verified email, display name and optional avatar URL are stored with your VivaCreo account in our protected database hosted by Hetzner Online GmbH in Germany.
We do not sell Google user data, use it for advertising or creditworthiness decisions, or use it to train AI models. Google identity data is not sent to Pruna as part of the Google sign-in process. It is disclosed only to infrastructure and security providers where necessary to operate and protect the account, or to authorities where disclosure is legally required.
Google user data is retained while your VivaCreo account remains active. To remove the Google identity associated with VivaCreo, you can request account deletion through Account settings. Account deletion disables access immediately and places the associated Google identity data into the deletion process, subject to legal retention and security requirements.
4. Images, prompts and AI processing
We process uploaded source and reference images, audio, video, prompts, generation parameters, operation identifiers, status/error information and generated outputs to perform the operation you request under Article 6(1)(b) GDPR. Files are stored in protected project storage on the configured Hetzner server. VivaCreo does not provide public profiles, public galleries or public share links for creations.
Inputs required for generation are transmitted to the selected AI inference provider: Pruna receives data for Pruna operations, and Google Vertex AI receives the prompt and optional image for Google operations such as Lyria music generation. The selected provider returns generated output and operational telemetry. Do not upload special-category or highly confidential data unless strictly necessary and lawful. VivaCreo does not use your files to train its own models.
We record your acceptance of the Content Rules before the first generation under the version in force, including the time and keyed security hashes of the IP address and user agent. This serves contract documentation, safety enforcement and fraud prevention under Article 6(1)(b) and Article 6(1)(f) GDPR.
5. Billing and payments
We process orders, product and pricing version, currency, amounts, tax totals, Stripe customer and transaction references, subscription status, credit ledger entries, consent time and keyed hashes of IP address and user-agent for contract evidence and fraud prevention. Legal bases are contract performance (Article 6(1)(b)), legal accounting and tax duties (Article 6(1)(c)) and fraud/security interests (Article 6(1)(f)).
Checkout is provided by Stripe Payments Europe, Limited and applicable Stripe group companies. Stripe may receive name, email, billing address, tax identifiers, payment details, IP/device information and transaction data and may act as processor or independent controller for regulated payment, compliance and fraud functions. VivaCreo does not store full card numbers.
6. Support and transactional email
We process support messages, attachments, ticket status and account/order context to answer requests and protect legal claims under Articles 6(1)(b) and 6(1)(f) GDPR. Verification, password reset, security, billing and service messages are sent through Hetzner Online GmbH. Marketing email remains optional and uses a separate lawful opt-in where required.
7. First-party, cookieless analytics
We operate internal analytics on our own server to understand page visits, registrations, tool usage, operation outcomes, payments and referral sources. The analytics dataset stores canonical route names rather than full URLs, referrer host rather than the full referring URL, campaign values, broad device/browser/OS family, event time and an account ID for signed-in events. Query strings, raw IP addresses, full user-agent strings and cross-site advertising identifiers are not stored in the analytics event table. Recognized bots are counted separately in daily aggregates.
The legal basis is our legitimate interest in measuring and improving the service, detecting operational problems and understanding acquisition without advertising tracking (Article 6(1)(f) GDPR). You may object for reasons arising from your particular situation. If a necessary service session already exists, a short first-touch attribution snapshot may be kept in that server-side session until it expires; VivaCreo does not create a separate analytics identifier or tracking cookie.
8. Cookies and browser storage
VivaCreo uses only storage necessary for a service you request: an encrypted/signed session identifier, CSRF protection and temporary sessionStorage entries for returning to a workflow and caching a pricing response within the browser tab. A small attribution snapshot, when available, is kept inside the same necessary server-side session and is not a separate tracking cookie. These items are not used for advertising or cross-site tracking. Under German law, consent is not required where storage or access is strictly necessary to provide the requested digital service. Details and current lifetimes are listed in the Cookie and Storage Notice.
9. Recipients and international transfers
- Hetzner Online GmbH - hosting, database and protected media storage.
- Pruna AI GmbH and Google Vertex AI (when a Google model is selected) - requested AI inference and temporary file transfer.
- Stripe Payments Europe, Limited and applicable Stripe group companies - checkout, payment, tax, subscription and fraud processing.
- Google Ireland Limited and applicable Google group companies - only when you choose Google authentication.
- Hetzner Online GmbH - transactional email delivery.
- Professional advisers, auditors, authorities and courts where legally required or necessary to establish, exercise or defend legal claims.
Where a recipient processes data outside the EEA, transfers rely on an adequacy decision, the EU Standard Contractual Clauses with supplementary safeguards, or another lawful Chapter V GDPR mechanism. Stripe states that it uses the EU-US Data Privacy Framework where applicable and SCCs as an additional mechanism. Further information can be requested at help@vivacreo.com.
10. Retention and deletion
- Account and preference data: while the account is active. A deletion request disables the account and places its data into the deletion process. Data is then deleted or anonymized after the applicable waiting period, except for records subject to legal retention.
- Source/reference images: until you delete them or, if selected in Privacy settings, after 7, 30, 60 or 90 days once no active operation needs them.
- Generated outputs: until you delete them or request a media purge. Temporary provider and Pruna staging files are eligible for cleanup under the applicable processing workflow.
- Sessions: normally expire after 120 minutes of inactivity.
- Orders, invoices, credit ledger and consent evidence: for the applicable statutory commercial, tax, limitation and fraud-prevention periods.
- Support and security records: for as long as needed to handle the request or incident and then for applicable limitation periods.
- Raw internal analytics: only as long as necessary to create and verify aggregate statistics. Aggregated statistics may be retained longer where they no longer identify a person.
- Backups: until overwritten under the documented backup rotation; deleted data is not restored to the live service except for disaster recovery.
Deletion can be delayed where data is needed for an active transaction, legal hold, security investigation or statutory retention duty. It is then restricted to that purpose.
11. Your rights
Subject to legal conditions, you may request access (Article 15), rectification (16), erasure (17), restriction (18), portability (20) and object to processing based on legitimate interests (21). Where processing relies on consent, you may withdraw it prospectively at any time. You may lodge a complaint with a supervisory authority, especially in the EEA state of your habitual residence, workplace or the alleged infringement.
You can export core account data and request media or account deletion in Account settings , or contact help@vivacreo.com . We may need proportionate information to verify identity. The competent supervisory authority is Bayerisches Landesamt für Datenschutzaufsicht (BayLDA), Promenade 18, 91522 Ansbach.
12. Required data and automated decisions
Account email, credentials or an OAuth identity and the data required for a selected operation are contractual requirements; without them we cannot provide that feature. Optional profile fields, Google sign-in and marketing preferences are not required. VivaCreo does not make decisions based solely on personal data that produce legal or similarly significant effects within Article 22 GDPR. AI image generation is initiated and configured by you and does not decide your legal rights.
13. Security, children and changes
We use access controls, owner-scoped records, signed protected downloads, hashed evidence fields, rate limits and operational safeguards. No service can guarantee absolute security. VivaCreo is not directed to persons under 18. If you believe a child supplied data, contact us for review.
We will update the effective date when this policy changes and provide additional notice where a change materially affects existing processing or requires consent.
14. Contact
Privacy requests: help@vivacreo.com. Postal requests may be sent to the controller address in section 1. General support is available through the Help page.