GDPR information

Privacy Notice

Effective 20 July 2026 · Version 2026-07-20

1. Who is responsible for your data

BC Studios Romania operates GENR8 and is the controller for the personal data described in this Notice. Contact: contact@genr8art.com. Website: https://genr8art.com.

We have not appointed a Data Protection Officer; privacy requests can be sent to the contact above.

2. Scope and important distinction

This Notice applies to visitors, account holders, creators, report submitters, and people who communicate with GENR8. It explains personal-data processing; it does not transfer copyright in creator content.

Acknowledging this Notice confirms only that it was presented to you. It is not consent to advertising, marketing, analytics cookies, or AI training.

3. Data we process

  • Account and authentication data: email address, account identifier, authentication status, and password credential managed in hashed form by the authentication provider. GENR8 does not receive your plaintext password.
  • Google sign-in data: Google account identifier, email address, name, and profile image made available through the sign-in flow.
  • Profile data: username, display name, biography, avatar, website, skills, AI tools, availability, membership and founder status, and profile settings.
  • Creator content: uploaded images, video, audio, covers, reference images, workflows, prompts, descriptions, tags, tool and platform labels, licensing choice, albums, and associated metadata.
  • Community activity: follows, likes, comments, views, competition or exhibition activity, reports, moderation outcomes, rewards, and founder applications.
  • Private communications: message text, attachment metadata and files, participants, read state, and timestamps.
  • Technical and security data: IP address and request metadata processed by hosting providers, browser/device information, security events, error traces, performance timings, and limited diagnostic context. Session replay is disabled and Sentry is configured not to send default PII.
  • Support and legal data: correspondence, rights requests, copyright or illegal-content notices, evidence, decisions, and legal-document acceptance records.

4. Where data comes from

Most data comes directly from you or from your use of GENR8. Authentication data may come from Google when you choose Google sign-in. Technical data comes from your device and our service providers. Public opportunity/news sources may be ingested for platform listings; where those records identify a person, the source is the referenced public webpage.

5. Purposes and legal bases

  • Contract (GDPR Article 6(1)(b)): create and authenticate accounts; provide profiles, publishing, private messages, storage, social features, memberships, and requested support; enforce the account agreement.
  • Legitimate interests (Article 6(1)(f)): secure and troubleshoot the Platform; prevent fraud and abuse; maintain service reliability; measure basic product operation; defend legal claims; moderate content; and improve features. We balance these interests against user rights and minimise the data used.
  • Legal obligation (Article 6(1)(c)): respond to valid authority requests, comply with applicable platform and consumer rules, maintain legally required records, and handle qualifying security incidents.
  • Consent (Article 6(1)(a)): used only where we clearly request an optional choice, such as future marketing or non-essential tracking. You may withdraw consent without affecting earlier lawful processing. GENR8 currently does not use creator content to train generative AI models and would require a separate specific opt-in before doing so.

6. Public and private areas

Public profiles and content are available to visitors and may be indexed by search engines unless a route is excluded. Portfolio-only and Licensable posts are public visibility choices; 'Licensable' does not itself grant a licence. Private posts are restricted to their owner and delivered through time-limited access links.

Private messages are intended only for conversation participants and authorised operations staff when access is necessary for security, support, or legal compliance. Do not publish confidential information in a public field.

7. Service providers and recipients

We do not sell personal data. The following providers process limited data for the stated purposes under their own contractual and security terms:

  • Supabase: database, authentication, row-level access controls, and related backend services.
  • Vercel: website hosting, delivery, deployment, and operational request logs.
  • Cloudflare R2: public creator media and access-controlled private media storage and delivery.
  • Sentry: production error and performance monitoring with replay disabled and default PII collection disabled.
  • Google: identity services only when you choose Google sign-in.
  • Professional advisers, authorities, or counterparties only where reasonably necessary for legal obligations, claims, safety, or a corporate transaction subject to appropriate confidentiality safeguards.

8. International transfers

Some providers may process data outside the EEA. Where GDPR Chapter V requires a transfer safeguard, we rely on an applicable adequacy decision, the European Commission's Standard Contractual Clauses with appropriate supplementary measures, or another lawful mechanism. The operator must maintain current Data Processing Agreements and transfer documentation for each provider; contact us for information about the relevant safeguard.

9. Retention

These are retention criteria rather than promises that override legal duties. The operator must keep and periodically review an internal retention schedule with exact system-specific periods before commercial launch.

  • Account and profile data: while the account is active, then removed from active systems when account deletion completes, subject to the exceptions below.
  • Creator content and private messages: until you delete the item or account, or until moderation/legal preservation is required. A conversation participant may retain messages visible in their own lawful records where applicable.
  • Authentication and legal-acceptance records: for the life of the account and afterwards only for the applicable legal-claims or statutory period.
  • Security, hosting, and diagnostic logs: short operational windows set according to security need and provider configuration, followed by deletion or aggregation.
  • Reports, appeals, support, and rights correspondence: until the matter is closed and then for the period reasonably needed for repeat-abuse controls, accountability, or legal claims.
  • Backups: protected residual copies are isolated from normal use and expire through provider backup cycles. They may be restored only for disaster recovery, after which deletion instructions are reapplied.

10. Your GDPR rights

Send requests to contact@genr8art.com. We may request proportionate information to verify identity. We will respond without undue delay and normally within one month; GDPR permits an extension for complex or numerous requests, with notice. Rights can be limited where an applicable legal exception applies.

  • Access your personal data and receive information about its processing.
  • Correct inaccurate or incomplete personal data.
  • Request erasure where the legal conditions apply; account deletion is available in Settings.
  • Request restriction of processing or object to processing based on legitimate interests.
  • Receive data you provided in a structured, commonly used, machine-readable format where portability applies.
  • Withdraw consent at any time for processing based on consent.
  • Complain to your local supervisory authority. The Romanian authority is ANSPDCP (dataprotection.ro).

11. Automated decisions

GENR8 does not make solely automated decisions that produce legal or similarly significant effects about users. Feed ordering, spam signals, or automated security checks may assist the service, but material account or content enforcement should remain reviewable by a person.

12. Security

We use risk-appropriate technical and organisational measures including TLS in transit, provider-managed password hashing, server-only privileged credentials, database row-level access policies, role-based administration, type and size controls on uploads, separate private storage with time-limited signed delivery, monitoring, and controlled deletion paths.

No internet service can guarantee absolute security. Users should keep independent copies of valuable work, choose Private visibility for non-public work, and report suspected account compromise promptly. We assess incidents and notify the competent authority and affected individuals where GDPR notification thresholds are met.

13. Cookies and similar storage

GENR8 uses essential authentication/session storage and local device storage needed for requested features and preferences. We do not currently use advertising cookies or optional behavioural analytics cookies. Google Identity may use its own storage when you request Google sign-in. Sentry receives diagnostic events but GENR8 does not enable Sentry session replay. See the Cookie Policy for current details.

14. Children

GENR8 is not directed to anyone under 16 and does not knowingly permit those users to create accounts. If you believe a child under 16 has provided data, contact us so we can investigate and take appropriate action.

15. Changes to this Notice

We will publish a new version date and provide prominent notice of material changes. A privacy notice is not accepted by continued use. If a new purpose requires consent, we will request that consent separately before the processing begins.

16. Contact

Privacy and rights requests: contact@genr8art.com Controller: BC Studios Romania Website: https://genr8art.com