Last updated: June 23, 2026
This Privacy and Cookies Policy constitutes a definitive transparency notice outlining how Fourmeta LTD ("we", "us", or "our"), a company incorporated and registered under the laws of England and Wales, collects, stores, processes, and protects your Personal Data. This Policy governs all interactions with our AI-driven virtual try-on and image generation platform tailored for the e-commerce sector, accessible at https://fourmula.ai/ (the "Service" or "Platform").
Acting as a designated "Data Controller" under the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018 (DPA 2018), and relevant provisions of the EU GDPR (EU) 2016/679, we dictate the specific purposes and organisational means for managing your personal records.
Personal Data encompasses any specific information that directly or indirectly identifies you as an individual. By creating a user account, accessing our system interface, or generating visual content, you acknowledge that you have read and understood the data workflows detailed herein. If you do not accept these baseline data practices, please cease all interactions with our Platform immediately.
In delivering our Service, we process data supplied directly by your inputs during registration or system configurations, alongside technical device parameters recorded automatically by our servers. We enforce data minimisation across all operations.
The structured matrix below outlines the specific data attributes processed, their business objectives, and their corresponding lawful bases under Article 6 of the UK GDPR:
| Data Category | Specific Data Fields & Engineering Identifiers | Primary Purpose of Processing Operations | Lawful Basis under UK GDPR |
|---|---|---|---|
| Authentication & Identity Data | Auto-increment integer ID, unique case-insensitive email, email verification timestamp (email_verified_at), and Bcrypt-hashed account password. | To uniquely verify user identity, execute framework authentication routines, validate email ownership to block spam, and manage secure account recovery. | Contract Performance (Art. 6(1)(b)): Mandatory to establish and fulfil your contract concluded by accessing the Service. |
| Guest Session Tokens | Unique, nullable cryptographic session tracking string (hash). | To bind unauthenticated guest projects and Product Detail Page (PDP) records to anonymous browsers, allowing seamless asset transfers when registering. | Legitimate Interests (Art. 6(1)(f)): Providing an optimised onboarding experience for new Platform users. |
| Persistent Session Data | Nullable secure browser token (remember_token). | To maintain continuous, secure user login states over extended periods as configured by the user's browser. | Contract Performance (Art. 6(1)(b)): Fulfilling user requests for persistent Platform access. |
| Profile Personalisation | Nullable name string, nullable custom user avatar storage path, and avatar cloud disk location identifiers. | To customise dashboard UI graphics, deliver personal notifications, and ensure correct data routing across multi-cloud configurations. | Your consent (Art. 6(1)(a)): Non-mandatory profile elements populated at your sole option. |
| Credits, Metering & Consumption | Integer values for credits_balance, credits_used, and historical tracking of credits_purchased. | To monitor computational generation capacity, conduct internal analytics, determine Customer Lifetime Value (CLV), and manage server resource allocations. | Contract Performance (Art. 6(1)(b)): Tracking and managing usage metrics linked directly to payment tiers. |
| Subscription Lifecycles | Timestamps and integers for credits_refilled_at, credits_monthly, and upcoming credits_renewal_date. | To automate monthly billing cycles, award tier-specific credit drops, process automated renewals, and eliminate duplicate allocations. | Contract Performance (Art. 6(1)(b)): Administering continuous subscription agreements. |
| Stripe Merchant Metadata | Tracking tokens including stripe_id, payment method string (pm_type), masked digits (pm_last_four), and trial_ends_at. | To map profile architectures to our merchant provider, optimize payment pathways, present safety verification masks, and enforce promotional trial thresholds. | Contract Performance (Art. 6(1)(b)) & Legal Obligation (Art. 6(1)(c)): Executing transactions and maintaining mandatory accounting logs. |
| Notification Control & Throttling | Operational timestamps for last_purchase_email_sent_at and last_images_generated_email_sent_at. | To throttle system transactional communications, eliminate duplicate messages, and safeguard consumer inboxes from digital fatigue. | Legitimate Interests (Art. 6(1)(f)): Maintaining optimal infrastructure performance and eliminating communication spam. |
| System Diagnostics & Audit Trails | Technical metadata including created_at, tracking metric updated_at, and soft-delete tracker deleted_at. | To manage back-end registration metrics, support security audit trails, maintain database integrity, and run account recovery features. | Legitimate Interests (Art. 6(1)(f)): Enforcing system performance stability, database reliability, and compliance security. |
| AI Generation Inputs (Uploaded Assets) | User-provided product looks, model silhouettes, and custom graphical files are used as inputs. | To run requested generative AI transformations and render virtual try-on assets onto target templates. | Contract Performance (Art. 6(1)(b)): Necessary to deliver the specific AI-generated image requested by the user. |
Please note that in case the uploaded product or model images contain human likenesses or facial representations, our AI image generation routines, as a part of the Service, do not extract structural facial dimensions or mathematical physiological matrices to identify any natural person. So, we do not process Special Category Biometric Data.
We do not sell, rent, or lease your personal information to third parties. To fulfil our contract performance duties, data is shared securely with designated service providers acting as Data Processors under strict Data Processing Agreements (DPAs) in compliance with Article 28 of the UK GDPR:
Stripe Inc. (Merchant Processing Operations): We share your email address, display name, and direct transaction inputs. All financial details bypass our servers entirely via PCI-DSS-compliant infrastructure. Our local databases store only non-sensitive tokens (stripe_id, pm_type, pm_last_four) to prevent fraud and manage subscriptions.
Amazon Web Services (AWS S3 Cloud Infrastructure): We store uploaded product models, final generative image outputs, and custom user avatars. Files are isolated using a deterministic directory layout: user_hash/project_id/pdp_id/type/, protected by restrictive IAM service access controls.
AI Compute Processors (NanoBanana / RunComfy Nodes): We share uploaded product/model image frames, generation configuration parameters, and short-term, cryptographically signed S3 URLs. No identifying account metrics (such as your email address or account name) are shared with these processing nodes. Data payloads are transient, held in volatile memory strictly for the processing lifecycle, and are never utilised to train neural networks or foundational models.
Transactional Messaging Infrastructure: We pass your email address and system status updates to external messaging systems to execute critical transaction alerts and billing updates.
Localised Data Isolation Safeguards. The following localised information fields remain enclosed within our isolated databases and are explicitly exempted from third-party data transfer pipelines:
Legal Exceptions and Corporate Structural Shifts. We may share personal records if required to comply with a valid legal process or enforceable government warrant; to investigate Platform fraud or technical security concerns; or to protect the safety of our users, the public, or the Controller as permitted by law. In the event of a corporate merger, acquisition, or sale of assets, we will maintain strict confidentiality and provide advanced notification before any personal data transitions to a different privacy framework.
External Channels and Links. Our web interface may contain hyperlinks to independent third-party websites, plug-ins, or networks. Following an outbound link means you interface with an autonomous entity operating under separate data practices. We accept no liability or legal responsibility for the privacy frameworks of external domains. We encourage you to review their respective privacy notices before transmitting personal information.
Our Service utilizes technical tracking strings and temporary session elements to maintain core web functionality:
Essential Authentication Cookies: These technical entries are required to bridge data states from anonymous guest sessions (hash) into authenticated user structures when you register. Disabling these tracking fields will break key parts of the Platform's authentication loops and stop image generation tools from working.
Interface Preferences: These track and store interface configurations, layout preferences, and language selections across browsing sessions.
You retain the absolute right to configure your web browser to block, reject, or delete cookies.
| Cookie | Domain | Description | Duration | Type |
|---|---|---|---|---|
| _cfuvid | .fourmula.ai | Cloudflare sets this cookie to track users across sessions to optimize user experience by maintaining session consistency and providing personalized services | session | Necessary |
| _ga_* | .fourmula.ai | Google Analytics sets this cookie to store and count page views. | 1 year 1 month 4 days | Analytics |
| _ga | .fourmula.ai | The _ga cookie, installed by Google Analytics, calculates visitor, session and campaign data and also keeps track of site usage for the site's analytics report. The cookie stores information anonymously and assigns a randomly generated number to recognize unique visitors. | 1 year 1 month 4 days | Analytics |
| _gcl_au | .fourmula.ai | Google Tag Manager sets this cookie to experiment advertisement efficiency of websites using their services. | 3 months | Advertisement |
| _fbp | .fourmula.ai | Facebook sets this cookie to store and track interactions. | 3 months | Advertisement |
| _gcl_ls | fourmula.ai | Google Ads | 3 months | Marketing |
| lastExternalReferrerTime | fourmula.ai | Meta Pixel (Facebook) | session | Marketing |
| preloader_visited_v2 | fourmula.ai | Our website | session | Functional |
| isDarkMode | fourmula.ai | Our website | session | Functional |
| site-user-zoom | fourmula.ai | Our website | session | Functional |
| _gcl_au | Google tag / Google Ads | Measures ad and conversion performance | 3 months | Marketing / Conversion |
| intercom-device-id-* | Intercom | Identifies the device for Messenger functionality and security. | 9 months / 270 days | Functional / Support |
| intercom-session-* | Intercom | Maintains chat session continuity and access to previous conversations | 1 week | Functional / Support |
We implement technical and organisational security controls to protect personal data from unauthorised access, loss, modification, or deletion:
Cross-Border Infrastructure Transfers. As our backend infrastructure depends on distributed cloud networks (such as Amazon Web Services and international AI compute nodes), your personal data may be transferred to and stored outside the United Kingdom and the European Economic Area (EEA).
For all such international transfers, we ensure that data recipients are contractually bound to provide equivalent data protection safeguards by executing the UK Information Commissioner's Office (ICO) International Data Transfer Agreements (IDTAs), the approved UK Addendum to the European Commission's Standard Contractual Clauses, or valid adequacy frameworks.
Security Disclaimer. While we apply enterprise-grade defences, no method of data transfer or cloud storage is completely secure. We cannot guarantee absolute security against sophisticated third-party cyber-attacks or illegal interceptions that circumvent applicable laws.
Our Platform provides professional design utilities engineered exclusively for business operations, commercial companies, and e-commerce enterprises. The Service is not intended for or marketed to individuals under the age of 18. So, we do not knowingly collect, maintain, or process data strings linked to minors. To use our Platform, you must maintain an adult legal status in your resident jurisdiction. If we find that an account belongs to a minor, we will take immediate steps to remove their information from our records.
We manage separate retention timelines tailored to your account's lifecycle stage, keeping records no longer than permitted by law or necessary for business operations:
Active Platform Profiles: All data attributes, tracking fields, and transaction parameters remain populated across our active databases for the duration your Platform account stays active.
Guest Accounts: Interactions executed by unauthenticated guests remain tied to an isolated tracking string (hash). If the session remains inactive and does not transition into a full registration, these temporary records are purged automatically based on our automated database cleanup schedules.
Soft-Deleted Profiles: If you request account termination, the records are shifted into an inactive state using a deleted_at timestamp flag. During this buffer window, the account profile, associated projects, and past generation histories can be fully restored by our support team upon user request.
Permanent Deletion and Archiving: Following the expiration of our soft-delete window, or to satisfy statutory financial, accounting, and tax auditing rules, billing records and purchase metadata parameters will be moved to an isolated archive for seven (7) years following the transaction date before permanent erasure occurs.
While our service relies on advanced generative artificial intelligence models to process uploaded imagery and render customised visual assets based on your prompt configurations, these workflows are strictly tools used to deliver the specific graphic service you request.
We do not utilise personal datasets to run automated decision-making engines or profiling structures that produce binding legal implications, evaluate behavioural scores, or otherwise significantly impact your civil freedoms or statutory protections.
We reserve the right to modify, amend, or update this Privacy and Cookies Policy at any time to reflect software changes, infrastructural shifts, or new legal requirements under the UK GDPR or AI regulation acts. Any updates will be published openly on our web interface.
If we implement material modifications to how we process your personal records, we will alert you in advance via prominent notifications within the Platform dashboard or directly through your registered email address. We encourage you to review this policy periodically to stay informed about our data protection practices.
If you access our Platform from the United Kingdom or the European Union, you hold specific statutory rights regarding your personal information:
To exercise any of these protections, please submit an explicit request to our privacy intake team using the contact details provided in Section 12 below. You also have the right to lodge a formal complaint regarding our data handling with the UK Information Commissioner's Office (ICO) via www.ico.org.uk.
To maintain compliance across all generative AI pipelines, Fourmeta LTD manages a dedicated internal data protection and compliance program. We maintain an internal Data Privacy specialist tasked with keeping our technical staff updated on shifting data security landscapes, conducting regular privacy impact assessments (PIAs) on external AI node configurations, running platform risk audits, and resolving data privacy inquiries proactively.
Our team serves as your primary interface to explain how your data is used, handle erasure requests, and detail the organisational measures we use to protect your privacy.
You can contact us at any time to share your views about our privacy practices, ask questions about this Policy, or exercise your statutory data protection rights by directing an inquiry to our dedicated endpoints:
FOURMETA LTD — infot@fourmeta.com