Privacy notice
This notice explains how Clonix (public website https://clonix.cloud and related platform) processes personal data, with reference to Regulation (EU) 2016/679 (GDPR) and applicable national data-protection law.
It covers public browsing, registration, and use of the platform. Uploads of images or video of recognisable people may also be subject to in-app notices and consents shown in the private area.
1. Data controller
The data controller is identified as follows:
Controller / provider: Daniele Cadeddu
Trading name: Clonix
Registered address: Località Cannedu, 09028 Sestu (CA), Italia
Country: Italia
2. Categories of data processed
Depending on how you use Clonix, we may process the following categories of personal data:
- account data (email address, credentials in protected form, profile preferences and settings);
- billing and payment data, generally handled via external payment providers (for example payment processors); Clonix does not necessarily store full card details;
- user-uploaded or generated content (prompt text, images, video, audio and related technical metadata);
- photographs and videos of faces or other images of people: where they allow a natural person to be identified they are personal data; they are not automatically “special categories” of data; they may constitute biometric data under the GDPR only if processed with specific technical means aimed at uniquely identifying a natural person. Not every avatar generation or image transformation is in itself biometric processing;
- technical, security and diagnostic logs (IP addresses, session identifiers, timestamps, error events and anti-abuse measures);
- cookies and similar device storage technologies (see the Cookie Policy and the dedicated section).
3. Purposes and legal bases
Data are processed for the purposes and on the legal bases below, only as far as actually necessary:
- providing the requested service and managing accounts, plans and credits (performance of a contract or pre-contractual steps, Art. 6(1)(b) GDPR);
- user support and operational communications about the service (Art. 6(1)(b) and/or (f) GDPR);
- complying with legal obligations, including tax and accounting duties where applicable (Art. 6(1)(c) GDPR);
- security, fraud and abuse prevention, and protection of Clonix’s and third parties’ rights (legitimate interests, Art. 6(1)(f) GDPR), balanced against data subjects’ rights;
- where required by law, promotional communications or non-essential cookies only with consent (Art. 6(1)(a) GDPR), which may be withdrawn at any time.
4. Mandatory or optional provision of data
Providing data needed to create and manage an account and deliver the service is mandatory for contractual purposes: without it you cannot register or use authenticated features.
Uploading content (images, video, audio, prompts) is optional but required if you want to use the related generation or transformation features.
Consent for consent-based processing (where applicable) is always optional; refusal or withdrawal does not affect features that do not depend on that consent, subject to the technical limits of the service.
5. Recipients and processor categories
Data may be disclosed, within the stated purposes, to:
- hosting, storage, CDN and technical infrastructure providers;
- AI and media processing providers used to generate or transform content at your request;
- payment and billing providers, where you use paid plans;
- transactional email, error monitoring or security providers, if enabled;
- public authorities, where required by law or a binding order;
- professional advisers bound by confidentiality, as needed.
6. Transfers outside the EEA
Some technical providers may process data outside the European Economic Area. Where a transfer requires safeguards under Articles 44–49 GDPR, Clonix intends to rely on mechanisms provided by law (for example adequacy decisions or standard contractual clauses), if and to the extent they actually apply to the relationship with the provider.
This notice does not claim that all data always remain in Europe, or that every provider applies specific safeguards, until those elements are verified and documented for each processing activity.
7. Retention
Data are retained for as long as needed for the purposes collected and for legal obligations. As a general criterion:
- account data: for the duration of the relationship and a subsequent period justified by legal, dispute or security needs;
- billing data: according to retention periods under applicable tax and accounting law;
- uploaded and generated content: according to service retention policies, plan limits and erasure requests, subject to mandatory retention;
- security logs: for periods proportionate to security and abuse-prevention needs;
- cookie preferences stored locally on your device: up to 365 days or until manually cleared (see Cookie Policy).
8. Your rights
Within the limits of the GDPR, you may exercise rights of access, rectification, erasure, restriction, portability and objection and, where processing is based on consent, withdraw consent without affecting the lawfulness of prior processing.
Requests may be sent to the privacy channel listed in Contacts. You also have the right to lodge a complaint with a competent data-protection supervisory authority.
Account and associated content deletion may be requested from the authenticated area (deletion request) or by emailing the privacy/support channel listed in Contacts. The request is logged and handled under internal criteria; automatic or immediate erasure, or a self-service data wipe, is not guaranteed. Some data may be retained where required by law or for overriding legitimate interests (for example security or legal defence).
9. Children
The service is not directed to anyone under 18. We do not knowingly collect personal data from children. If you believe a child has provided data, contact us via the privacy channel so appropriate steps can be assessed, including erasure where due.
10. Automated decisions and profiling
Clonix uses automated systems (including third-party AI models) to generate or transform content at the user’s request. That does not in itself amount to automated decision-making producing legal or similarly significant effects under Article 22 GDPR.
If relevant profiling or automated decisions under that provision are introduced later, this notice will be updated and any additional information required by law will be provided.
11. Cookies and local storage
The private application (SPA) may offer optional analytics (for example PostHog) only after an explicit in-app choice; analytics are off by default and can be refused or withdrawn. Those tools are outside the public-site cookie banner (Case A), but are disclosed here for transparency.
12. Changes to this notice
We may update this notice to reflect changes to the service, the law or the controller’s identity. Version and effectiveness information appear at the top of the document. For material changes, additional communication may be used where appropriate.
13. Contacts
Verified contacts: privacy: cadeddudaniele79@gmail.com; support: cadeddudaniele79@gmail.com.