Summary
This page complements our Privacy Policy. Where the two overlap, the Privacy Policy describes the detail and this page focuses on GDPR-specific rights and safeguards.
1. Our role under the GDPR
Shroom Studio is the data controller for personal data that users provide directly to create and maintain an account (e.g. email address, profile, billing data).
Shroom Studio is a data processor for personal data submitted by workspace members in the course of using the Service — such as prompts, uploaded reference images, generated outputs, and comments. The workspace owner acts as the controller for that data.
2. Lawful bases for processing
We process personal data under one or more of the lawful bases set out in Article 6 of the GDPR:
| Processing activity | Lawful basis |
|---|---|
| Delivering the Service you requested (authentication, generations, storage) | Contract (Art. 6(1)(b)) |
| Billing, invoicing, tax reporting | Contract / Legal obligation (Art. 6(1)(b) & (c)) |
| Security, fraud prevention, audit logs | Legitimate interests (Art. 6(1)(f)) |
| Service analytics and product improvement (aggregated) | Legitimate interests (Art. 6(1)(f)) |
| Marketing emails and newsletters | Consent (Art. 6(1)(a)) |
| Responding to legal requests | Legal obligation (Art. 6(1)(c)) |
3. Categories of personal data
- Identity & contact data: email, display name, authentication identifiers.
- Account data: workspace membership, project roles, invitations, preferences.
- Content data: prompts, uploads, generated images, comments, activity logs.
- Billing data: plan, credit balance, invoice history, tokenised payment references from Stripe.
- Technical data: IP address, user agent, timestamps, error/performance logs.
We do not intentionally collect special categories of personal data (health, biometric, political, etc.). Please do not submit such data to the Service unless strictly necessary.
4. Your rights
Under the GDPR and UK GDPR, you have the right to:
| Right | What it means in Shroom |
|---|---|
| Access (Art. 15) | Receive a copy of the personal data we hold about you. |
| Rectification (Art. 16) | Correct inaccurate or incomplete personal data from Account settings or by contacting us. |
| Erasure (Art. 17) | Delete your account and associated personal data, subject to legal retention obligations (e.g. tax records). |
| Restriction (Art. 18) | Ask us to pause processing in specific circumstances (e.g. while a dispute is resolved). |
| Data portability (Art. 20) | Receive your content and account data in a structured, machine-readable format and/or have it transmitted to another controller where technically feasible. |
| Object (Art. 21) | Object to processing based on legitimate interests, including profiling. |
| Withdraw consent | Opt out of marketing emails at any time via the unsubscribe link or by contacting us. |
| Not be subject to solely automated decisions (Art. 22) | We do not make legal or similarly significant decisions about you using solely automated processing. |
5. How to exercise your rights
- Self-serve: most edits, downloads of your generations, and account deletion are available from the Account and Settings pages.
- Email us: send your request to [email protected] from the address associated with your account, or include details that let us verify your identity.
- Response time: we will respond within 30 calendar days. Complex or multiple requests may be extended by up to 60 days, in which case we will notify you.
- Cost: exercising your rights is free. We may refuse or charge a reasonable fee for manifestly unfounded or excessive requests, as permitted by law.
If your data is controlled by a workspace owner (your employer, client, or organisation), we may need to direct your request to them and assist in fulfilling it.
6. Subprocessors
We use a small number of vetted subprocessors to deliver the Service. Each is bound by a data-processing agreement with confidentiality, security, and cross-border transfer obligations at least equivalent to ours.
| Subprocessor | Purpose | Location |
|---|---|---|
| Amazon Web Services (AWS) | Hosting, storage (S3, DynamoDB), Cognito authentication, SES email, Lambda compute | United States / EU |
| Vercel Inc. | Frontend hosting and edge delivery | Global CDN |
| Stripe, Inc. | Subscription & credit top-up payments | United States |
| OpenAI, L.L.C. | AI model inference (when selected) | United States |
| Google LLC (Google AI) | AI model inference (when selected) | United States |
| Black Forest Labs (Flux) | AI model inference (when selected) | Germany / United States |
| xAI Corp. | AI model inference (when selected) | United States |
| Fal AI, Inc. | Hosted AI model inference (when selected) | United States |
We will post updates to this list before engaging new subprocessors that process personal data. Workspace owners with a signed DPA will be notified by email.
7. International transfers
Personal data of EEA/UK residents may be transferred to countries outside the EEA or UK, including the United States. When we do this, we rely on one or more of:
- The European Commission's Standard Contractual Clauses (2021/914) and the UK International Data Transfer Addendum;
- Adequacy decisions where applicable (e.g. EU-US Data Privacy Framework for certified recipients);
- Supplementary technical and organisational measures (encryption in transit and at rest, access controls, logging).
You may request a copy of the relevant transfer mechanism for a specific subprocessor by emailing us.
8. Security & breach notification
Technical & organisational measures
- TLS 1.2+ for data in transit; AES-256 for data at rest.
- Least-privilege IAM policies, MFA for administrative accounts, and segregated production environments.
- Automated audit logs for generation, billing, and moderation-sensitive actions.
- Regular dependency scanning, secret rotation, and periodic access reviews.
Breach notification
If we become aware of a personal data breach likely to result in a risk to your rights and freedoms, we will notify the relevant supervisory authority within 72 hours where required, and will inform affected users without undue delay.
9. Data Processing Agreement (DPA)
Workspace owners acting as controllers can enter into a Data Processing Agreement with Shroom that incorporates the Standard Contractual Clauses. Our standard DPA covers:
- Subject matter, duration, nature and purpose of processing;
- Types of personal data and categories of data subjects;
- Controller and processor obligations, including assistance with data-subject requests and DPIAs;
- Subprocessor authorisation and audit rights;
- Cross-border transfer safeguards.
To request a countersigned DPA, email [email protected] with your workspace name and legal entity details.
10. Retention & deletion
We retain personal data only as long as necessary for the purposes described in our Privacy Policy. On verified deletion request:
- Your account profile is deleted within 30 days.
- Generated media and prompts associated solely with your account are deleted within 30 days, unless a workspace owner requires retention for shared project history.
- Billing records are retained for up to 7 years to satisfy tax and accounting laws.
- Backups are purged on a rolling basis within 90 days after deletion.
11. Supervisory authority
If you are in the EEA, UK, or Switzerland and believe our processing infringes applicable data-protection law, you have the right to lodge a complaint with your national supervisory authority:
- EEA: your national data protection authority;
- UK: Information Commissioner's Office (ICO);
- Switzerland: Federal Data Protection and Information Commissioner (FDPIC).
We encourage you to contact us first so we can try to resolve your concern directly.
12. Contact
For all GDPR-related requests, including DPA requests, subprocessor lists, or transfer-mechanism documentation, email [email protected] with the subject line "GDPR".