Legal
Privacy policy
Effective date: 4 October 2026
This policy explains what personal data Artiz Studio handles, why, and what control you have over it. The short version: your original photos stay on your own computer, our AI runs on your device and never sends your photos to outside AI services, we do not sell data or use advertising trackers, and our cloud servers are in India. If you are a photography studio, we look after your account data as its Data Fiduciary. If you are a client or guest of a studio, the studio decides how your photos are used and we process them only on its behalf.
Who we are
Artiz Studio is a product of NEW.E AI Solutions, with its registered office at Chennai, India ("we", "us", "our"). The "Service" means our website (https://artizz.in), web app (https://app.artizz.in), Windows desktop app, and the galleries, album approval pages, photo-booth kiosk and live event wall that studios share through them.
Who this policy covers
This policy applies to three groups of people:
• Studios and their team members: photographers and staff who create an account and use the Service. • Clients and guests: couples, families, event guests and other people who open a link shared by a studio, choose photos, review albums or use the photo-booth or event wall. They do not need an account. • Website visitors: anyone who browses artizz.in.
Our role: Data Fiduciary and Data Processor
India's Digital Personal Data Protection Act, 2023 (the "DPDP Act") uses two terms that matter here.
A Data Fiduciary decides why and how personal data is processed. We are the Data Fiduciary for studio account data: names, e-mail addresses, team members, billing records, sign-in records and similar information about our customers.
A Data Processor processes personal data on behalf of a Data Fiduciary. When a studio uploads or shares photos and information about its own clients and guests, the studio is the Data Fiduciary for that data and we act as its Data Processor. We process that data only to provide the Service to the studio and on its instructions. We do not use it for our own purposes.
What this means if you are a client or guest: the studio you hired, or the studio covering your event, is responsible for how your photos are collected, shared and kept. If you want a photo removed, a gallery taken down, or a copy of your data, please contact that studio first. If you cannot reach the studio, or you need help, write to us at hello@artizz.in and we will pass your request to the studio and assist it in responding.
Information we collect
Account and profile information. When a studio signs up we collect the studio name, the name and e-mail address of the person signing up, and a password (stored only in a securely hashed form). If you choose "Sign in with Google", Google shares your name, e-mail address and profile photo with us; we do not receive your Google password. Studios can add team members, in which case we store each member's name, e-mail address and role.
Studio content. This is the material a studio places in the cloud part of the Service: smart previews (reduced-size copies of photos), retouched renders, album designs, client selections and comments, delivery files the studio chooses to share, and the studio's branding and logo.
Client and guest information. When a client or guest uses a shared link, we store what they enter or do there on the studio's behalf: favourites and notes, a typed name when a family member reviews an album, and album approvals. When a client approves or e-signs an album design, we record the typed name, the date and time, and the IP address, so the studio has a reliable approval record.
Guest selfies for "Find my photos". At live events a guest may choose to take a selfie to find their own photos. This is explained in its own section below.
Billing information. Payments are handled by Razorpay. We receive and keep the plan chosen, amounts, dates, payment status, the subscription or mandate reference, and invoice details. We never see or store full card numbers, CVV, UPI PINs or netbanking passwords; these are entered directly with Razorpay or your bank.
Security and usage records. We log sign-ins with the IP address and time, and keep an audit log of important account actions, to protect accounts and investigate misuse. We also keep aggregated usage counters, such as the number of requests, storage used and bandwidth, to run the Service, apply plan limits and plan capacity.
Messages. If you e-mail us, we keep the correspondence so we can help you.
We do not use third-party analytics tools or advertising trackers, and we do not build advertising profiles.
Photos and on-device AI
Your original photo files stay on your own computer. They are not uploaded to our cloud, unless your studio chooses to run its own local server, in which case they are stored on that server under your control.
Artiz Studio's AI features, including face detection and recognition, sharpness and blink detection, culling and retouching, run locally on your computer or in your browser. Your photos are not sent to third-party AI services, and we do not use your photos, or your clients' photos, to train AI models.
Studios should use face features only in ways their clients would reasonably expect and, where required, with their consent.
Guest selfies and face templates
Face data is sensitive, so we treat the "Find my photos" feature with extra care.
• It is optional. Before a guest takes a selfie, we ask for clear, explicit consent and explain what will happen. A guest who does not agree can still view the event's public photos. • From the selfie we compute a face template (a set of numbers describing facial features) and use it only to find that guest's photos within that one event. • The template is stored on our servers privately. It is not shown to other guests and is not used for any other event, studio or purpose. • The selfie is not shown on the studio's public event wall and is not shared with other guests. • Templates are deleted automatically at the end of the event period set for the Service. A guest can also ask for earlier deletion by contacting the studio or writing to us.
The studio running the event remains the Data Fiduciary for this data, and we process it on its behalf as described above.
How we use information
We use personal data to:
• create and manage accounts, team access and sign-in; • provide the Service, including storing and showing galleries, album designs, approvals, deliveries and event walls as each studio sets them up; • process subscriptions, payments, invoices and refunds; • send service e-mails such as password resets, receipts, payment reminders and trial reminders; • keep the Service secure, detect and prevent fraud or abuse, and investigate problems; • respond to support requests, complaints and data requests; • apply plan limits and improve reliability, using aggregated usage figures; and • meet our legal obligations, such as tax and accounting rules, and respond to lawful requests from authorities.
The basis for our processing
For studio account data, we process personal data because you gave it to us to use the Service, a legitimate use recognised by the DPDP Act, and, where needed, with your consent. Some processing is required by law, such as keeping billing records. Where we rely on consent, you can withdraw it at any time by writing to us; this will not affect processing already done, but some features may stop working.
For client and guest data, the studio is responsible for having a valid basis, including consent where required. For the "Find my photos" selfie, we collect explicit consent from the guest on the studio's behalf before processing.
Who we share information with
We share personal data only as needed to run the Service, and only with organisations that are bound to protect it:
• DigitalOcean, which hosts our servers and backups in its Bangalore (India) data centre. • Razorpay, which processes subscription payments, UPI AutoPay mandates, cards and netbanking. • An e-mail delivery provider, which sends our transactional e-mails on our behalf. • Messaging providers (Meta's WhatsApp Business Platform, and SMS providers), which deliver sign-in codes and, when a studio chooses "Send on WhatsApp", the link it is sending to its client. They receive only the phone number and the message. • Google, if you use "Sign in with Google", to confirm your identity.
Within the Service, information is shared as the studio decides: clients see the galleries shared with them, and the studio sees its clients' selections, notes and approvals.
We may also disclose information if required by law, court order or a lawful request from a government authority, or where necessary to protect the rights, safety or property of our users, the public or ourselves. If NEW.E AI Solutions is involved in a merger, acquisition or sale of its business, personal data may transfer to the new owner, who will be bound by this policy or one offering equal protection, and we will tell you before that happens.
Where your data is stored
Our cloud data is stored on servers in Bangalore, India. Some providers listed above, such as Google and our e-mail delivery provider, may process limited data (for example an e-mail address or IP address) outside India, in line with the DPDP Act and any restrictions the Government of India notifies.
How long we keep data
• Active accounts: we keep studio account data and studio content while the account is active. • After cancellation or expiry: the account becomes read-only and we keep the data for 60 days so you can renew or export it. After that it is deleted from our active systems, and copies in our weekly backups are overwritten within about 30 more days. • Deleted accounts: if you delete your account, we delete your cloud data in the same way, from active systems and then from backups. • Client and guest data: kept for as long as the studio keeps it in the Service, or until the studio's account data is deleted as above. Studios can delete galleries, events and client data at any time, and links stop working when a studio sets them to expire. • Face templates: deleted automatically at the end of the event period, as explained above. • Security logs: sign-in and audit records are kept for at least one year, or longer if required by law or needed to investigate an incident. • Billing and tax records: invoices and payment records are kept for the period required by Indian tax and company law, even after an account is deleted.
How we protect data
We use reasonable security practices suitable for the data we handle. These include encrypted connections (HTTPS), hashed passwords, access controls that limit who can reach data, token-based sessions, sign-in logging, server hosting in a professionally managed data centre, and regular backups. Optional PINs, watermarks and link expiry help studios control who sees their galleries.
No system is completely secure. Please use a strong, unique password and keep your own backups of your original photos, which live on your computer, not in our cloud.
If a personal data breach occurs, we will act promptly to contain it and will inform affected people and the Data Protection Board of India as required by the DPDP Act and its Rules. Where we act as a studio's Data Processor, we will notify the studio without delay and help it meet its own obligations.
Cookies and local storage
We do not use advertising cookies or third-party tracking cookies.
The web app uses your browser's local storage and IndexedDB to keep your studio's projects on your device and to remember your sign-in token, so you stay signed in. The desktop app stores similar information in its data folder on your computer. Clearing your browser data or uninstalling the app removes these local copies, so make sure your work is saved or synced first.
Our website remembers, in your browser's local storage, how you first arrived: the campaign tag in the link (for example, a link from a studio's client gallery) or the name of the website that referred you, and the first page you opened. If you create a studio account, this is sent with your sign-up so we know which channels bring us studios. It is never shared with anyone else, and we don't use it to follow you across other websites.
Your rights
Under the DPDP Act, and subject to its conditions and timelines, you have the right to:
• get a summary of the personal data we process about you and the processing activities; • know the categories of people or organisations we have shared it with; • correct, complete or update inaccurate or incomplete data; • have your data erased when it is no longer needed for the purpose it was collected for, unless the law requires us to keep it; • withdraw consent you have given, as easily as you gave it; • nominate another person to exercise your rights if you die or become unable to do so; and • have your grievance addressed by us, and, if you are not satisfied, complain to the Data Protection Board of India.
Studios can update most account details on the Account page, export their data and delete their account. For anything else, write to hello@artizz.in from the e-mail address linked to the account; we may need to verify your identity first. Clients and guests should contact the studio first, as explained above, and we will support the studio in responding.
Children
The Service is not directed at anyone under 18, and only adults may open a studio account. We do not knowingly collect personal data directly from children.
Wedding and event photos often include children. The studio is responsible for obtaining verifiable consent from a parent or lawful guardian wherever the law requires it before processing children's photos through the Service, and for not using children's data in ways that could harm them. The "Find my photos" selfie feature is intended for adult guests only.
Changes to this policy
We may update this policy as the Service or the law changes. We will post the updated version here with a new effective date and, for significant changes, notify studios by e-mail or in the app before they take effect.
Grievance Officer and contact
If you have a question, request or complaint about privacy or about content on the Service, please contact our Grievance Officer:
• Designation: Grievance Officer, NEW.E AI Solutions • Address: Chennai, India • E-mail: hello@artizz.in
We will acknowledge your complaint within 24 hours and aim to resolve it within 15 days, and in any case within the time required by applicable law. If you are not satisfied with our response to a data protection complaint, you may approach the Data Protection Board of India.
Questions? Write to hello@artizz.in.