Privacy Policy
This policy explains what data we process, why, and for how long. It includes a dedicated section on people photographed at an event, which is the most sensitive processing we carry out.
17 September 2026 21 September 2026 1.1
1. Who processes your data
The controller of the data collected through this website and in connection with the purchase of our products is:
- Company: TWO MILLIONS DREAMS, S.L. («PictiaX», «we»)
- Tax ID: B13744396
- Registered address: Calle Correa de Araujo 2, 41702 Dos Hermanas (Seville), Spain
- Data protection contact: hello@pictiax.com
PictiaX® is a brand of TWO MILLIONS DREAMS, S.L. Write to that address for anything relating to this policy or to exercise your rights.
2. Three very different situations: you, the guests at your events, and the trial on this website
This is the most important section of the policy, because it determines who is answerable for what. Our product operates on three levels and we play a different role in each.
If you are our customer
If you buy the system, contact us, subscribe to our updates or browse this website, we are the controller of that data and we decide what it is used for. Everything below applies to you directly.
If you were photographed at an event
When an operator uses our system at a wedding, a trade fair or a corporate party, the controller is that operator, not us. They organise the event, they decide to capture your photograph and your email address, they obtain your consent and they determine what the result is used for.
We act as a processor within the meaning of Article 28 of the General Data Protection Regulation: we supply the tool and process the image on their documented instructions, and we do not use that data for our own purposes.
If you had a caricature drawn at an event and wish to exercise your rights, contact the organiser of that event first, as they are the one with a relationship with you. If you cannot identify them or they do not reply, write to hello@pictiax.com and we will help you identify them and pass your request on.
Every operator using our system accepts a data processing agreement under which they undertake, among other things, to inform attendees, obtain their consent and display the relevant notices at the event itself.
If you try the caricature on this website
If you upload your photograph through the trial form on this website, we are the controller, just as we are for our customers: you hand it to us directly and we decide what is done with it. That processing has its own rules, set out in section 5.
3. What we process, on what legal basis, and for how long
We process only the data needed for each purpose. This is the full list:
| Purpose | Data | Legal basis | Retention |
|---|---|---|---|
| Selling, delivering and supporting the system | Name, company, tax or VAT number, address, phone, email, order and licence details | Performance of the contract | For the duration of the relationship and 6 years thereafter, as required by Spanish commercial law |
| Taking payment | Amount and payment reference. Card details are handled by Stripe; we never see or store them | Performance of the contract and legal obligation | 6 years |
| Answering your enquiry | Name, email, company, phone and the message itself | Our legitimate interest in replying to people who contact us | Until the enquiry is resolved, plus 12 months |
| Sending you updates and running prize draws | Name, email and phone | Your consent | Until you unsubscribe, which you can do in any message |
| Measuring website use and serving advertising | Cookie identifier, IP address, pages viewed, device | Your consent, except for strictly necessary cookies | 24 months maximum, after which consent is requested again |
| Generating a guest's caricature and sending it to them | Photograph, resulting caricature, name and email | The guest's consent, obtained by the event organiser | Photograph, 7 days. Portrait and email, 30 days |
If we ever wanted to use your data for anything other than the above, we would tell you first and ask for your permission.
4. Photographs taken at an event
This is the processing we most want to explain properly, because it affects people who are not our customers and who simply walked up to a robot at a party.
What actually happens
- The guest has their photograph taken at the point set up by the organiser.
- That image is sent to our artificial intelligence provider, which generates the portrait.
- The robot draws it on paper and the guest takes it away.
- If the guest asked for it, a digital copy is also sent to the email address they provided.
What we do NOT do with those images
- We do not use them to train artificial intelligence models, whether ours or anyone else's.
- We do not use them in our advertising unless there is express, specific permission from the person appearing in the image. Permission from the organiser is not enough.
- We do not sell or transfer them to anyone for commercial purposes.
- We do not match them across events or build any profile of the person from them.
How long they are kept
The source photograph is kept for 7 days from capture and is then deleted.
The portrait and the delivery email address are kept for 30 days from the event and are then deleted. Where the organiser instructs us in writing to use a shorter period, theirs applies.
Withdrawing consent. Anyone photographed may ask for their image and portrait to be deleted before those deadlines, without giving a reason and at no cost. We action such requests even when they come to us directly rather than to the organiser.
5. The caricature trial on this website
This website offers a trial: you upload a photograph of yourself and we email you a caricature generated with the same engine the robot uses. Here we are not anyone's processor: we are the controller of that photograph, because you hand it to us directly and we decide what is done with it. This is the difference from what happens at an event, where the operator is the controller.
What we process, and why
We process the photograph you upload, your email address and, if you provide it, your name. The legal basis is your consent (Article 6(1)(a) of the General Data Protection Regulation), which you give by ticking the box on the form before submitting it. The form will not submit unless that box is ticked.
What it is used for, and what it is not
The photograph is used solely to generate that caricature and send it to you. Your email address is used solely to deliver the result and to be able to reply if you write to us about it. Using the trial does not add you to any marketing list, we do not pass your data to anyone for advertising purposes, and we do not publish your photograph or the resulting drawing anywhere.
How long we keep it
The photograph is not stored: it enters the process, the drawing is generated and it is gone when the process ends. No copy remains on our systems or in any archive. Your email address is kept for twelve months from the date we send the drawing, so that we can assist you if you write to us about it, and is then deleted.
Who processes it
To generate the drawing, the photograph is sent to OpenAI, acting as a processor on our behalf, under the same terms described in sections 7 and 9. The images are not used to train artificial intelligence models.
Upload only your own photograph. Do not upload an image of another person without their permission, and never upload one of a child. If we detect that a photograph does not meet this condition, it is not processed.
This processing is not biometric identification: we do not measure or store facial features in order to recognise anyone, as explained in section 6. You may withdraw your consent and request deletion of your email address at any time by writing to hello@pictiax.com.
6. We do not carry out biometric identification
We state this explicitly because it is a fair question when a machine analyses a face.
PictiaX® does not generate, compute or store facial templates, face geometry or any other biometric identifier intended to uniquely identify or verify a person, within the meaning of Article 4(14) of the General Data Protection Regulation. Nor within the meaning of US biometric privacy legislation, in particular the Illinois Biometric Information Privacy Act, the Texas CUBI statute and Washington State HB 1493.
The analysis performed by the system serves only to turn an image into a drawable path. It is a momentary computation: it is not stored, not reused, and does not allow that person to be recognised in another photograph or at another event.
If an operator were to connect third-party tools that do perform facial recognition on the generated material, they would be the controller of that processing for all purposes, would have to obtain the legal bases and specific consents required by law, and would hold us harmless against any resulting claim.
7. Artificial intelligence
The system uses OpenAI artificial intelligence models to turn a photograph into a drawable portrait. You should be aware of the following:
- The output is generated by artificial intelligence, and the person is told so at the point of capture, in line with Article 50 of Regulation (EU) 2024/1689 on Artificial Intelligence.
- It is not an automated decision producing legal effects within the meaning of Article 22 of the General Data Protection Regulation: a drawing is generated, no decision is taken about the person.
- The output is not unique. Similar generative models given similar photographs may produce similar results. We do not guarantee exclusivity of the result.
- The images we send to OpenAI are not used to train its models, under the terms of its business application programming interface.
8. Children
There are children at events, and that cannot be dealt with in a throwaway line.
In Spain, Article 7 of Organic Law 3/2018 allows a person to consent to the processing of their own data from the age of 14. Below that age, consent from a parent or guardian is required. Other countries set different ages, and the organiser must apply whichever applies where the event takes place.
We pass this obligation on to the event organiser by contract. They undertake to:
- Obtain consent from the responsible adult where the person photographed is below the applicable age.
- Not collect a young child's email address: the digital copy goes to the accompanying adult.
- Give this information at the event itself, not only on a screen nobody reads.
Our website and shop are not directed at children and we do not knowingly collect children's data through them.
9. Who we share data with, and international transfers
We do not sell personal data. We share the minimum necessary with providers who serve us as processors, under contract:
- Portrait generation: OpenAI. The guest's photograph is sent to OpenAI, which generates the portrait from it. This is the only processing in which the image leaves our systems.
- Payments: Stripe, to process payment.
- Infrastructure and security: Cloudflare, to serve and protect the website.
- Measurement: Google, for website analytics, only if you accept those cookies.
- Email: our communications provider.
These providers are established outside the European Economic Area. Where that is the case, the transfer relies on a European Commission adequacy decision, on the EU-US Data Privacy Framework where the provider is certified, or on standard contractual clauses approved by the Commission, together with the corresponding transfer impact assessment.
You may ask us at any time for the current list of providers, with their function, location and the safeguard relied on.
We may also disclose data to public authorities where the law requires it.
10. Your rights
You may exercise the following rights at any time:
- Access: find out what data we hold about you.
- Rectification: have inaccurate data corrected.
- Erasure: ask us to delete it.
- Objection: object to processing based on our legitimate interest.
- Restriction: ask us to keep it but not use it.
- Portability: receive it in a format you can take elsewhere.
- Withdraw consent at any time, without affecting processing carried out beforehand.
Write to hello@pictiax.com saying which right you wish to exercise. We will reply within one month. Exercising these rights is free of charge.
If you believe we have not handled your request properly, you may complain to the Spanish Data Protection Agency at www.aepd.es, or to the supervisory authority in your country of residence.
11. If you are outside the European Union
We sell and provide services worldwide. In addition to the above, note the following depending on where you are:
United Kingdom
We apply the UK GDPR and the Data Protection Act 2018 to UK residents, with the same rights set out in section 10. The supervisory authority is the Information Commissioner's Office.
Switzerland
We apply the Swiss Federal Act on Data Protection to residents of Switzerland.
United States
Regardless of the fact that, given our size and volume, we do not currently meet the applicability thresholds of the California Consumer Privacy Act, we voluntarily extend to California residents the rights to know what information we collect, to request its deletion, to correct it and not to be discriminated against for exercising them.
We do not sell personal information within the meaning of that statute, nor do we share it for cross-context behavioural advertising. We honour global browser opt-out signals such as Global Privacy Control.
Latin America and the rest of the world
We comply, in addition to the above, with applicable local law, and in particular with Brazil's General Data Protection Law for residents of that country. You may exercise your rights at the same contact address.
12. Security
We apply technical and organisational measures to protect data: encryption in transit, role-based access control, access logging, backups and confidentiality undertakings from staff.
No system is infallible. Should a security breach occur that poses a risk to your rights, we will inform you and notify the supervisory authority within the period required by law.
14. Changes to this policy
We may update this policy when the law changes or when the way we work changes. The version in force is always the one published on this page, with its date and version number shown at the top and bottom.
If a change is material and affects you as a customer, we will notify you by email at least 30 days in advance.
Version 1.1, dated 21 September 2026. We keep previous versions of this policy and will provide the one in force on a given date on request.