Effective Date: November 25, 2025
INTRODUCTION AND OVERVIEW
Welcome to Maison Model X ("Company," "we," "us," "our," or "MMX"). This Privacy Policy governs your visit to https://maisonmodelx.com/ and related services (the "Website"), and explains how we collect, use, safeguard, and disclose information that results from your use of our Services.
Maison Model X is an AI-powered fashion and jewelry model photography service that generates high-quality, customized AI model images and consistent face reference packs for brands, designers, photographers, and e-commerce businesses. We leverage generative artificial intelligence technology to deliver professional-grade digital models without the need for traditional photoshoots.
By accessing, browsing, or using our Service, you acknowledge that you have read, understood, and agree to be bound by all terms and conditions of this Privacy Policy.
LEGAL BASIS AND REGULATORY COMPLIANCE
This Privacy Policy is prepared in compliance with:
- Digital Personal Data Protection (DPDP) Act, 2023 – India's primary data protection legislation
- Information Technology Act, 2000 and related rules
- Consumer Protection Act, 2019
- Indian Contract Act, 1872
- International best practices for data protection and privacy
KEY DEFINITIONS
| Term |
Definition |
| Personal Data |
Any information relating to an identified or identifiable individual, including name, email address, billing address, phone number, and order details. |
| Client Content |
Information, specifications, images, descriptions, reference materials, accessories, color palettes, and other content you provide when placing an order. |
| Generated Content |
The AI-generated model images, reference packs, and photography we create based on your order specifications. |
| Service |
Our website, order platform, AI model generation services, and Consistent Faces reference pack services. |
| Third-Party Service Provider |
External platforms and service providers we use to process orders, store data, generate models, and deliver services. |
| Processing |
Any operation performed on Personal Data, such as collection, storage, use, transfer, or deletion. |
1. DATA COLLECTION AND PERSONAL DATA WE COLLECT
1.1 When We Collect Data
We collect personal data ONLY when you place an order through our order form on the Website. Browsing the Website without placing an order does not result in collection of personal data (except for standard technical data described below).
1.2 Personal Data Collected at Ordering
When you submit an order, we collect:
Contact Information:
- Full name or business name
- Email address
- Billing address (street, city, state/province, postal code, country)
- Phone number (if provided)
Payment Information:
- Card type (Visa, Mastercard, American Express, etc.)
- Last four digits of payment card
- Billing address (may differ from shipping address)
- Payment processor reference number
Order and Specification Information:
- Order number and date
- Model specifications (age, ethnicity, body type, clothing, styling preferences)
- Accessories and customization details
- Color palettes and reference materials
- Number of angles/variations requested (for Consistent Faces)
- Delivery preferences (standard or rush)
- Special requests or customization notes
Client Content:
- Any reference images you provide
- Design descriptions and creative direction
- Brand guidelines or style inspiration you submit
- Accessory images or product specifications
Service Tier Information:
- Service selected (General AI Model Generation or Consistent Faces)
- Pricing tier and payment amount
- Revision preferences and customization level
- Rush delivery request (if applicable)
Communication Data:
- Your email communications with us
- Refinement requests and support inquiries
- Feedback, complaints, or quality concerns
Technical Data (automatically collected):
- IP address and device identifier
- Browser type and version
- Operating system
- Pages visited and features used
- Time and duration of visit
- Referring website
1.3 Client Content – Special Privacy Considerations
Important: Client Content (reference images, design details, brand specifications you provide) is sensitive and is handled with heightened security:
- Reference images are used solely to generate your custom models
- Design specifications are not retained longer than necessary to fulfill your order
- Client Content is never used to train AI models, improve our algorithms, or for any secondary purpose
- Accessory images and color palettes are deleted after order fulfillment and the 7-day revision window
- You retain full ownership of all Client Content
2. LEGAL BASIS FOR DATA PROCESSING
We process your Personal Data based on the following legal grounds:
| Purpose |
Legal Basis |
Duration |
| Order Processing & Fulfillment |
Contractual necessity – to process your order and deliver AI models |
Duration of order fulfillment + 7 days |
| Payment Processing |
Contractual necessity – to complete payment transactions |
Until payment confirmed |
| Model Generation |
Contractual necessity – to generate your custom models |
Duration of generation process |
| Delivery |
Contractual necessity – to send completed models to your email |
At time of delivery |
| Customer Communication |
Legitimate interest – to provide order updates, respond to inquiries |
During 7-day revision window + 30 days for support |
| Refinement Support |
Contractual necessity – to process revision requests and deliver refinements |
Until order completion and 7-day window expires |
| Legal Compliance |
Legal obligation – to comply with Indian laws and regulations |
As required by law (typically 7 years for records) |
| Dispute Resolution |
Legitimate interest – to address disputes and quality concerns |
Until dispute resolved + 2 years for records |
| Fraud Prevention |
Legitimate interest – to prevent fraudulent transactions |
2 years after transaction |
3. HOW WE USE YOUR PERSONAL DATA
3.1 Primary Uses
Your Personal Data is used exclusively for:
Order Fulfillment:
- Processing your order and payment
- Generating your custom AI models based on your specifications
- Delivering digital files to your email
- Tracking order status and providing updates
- Managing refinements and revisions during the 7-day window
Communication:
- Sending order confirmations and delivery notifications
- Providing updates on order status
- Responding to your inquiries and support requests
- Notifying you of refinement completion
- Communicating refund determinations
Service Improvement:
- Understanding how you use our Services
- Identifying and resolving technical issues
- Enhancing user experience and website performance
- Collecting feedback on service quality
Legal Compliance:
- Complying with applicable laws and regulations
- Responding to legal requests and court orders
- Maintaining records for tax and accounting purposes
- Documenting order history for dispute resolution
3.2 Purposes We DO NOT Use Your Data For
We explicitly DO NOT use your Personal Data for:
- Training or improving our AI models
- Building customer profiles for analytics or behavioral tracking
- Marketing or promotional purposes (unless you separately opt-in)
- Selling to third parties
- Creating a customer database or mailing list
- Profiling or creating consumer insights
- Secondary commercial purposes
- Any purpose outside order fulfillment and legal compliance
4. DATA RETENTION AND DELETION
4.1 Retention Periods by Data Type
We retain Personal Data for specific periods based on the type of data and applicable legal requirements:
| Data Type |
Retention Period |
Reason |
| Order Information |
7 days after delivery + 2 years |
Address refund requests (7-day window) + legal/tax compliance |
| Payment Records |
As required by law (typically 7 years) |
Compliance with Indian tax and financial regulations |
| Support Communications |
Until dispute is resolved + 2 years |
Document order issues, refinement requests, and disputes |
| Delivery Records |
2 years |
Verify delivery dates and support future disputes |
| Client Content (reference images) |
Until order completion + 7 days |
Generate models and process refinements; deleted after revision window |
| Temporary Processing Files |
Until order completion |
AI generation and optimization; deleted upon delivery |
| Technical/Access Logs |
30–90 days |
System security and performance monitoring |
| Communication Records |
Until resolution + 2 years |
Support and dispute documentation |
| Payment Processor Records |
7 years (held by processor) |
Legal compliance; retained by payment processors, not by us |
4.2 Automatic Deletion
After retention periods expire, Personal Data is automatically deleted from our systems and third-party service providers' systems, unless:
- You request extended retention for legitimate business purposes
- Legal requirements mandate continued retention
- Dispute or legal action is ongoing
- You provide consent for alternative uses
4.3 Your Right to Request Deletion
You have the right to request deletion of your Personal Data at any time, subject to:
- Legal retention requirements (we cannot delete records required by law)
- Ongoing disputes or active orders (we retain data during resolution)
- Fraud investigations or security concerns (we retain data as needed)
To request deletion:
- Email maisonmodelx@gmail.com with your order number
- State your reason for deletion request
- Include "Data Deletion Request" in subject line
- We will respond within 30 days
Important Note: Since we do not create user accounts or maintain profiles, deletion applies only to Personal Data associated with your specific order(s). We do not maintain a persistent customer database that requires account deletion.
5. THIRD-PARTY DATA PROCESSING AND SERVICE PROVIDERS
5.1 Third-Party Service Provider Use
All customer orders, data processing, and file delivery are managed through third-party service providers. We do not independently store, process, or manage customer data in our own systems.
We work with third-party providers to:
- Store and secure order information
- Process payments and payment authorization
- Generate AI models based on your specifications
- Store and organize deliverable files
- Manage email delivery of generated models
- Provide CRM and business management functions
- Maintain data backups and disaster recovery
- Handle customer support and order tracking
5.2 Specific Third-Party Functions
When you submit an order through our Website:
- Order Form Submission: Your order form data is transmitted to third-party CRM/order management platforms (e.g., Bitrix24 or similar)
- Payment Processing: Payment information is sent to PCI-DSS compliant payment processors (e.g., Stripe, PayPal)
- Model Generation: Your order specifications are transmitted to AI generation platforms (e.g., Lovart.ai or similar)
- File Storage and Delivery: Generated files are stored on secure cloud hosting and delivered via email
- Communication: Support communications and updates are managed through third-party email and customer management systems
5.3 Third-Party Service Provider Selection Criteria
We select third-party service providers based on their implementation of:
- Encryption standards: Data encrypted in transit (TLS 1.2+) and at rest (AES-256 or equivalent)
- Access controls: Role-based access, multi-factor authentication, staff training
- Security monitoring: Regular security audits, vulnerability assessments, intrusion detection
- Compliance: GDPR compliance (for international standards), SOC 2 certification, ISO 27001
- Data protection: Contractual data protection agreements, data processing terms, liability clauses
- Incident response: Breach notification procedures, incident response plans, remediation processes
- Backup and recovery: Secure backups, disaster recovery protocols, business continuity plans
5.4 Data Processing Agreements
We do not disclose specific third-party company names to protect business operations and maintain service flexibility. All third-party providers are contractually bound to:
- Maintain data security and implement required protections
- Comply with Indian data protection laws (DPDP Act, 2023)
- Process data only for the purposes specified
- Not disclose data to unauthorized parties
- Delete data upon completion or at our instruction
- Cooperate with data subject rights requests
- Notify us of any security breaches or incidents
6. SECURITY MEASURES AND DATA PROTECTION
6.1 Security Infrastructure
While we rely on third-party service providers' security infrastructure, we implement the following protections:
Data in Transit:
- All data transmitted between your device and our servers uses HTTPS with TLS 1.2+ encryption
- Secure transmission protocols protect order data, payment information, and Client Content
- Email communications use encrypted channels where available
Data at Rest:
- Personal Data stored on third-party platforms is encrypted using AES-256 or equivalent
- Access is restricted to authorized personnel only
- Multi-factor authentication is required for administrative access
- Regular security updates and patches are applied
Payment Security:
- We do not store full credit card numbers locally
- Payment processing is handled by PCI-DSS compliant third-party processors
- All payment information is encrypted and processed through secure gateways
- Tokenization is used to prevent unauthorized card reuse
Access Controls:
- Personal Data is accessible only to MMX staff with legitimate business needs
- Staff sign confidentiality agreements
- Access is logged and monitored
- Unnecessary data access is prevented through role-based permissions
System Security:
- Regular security audits and vulnerability assessments
- Intrusion detection and prevention systems
- Regular software updates and security patches
- Firewalls and network segmentation
- Security monitoring and incident response procedures
6.2 Your Security Responsibilities
To protect your Personal Data, you agree to:
- Keep your email password confidential and unique
- Do not share your order information with unauthorized individuals
- Report any suspicious activity immediately
- Use secure internet connections (not public WiFi) for sensitive transactions
- Update your browser and security software regularly
7. PAYMENT PROCESSING AND FINANCIAL DATA
7.1 Payment Processing
Payment processing is handled exclusively by third-party payment processors (Stripe, PayPal, or similar). We do not handle payment information directly.
How Payment Processing Works:
- You enter payment information on our secure payment form (hosted by processor)
- Payment information never passes through our servers
- Processor authorizes the transaction and notifies us of success/failure
- We receive only a transaction reference number and authorization status
- Your payment method is securely stored (encrypted) by the processor, not by us
7.2 Credit Card Information
We do NOT store:
- Full credit card numbers
- CVV/CVC security codes
- Expiration dates
- Other sensitive card details
Payment processors securely store:
- Tokenized payment method information (encrypted, non-usable data)
- Transaction history
- Payment authorization records
7.3 Payment Information Security
All payment information is:
- Encrypted using industry-standard protocols (TLS 1.2+)
- Processed through PCI-DSS compliant payment gateways
- Protected by additional security measures (fraud detection, address verification)
- Never transmitted in plain text or unencrypted form
8. DATA BREACH NOTIFICATION
8.1 Breach Response Procedures
In the event of a personal data breach affecting our customers, we will:
- Immediate Investigation: Identify the scope and nature of the breach
- Customer Notification: Notify affected customers as soon as possible (within 72 hours when feasible)
- Regulatory Notification: Notify the Data Protection Board of India (DPBI) within 72 hours as required by law
- Breach Communication: Provide clear information about:
- What data was compromised
- When the breach occurred
- Measures we are taking to address it
- Steps customers should take to protect themselves
- Remediation: Implement corrective measures to prevent similar breaches
- Documentation: Maintain detailed records of the breach, notification, and remediation
8.2 Breach Documentation
We maintain records of any security incidents, including:
- Date and time of discovery
- Scope of affected Personal Data
- Affected individuals
- Remediation steps taken
- Notifications sent
- Outcome and lessons learned
9. YOUR DATA PROTECTION RIGHTS
Under India's Digital Personal Data Protection (DPDP) Act, 2023, you have the following rights regarding your Personal Data:
9.1 Right to Access
You have the right to request and receive:
- A complete copy of your Personal Data we hold
- Details of how your data is being processed
- Purposes for which your data is used
- Duration of data retention
- Recipients of your data (third parties)
- Source of your data (if collected from others)
To exercise this right:
- Contact us at maisonmodelx@gmail.com with your order number
- Include "Data Access Request" in the subject line
- We will provide your information within 30 days
- Information will be provided in a portable, machine-readable format (CSV, PDF, etc.)
9.2 Right to Correction
You have the right to request correction of inaccurate or incomplete Personal Data.
This includes:
- Correcting spelling errors in your name or address
- Updating email or contact information
- Correcting billing or payment details
- Clarifying ambiguous or incomplete information
To exercise this right:
- Contact us at maisonmodelx@gmail.com
- Clearly specify which information is inaccurate
- Provide corrected information
- Include "Data Correction Request" in subject line
- We will correct your data within 30 days
- We will notify you of the correction
9.3 Right to Deletion (Right to Be Forgotten)
You have the right to request deletion of your Personal Data, subject to:
- Legal retention requirements – We cannot delete records required by law (e.g., payment records required for 7 years by tax law)
- Ongoing disputes – We retain data during active refund claims or disputes
- Fraud investigations – We retain data during fraud investigations or security incidents
- Legitimate business interest – In limited circumstances where retention is necessary
Grounds for Deletion:
- Your data is no longer necessary for the original purpose
- You withdraw consent for processing
- You object to processing and there is no overriding reason to retain data
- Your data has been processed unlawfully
- Legal obligation requires deletion
To exercise this right:
- Contact us at maisonmodelx@gmail.com with your order number
- Clearly state your reason for deletion
- Include "Data Deletion Request" in subject line
- We will delete your data within 30 days unless legal reasons require retention
- We will notify you of the deletion or reasons for non-compliance
9.4 Right to Restrict Processing
You have the right to request that we restrict processing of your Personal Data while we verify accuracy or investigate disputed claims.
This means:
- Your data will be stored securely but not actively processed
- We will not use your data for marketing, analytics, or secondary purposes
- We may continue processing for legal compliance or legitimate business reasons
To exercise this right:
- Contact us at maisonmodelx@gmail.com
- Include "Data Restriction Request" in subject line
- We will restrict processing within 30 days
9.5 Right to Withdraw Consent
For any processing based on your consent, you have the right to withdraw that consent at any time.
- Withdrawal will be effective immediately upon receipt
- Withdrawal does not affect the lawfulness of processing before withdrawal
- We will not continue processing based on withdrawn consent (but may continue for other legal reasons)
To exercise this right:
- Contact us at maisonmodelx@gmail.com
- Include "Consent Withdrawal Request" in subject line
- Specify which consent you are withdrawing
- We will acknowledge withdrawal within 30 days
9.6 Right to Nominate a Representative
You have the right to nominate a representative (an individual or organization) to exercise your data protection rights on your behalf.
This is particularly useful for individuals who are:
- Minors
- In custody or care arrangements
- Unable to assert rights independently
To nominate a representative:
- Contact us at maisonmodelx@gmail.com
- Provide written authorization from your representative
- Include "Representative Nomination" in subject line
- We will require proof of authorization and legal standing
9.7 Right to Complain
You have the right to lodge a complaint with the Data Protection Board of India if you believe we have violated your data protection rights.
Contact Information for Complaints:
- Data Protection Board of India (DPBI) – formal complaints regarding DPDP Act violations
- District Consumer Commission – for consumer protection complaints
- Contact through: Your state's official channels or the DPBI portal
10. RESPONSE TO DATA SUBJECT RIGHTS REQUESTS
10.1 Response Timeline
We will respond to your data protection rights requests within 30 days from the date of receipt. This includes:
- Confirming receipt of your request
- Providing requested information or taking requested action
- Explaining any delays or reasons for non-compliance
10.2 Request Extension
If responding to your request requires significant additional time due to complexity or volume:
- We will notify you within 30 days
- We will provide a revised timeline (not exceeding 60 days total)
- We will explain the reason for the extension
10.3 Verification of Identity
To protect your privacy and prevent unauthorized access to your data:
- We may request verification of your identity
- We may ask for your order number
- We may request additional identifying information
- This verification process will not unreasonably delay your request
10.4 Reasonable Requests
We will honor all reasonable requests that comply with applicable law. Requests that are:
- Frivolous, vexatious, or repetitive
- Manifestly unfounded or excessive
- Impossible to fulfill
- Potentially harmful to our business or others' privacy
...may be declined, and we will explain our reasoning.
11. INTELLECTUAL PROPERTY RIGHTS REGARDING YOUR DATA
11.1 Your Ownership of Client Content
You retain full ownership of all Client Content (specifications, descriptions, reference images, design details, accessories, color palettes, and other materials) that you provide to us when placing an order.
11.2 Limited License to MMX
By submitting Client Content, you grant us a limited, non-exclusive license to use your Client Content solely for:
- Generating your custom AI models and images
- Fulfilling your order
- Providing refinements and revisions within the 7-day window
- Quality assurance and technical optimization
- Improving our generation processes (only in aggregate, anonymized form)
This license terminates once your order is completed and delivered.
11.3 Your Rights to Generated Content
Upon full payment of your order, you receive exclusive commercial rights to use the Generated Content (AI-generated model images and reference packs we create for you).
Specifically, you receive:
- Worldwide, perpetual, royalty-free commercial license for all lawful uses
- Full ownership of Generated Content upon delivery and payment
- Right to modify, adapt, or create derivatives of Generated Content for your use
- Right to use across all platforms without geographic limitation
- Right to sublicense only for specific commercial partnerships (with separate agreements)
11.4 MMX Rights to Generated Content
MMX retains NO ownership rights to Generated Content after delivery and full payment. We explicitly do NOT:
- Retain copies of Generated Content after delivery
- Use your Generated Content for marketing, portfolio display, or promotion (without your consent)
- Use your Generated Content to train or improve our AI models
- Use your Generated Content for secondary commercial purposes
- Share your Generated Content with third parties
11.5 Portfolio Use – Optional Permission
If you wish to allow MMX to showcase your Generated Content in our portfolio, marketing materials, case studies, testimonials, or social media:
- You may grant this permission separately in writing
- Permission is entirely optional and not required for service
- You may revoke permission at any time
- We will remove your content from public display within 30 days of revocation
- Contact us at maisonmodelx@gmail.com to authorize or revoke portfolio use
12. INTERNATIONAL DATA TRANSFERS
12.1 Data Processing Location
The Services are hosted and operated in India. All data processing, storage, and management occur on:
- Servers located in India, OR
- Third-party service providers based in India, OR
- Secure cloud infrastructure with data residency in India
12.2 Cross-Border Data Transfers
If you access the Services from outside India, your Personal Data will be:
- Transferred to India for processing and storage
- Processed according to Indian law (DPDP Act, 2023, IT Act, 2000)
- Protected by Indian data protection standards and MMX security measures
- Stored in India unless you authorize alternative arrangements
12.3 Your Consent to International Transfer
By using our Services, you consent to:
- Transfer of your Personal Data to India
- Processing of your data according to Indian law
- Storage of your data on Indian or India-based infrastructure
- Potential differences in data protection standards between India and your home country
12.4 Non-Indian Users – Important Acknowledgments
Users from other countries (EU, US, Canada, etc.) acknowledge that:
- Indian data protection laws may differ from your home country's laws
- You may have fewer statutory protections than in your home jurisdiction
- Your data will be transferred out of your country of residence
- You are voluntarily submitting to Indian jurisdiction and Indian law
- You waive any claim that data transfer violates your home country's laws
13. CHILDREN'S DATA PROTECTION
13.1 Age Restrictions
We do not knowingly collect Personal Data from children under 13 years of age.
The Services are intended for users 13 years and older. Minors under 18 must have parental or guardian permission to use the Services.
13.2 Parental Consent for Minors
If a minor (under 18) uses our Services with parental consent:
- Parents/guardians are responsible for reviewing this Privacy Policy
- Parents/guardians authorize data collection on behalf of the minor
- Parents/guardians accept liability for the minor's use
- Children must provide accurate information and comply with our Terms
13.3 Accidental Collection from Children
If we become aware that we have collected Personal Data from a child under 13 without verifiable parental consent:
- We will delete such data immediately
- We will notify parents/guardians of the data collection
- We will delete the child's account (if created)
- We will not process the child's data further
13.4 Reporting Children's Data Collection
To report: If you believe we have collected data from a child under 13 without proper consent:
- Contact us immediately at maisonmodelx@gmail.com
- Include "Child Data Protection Concern" in subject line
- Provide the child's details and circumstances
- We will investigate and respond within 24 hours
14. THIRD-PARTY LINKS AND EXTERNAL WEBSITES
14.1 Third-Party Links
Our Website may contain links to third-party websites and services. This Privacy Policy applies only to our Services.
14.2 No Responsibility for Third Parties
We are not responsible for:
- Privacy practices of third-party websites
- Data collection or processing by third parties
- Third-party terms of service or privacy policies
- Accuracy, completeness, or legality of third-party content
- Harm caused by third-party services or content
14.3 Third-Party Privacy Policies
When you access third-party websites:
- This Privacy Policy no longer applies
- The third party's privacy policy governs your data
- We recommend reviewing third-party privacy policies before providing information
- We are not liable for third-party data practices
14.4 User Responsibility
By accessing third-party links, you:
- Assume all risks associated with third-party services
- Waive claims against MMX for third-party conduct
- Agree to third-party terms and privacy practices
- Accept responsibility for your own data protection
15. COOKIES AND TRACKING TECHNOLOGIES
15.1 Website Cookies
Our Website may use cookies and similar tracking technologies to:
- Remember your preferences
- Understand how you use our Services
- Improve website performance
- Track analytics and usage patterns
15.2 Types of Cookies
Essential Cookies (Required):
- Session cookies for order processing
- Security cookies for protection against fraud
- Necessary for core functionality
Analytics Cookies (Optional):
- Google Analytics or similar tools
- Understand traffic patterns and user behavior
- Improve website experience
15.3 Cookie Consent
By using our Website, you consent to cookie use. You may:
- Disable cookies in your browser settings
- Opt out of analytics tracking
- Clear cookies from your device
Note: Disabling essential cookies may prevent use of certain Services.
15.4 No Third-Party Tracking Pixels
We do NOT use:
- Third-party tracking pixels
- Spyware or malware
- Hidden data collection mechanisms
- Unauthorized tracking software
16. EMAIL COMMUNICATIONS AND PREFERENCES
16.1 Email Communications Only
We communicate with you exclusively via email at the email address you provide during ordering.
We only send emails related to:
- Order confirmation and status updates
- Delivery notifications and file links
- Refinement request acknowledgments
- Refund determinations
- Customer support and responses to your inquiries
- Service-related announcements (if critical)
16.2 Email Address
16.3 No Optional Communications
Since we only send order-specific communications:
- There are no email preferences to modify
- All communications are necessary for order fulfillment
- You cannot opt out of order-related emails
- Communications cannot be deferred or delayed
16.4 Opting Out of Service
If you do not wish to receive any communications from us:
- You must opt out of using our Services entirely
- Do not place orders
- Discontinue use of our Website
- Contact us to request account data deletion
18. COMPLIANCE WITH INDIAN LAWS
18.1 Digital Personal Data Protection (DPDP) Act, 2023
We comply with the DPDP Act, 2023 by:
- Collecting only necessary and relevant Personal Data
- Processing data based on lawful grounds (consent, contract, legal obligation, legitimate interest)
- Maintaining data accuracy and completeness
- Implementing security measures to protect Personal Data
- Honoring data subject rights (access, correction, deletion, withdrawal of consent)
- Notifying data breaches within 72 hours
- Maintaining records of data processing
- Providing clear transparency about data practices
18.2 Information Technology Act, 2000
We comply with the Information Technology Act, 2000 by:
- Implementing adequate security measures (Rule 8)
- Maintaining reasonable data security standards
- Following secure practices for password and access management
- Implementing encryption and authentication controls
- Conducting regular security audits
- Maintaining incident response procedures
18.3 Consumer Protection Act, 2019
We comply with the Consumer Protection Act, 2019 by:
- Providing clear, accurate information about our Services
- Processing complaints and disputes fairly
- Offering reasonable refund options
- Protecting consumer data and privacy
- Maintaining transparency in pricing and terms
- Honoring consumer protection rights
19. UPDATES TO THIS PRIVACY POLICY
19.1 Right to Modify
We reserve the right to modify this Privacy Policy at any time. Changes will be effective immediately upon posting to our Website.
19.2 Notification of Significant Changes
For significant changes (material alterations to data practices, new uses of data, or reduced privacy protections):
- We will provide notice via email when feasible
- We will post notice prominently on our Website
- We will provide a 15-day notice period before changes take effect
Significant changes include:
- Changes to types of data collected
- Changes to data retention periods
- New purposes for processing data
- Changes to data sharing practices
- Changes to your data protection rights
19.3 Last Updated
This Privacy Policy was last updated on January 3, 2026.
Version History:
- v1.0 (November 20, 2025): Initial publication
- v2.0 (November 25, 2025): Consolidated with Consistent Faces Service; enhanced compliance and clarity
20. ADDITIONAL PRIVACY PROTECTIONS
20.1 Transparency Commitment
We are committed to transparency about data practices:
- We clearly explain what data we collect
- We explain why we collect data
- We explain how we use and protect data
- We explain how long we retain data
- We explain your rights regarding your data
20.2 Data Minimization Principle
We collect only the data necessary to:
- Process your order
- Deliver our Services
- Fulfill legal obligations
- Protect business interests
We do NOT engage in unnecessary or excessive data collection.
20.3 Purpose Limitation Principle
Your Personal Data is used only for purposes:
- Disclosed in this Privacy Policy
- Authorized by you explicitly
- Required by law
- Reasonably related to our Services
20.4 Integrity and Confidentiality
We ensure Personal Data is:
- Accurate and kept current
- Protected against unauthorized access
- Kept strictly confidential
- Handled only by authorized individuals
- Deleted securely when no longer needed
21. ACKNOWLEDGMENT AND ACCEPTANCE
21.1 Your Acknowledgment
By using Maison Model X's Services, you acknowledge that:
- You have read, understood, and agree to this Privacy Policy
- You understand how your Personal Data is collected, used, and protected
- You consent to the processing of your Personal Data as described
- You understand your data protection rights
- You understand data transfer to India
- You have the right to withdraw consent or file complaints
21.2 Acceptance
Your use of our Services constitutes your full acceptance of this Privacy Policy, including all data practices, protections, and limitations described.
21.3 Disagreement
If you do not agree with any provision of this Privacy Policy, you must discontinue use of the Services immediately.
Continued use constitutes acceptance.
22. FINAL PROVISIONS
This Privacy Policy was created to protect your Personal Data while enabling Maison Model X to provide high-quality AI model generation and Consistent Faces services. We are committed to complying with Indian data protection laws, maintaining security, and respecting your privacy rights.
For questions, clarifications, or to exercise your data protection rights, contact us at maisonmodelx@gmail.com.
END OF PRIVACY POLICY
Last Updated: January 3, 2026