Legal · Privacy
Privacy Policy
1. Who controls your personal data
HOMMMEDIA LIMITED, company number 17287261, is intended to be the controller for the personal data described here. Registered or business address: 128 City Road, London, England, EC1V 2NX, United Kingdom. Privacy enquiries: info@hommm.net.
2. Data we process
- Identity and account data received from Google or GitHub, such as name, email address, avatar and provider identifier.
- Reservation and service data, including plan, selected model, optional alternative-model vote, status, dates and support history.
- Limited billing metadata from Paddle, such as customer, transaction and subscription identifiers, billing contact details and payment-method brand and last four digits. We do not receive or store full card details.
- Security and technical data, such as IP address, browser details, request identifiers, authentication events and logs needed to protect the service.
- Consent choices and, only when permitted, campaign parameters, advertising click identifiers, sanitised landing path and referrer, first- and last-touch attribution and conversion-delivery status. We do not intentionally place account details, credentials, prompts or model output in analytics events.
3. Why we use data and our legal bases
- Account, reservation and requested service: to take steps at your request and perform our contract.
- Checkout, billing, tax and records: to perform our contract and comply with legal obligations; Paddle also acts as Merchant of Record for relevant transactions.
- Security, abuse prevention and reliability: our legitimate interests in protecting users and operating the service, balanced against your rights.
- Optional analytics and advertising: your consent, which you can refuse or withdraw at any time through Cookie settings.
- Service and legal communications: contract performance, legal obligations or legitimate interests, depending on the message.
4. Where data comes from
We receive data directly from you, from your selected identity provider, from Paddle during the reservation and billing lifecycle, and automatically from the devices and systems used to access the service.
5. Providers and recipients
We use service providers only for defined operational purposes. Current categories include Supabase for social-login verification, Google and GitHub as identity providers, Paddle for checkout and Merchant of Record services, hosting and database infrastructure providers, and Google Tag Manager with any analytics or advertising destinations enabled only according to your choices.
Providers may act as processors, independent controllers or both depending on the activity. Their own notices apply where they determine their purposes, including hosted identity and payment interactions.
6. International transfers
Some providers may process data outside the UK. Where the destination is not covered by UK adequacy regulations, we use an applicable safeguard such as the UK International Data Transfer Agreement, the UK Addendum to approved contractual clauses, or another lawful transfer mechanism. Information about the safeguard relevant to your data can be requested from the privacy contact.
7. Retention
We keep data only as long as needed for the purpose, to establish or defend legal claims, and to meet tax, accounting and regulatory requirements. Account and reservation records follow the account lifecycle and our deletion schedule; security logs are kept for a proportionate security period; Paddle retains billing records under its own legal duties. Current retention information can be requested from the privacy contact.
8. Your rights
Depending on the circumstances, UK data protection law may give you rights of access, rectification, erasure, restriction, objection, portability and withdrawal of consent. You may also ask for information about safeguards used for international transfers. Withdrawing consent does not affect earlier lawful processing.
Contact info@hommm.net. We may need to verify your identity. You can also complain to the Information Commissioner’s Office.
9. Automated decisions and children
We do not intend to make decisions based solely on automated processing that produce legal or similarly significant effects. The service is intended for adults and is not designed for children.
10. Cookies, security and changes
See our Cookie Policy for storage and tracking choices. We use technical and organisational safeguards appropriate to the service, but no online system can be guaranteed completely secure. Material policy changes will be communicated in an appropriate way and the effective date will be updated.