Controller and contact
EURL ZENATI, 60 rue François Ier, 75008 Paris, France, SIREN 981 830 227, is the controller of the data processing needed to run BelleImage, to keep it secure and to handle the requests it receives.
For any question or request about your data, use the contact details.
Your images and results
Selected files stay on your device until processing starts. They are then uploaded for compression, conversion or resizing. The service uses their content, names, sizes, technical characteristics and processing records. Uploaded originals and results are private and accessible only through the owning account.
Account required
An account with an email address and password is required before an image is uploaded or processed. This gives each file, result and history entry one permanent owner across your devices. You can create the account or sign in to an existing one before selecting the processing action.
Logs
Infrastructure and security logs may contain IP addresses, access times and request information. Processing engine logs contain neither images nor file names. Activity and hosting logs are kept for 7 days and usage statistics for 30 days. Technical history is limited to the last 1000 executions, separately from the processing records kept for 90 days.
Purposes and legal bases
Image processing, requested storage and account management rely on performance of the service you request, Article 6(1)(b) of the GDPR. Preventing abuse and diagnosing incidents rely on our legitimate interest in protecting the service. Requests to exercise your rights are handled to meet our legal obligations.
If your images contain data about other people, it is your responsibility to have a legal basis and the permissions needed to process and transmit them.
Hosting and recipients
Accounts and your data are hosted on Scaleway, provided by Scaleway SAS, in Paris (European Union).
Sign-in codes are sent by Scaleway Transactional Email, a service of Scaleway SAS (France), from servers located in France.
The recipients are the authorised people at EURL ZENATI for operating the service and handling requests, the host and the technical providers involved in delivering the service. The competent authorities may receive information where the law requires it.
The hosting provider describes its data processing practices in its privacy policy and contractual documentation. You can ask us for details through the Contact page.
Contact messages
Emails sent to our contact address are routed by Forward Email and then received and processed in Gmail (Google). These providers process the content of the messages, any attachments and the data needed to deliver them. This route may involve processing outside the European Union; it is separate from the storage of your data in your account.
The privacy policies of Forward Email and Google describe their practices. Prefer an example without confidential data when you report a problem to us.
Retention and deletion
Input files, results and processing records are kept for 90 days (about three months), from the creation date of each item. Signing in or downloading does not extend this period. Cleanup runs every 5 minutes: deletion occurs on the next run after expiry. Delete files from the workspace or your history. Deleting an account erases its files and history. Deleting a history item erases the result and its record; the original is also deleted unless another transformation still uses it. An account deletion marker is kept for 24 hours to prevent delayed executions from recreating files.
Account retention
An account is kept until you delete it. Files, results and history entries expire after their own 90-day period, and the service is not a permanent archive: keep your originals and download the results you need. Copies already downloaded stay on your device.
Technical backups
Encrypted technical backups cover accounts, processing records and image files. They run daily and are retained for seven days. Deleted data may remain in a backup until it expires and is not accessible through the application. Before restoring service after a recovery, deletions and expirations since the backup must be applied again.
Storage in your browser
API session cookies, and fallback local storage when necessary, protect access to your files. Your light or dark theme stays in local storage until changed or until site data is cleared. Previews and results retrieved in the workspace remain in the memory of the tab. No advertising tool or external audience measurement service is integrated, so no consent banner is shown.
Your rights
Under the conditions set by the GDPR, you can ask for access to your data, its rectification or erasure, the restriction of a processing operation and the portability of the data concerned. You can also object, on grounds relating to your situation, to processing based on legitimate interest, and give instructions on what happens to your data after your death.
Send your request to the contact details for personal data, from the email address of your account when the request concerns it. We may ask for the information strictly necessary to verify your link with the data. There is no need to send a copy of your identity document unprompted.
A reply is normally given within one month of receiving the request. This period may be extended by two months because of the complexity or the number of requests; you are then informed of the extension and its reasons within the first month.
You can lodge a complaint with the CNIL without having to contact us first.
Security and changes
The measures for transmission, access control and retention are presented on the Security page. The service makes no automated decision producing legal effects concerning you.
This policy may change with the service. Its update date is shown below. Information about a new purpose must be given to you before the corresponding processing.
Last updated: 24 September 2026.