FloorFiller Privacy Policy
Last updated: Aug 2, 2026 · Version 1.1
This policy explains which personal data we process, why, on what legal basis, how long we retain it, and what rights you have. It is drafted on the basis of the GDPR (Regulation (EU) 2016/679), the GDPR Implementation Act (Netherlands), and the AI Act (Regulation (EU) 2024/1689).
1. Who we are
FloorFiller
Minckelersstraat 193, 1223 LE Hilversum · KvK 57535612 · contact form
You can submit privacy questions via the contact form.
2. Our role: processor or data controller?
This determines who you can contact.
2.1 The Service
If you use our visualisation button (the "Service") on an account holder's website, the account holder of that website determines the purposes for which your data is used. The account holder is the data controller; we are the processor. We process data exclusively on their documented instructions.
That applies to your uploaded photo, the generated visualisation, your name and email address, the protected results page on floorfiller.ai, and the usage statistics in the account holder's dashboard. Even though that results page is on our domain, we provide it on behalf of the account holder.
In that case, the privacy statement of that website applies in the first instance. This policy applies additionally and describes what we actually do. We have entered into a data processing agreement with each connected account holder.
Do you have a request regarding that data? Please contact the website. If it reaches us anyway, we will forward it without delay and confirm that to you.
In this context we are the processor.
2.2 floorfiller.ai and account holders
Only for the following processing activities do we ourselves determine the purposes and means, and you can exercise your rights directly with us:
- Website visits: your visit to floorfiller.ai outside the Service, for example via a search engine, a demo request, or the contact form
- Account holders: an account holder's account, billing, and our business communications
- Anonymised statistics: fully anonymised business statistics that cannot be traced back to individuals and therefore fall outside the scope of the GDPR
In this context we are the data controller.
2.3 Security
Security, abuse prevention, request limits, and troubleshooting are carried out to comply with Article 32 GDPR in our role as processor. That is not an independent purpose of ours.
3. Which data we process
3.1 Visitors to the Service
On behalf of the account holder, we process among other things:
- Room photo: the photo you upload or take
- Generated visualisation
- Selected product: the product and product context supplied by the account holder
- Name and email address, if you provide them for the higher-resolution version or your results page
- Technical data: IP address (hashed in stored form), browser and device characteristics, timestamp, error messages
- Usage events: opening the Service, uploading, generating, downloading, deleting, aborting
- Proof of consent: timestamp, version of the terms, and a technical identifier
In this context we are the processor.
3.2 Account holders
We process among other things:
- Business details: name, business email address, phone number, company name, Chamber of Commerce (KvK) and VAT number
- Login credentials: we store the password in encrypted form and cannot read it ourselves
- Billing: billing and payment details, processed via our payment service provider
- Account usage: product configuration, settings, and support history
In this context we are the data controller.
3.3 Visitors to floorfiller.ai
We process among other things:
- Technical data: IP address, browser and device information, pages visited, timestamp
- Forms: data you enter in a contact or demo form
In this context we are the data controller.
3.4 What we do not process
We do not request or process special categories of personal data within the meaning of Article 9 GDPR. Such data may unintentionally be visible in an uploaded photo. We therefore explicitly ask you not to upload photos containing persons, and we apply the measures set out in Section 5.
4. Purposes, data used, and legal basis
When you use the Service, the website determines the legal basis. Below we indicate which legal basis applies and what role we play.
| Purpose | Data | Legal basis (Art. 6 GDPR) | Our role |
|---|---|---|---|
| Generating and displaying a visualisation | Room photo, selected product, technical data | Consent (Art. 6(1)(a)) | Processor |
| Delivering the higher-resolution version and making the results page available | Name, email address, visualisations | Consent | Processor |
| Displaying data to the website so it can handle your request | Name, email address, visualisation | Consent | Processor |
| Demonstrating that consent was given | Timestamp, version, identifier | Legal obligation (Art. 7(1) GDPR) | Processor |
| Security, abuse prevention, and request limits | IP address, device characteristics, logs | Compliance with Art. 32 GDPR on behalf of the website | Processor |
| Making recognisable persons in photos unrecognisable | Room photo | Compliance with Art. 32 GDPR, in the interests of data subjects | Processor |
| Usage statistics in the account holder's dashboard | Events, hashed IP address | Legitimate interests of the account holder (Art. 6(1)(f)) | Processor |
| Account, billing, and support for account holders | Account and billing data | Performance of a contract (Art. 6(1)(b)) | Controller |
| Contact and demo requests via our website | Name, email, message | Performance of a contract or legitimate interests | Controller |
| Statutory retention obligation | Billing data | Legal obligation (Art. 6(1)(c)) | Controller |
Withdrawing consent. You can withdraw your consent at any time via the website, via the contact form, or by deleting your results yourself. Withdrawal takes effect prospectively and does not affect the lawfulness of earlier processing.
Objection. You may object to processing based on legitimate interests with the data controller.
No model training. We do not use your data to train AI models. Our AI provider does not use submitted input or generated output from the paid service we use to improve its products or models either. That is contractually agreed.
5. Protection of recognisable persons in photos
5.1 No persons in photos
Our service is intended for photos of empty rooms. We expressly ask you not to upload photos on which persons are visible.
5.2 Face detection
As an additional safeguard, we apply automated face detection within our capabilities to make recognisable faces unrecognisable, for example by blurring them, before the photo is further processed or displayed. We use that detection solely to edit images, not to identify persons, and we do not store a biometric profile in doing so. We process no more than necessary and convert the original photo as quickly as possible.
5.3 Best-efforts obligation
This is expressly a best-efforts obligation and not a guarantee. Automated detection is not fully reliable and may miss persons, for example in profile view, partial occlusion, reflections, or poor lighting. Other identifiable details, such as licence plates, mail, screens, or personal belongings, are not detected.
5.4 Deleting yourself
You can delete an image yourself at any time via your results page. If you nevertheless see a recognisable person or other privacy-sensitive detail, please report it via the contact form. We will then delete it as soon as reasonably possible.
6. How long data is retained
Default: personal data is not retained for longer than twelve months, and for a shorter period where possible. We retain data for longer only where the law requires it. Deletion is automated; in addition, you can delete data yourself at any time.
| Data | Retention period | Reason |
|---|---|---|
| Uploaded room photo | Deleted once the visualisation is ready, at the latest 7 days after upload | Needed only to generate and to regenerate in the event of an error |
| Generated visualisation | 12 months after creation, or earlier upon self-deletion, withdrawal of consent, or a deletion request | So you can retrieve your result |
| Visitor name and email address | 12 months after the last activity, or earlier upon request | Access to your results page and follow-up by the website |
| Technical logs (hashed IP, browser, timestamp) | 12 months | Security, troubleshooting, and abuse prevention |
| Data for request limits | Maximum 24 hours | Technical protection against abuse |
| Proof of consent | For as long as the related processing continues, thereafter a maximum of 12 months | Accountability obligation (Art. 5(2) and Art. 7(1) GDPR) |
| Account holder account data | Duration of the agreement plus 12 months | Contract completion and aftercare |
| Invoices and financial administration | 7 years | Statutory tax retention obligation (Art. 52 Dutch Tax Administration Act) |
| Aggregated statistics | Unlimited, in anonymised form | No longer contains personal data and is not traceable |
Deleting yourself. Via your results page you can permanently delete your visualisations at any time. We cannot restore a deleted image. If an account holder deletes a visitor, the related data is automatically deleted as well.
One retention period over which we have no control. Google retains submitted input and generated output under the paid Gemini API for a limited period, solely to detect violations of the prohibited-use policy and to comply with legal or supervisory obligations. That logging is separate from our own storage with Supabase. We cannot influence its duration and cannot guarantee deletion from it. If you delete a visualisation with us, it is deleted from our systems, but possibly not immediately from that logging. Google does not use the logged data to train or improve its models.
7. Who processes data on our behalf
We engage specialised suppliers. They may use your data only to provide our service, not for their own purposes. With all these parties, processor terms apply with the safeguards required by the GDPR, including standard contractual clauses where necessary. Below we name them and link to their processor terms.
7.1 Delivery of the Service
Google (Gemini API) generates the visualisation using AI. Contracting party: Google Cloud EMEA Limited, 70 Sir John Rogerson's Quay, Dublin 2, Ireland. Processing may take place in the United States and other countries where Google or its agents have facilities. Processor terms: business.safety.google/processorterms.
Supabase provides database and file storage. Contracting party: Supabase Pte. Ltd., Singapore. Storage in the European Union (Ireland region, eu-west-1). Processor terms: supabase.com/legal/dpa.
Vercel provides hosting and content delivery. Contracting party: Vercel Inc., United States. Processing in the EU and US via a global edge network. Processor terms: vercel.com/legal/dpa · sub-processors.
Brevo (Sendinblue) sends transactional email, such as download and access links. Contracting party: Sendinblue SAS, 9-17 rue Salneuve, 75017 Paris, France (RCS Paris 498 019 298). Processing in the European Union. Processor terms: Data Processing Agreement, Appendix 3 at brevo.com/legal/termsofuse.
7.2 Our business operations
These suppliers do not process data from visitors who use the Service, but only data from account holders with an account and from visitors to floorfiller.ai.
Mollie processes payments for account holder subscriptions and credits. Mollie takes the position that in payment processing it is not a processor but an independent data controller alongside us. We therefore do not enter into a data processing agreement with Mollie for payment data; both parties bear their own responsibility. See Mollie's privacy statement.
Supabase, Vercel, and Brevo are also used for account data and website traffic, under the same terms as in Section 7.1.
OpenPanel provides cookieless website analytics for floorfiller.ai (pages visited and general traffic). When we use OpenPanel Cloud, processing takes place in the EU. See also Section 9.
7.3 Changes and further disclosure
If we change a supplier, we update this section and inform connected account holders at least 30 days in advance, with a right to object. A more detailed list with the processing purpose per supplier is available free of charge on request via the contact form.
In addition, data is disclosed to the website where you use the Service, insofar as you have left your data; to competent authorities where legally required; and to an acquiring party in the event of a merger or business acquisition, with prior notice.
Data is never sold and is not shared with advertisers or data brokers.
8. Transfers outside the European Economic Area
8.1 AI processing via Ireland
To generate visualisations, we use Google's paid Gemini API. Our contracting party for this is Google Cloud EMEA Limited, established in Dublin, Ireland. That entity is determined by the billing address of our Google Cloud billing account; for customers in the Netherlands, that is the Irish entity.
This means we ourselves transfer data to a processor within the EEA. Google then also processes that data partly outside the EEA and is itself responsible to us for that, on the basis of the processor terms to which we refer in Section 7.
8.2 No data residency in the EEA
The data we submit to generate a visualisation may temporarily be stored or cached by Google in any country where Google or its agents have facilities, including the United States. We therefore offer no guarantee that your photo will not leave the EEA.
Supabase: the storage itself is in the EU (Ireland), but our contracting party is established in Singapore, which means management and support access from outside the EEA may occur.
Vercel is established in the United States and delivers content worldwide.
8.3 Safeguards we rely on
The GDPR does not require data residency, but it does require a valid basis for transfer. We rely on the European Commission's standard contractual clauses (Art. 46(2)(c) GDPR), as included in our suppliers' processor terms and, where applicable, in the arrangements between those suppliers and their own sub-processors.
Where applicable, we also rely on an adequacy decision, including the EU-US Data Privacy Framework for US parties certified under it.
In addition, we take supplementary measures: encryption in transit, minimisation of what we submit, automated anonymisation of faces (Section 5), and a contractual prohibition on use for model training.
Under Article 46(1) GDPR, you can request a copy or description of these safeguards via the contact form.
9. Cookies and similar technologies
Essential cookies and local storage. Required to make the service work: signing in, session management, security, and remembering your progress in the Service. No consent is required for this (Article 11.7a(3) of the Dutch Telecommunications Act).
Statistics. For floorfiller.ai we use OpenPanel for website statistics (such as pages visited and general traffic). OpenPanel is cookieless: no analytics cookies are placed on your device. Where possible, data is aggregated to help us improve the site. Processing is based on our legitimate interest (Art. 6(1)(f) GDPR) and, when using OpenPanel Cloud, takes place in the EU. You may object via the contact form.
For the Service, usage statistics that the account holder sees in their dashboard are based on events on our servers. To count unique visits we compute an irreversible encrypted value from your IP address and browser characteristics, combined with a secret value that we rotate regularly. We do not store your IP address itself and do not trace it back to individuals. Legal basis: legitimate interests of the account holder for the statistics in their dashboard. You may object to this via the contact form.
We do not place third-party advertising or tracking cookies and do not share data with advertising networks.
All details, including an overview per cookie, are set out in our cookie policy.
10. Email we send
We send email that is necessary for the service: a download link, an access link to your results page, account notifications, and invoices. In doing so, we record whether a message was delivered or returned as undeliverable, so delivery problems can be resolved.
You receive commercial email only from the website, and only where there is a valid legal basis for it.
11. About the AI visualisation
Generative artificial intelligence is used for the visualisations. In line with Article 50 of the AI Act, we inform you about this.
11.1 AI-generated content
We make clear that the result is AI-generated content, in the interface and, where technically possible, by marking the image or file metadata.
11.2 Indication, not a representation
The result is an indication, not an exact representation. Colour, structure, pattern, scale, and lighting may differ. The model can make mistakes.
11.3 Physical sample
Always request a physical sample from the website before making a purchase decision.
11.4 No automated decision-making
No automated decision-making takes place with legal or similarly significant effects for you (Art. 22 GDPR).
11.5 No model training
Your photo is not used to train models.
12. Age
The Service is intended exclusively for persons aged eighteen or older. This limit follows in part from the terms of our AI provider, which prohibit use of the model in services aimed at or likely to be accessible to minors. Connected account holders are contractually required not to place the Service on pages aimed at minors.
If it appears that we have nevertheless processed data from a minor, we will delete it as soon as possible. Please report this via the contact form.
13. Security
We take appropriate technical and organisational measures (Art. 32 GDPR).
13.1 Encryption
All traffic runs over TLS/HTTPS. Stored data is encrypted with our cloud providers.
13.2 Access and separation
Data is strictly separated per customer in our database. Access is based on role and necessity; administrators use two-factor authentication.
13.3 Logging and deletion
We log access to sensitive parts. Deletion is automated according to the periods in Section 6; execution is logged.
13.4 Evaluation
We periodically evaluate our measures and suppliers.
13.5 Data breaches
No system is completely secure. In the event of a data breach posing a risk to data subjects, we report this without delay as processor to the relevant account holder, who then decides on notification to the Dutch Data Protection Authority (Autoriteit Persoonsgegevens) within 72 hours and to data subjects under Article 34 GDPR. For processing for which we are ourselves the controller, we report directly.
13.6 Vulnerabilities
Do you suspect a vulnerability? Please report it via the contact form. We handle responsible disclosure carefully.
14. Your rights
Under the GDPR, you have the right of access, rectification, erasure, restriction, portability, objection, and withdrawal of consent.
14.1 Where do you submit a request?
Does it concern data from the Service? Please contact the website where you used the Service. They are the data controller. We provide them with technical assistance.
Does it concern floorfiller.ai, your contact request, or your business account? Please contact us via the contact form.
Not sure? Feel free to contact us; we will forward your request without delay and confirm that to you.
14.2 Time limit
We respond within one month. For a complex request, that period may be extended by two months, with reasons given within the first month.
14.3 Identity verification
To prevent someone else from requesting your data, we may ask for additional information. We never ask for a copy of your identity document; confirmation via the known email address is usually sufficient.
14.4 Manage it yourself directly
You can delete your visualisations yourself without submitting a request via your results page.
14.5 Complaint to the supervisory authority
You have the right to lodge a complaint with the supervisory authority in the country of your habitual residence, your place of work, or the place of the alleged infringement. In the Netherlands, that is the Dutch Data Protection Authority (Autoriteit Persoonsgegevens), Postbus 93374, 2509 AJ Den Haag, autoriteitpersoonsgegevens.nl.
15. Changes to this policy
We may amend this policy, for example if our service or the regulations change. The current version is always available at floorfiller.ai/en/privacy, with the date of the last change and a version number. In the event of a material change, we inform connected account holders by email and ask visitors to agree again on next use.
16. Contact
FloorFiller · Minckelersstraat 193, 1223 LE Hilversum · KvK 57535612 · contact form