Privacy policy

Last updated: May 14, 2026

Purpose of this policy

This policy explains how Granit processes personal data from marketing visitors, people who contact us, platform users and, where applicable, clients or collaborators invited into private galleries.

Data controller

The data controller is [company name], [full address], reachable at privacy@granit.app. Final corporate details and, if applicable, DPO or privacy contact details must be confirmed before final publication.

Data we collect

Granit may process identity and contact details, account information, language preferences, billing data handled through Stripe, technical logs, security data, and the media, metadata and content voluntarily entrusted by users.

Purposes and legal bases

Processing is used to provide the service, manage accounts and subscriptions, secure the platform, respond to requests, comply with legal obligations, improve the product and, where consent is required, measure audience or send communications. Legal bases may include contract performance, legitimate interest, legal obligation or consent.

Processors and transfers

Data may be entrusted to hosting, database, object storage, CDN, payment, transactional email, support or analytics providers. The precise list of processors, their locations and safeguards for transfers outside the EEA must be maintained in the legally approved version.

Retention

Data is kept for as long as necessary for the purposes described: active account duration, statutory invoicing and accounting periods, limited security log retention, then deletion or anonymisation when applicable obligations allow.

Your rights

You may request access, rectification, erasure, restriction, objection or portability where these rights apply. Requests should be sent to privacy@granit.app. You may also lodge a complaint with the CNIL or the competent authority in your country.

Security

Granit applies proportionate technical and organisational safeguards: access control, logging, encryption in transit, environment separation, backups and limited data access for service operations.