LENSA APP PRIVACY POLICY

You can see our previous Privacy Policy here

Effective date: 10 July, 2023

INTRODUCTION AND SCOPE

This Lensa App Privacy Policy (“Privacy Policy”) is delivered on behalf of Prisma Labs, Inc. (“Prisma Labs”, “we”, “us”, and “our”) and governs the Personal Data (as defined below) collected from or processed about you when you use the Lensa Photo Editor mobile application (“Lensa”, the “app”, or the “application”), including by downloading, installing, registering with, accessing or otherwise using the application (collectively referred to herein as “Use”).

We provide this Privacy Policy to explain our practices for collecting, using, processing, and disclosing the Personal Data we process about Lensa users (“users”, “you”, or “your”, as applicable), and to tell you about the rights you may have in relation to your Personal Data and choices you may be able to make in relation to it. By Personal Data we mean (i) information that is associated with an identified or identifiable natural person, and (ii) protected as personal data under applicable data protection laws.

This Privacy Policy applies to Personal Data we or any third party collects from you offline or on any of our other apps (e.g., Prisma) or websites, including websites you may access through Lensa.

Please read this Privacy Policy carefully to understand our privacy practices. We also encourage you to get acquainted with our Terms of Use to understand how we provide services to you. For information on how we process photos in connection with various features of our app, including the Magic Avatars feature, please see Section 3: How We Process, Share and Retain Your Photos, Videos, and Image Data.

If you do not want us to process your Personal Data as it is described in this Privacy Policy, please do not Use Lensa.

Questions? If you have any questions about this Privacy Policy or Lensa, please contact us at [email protected]. For additional contact information, please see Section 15: How to Contact Us.

U.S. State Supplements:

TABLE OF CONTENTS

1. PERSONAL DATA WE COLLECT AND HOW WE COLLECT IT

We may collect Personal Data from and about you:

2. PERSONAL DATA YOU PROVIDE TO US DIRECTLY

You may provide Personal Data to us directly, or to service providers that act on our behalf, when you Use Lensa. The Personal Data you provide depends on which features of Lensa you Use and how you interact with the app.

3. HOW WE PROCESS, SHARE, AND RETAIN YOUR PHOTOS, VIDEOS AND IMAGE DATA

We process your photos and videos to provide you with the features of the Lensa application that you choose to Use. In doing so, when you upload photos or videos to Lensa, we process your photos and videos using technology that identifies data that is in the photos and videos and provides us with information, such as information about your facial position, orientation and topology (“Face Data”), and other elements of your photo (collectively, “Image Data”). The following describes how we process, share, and retain your photos, videos and Image Data in connection with various features of the Lensa app. Please note, however, that we may retain your data for longer time periods than set forth below where required to do so by law.

4. PERSONAL DATA WE COLLECT AUTOMATICALLY

When you Use Lensa, we or third parties we permit to do so, may automatically collect certain information, including Personal Data, from you (this is subject to your consent where this is required by law). The information collected from you automatically when you Use Lensa may include:

Other than with respect to Image Data, we and third-parties we engage may use cookies, Software Development Kits (SDKs), and other tracking technologies to automatically collect the Personal Data set forth above. For more information regarding our use of these technologies, please see Section 7: Cookies, Software Development Kits, and Other Tracking Technologies.

5. THE PURPOSES AND OUR LEGAL BASES FOR PROCESSING YOUR PERSONAL DATA

We may use your Personal Data for a variety of purposes depending on the category of Personal Data and the way you Use and interact with the Lensa app, including the following:

6. TO WHOM WE DISCLOSE PERSONAL DATA

We may disclose the information we process about you, including any Personal Data, as follows:

7. COOKIES, SOFTWARE DEVELOPMENT KITS, AND OTHER TRACKING TECHNOLOGIES

When you Use Lensa, we and our service providers, vendors, and partners, including third parties, may use cookies (a small text file placed on your computer or mobile device to identify your computer and web browser) and other similar technologies to collect or receive certain information about you and/or your Use of Lensa. We also use third-party analytics tools like Google Firebase, Facebook Analytics, AppsFlyer, and Amplitude to help us measure traffic and usage trends for Lensa and for other purposes. Such analytics tools collect information via third-party SDKs incorporated into Lensa, which includes information about features of Lensa you visit or Use, your actions in Lensa, and information about your subscription. Such information may be used to provide content, advertising, or functionality or to measure and analyze ad performance on Lensa or other websites or platforms. Third parties may also use such information for their own purposes. For the avoidance of doubt, we do not use Image Data for advertising purposes.

Interest-based Advertising. We may partner with ad networks and other ad-serving providers that serve ads on behalf of us and others on non-affiliated platforms. Some of those ads may be personalized, meaning that they are intended to be relevant to you based on information ad networks and ad serving providers collect about your Use of the app over time, including information about relationships among different browsers and devices. This type of advertising is known as interest-based advertising.

Your Choices. Most browsers and devices are configured to accept cookies and similar tracking technologies automatically. You may be able to set your browser and device options so to limit such technologies. You can visit the Digital Advertising Alliance (“DAA”) Webchoices tool at www.aboutads.info to learn more about this interest-based advertising and how to opt out of this kind of advertising by companies participating in the DAA self-regulatory program, and http://www.aboutads.info/appchoices for information on the DAA’s mobile app opt-out program. You can also opt out of receiving interest-based ads from members of the Network Advertising Initiative (“NAI”) by visiting the NAI consumer opt-out page at http://optout.networkadvertising.org/?c=1#!/. Opting out of receiving interest-based ads does not mean that you will no longer receive ads from us, but rather that the ads will not be tailored to your perceived interests.

You may find that some parts of the app may not function properly if you have refused cookies or similar tracking technologies, and you should be aware that disabling cookies or similar tracking technologies may prevent you from accessing some of our content. Your choices are typically device and browser specific

8. YOUR RIGHTS IN RELATION TO YOUR PERSONAL DATA

Access, modification, correction and erasure. You can send us an email at [email protected] to request access to, modification, correction, update, erasure or portability of any Personal Data that you have provided to us and that we have about you. You can also request deletion of your account inside the app, both for iOS and Android users. We may not accommodate a request to change information if we believe the change would violate any law or legal requirement or cause the information to be incorrect.

EEA/UK individuals. Individuals in the European Economic Area (“EEA”) and the United Kingdom (“UK”) have certain statutory rights in relation to their Personal Data including under the General Data Protection Regulation (Regulation (EU) 2016/679) (“EEA GDPR”) and the UK version of the EEA GDPR (“UK GDPR”) (collectively, the “GDPR”), including the rights specified below. You can exercise these rights by contacting us (for contact information, please see Section 15: How to Contact Us). We will do our best to accommodate your request or objection but please note that not all rights are absolute.

Please keep in mind that in case of a vague request to exercise any of the aforementioned rights we may engage with you in a dialogue to ask for more details if so needed to complete your request. In case this is impossible, we reserve the right to refuse granting your request. Following the provisions of the applicable law, we might also ask you to prove your identity (for example, by requesting your username or some other proof of your identity) in order for you to invoke the mentioned rights. This is made to ensure that no right of third parties is violated by your request, and the mentioned rights are exercised by an actual Personal Data subject or an authorized person.

Please note that we will process your request within one month after receiving it. We may extend this period by up to two months where necessary, taking into account the complexity and number of the requests. If we extend the response period, we will let you know within one month from your request. We will not discriminate against you for exercising your rights under the law.

9. YOUR CHOICES ABOUT OUR COMMUNICATIONS WITH YOU

If you are using Lensa you may receive electronic communications from us (e.g., by posting in-app notices in Lensa, push notifications or emails). We send some of these communications to you, such as those related to your subscriptions, technical and security notices and updates to the Privacy Policy and Terms of Use, where necessary to perform our contract with you to provide Lensa or otherwise based on our legitimate interest in contacting you.

If required by law, we will ask for your consent to send you promotional and marketing emails, in-app communications and push notifications about new products, features or offers from Lensa and its affiliates.

Marketing & Promotional Emails. If you wish to opt-out of our promotional and marketing emails, you can do so:

Push Notifications. If you wish to opt-out of push notifications, you can do so through your mobile device settings by tapping “Settings” -> “Notifications” -> Choose Lensa - > press the toggle to allow or forbid push notifications from the app.

10. DATA SECURITY

We use reasonable and appropriate information security safeguards to help keep your Personal Data secure and in an effort to protect it from accidental loss and unauthorized access, use, alteration and disclosure. Unfortunately, the transmission of information via the internet is not completely secure. Although we take measures to do our best to protect your Personal Data, we cannot guarantee the security of the collected information transmitted to or through Lensa or an absolute guarantee that such information may not be accessed, disclosed, altered, or destroyed. Any transmission of your Personal Data is at your own risk. We are not responsible for the circumvention of security measures contained in Lensa. Please understand that there is no ideal technology or measure to maintain 100% security.

The safety and security of your information also depends on you. For instance, we are not responsible for how you choose to share the photos, videos, Avatars or other information processed in your Lensa account, such as via social media services. We are not responsible for the functionality, privacy, or security measures of any other organization.

11. DATA RETENTION

Other than as set forth in Section 3: How We Process, Share and Retain Your Photos, Videos and Image Data, we generally retain your Personal Data until you delete your Lensa account. If you delete your Lensa account, we will generally delete your account within 4 hours.

To make a request to delete your Lensa account, please contact us at [email protected] or procede through Lensa settings.

Notwithstanding the foregoing, please note that we may retain your Personal Data, photos, videos, Image Data and Avatars for longer periods of time than set forth above, such as in connection with your privacy-related requests and communications with us, if any, as necessary to comply with our legal obligations, to resolve disputes, or to enforce our agreements. Even if we delete some or all of your Personal Data, we may continue to retain and use anonymized data previously collected that can no longer be used for personal identification.

12. CROSS-BORDER DATA TRANSFERS

We and certain of our service providers are incorporated in the United States. Accordingly, your Personal Data may be transferred to and stored in the United States.

Where required under the EEA GDPR, in case of transfers of personal data from the EEA to countries outside the EEA, where we cannot rely on adequacy decisions adopted by the European Commission (for more information, please see here) we ensure appropriate safeguards are in place to guarantee the continued protection of your personal data, particularly by signing the Standard Contractual Clauses of the European Commission (article 46(2)(c) GDPR). For more information on these Standard Contractual Clauses, please see here.

Where required under the UK GDPR, in case of transfers of personal data to countries outside the United Kingdom, we ensure appropriate safeguards are in place to guarantee the continued protection of your personal data, particularly by signing the UK Addendum to the EU Standard Contractual Clauses or the UK International Data Transfer Agreement, whichever is more appropriate in the given situation. For more information on UK Addendum and the UK International Data Transfer Agreement please see here. We may also guarantee the protection of your personal data by relying on adequacy decisions adopted or approved by the authorities in the United Kingdom.

As to the location of our servers, we use AWS servers located in the USA for Lensa operation, while our analytics operations are processed both on the servers provided by AWS (located in the USA) and by Google LLC (located in the Republic of Ireland).

For further information please contact [email protected]

13. CHILDREN

General age limitation. Lensa is not intended for or directed at children under 13, and we do not knowingly collect or solicit any information from anyone under the age of 13 or knowingly allow such persons to Use Lensa. If you are under 13, do not: (i) Use or provide any information in Lensa or through any of its features, or (ii) provide any information about yourself to us, including your name, address, telephone number or email address. If you are a parent or guardian and believe we have collected information from your child who is under the age of 13, please contact us at [email protected].

Age limitation for EEA individuals. You must be at least 18 years old in order to Use Lensa. We do not allow Use of Lensa by EEA individuals younger than 18 years old. If you are aware of anyone younger than 18 Using Lensa, please contact us (for contact information, please see Section 15: How to Contact Us), and we will take the required steps to delete the information provided by such persons.

Age limitation for UK individuals. You must be at least 18 years old in order to Use Lensa. We do not allow Use of Lensa by UK individuals younger than 18 years old. If you are aware of anyone younger than 18 Using Lensa, please contact us (for contact information, please see Section 15: How to Contact Us), and we will take the required steps to delete the information provided by such persons.

14. THIRD-PARTY WEBSITES AND SERVICES

We are not responsible for the practices employed by any websites or services linked to or from Lensa, including the information or content contained within them. Where we have a link to a website or service, linked to or from Lensa, we encourage you to read the privacy policy stated on that website or service before providing information on or through it.

15. HOW TO CONTACT US, EEA/UK REPRESENTATIVE, AND DATA PROTECTION OFFICER

General contact details. If you have any questions about this Privacy Policy or Lensa, please contact us via email at [email protected].

Appointed EEA/UK representative. If you are an individual in the EEA or the UK and you have any questions about this Privacy Policy or Lensa, please contact us via email at [email protected] or at our representative mailing address:

For the EEA: DPOEU LTD
Office 902 Oval Krinou 3 Agios Athanasios 4103 Limassol, Cyprus
Email: [email protected]

For the UK: Palta UK Ltd
Sterling House Fulbourne ROA, Walthamstow, London, E17 4EE
Email: [email protected]

Data protection officer. If you are an individual in the EEA or the UK and you wish to exercise your rights under Section 8, or you have any questions about this Privacy Policy or Lensa, you can contact our data protection officer via email at [email protected].

16. CHANGES TO OUR PRIVACY POLICY

The date this Privacy Policy was last revised is indicated at the top of the page. We may modify or update this Privacy Policy from time to time. Some changes do not require your consent. However, if we determine that the changes may pose risk to your rights and freedoms, we will ask for your consent to those changes separately from this Privacy Policy.