Imazen Product Subscriptions Privacy Policy

Updated 

Imazen LLC Subscription Privacy Policy

Imazen LLC (“Imazen,” “we,” “us,” or “our”) is committed to safeguarding your privacy. This Privacy Policy outlines how we collect, use, disclose, and protect your information when you subscribe to our services or deploy or use our software (the “Services”).

1. Information We Collect

1.1 Subscription and Billing Information

We use Chargebee and Stripe to manage subscriptions and process payments. We use Heroku and AWS S3 and process subscription data, update or create license key files, and store license validation and telemetry data.

When creating or modifying a subscription, account, or product trial with Imazen, by web or email, you may share mandatory and optional information with Imazen and our subprocessors.

This information may include, but is not limited to:

Billing and shipping addresses, contact information, email addresses, phone numbers, company details, subscription plan details, payment history, payment method information, company and project website, licensed domain names, company size and tax ID, invoice details, and other information needed to administer your account, and to process payments.

We also record emails and actions taken in regards to your account, such as account creation, subscription modification, overdue notices, and failed and successful payments.

When utilizing the web services provided by Chargbee and Stripe, such as https://account.imazen.io, they may collect additional information, such as IP address, browser type, and other security information to protect against fraud.

1.2 Visible License Key Information

ImageResizer and Imageflow provide a way for anyone to inspect a portion of the license key associated with a deployment of the software, to verify that the correct license key is being used by the correct party.

This information includes the license owner, (company name), the license kind, license id, issued and expiry dates, enabled features, domain names (if restricted by license), org-size restrictions/discounts, and billing status if the subscription paused, canceled, or overdue.

This information is visible at /imageflow.license or /resizer.license on the domain or server that you have deployed the software to.

1.3 Software Usage Information

When our software fetches a license key, we collect certain technical and usage information. This information is tied to your license key, which is typically associated with a corporation or organization, not an individual person (although the license subscription may have associated contacts, that information is not involved in the telemetry data).

When running the software, you can inspect the exact data being sent by browsing to the /imageflow.debug or /resizer.debug pages. This information is not visible to others unless you have configured the software to allow it.

The data collected by our software includes, but is not limited to:

  • License ID: A unique identifier for your license key.
  • Anonymized data: Certain data, such as MAC addresses, processor GUIDs, and application paths, are anonymized via hash digests so that we cannot reconstruct the original data, but we can still detect changes in the data over time.
  • Timing information: The uptime of the software, the last time the software fetched a license key, and the number of fetches.
  • Reporting Version: The version number of the reporting protocol.
  • Processor and System Information: Details such as whether your system is 64-bit, processor GUID, .NET version, IIS version, integrated pipeline status, working set memory usage, and application path hash.
  • Modules and Plugins Used: Information about the modules and plugins loaded by the software.
  • Hardware Information: Logical core count, MAC address digest, operating system details, drive information, and network status.
  • Performance Metrics: Job completion statistics, encoding and decoding times, scaling ratios, error names and counts, image types and sizes used, and other performance-related data.
  • Configuration Data: The configuration of the software, including the version of the software and certain configuration settings, excluding any credentials or secrets.
  • Image and Query Data: Domain names used to access images, query keys (commands/features) used to modify images, and other usage patterns.

The data collected by AWS S3 and Cloudflare may include but is not limited to the above and the following (in the S3 access logs):

  • IP Address: The IP address of the Imageflow or ImageResizer deployment (not a user or customer). We later redact these IP addresses when processing them.

License keys are replicated to both USA and EU data centers, and the data is encrypted in transit and at rest. Depending on availability, the information may be transmitted or stored in either the USA, EU, or both.

2. Purpose of Collection

We collect this information to:

  • Administer and Manage Accounts: Ensure that your subscription and licensing are active and properly configured.
  • Verify Usage: Confirm that the software is used in compliance with our licensing agreements.
  • Performance Analysis: Understand overall patterns of performance, reliability, and feature usage to improve our services.
  • Technical Support: Assist in diagnosing and resolving technical issues for individual accounts.

3. Data Storage and Retention

  • Storage: The collected information is transmitted securely to us or our subprocessors and stored in encrypted Amazon S3 buckets.
  • Retention Period: We retain this information for a minimum of 30 days and up to 10 years. Retention periods may vary depending on whether there are ongoing billing or technical issues associated with your account.
  • Account Deletion: Customers with paid-up accounts can request deletion of their data. For other accounts, we retain data as necessary for legitimate business purposes and to comply with legal obligations.

4. Data Sharing and Disclosure

  • Third-Party Services: We utilize trusted third-party service providers such as AWS, Cloudflare, Chargebee, Stripe, and Heroku to deliver our services. These providers have their own privacy policies, and we recommend reviewing them.
  • Legal Requirements: We may disclose your information if required by law or in response to valid requests by public authorities.
  • Data Sales: We do not sell or rent your data to third parties.

5. Security Measures

We are committed to protecting your data:

  • Encrypted Storage: All log files and collected data are stored in encrypted formats.
  • Access Control: Access to data processing machines and stored information is protected by strong passwords and is limited to authorized personnel.
  • Data Protection: We employ industry-standard security measures to safeguard your information against unauthorized access or disclosure.

6. Transparency and Access

  • Immediate Transparency: You can access /imageflow.debug or /resizer.debug within your deployment of our software at any time to view the exact information being sent. See /imageflow.license or /resizer.license for the public portion of your license key.
  • Data Requests: If you require a copy of the data we have collected from your license key, you can request it by contacting us at support@imazen.io.

7. Your Rights and Choices

  • License Terms: Our license terms permit source code modification. You may choose to disable telemetry and license key verification if desired.
  • Consent: By using our software, you agree to the collection and use of information as outlined in this policy.
  • Access and Control: You have the right to access, correct, or delete your personal information, subject to our legal obligations.

8. International Users

Our services are available globally:

  • Jurisdiction: This policy is governed by the laws of the State of Colorado, USA.
  • User Rights: Users worldwide have the right to access their data and request corrections or deletions, subject to applicable laws.
  • Age Restriction: The Services are exclusively for the use of individuals who are at least 18 years old and may not be used by minors under 18 years of age.

9. Policy Updates

  • Notification of Changes: Updates to this privacy policy will be posted on this page.
  • Review: We encourage you to review this policy periodically to stay informed about how we are protecting your information.
  • Revision Date: The revision date at the top of the policy will be updated with each change.
  • Historical Versions: Prior versions of the privacy policy are available upon request.

10. Third-Party Service Providers

We use the following third-party service providers to manage subscriptions and process payments:

The Data Processing Agreements (DPAs) provided by these services:

11. Contact Us

If you have any questions or concerns about this privacy policy, or have data protection inquiries, please contact us at:

Email: support@imazen.io or privacy@imazen.io

Mailing Address: Imazen LLC 2093 Philadelphia Pike #1555 Claymont, DE 19703

12. GDPR Compliance and International Data Transfers

We comply with the EU General Data Protection Regulation (GDPR). When transferring data internationally, we rely on appropriate safeguards such as Standard Contractual Clauses. EU users have rights under GDPR, including access, rectification, erasure, and data portability. To exercise these rights, please contact us at privacy@imazen.io.

13. Data Breach Notification

In the event of a data breach affecting your personal information, we will notify affected users and relevant authorities without undue delay, where feasible within 72 hours of becoming aware of the breach, in accordance with applicable law.

14. Subprocessor Management

We carefully select and monitor our subprocessors to ensure they maintain appropriate security and privacy standards. A current list of subprocessors is available upon request. We will inform our business clients of any intended changes concerning the addition or replacement of subprocessors.

15. Our Role as Data Controller

Imazen LLC acts solely as a data controller for the personal data we collect directly from our customers for account management, billing, and software licensing purposes. Our software is designed to collect only aggregated, anonymized data necessary for license enforcement and product improvement.

We do not act as a data processor on behalf of our clients. Our customers are responsible for ensuring their use of our software complies with their own data protection obligations.

The data we collect is used exclusively for our own business purposes and is not processed on behalf of or according to the instructions of our clients. This approach ensures that our customers retain full control and responsibility over any personal data they may handle using our software.

16. Dispute Resolution

If you have any complaints regarding our compliance with this Privacy Policy, please contact us first. We will respond to your complaint promptly. If you are not satisfied with our response, you may have the right to lodge a complaint with a data protection authority in your jurisdiction.

Our customer portal and signup pages at https://account.imazen.io utilize necessary cookies to ensure proper functionality. These pages are managed by our third-party service providers, Chargebee and Stripe.

17.1 What are Cookies?

Cookies are small text files that are placed on your device when you visit a website. They are widely used to make websites work more efficiently and provide information to the website owners.

17.2 Necessary Cookies

We use only necessary cookies on our customer portal and signup pages. These cookies are essential for you to browse the website and use its features, such as accessing secure areas of the site. Without these cookies, services you have asked for cannot be provided.

17.3 Third-Party Cookies

Chargebee and Stripe may use their own cookies as part of providing their services. These cookies are subject to their respective privacy policies:

17.4 Managing Cookies

Most web browsers allow you to control cookies through their settings preferences. However, if you limit the ability of websites to set cookies, you may worsen your overall user experience and/or lose access to some of the functionality of our customer portal and signup pages.

We may update our Cookie Policy from time to time. We encourage you to periodically review this policy for the latest information on our cookie practices.

18. Customer Portal and Signup Pages

Our customer portal and signup pages at account.imazen.io are managed by Chargebee and Stripe. When you use these services, you are subject to their respective privacy policies and terms of service:

These third-party services may collect additional information, such as your IP address, browser type, and other data necessary for fraud prevention and security purposes. We recommend reviewing their privacy policies for more detailed information on how they handle your data.

19. Governing Law and Jurisdiction

This Privacy Policy shall be governed by and construed in accordance with the laws of the State of Colorado, United States, without regard to its conflict of laws principles. Any disputes arising under or in connection with this Privacy Policy shall be subject to the exclusive jurisdiction of the courts located in Colorado.

20. Limitation of Liability and Disclaimer of Warranties

By using the Services, you agree to the following:

  1. Limitation of Liability: To the maximum extent permitted by law, Imazen LLC, including its developers, administrators, and affiliates, shall not be liable for any indirect, incidental, special, consequential, or punitive damages arising out of your access to or use of the Services or Software.

  2. Disclaimer of Warranties: The Services and Software are provided on an “as is” and “as available” basis without any warranties of any kind. We do not guarantee the accuracy, reliability, completeness, or timeliness of our Services or content.

21. Severability

If any provision of this Privacy Policy is held invalid or unenforceable, the remaining provisions will remain in effect.

22. Your Acceptance

By using or accessing the Services in any manner, you acknowledge that you accept the practices and policies outlined in this Privacy Policy. If you do not agree with this Privacy Policy, please do not use our Services.