Pixel Mill · Privacy Policy · v1.0 · Effective 21 July 2026
| Field | Value |
| Operator | MANAGEMENT RESILIENCE LTD |
| Company number | 15587224 |
| Registered office | 20 Wenlock Road, London, England, N1 7GU |
| Trading name / brand | Pixel Mill |
| Website | https://pixel-mill.com |
| Contact email | info@pixel-mill.com |
| Support / complaints | info@pixel-mill.com; written correspondence may also be sent to the registered office |
| Governing law | England and Wales |
| Document version | v1.0 |
| Effective date | 21 July 2026 |
| Important: Pixel Mill uses personal data to operate Accounts, payments, Token fulfilment and image generation; payment credentials are handled by the checkout provider, and privacy rights remain available. |
| Who this Policy applies to: customers, prospective customers, Account users, website visitors, rights holders, complainants, authorised representatives and business contacts interacting with Pixel Mill. |
1. Introduction and scope
1.1 This Privacy Policy explains how Pixel Mill processes personal data of customers, prospective customers, Account users, website visitors, rights holders, complainants and business contacts. In practice, introduction and scope is assessed through the data, purpose, lawful basis, recipient, retention need and individual request, with the result reflected in the processing decision, response record and protective measure.
1.2 It covers the website, Account, checkout, Token fulfilment, image generation, downloads, support, security and associated communications. When applying introduction and scope, those indicators are considered together rather than relying on a single unverified assertion. The applicable framework includes the United Kingdom General Data Protection Regulation, Data Protection Act 2018, Privacy and Electronic Communications Regulations 2003 and applicable Data (Use and Access) Act 2025 amendments.
2. Controller and contact
2.1 MANAGEMENT RESILIENCE LTD is the controller for Pixel Mill’s own processing and is registered at 20 Wenlock Road, London, England, N1 7GU. The operational checkpoint for controller and contact is applicable status, user location, request details, correspondence and mandatory legal conditions; completion is shown by the reasoned response, escalation route and preserved statutory option.
2.2 Privacy enquiries and rights requests should be sent to info@pixel-mill.com, and postal requests may be sent to the registered office.
2.3 Service providers may act as processors or independent controllers depending on their payment, security, regulatory or operational purpose. This treatment of controller and contact is traceable without expanding collection or restriction beyond what the situation requires.
3. Age position
3.1 The Service is intended for adults aged 18 or over and is not directed to children.
3.2 If Pixel Mill learns that a child submitted personal data, it may suspend access, verify authority, delete appropriate data and retain limited safeguarding or legal records. For age position, relevant indicators include age requirement, Account control, payment authority and any credible safeguarding information, and the resulting action is documented through the eligibility decision, protective restriction and limited disclosure record.
3.3 Users must not upload a child’s image or data without lawful authority, appropriate safeguarding and a permitted purpose.
3.4 The age position approach is calibrated to the transaction, request or risk actually identified and preserves any mandatory remedy.
4. Categories of personal data
4.1 Pixel Mill processes Account identifiers, transaction and entitlement data, payment metadata, device and usage data, prompts, uploads, outputs, communications, consent preferences, security signals and rights-management information. Implementation of categories of personal data links data category, purpose, lawful basis, recipient, location and retention criterion to the processing record, rights response and deletion or retention action, so the practical consequence can be explained and reviewed.
4.2 A physical shipping address is not ordinarily needed because the Service delivers only digital products, although billing country or address may be collected for payment, tax, authentication or risk. No categories of personal data outcome is based solely on a technical label where reliable contrary evidence is available. Special-category data is not required and should not be submitted unless an expressly supported feature and lawful basis justify it.
Personal data categories
| Category | Examples | Source | Purpose |
| Account and identity data | Name or display name, email, Account ID, authentication events, age confirmation | User and Service | Create, secure and administer the Account |
| Transaction and entitlement data | Order, amount, currency, tax, masked method, Token balance, downloads and refunds | User, payment provider and Service logs | Process orders, fulfil entitlements, accounting and disputes |
| Prompt, upload and output data | Prompt text, reference images, settings, safety flags and Generated Outputs | User and generation systems | Produce outputs, moderate misuse and troubleshoot |
| Technical and usage data | IP address, device, browser, timestamps, logs and feature events | Device, hosting and security providers | Security, functionality, analytics and improvement |
| Communications data | Support requests, rights notices, complaints and feedback | User and authorised representatives | Respond, investigate and establish legal claims |
| Marketing and consent data | Marketing choice, cookie consent, campaign interaction and suppression status | User, consent and email systems | Respect preferences and send lawful communications |
5. Sources of personal data
5.1 Most personal data comes directly from users through registration, checkout, prompts, uploads, settings, downloads and support. Pixel Mill verifies sources of personal data against data category, purpose, lawful basis, recipient, location and retention criterion and records the action in the processing record, rights response and deletion or retention action.
5.2 Payment providers supply transaction status, masked method data, authentication results and identifiers, while hosting, security, analytics and email systems generate technical events.
5.3 Pixel Mill may also receive rights complaints, fraud reports and authorised business-contact information from third parties. The sources of personal data record supports user communication, internal control and any provider, authority or court process that lawfully follows.
6. Purposes of processing
6.1 Personal data is used to create and secure Accounts, process orders, credit Tokens, generate and deliver outputs, provide downloads and send transactional communications.
6.2 It is also used to prevent fraud and misuse, moderate unlawful requests, resolve disputes, comply with tax and accounting obligations, improve reliability and respond to legal claims. The practical standard for purposes of processing is tested using the data, purpose, lawful basis, recipient, retention need and individual request; the processing decision, response record and protective measure then evidences the action taken.
6.3 Marketing is separated from service communications and is sent only through a lawful consent or electronic-marketing route.
6.4 Timing, scope and any exception under purposes of processing are determined from the actual Service stage rather than a generic classification.
7. Lawful bases
7.1 Contract supports Account administration, orders, Token crediting, generation, downloads and transactional support. Operational review of lawful bases focuses on applicable status, user location, request details, correspondence and mandatory legal conditions, after which the reasoned response, escalation route and preserved statutory option confirms the result.
7.2 Legal obligation supports tax, accounting, authority and certain compliance duties, while legitimate interests support proportionate security, fraud prevention, service improvement and legal-claim management. The lawful bases distinction prevents an Account, payment, content or rights issue from being treated as if every consequence were identical. Consent supports non-essential cookies, optional marketing and any processing for which law requires consent, and it may be withdrawn prospectively.
Lawful bases
| Processing activity | Lawful basis | Notes |
| Account creation, Token crediting, generation and downloads | Contract | Necessary to provide the purchased or requested Service. |
| Payment reconciliation, refunds and transaction support | Contract; legal obligation | Pixel Mill retains limited payment metadata, not full credentials. |
| Fraud prevention, Account security and misuse investigation | Legitimate interests; legal obligation where applicable | Balanced against rights; contested material outcomes can receive human review. |
| Tax, accounting, authority and legal-claim records | Legal obligation; legitimate interests | Retained for statutory compliance and establishment or defence of claims. |
| Non-essential analytics, advertising and optional marketing | Consent | Can be withdrawn through preferences or unsubscribe tools. |
| Service reliability and product improvement | Legitimate interests | Uses minimisation and aggregation where practicable. |
8. Payments and checkout
8.1 Card and wallet credentials are collected through the secure interface of the authorised payment service provider shown at checkout. For payments and checkout, Pixel Mill considers checkout disclosure, provider status, issuer response, amount, currency and authentication result and uses the reconciled order, provider reference and financial-status record to close or escalate the matter.
8.2 Pixel Mill does not store full card numbers or card security codes and receives only transaction status, amount, currency, tax, masked method, provider identifiers and relevant risk or authentication information.
8.3 The payment provider may process data independently for network, security, sanctions, authentication and financial-law obligations. The payments and checkout outcome remains proportionate to severity, recurrence, user impact and the legal or contractual duty involved.
9. Cookies and similar technologies
9.1 Cookies, local storage, pixels, scripts, tags and comparable technologies may support session security, consent, preferences, performance, analytics and marketing.
9.2 Strictly necessary technologies operate where required for a requested service or security, and non-essential technologies are controlled under the Cookie Policy and consent interface. In practice, cookies and similar technologies is assessed through technology purpose, storage duration, provider, consent state and browser signal, with the result reflected in the consent record, preference state and deployment inventory.
9.3 Where an online identifier relates to a person, it is also handled as personal data under this Policy.
9.4 When applying cookies and similar technologies, those indicators are considered together rather than relying on a single unverified assertion.
10. Sharing of personal data
10.1 Data may be shared with payment processors, hosting and content-delivery providers, artificial intelligence model or inference providers, email and support vendors, consent and analytics providers, security services, advisers and competent authorities. The operational checkpoint for sharing of personal data is data category, purpose, lawful basis, recipient, location and retention criterion; completion is shown by the processing record, rights response and deletion or retention action.
10.2 Artificial intelligence providers may receive prompts, uploaded references, generation settings and technical metadata needed to create outputs and enforce safety. This treatment of sharing of personal data is traceable without expanding collection or restriction beyond what the situation requires. Pixel Mill does not sell personal data for money and controls advertising-related sharing under applicable consent and opt-out rules.
11. International transfers
11.1 Service providers may process data in the United Kingdom, European Economic Area, United States or other locations. For international transfers, relevant indicators include data category, purpose, lawful basis, recipient, location and retention criterion, and the resulting action is documented through the processing record, rights response and deletion or retention action.
11.2 Where a United Kingdom transfer requires a safeguard, Pixel Mill uses an approved agreement, addendum, adequacy route, transfer assessment or supplementary technical measure.
11.3 Provider-specific transfer information may be supplied on a reasoned request where disclosure does not compromise security or confidentiality. The international transfers approach is calibrated to the transaction, request or risk actually identified and preserves any mandatory remedy.
12. Retention
12.1 Personal data is kept only for the purpose collected, including contract performance, support, security, tax, accounting and legal claims.
12.2 Account workspace data is ordinarily retained while active and removed or anonymised after closure on the stated timetable, while transaction and dispute records remain longer. Implementation of retention links data category, purpose, lawful basis, recipient, location and retention criterion to the processing record, rights response and deletion or retention action, so the practical consequence can be explained and reviewed.
12.3 Active legal holds, fraud investigations, authority requests and unresolved disputes may extend a period.
12.4 No retention outcome is based solely on a technical label where reliable contrary evidence is available.
Retention schedule
| Data category | Retention period | Trigger / criterion |
| Account profile and security data | Account life plus 24 months | Closure, last security event or resolution of investigation |
| Order, tax, refund and payment metadata | 7 years after transaction | Accounting, tax and legal-claim requirements |
| Token ledger and fulfilment evidence | 7 years after transaction or final dispute | Entitlement, refund, chargeback and audit evidence |
| Prompts, uploads and Generated Outputs | Active Account plus up to 90 days after closure | User access, recovery and deletion cycle |
| Support and complaint records | 3 years after closure of the matter | Service quality, repeat issues and legal claims |
| Security and access logs | 12 months, extended for incidents | Detection, investigation and system integrity |
| Marketing consent and suppression records | Consent life; suppression while relevant | Proof of consent and respect for opt-out |
| Encrypted backups | Rolling cycle up to 90 days | Continuity and disaster recovery |
13. Security
13.1 Pixel Mill uses encryption in transit, credential protection, least-privilege access, logging, vendor due diligence, monitoring, environment separation and incident procedures proportionate to the Service. Pixel Mill verifies security against risk signals, access logs, payment evidence, technical events, severity and recurrence and records the action in the proportionate protective measure, preserved evidence and review route.
13.2 Users must protect credentials, avoid unnecessary sensitive data in prompts and report suspected compromise promptly. The security record supports user communication, internal control and any provider, authority or court process that lawfully follows. Where a personal data breach triggers a legal notification duty, Pixel Mill will notify the competent authority and affected individuals within the applicable timeframe.
14. Privacy rights
14.1 Subject to legal conditions and exemptions, individuals may request access, correction, erasure, restriction, portability, objection and information about processing. The practical standard for privacy rights is tested using data category, purpose, lawful basis, recipient, location and retention criterion; the processing record, rights response and deletion or retention action then evidences the action taken.
14.2 They may withdraw consent, object absolutely to direct marketing and challenge a solely automated decision that has a legal or similarly significant effect, including seeking human intervention where applicable.
14.3 Requests are normally answered within one month, and complaints may be made to the Information Commissioner’s Office or another competent authority. Timing, scope and any exception under privacy rights are determined from the actual Service stage rather than a generic classification.
15. Marketing communications
15.1 Marketing messages are sent only where a lawful route exists and include an unsubscribe mechanism.
15.2 Transaction receipts, security alerts, service notices and policy changes are not marketing and may continue where necessary. Operational review of marketing communications focuses on the wording presented, affirmative user action, timestamp, channel and later preference, after which the consent or suppression record and the resulting communication setting confirms the result.
15.3 After opt-out, Pixel Mill may retain a minimal suppression record so the preference remains effective.
15.4 The marketing communications distinction prevents an Account, payment, content or rights issue from being treated as if every consequence were identical.
16. Automated decision-making and profiling
16.1 Automated signals may score payment risk, detect Account takeover, identify abnormal generation patterns, enforce rate limits, filter unsafe prompts and prioritise support. For automated decision-making and profiling, Pixel Mill considers the data, purpose, lawful basis, recipient, retention need and individual request and uses the processing decision, response record and protective measure to close or escalate the matter.
16.2 A signal may trigger authentication, delay, block or manual review, but Pixel Mill does not use the Service to make credit, employment, insurance or comparable eligibility decisions about users. The automated decision-making and profiling outcome remains proportionate to severity, recurrence, user impact and the legal or contractual duty involved. A contested material suspension or refusal can be referred to support for human assessment.
17. Third-party services and links
17.1 External payment pages, social platforms, websites and tools control their independent processing and apply their own notices. In practice, third-party services and links is assessed through provider role, contractual instruction, returned status, security control and independent legal duty, with the result reflected in the supplier record, user-facing status and any necessary escalation.
17.2 Before sending data to an integration, users should review the destination and avoid unnecessary personal or confidential information.
17.3 Business customers integrating Generated Outputs into another service must satisfy their own privacy obligations. When applying third-party services and links, those indicators are considered together rather than relying on a single unverified assertion.
18. Changes to this Policy
18.1 Pixel Mill may update this Policy to reflect changes in law, guidance, technology, processors or Service operation.
18.2 The version and effective date identify the current text, and material changes will be highlighted through the website, Account or email where appropriate. The operational checkpoint for changes to this policy is the previous version, reason for change, affected feature, notice route and transaction date; completion is shown by the effective version, preserved accrued right and future-use rule.
18.3 Consent will be refreshed where a new processing purpose legally requires it.
18.4 This treatment of changes to this policy is traceable without expanding collection or restriction beyond what the situation requires.
19. Governing standards and complaints
19.1 Privacy processing is governed principally by United Kingdom data protection and electronic communications law. For governing standards and complaints, relevant indicators include applicable status, user location, request details, correspondence and mandatory legal conditions, and the resulting action is documented through the reasoned response, escalation route and preserved statutory option.
19.2 Contractual governing-law wording does not restrict the competence of the Information Commissioner’s Office or another supervisory authority. The governing standards and complaints approach is calibrated to the transaction, request or risk actually identified and preserves any mandatory remedy. Individuals may complain to Pixel Mill first, but this does not prevent direct regulatory or court action.
20. Contact and request procedure
20.1 A request should be emailed to info@pixel-mill.com with the right or concern identified and enough information to locate the relevant Account or transaction. Implementation of contact and request procedure links applicable status, user location, request details, correspondence and mandatory legal conditions to the reasoned response, escalation route and preserved statutory option, so the practical consequence can be explained and reviewed.
20.2 Pixel Mill may verify identity and authority proportionately, and authorised agents should supply evidence of authority.
20.3 Users must not send passwords, full card details or unnecessary identity documents. No contact and request procedure outcome is based solely on a technical label where reliable contrary evidence is available.
21. Schedule 1 — Practical Retention Guide
21.1 Operational retention periods are stated in the table below and may be shortened when data is no longer needed or extended for a lawful hold.
21.2 Deletion from active systems may not immediately remove isolated encrypted backup copies, which expire through the backup cycle. Pixel Mill verifies schedule 1 — practical retention guide against data category, purpose, lawful basis, recipient, location and retention criterion and records the action in the processing record, rights response and deletion or retention action.
21.3 Account closure removes access, while a privacy erasure request is assessed separately against legal retention obligations.
21.4 The schedule 1 — practical retention guide record supports user communication, internal control and any provider, authority or court process that lawfully follows.