Legal
This policy explains how VisualiseO Limited(“Visualiseo”, “we”, “us”) handles personal data when you use our website, our dashboard, or the visualisation widget we provide to retailers. It is written to meet our obligations under the UK GDPR, the Data Protection Act 2018, and the Data (Use and Access) Act 2025.
VisualiseO Limited is a company registered in England and Wales (company number 17171606) with its registered office at 27 Beverley Close, Normanton, WF6 1BU.
Last updated: 21 July 2026
There are three groups of people whose data we may process:
The rules that apply to you depend on which of these you are.
Data protection law treats the person who decides why data is collected (the controller) differently from the person who processes it on their instructions (the processor). Where two organisations jointly decide the why and how, they are joint controllers under Article 26 UK GDPR. Our role changes depending on the context:
In some cases a retailer may pass us metadata about an end user's session (for example, a product ID) that the retailer has gathered on their own site. Where this is the case, the retailer is responsible for telling you about that collection in their own privacy notice.
| Purpose | Legal basis (UK GDPR Art. 6) |
|---|---|
| Create and administer your account, deliver the service | Art. 6(1)(b) — contract |
| Process payments and maintain billing records | Art. 6(1)(b) contract + Art. 6(1)(c) legal obligation (HMRC) |
| Send transactional emails (welcome, password reset, billing notices) | Art. 6(1)(b) — contract |
| Generate renders from end-user uploads | We process on behalf of the retailer as their processor; the retailer's own legal basis (typically Art. 6(1)(f) legitimate interest in offering a visualisation tool) applies. See the retailer's privacy notice. |
| Run a retailer's chat and quote assistant and store the conversation so the retailer can reply and follow up | We process on behalf of the retailer as their processor; the retailer's own legal basis applies — typically Art. 6(1)(f) legitimate interest in answering a sales enquiry, or Art. 6(1)(b) steps taken at your request before entering a contract. See the retailer's privacy notice. |
| Generate the assistant's replies with an AI language model | Same processor role and the same retailer legal basis as above. The conversation text is sent to Google (Gemini) as our sub-processor under a paid contract that prohibits training on it. |
| Publish a render in the public gallery | Art. 6(1)(a) explicit consent of the end user; Art. 9(2)(a) explicit consent for any special-category data that may incidentally be revealed. |
| Email a render to an end user who requested it ("Email me this render") | Art. 6(1)(b) / Art. 6(1)(a) — the end user's own request. We act as the retailer's processor for this. |
| Share that email + render with the retailer so they can follow up about the product | The retailer's Art. 6(1)(f) legitimate interest in responding to a product enquiry. We act as the retailer's processor. |
| Send the end user ongoing marketing about the retailer's products and offers | Art. 6(1)(a) — separate, optional opt-in, never pre-ticked, withdrawable at any time. |
| Show your quote enquiry from visualiseo.co.uk to worktop companies with your name, email and phone removed, so they can decide whether to quote | Art. 6(1)(a) — your consent, given when you ask for the quote. See section 6. |
| Give your name, email and phone to a worktop company that buys your enquiry, so they can contact you about the job | Art. 6(1)(a) — your consent, given when you ask for the quote. Not pre-ticked, and the quote is not sent without it. See section 6. |
| Detect fraud, abuse, and keep the service secure | Art. 6(1)(f) legitimate interest — documented LIA |
| Monitor usage against your plan limits | Art. 6(1)(b) — contract |
| Improve the service (aggregate, non-identifying metrics) | Art. 6(1)(f) legitimate interest — documented LIA |
Automated decision-making. We do not carry out automated decision-making that produces legal or similarly significant effects on you within the meaning of Articles 22 / 22A–22D UK GDPR. Render generation is automated but produces a visual preview, not a decision about you. You have the right to contest any automated processing and to request human intervention; contact privacy@visualiseo.co.uk.
We never use your uploaded images to train AI models. Every AI provider we use is engaged under a paid commercial contract that contractually prohibits training on customer inputs.
A photograph is not automatically special-category data under UK law; it becomes so only where it is processed for biometric identification (Art. 9 UK GDPR). We do not carry out biometric identification and our AI providers have confirmed contractually that inputs are not used for face-matching or identification.
However, a photograph of a space may incidentally reveal information that is special-category data under Art. 9 (for example, religious markers in the home, visible mobility aids, or details that suggest ethnicity). We minimise this risk by prohibiting and rejecting photos of people before any AI processing occurs and by stripping EXIF / GPS metadata from every upload.
For the render itself (the processing that happens even if you never publish to the gallery), we rely on your explicit consent under Art. 9(2)(a) UK GDPR, captured at the widget's pre-flight notice — the consent tick covers Article 6(1)(a) and Article 9(2)(a) and is the basis we use for any special-category information that might incidentally appear in the photo of your space.
For gallery publication, we rely on a separate, more granular explicit consent under Art. 6(1)(a) and Art. 9(2)(a) — captured at the Save popup, withdrawable via a tokenised link shown on the widget result screen at the moment of publication for you to copy and keep.
You may withdraw either consent at any time. Withdrawal stops future processing — it does not make past processing unlawful. The provider's file-API copy of your photo is deleted automatically within 48 hours regardless.
We rely on a small set of trusted sub-processors to run the service:
| Provider | Purpose | Location |
|---|---|---|
| Google (Gemini API) | AI image generation (primary) and generating the retailer chat and quote assistant's replies | United States |
| Google Cloud Vertex AI | AI image generation (alternate model chain, Gemini Enterprise) | United States / European Union |
| OpenAI | AI image generation (alternate model chain) | United States |
| Google Cloud Storage | Product and gallery image storage | European Union |
| Neon | PostgreSQL database hosting | European Union |
| Vercel | Web application hosting | United States / global edge |
| Stripe, Inc. | Payment processing | United States / Ireland |
| Resend | Transactional email delivery | United States |
| Pusher | Real-time delivery of chat messages — both our own support chat and conversations between a visitor and a retailer | United States |
The canonical list is published at /sub-processors. We give retailers at least 30 days' email notice of any material addition or replacement of a sub-processor, and retailers can object on reasonable data-protection grounds.
Email leads. Separately from the sub-processors above, when you ask us to email a render to you we share your email address, the render, and the product visualised with the retailer whose widget you used, so they can follow up about that product. The retailer is an independent controller of that lead and handles it under their own privacy notice. We pass it to them as their processor; we do not use it for our own purposes.
Quote enquiries made on visualiseo.co.uk. This applies only if you asked for a worktop quote on one of our ownpages — not to a quote form on a retailer's own website, which is covered above. When you ask for a quote here, you are asked to confirm that you are happy for worktop companies to contact you about the job. If you do not agree, the enquiry is not sent and none of the following happens.
Apart from the lead sale described immediately above, we do not trade or monetise personal data. We do not share it with advertisers. We do not use third-party analytics, cross-site tracking pixels, or behavioural advertising cookies.
We may disclose data where we are legally required to (for example, a court order) or where it is necessary to investigate fraud, abuse, or a threat to safety.
Some of our sub-processors are based outside the UK and EEA. Where this is the case we rely on safeguards recognised by UK data protection law, in particular:
We have completed a Transfer Risk Assessment for each international sub-processor. A summary is available on request from privacy@visualiseo.co.uk.
| Data | Retention |
|---|---|
| Uploaded photo (before render) | Not stored by us. Held briefly by the AI provider and automatically deleted within 48 hours under the provider's file-API retention policy. |
| Generated render (not shared) | Returned to your browser. Not stored by us. |
| Render saved on your device | Kept in your browser's IndexedDB until you clear browser data or remove it from the widget's recent-renders panel. Never sent to our servers. |
| Gallery submissions (public) | Until you withdraw consent or the retailer removes them. |
| Email leads (address, render reference, marketing opt-in status) | Kept for the retailer to action the enquiry while their subscription is active, and in any event no longer than 24 months. Deleted sooner if you or the retailer ask. Deleted in full when the retailer closes their account. |
| Visitor conversation with a retailer (no contact details given) | 90 days from your last message, then deleted together with the full transcript. This is any conversation where you did not give an email address or phone number and did not complete a quote request. |
| Visitor conversation with a retailer (contact details given, or quote completed) | Kept for the retailer to action while their subscription is active, and in any event no longer than 24 months from your last message. Deleted sooner if you or the retailer ask. Deleted in full when the retailer closes their account. |
| Quote enquiry made on visualiseo.co.uk (available as a lead) | Kept on the board while it is still worth quoting for and in any event no longer than 24 months from your last message, on the same schedule as any other quote enquiry. Removed from the board immediately if you withdraw consent, and we then hold it only as a record that you did. |
| Record of which companies bought your enquiry | Kept while it is needed to bill, refund and audit the sale, and in any event no longer than 24 months. This record is how we can tell you who was given your details. |
| Retailer account | Until you close the account, then 30 days, then deleted or anonymised. To close your account, email privacy@visualiseo.co.uk. In-dashboard self-serve account closure is planned but not yet available. |
| Payment and invoice records | 6 years (UK tax law). |
| Render metadata and analytics | 24 months. |
| Marketing-page analytics (incl. approximate location, no IP) | 24 months. |
| Widget session logs | 12 months. |
| Support chat conversations (closed) | 12 months from the last message, then deleted with all messages. Open conversations are not auto-deleted. |
| Security and server logs | 30 days. |
| Complaint records | 6 years (to evidence our handling of your right to complain). |
You have the following rights under UK data protection law:
If you used the widget on a retailer's website for a render, the retailer is the controller for that upload. You can contact either them or us — for the public gallery, because we are joint controllers, you can exercise your rights against either party (Art. 26(3) UK GDPR).
If you are an account holder, email privacy@visualiseo.co.uk or use /complaints. We will respond within one calendar month.
We only use first-party storage. We do not use advertising, analytics, or cross-site tracking cookies, so no cookie banner is shown. Our marketing-page analytics are cookieless and run server-side (see §1).
| What | Why | Basis | Lifetime |
|---|---|---|---|
| NextAuth session cookie | Keeps you signed in to the dashboard | Strictly necessary (PECR reg. 6 exemption) | Up to 30 days. If you don't tick "Remember me" the session inside the cookie expires after 24 hours; the cookie itself may persist until you clear browser data. |
| NextAuth CSRF cookie | Protects sign-in against cross-site attacks | Strictly necessary (PECR reg. 6 exemption) | Session |
| Widget consent flag (localStorage) | Remembers you accepted the widget safety notice so you don't see it every time | Strictly necessary to deliver the service in line with the pre-flight notice requirement | 7 days |
| Chat session (localStorage, inside the chat frame) | Remembers which conversation is yours — a random visitor ID, the conversation ID and an access token — so you can pick up where you left off | Strictly necessary to deliver the chat you started (PECR reg. 6(4) exemption). Only written once you send your first message; nothing is stored if you never use the chat. | Until you clear browser data |
| Widget recent renders (IndexedDB) | Shows your 3 most recent renders on the same device | Your explicit opt-in when you tick "Save on this device" in the Save popup | Until you clear browser data or remove the entry in the widget |
You can clear any of these at any time through your browser's privacy settings.
Visualiseo is not directed at children. You must be 18 or over to hold an account or to use the widget. We do not knowingly collect data from anyone under 18.
The widget accepts photographs of spaces only. A server-side check rejects any image that appears to contain a person before it is sent to any AI provider. We believe this restriction, combined with the age statement in the pre-flight notice, removes the material risks that the Children's Code and Online Safety Act 2023 are designed to address.
We have carried out a Children's Access Assessment (under the ICO Children's Code and the Online Safety Act 2023) and have concluded that the service is not likely to be accessed by children in significant numbers. Even so, we apply relevant standards — data minimisation, opt-in publication, no profiling, no dark patterns — as data protection by design.
If you believe a child has used our service, contact privacy@visualiseo.co.uk and we will delete their data.
Every render produced by the widget is AI-generated. In line with Article 50 of the EU AI Act (which applies to us when we serve EU users) and our own transparency commitments:
If we make a material change to this policy we will email account holders and update the “Last updated” date at the top of this page. Continuing to use the service after the change means you accept the updated policy.
You can also reach us by post at our registered office:
VisualiseO Limited