Flash Gen · Privacy Policy · v1.0 · effective 21 July 2026

FieldValue
OperatorARIES ACCESSIBILITY LTD
Company number15588986
Registered office20 Wenlock Road, London, England, N1 7GU
Trading name / brandFlash Gen
Websitehttps://flash-gen.com
Contact emailinfo@flash-gen.com
Support / complaintsinfo@flash-gen.com
Governing lawEngland and Wales
Document versionv1.0
Effective date21 July 2026
Important: This Policy explains how ARIES ACCESSIBILITY LTD uses personal data when you browse Flash Gen, create an account, buy Token Packs, submit prompts, generate images, contact support or exercise privacy rights.
Who this Policy applies to: This Policy applies to website visitors, individual Account holders, purchasers, authorised business users, support contacts and people whose personal data is included in prompts, uploads or rights requests.

1. Introduction and scope

1.1 The controlling rule is as follows: This Policy applies to website visitors, account holders, purchasers, authorised business users, support contacts and persons whose data is included in prompts or uploaded materials. It covers data collected through Flash Gen and related customer-support and payment workflows.

1.2 For introduction and scope, the operator limits collection to information reasonably connected with the stated purpose and restricts access by role. Data is deleted, aggregated or isolated when the purpose and applicable retention period end.

1.3 Mandatory consumer, privacy and payment rights continue to apply to introduction and scope; this Policy cannot be used to waive a protection that the law makes non-excludable.

2. Data controller and contact

2.1 For the Flash Gen service, ARIES ACCESSIBILITY LTD is the controller for personal data described here. Privacy requests may be sent to info@flash-gen.com or the registered office; the operator may verify identity before acting on a request.

2.2 The processing record for data controller and contact identifies the purpose, data category, recipient function, lawful basis and retention trigger. This allows privacy requests and incidents to be handled against a defined data lifecycle.

2.3 A user may ask support to review a material outcome concerning data controller and contact. Review can confirm the result, correct an error, narrow a restriction or identify the proper statutory process.

3. Age position

3.1 This section allocates responsibility clearly. Flash Gen is intended for adults aged 18 or over and is not directed to children. Users must not create accounts for minors or upload a child’s personal data without a lawful basis, appropriate authority and compliance with heightened safeguards.

3.2 Where age position involves a service provider, contractual controls require confidentiality, security, purpose limitation and deletion or return at the end of the engagement. Provider access is reviewed when functions change.

4. Categories of personal data

4.1 The Account and transaction outcome follows this position: Data may include account identifiers, contact information, order and billing metadata, Token ledger entries, prompts, uploaded reference files, Generated Output, technical logs, cookie choices, fraud signals, support correspondence and privacy-request records.

4.2 Requests relating to categories of personal data may require identity verification proportionate to the sensitivity of the data. A response explains the action taken, any lawful limitation and the available complaint route.

4.3 Reasonable verification may be required for categories of personal data, especially where value, Account control or sensitive data is involved. Verification is proportionate to the risk and information requested.

Data categories

CategoryExamplesSourcePurpose
Account and identityName, email, Account ID, organisation, login recordsUser; Account administratorCreate, authenticate and administer the Account
Transaction and paymentOrder, amount, currency, method type, status, limited card metadataUser; payment service providerAuthorise, fulfil, reconcile, refund and defend disputes
Token and fulfilmentToken credit, consumption, restoration, job and output-access eventsService systemsDeliver purchased services and evidence performance
Prompts and uploadsPrompt text, reference images, settings, safety resultsUserRun the requested generation and enforce safety rules
Generated OutputCreated image, metadata, download and deletion eventsService systemsDeliver files, support users and investigate failures
Technical and usageIP address, device, browser, logs, cookie choices, security signalsDevice; service providersSecurity, diagnostics, consent and performance
Support and rightsMessages, attachments, complaint and privacy-request recordsUser; representativeResolve issues and comply with legal duties

5. Sources of personal data

5.1 To keep the Service predictable, Data is obtained from users, authorised account administrators, devices and browsers, payment and fraud providers, hosting and artificial-intelligence infrastructure, analytics tools used with consent, and public or third-party sources used to investigate abuse or rights complaints.

5.2 Flash Gen uses aggregation or de-identification for sources of personal data where this can achieve the purpose with less exposure of identifiable information. Re-identification or unrelated use is prohibited by internal access controls.

5.3 The treatment of sources of personal data is recorded so that support, billing and enforcement remain consistent. A corrected error is reflected in the Account or transaction history.

6. How we use personal data

6.1 The practical and contractual position is this: Personal data is used to create and secure accounts, process orders, credit Tokens, execute generation jobs, deliver files, provide support, prevent fraud, enforce policies, maintain service quality, comply with law and send consent-based marketing.

6.2 If how we use personal data concerns another person included in a prompt or upload, the user must have authority to submit that data. The operator may restrict the material while rights, safety or legality are assessed.

7. Lawful bases for processing

7.1 In operational terms, Contract supports account, payment, fulfilment and support processing; legal obligation supports tax, accounting and lawful-request handling; legitimate interests support security, abuse prevention and service administration; consent supports non-essential cookies and direct marketing where required.

7.2 Security for lawful bases for processing combines technical controls, provider assurance, logging and incident response. A material personal-data breach is assessed for regulatory and individual notification duties.

7.3 No delay in enforcing lawful bases for processing is a permanent waiver. A later response remains available where the underlying breach, error or risk continues.

Lawful bases

Processing activityLawful basisNotes
Account, order, Token and generation fulfilmentContractNecessary to provide the requested paid or Account service
Tax, accounting and lawful authority requestsLegal obligationRecords retained and supplied where law requires
Security, fraud prevention and policy enforcementLegitimate interestsBalanced against user rights and limited to proportionate controls
Non-essential analytics and marketing cookiesConsentActivated only after consent where required and withdrawable
Direct electronic marketingConsent or legitimate interests where lawfulUnsubscribe and objection are always provided
Establishing or defending legal claimsLegitimate interests or legal obligationLimited to relevant evidence and retention periods

8. Payments and checkout

8.1 Payment-card data is entered into secure fields operated by the payment service provider. Flash Gen receives transaction status, amount, currency, method type, limited card metadata, fraud results and references needed for fulfilment, reconciliation, refunds and disputes.

8.2 The legal basis for payments and checkout is reviewed when the purpose changes. Consent is not substituted for contract or legal obligation merely because it is easier to obtain, and consent-based use stops after valid withdrawal.

8.3 If part of the rule on payments and checkout is unenforceable, it is adjusted only to the minimum extent necessary and the remaining provisions continue.

9. Cookies and similar technologies

9.1 The controlling rule is as follows: Strictly necessary technologies support login, checkout security, consent storage and service continuity. Functional, analytics and marketing technologies are governed by the Cookie Policy and are activated only under the applicable consent rules.

9.2 For cookies and similar technologies, the operator limits collection to information reasonably connected with the stated purpose and restricts access by role. Data is deleted, aggregated or isolated when the purpose and applicable retention period end.

10. Sharing of personal data

10.1 For the Flash Gen service, Data may be shared with payment, hosting, cloud, artificial-intelligence processing, customer-support, security, analytics, communications, professional-adviser and public-authority recipients where the function and legal basis require it.

10.2 The processing record for sharing of personal data identifies the purpose, data category, recipient function, lawful basis and retention trigger. This allows privacy requests and incidents to be handled against a defined data lifecycle.

10.3 Records supporting sharing of personal data are retained only for the applicable business, legal and evidential period and are protected under the Privacy Policy.

11. International transfers

11.1 This section allocates responsibility clearly. Some service providers may process data outside the United Kingdom. Transfers are supported by adequacy regulations, approved contractual safeguards or another lawful mechanism, together with risk-based technical and organisational protections.

11.2 Where international transfers involves a service provider, contractual controls require confidentiality, security, purpose limitation and deletion or return at the end of the engagement. Provider access is reviewed when functions change.

11.3 A business Account may allocate internal roles for international transfers, but the registered Account holder remains responsible for authorised access and accurate instructions.

12. Data retention

12.1 The Account and transaction outcome follows this position: Data is kept only for defined business, legal, security and evidential periods. Retention considers account status, transaction and tax obligations, chargeback windows, rights claims, security needs, user deletion controls and backup cycles.

12.2 Requests relating to data retention may require identity verification proportionate to the sensitivity of the data. A response explains the action taken, any lawful limitation and the available complaint route.

Retention

Data categoryRetention periodTrigger / criterion
Account profileActive Account plus 24 monthsClosure or last meaningful activity
Orders, invoices and refund records6 yearsEnd of the financial year containing the transaction
Token ledger and fulfilment evidence6 yearsTransaction or final dispute resolution
Prompts and Generated OutputUp to 90 days after job completion, unless retained by user or required for a disputeJob completion, deletion request or case closure
Security and access logs12 monthsLog creation, extended where an incident remains open
Support and complaint records24 months after closureFinal response or Account closure, whichever is later
Cookie-consent records3 years after the recorded choice is replacedConsent update or withdrawal
Marketing preference and suppression recordUntil withdrawal; suppression record up to 6 yearsOpt-out or last relevant communication

13. Data security

13.1 To keep the Service predictable, Controls include access restriction, encryption in transit, credential protections, logging, environment separation, provider due diligence, incident response and recovery measures. No online system is risk-free, so users must protect passwords and report suspected compromise promptly.

13.2 Flash Gen uses aggregation or de-identification for data security where this can achieve the purpose with less exposure of identifiable information. Re-identification or unrelated use is prohibited by internal access controls.

13.3 Users should raise concerns about data security promptly and preserve relevant confirmations, errors and communications so the issue can be resolved on reliable evidence.

14. Your privacy rights

14.1 The practical and contractual position is this: Subject to applicable conditions, individuals may request access, correction, erasure, restriction, portability or objection and may withdraw consent. They may also complain to the Information Commissioner’s Office without first contacting Flash Gen.

14.2 If your privacy rights concerns another person included in a prompt or upload, the user must have authority to submit that data. The operator may restrict the material while rights, safety or legality are assessed.

14.3 Any discretionary accommodation for your privacy rights is assessed consistently but does not create an automatic entitlement for materially different circumstances.

15. Marketing communications

15.1 In operational terms, Marketing is sent only where a valid permission or other lawful basis exists. Every electronic marketing message provides an unsubscribe route; service, security and transaction messages continue where necessary to administer the Account.

15.2 Security for marketing communications combines technical controls, provider assurance, logging and incident response. A material personal-data breach is assessed for regulatory and individual notification duties.

16. Automated decision-making and profiling

16.1 Fraud, security and content-safety tools may score transactions or activity and may temporarily block a payment or generation request. Significant adverse decisions receive proportionate human review where required by law.

16.2 The legal basis for automated decision-making and profiling is reviewed when the purpose changes. Consent is not substituted for contract or legal obligation merely because it is easier to obtain, and consent-based use stops after valid withdrawal.

16.3 The user remains responsible for downstream use connected with automated decision-making and profiling, including context, disclosures, third-party rights and compliance after an output is downloaded.

17. Third-party services and links

17.1 The controlling rule is as follows: External websites, payment interfaces and integrations operate under their own privacy terms. Users should review those terms before providing data, particularly when exporting Generated Output or connecting third-party services.

17.2 For third-party services and links, the operator limits collection to information reasonably connected with the stated purpose and restricts access by role. Data is deleted, aggregated or isolated when the purpose and applicable retention period end.

17.3 A restriction concerning third-party services and links can remain in place while a payment, safety or rights investigation is active and is reviewed when material new evidence becomes available.

18. Changes to this Policy

18.1 For the Flash Gen service, The Policy may be updated to reflect changes in law, providers, processing or product functions. Material changes are communicated through the website, Account or email where appropriate.

18.2 The processing record for changes to this policy identifies the purpose, data category, recipient function, lawful basis and retention trigger. This allows privacy requests and incidents to be handled against a defined data lifecycle.

19. How to contact us or submit a request

19.1 This section allocates responsibility clearly. Requests should identify the right being exercised, the relevant Account email and enough context to locate records. The operator normally responds within one month, subject to lawful extensions for complex or numerous requests.

19.2 Where how to contact us or submit a request involves a service provider, contractual controls require confidentiality, security, purpose limitation and deletion or return at the end of the engagement. Provider access is reviewed when functions change.

19.3 The operator will not impose a new price or recurring charge merely because how to contact us or submit a request requires verification, correction or support.

20. Governing law and statutory safeguards

20.1 The Account and transaction outcome follows this position: This Policy is administered under United Kingdom data-protection law and does not limit rights granted by the United Kingdom General Data Protection Regulation or the Data Protection Act 2018. Mandatory local rights remain available where they apply.

20.2 Requests relating to governing law and statutory safeguards may require identity verification proportionate to the sensitivity of the data. A response explains the action taken, any lawful limitation and the available complaint route.

20.3 Communications about governing law and statutory safeguards are sent to the Account email or another verified contact, and users must keep that route secure and current.

Schedule 1 – Practical Retention Guide

This guide translates the retention table into practical lifecycle outcomes. A longer period applies only where law, fraud, security or a live claim reasonably requires it.

Scenario / stepPractical rule
Account dataKept while active and normally for 24 months after closure to support recovery, complaints and security.
Payment and tax dataKept for six years where needed for accounting, tax and legal claims.
Prompt and output dataNormally available for up to 90 days after completion unless the user retains it, deletes it earlier or a dispute requires preservation.
Security logsNormally retained for 12 months and longer only where an incident remains open.
Support recordsNormally retained for 24 months after the final response or Account closure.
Deletion requestIdentity is verified, live data is removed where the right applies, and lawful retention copies are isolated until expiry.

Flash Gen · Privacy Policy · v1.0 · effective 21 July 2026 · Published on the website; subject to update; the current published version governs.

Your Shopping cart

Close