Flash Gen · Privacy Policy · v1.0 · effective 21 July 2026
| Field | Value |
| Operator | ARIES ACCESSIBILITY LTD |
| Company number | 15588986 |
| Registered office | 20 Wenlock Road, London, England, N1 7GU |
| Trading name / brand | Flash Gen |
| Website | https://flash-gen.com |
| Contact email | info@flash-gen.com |
| Support / complaints | info@flash-gen.com |
| Governing law | England and Wales |
| Document version | v1.0 |
| Effective date | 21 July 2026 |
| Important: This Policy explains how ARIES ACCESSIBILITY LTD uses personal data when you browse Flash Gen, create an account, buy Token Packs, submit prompts, generate images, contact support or exercise privacy rights. |
| Who this Policy applies to: This Policy applies to website visitors, individual Account holders, purchasers, authorised business users, support contacts and people whose personal data is included in prompts, uploads or rights requests. |
1. Introduction and scope
1.1 The controlling rule is as follows: This Policy applies to website visitors, account holders, purchasers, authorised business users, support contacts and persons whose data is included in prompts or uploaded materials. It covers data collected through Flash Gen and related customer-support and payment workflows.
1.2 For introduction and scope, the operator limits collection to information reasonably connected with the stated purpose and restricts access by role. Data is deleted, aggregated or isolated when the purpose and applicable retention period end.
1.3 Mandatory consumer, privacy and payment rights continue to apply to introduction and scope; this Policy cannot be used to waive a protection that the law makes non-excludable.
2. Data controller and contact
2.1 For the Flash Gen service, ARIES ACCESSIBILITY LTD is the controller for personal data described here. Privacy requests may be sent to info@flash-gen.com or the registered office; the operator may verify identity before acting on a request.
2.2 The processing record for data controller and contact identifies the purpose, data category, recipient function, lawful basis and retention trigger. This allows privacy requests and incidents to be handled against a defined data lifecycle.
2.3 A user may ask support to review a material outcome concerning data controller and contact. Review can confirm the result, correct an error, narrow a restriction or identify the proper statutory process.
3. Age position
3.1 This section allocates responsibility clearly. Flash Gen is intended for adults aged 18 or over and is not directed to children. Users must not create accounts for minors or upload a child’s personal data without a lawful basis, appropriate authority and compliance with heightened safeguards.
3.2 Where age position involves a service provider, contractual controls require confidentiality, security, purpose limitation and deletion or return at the end of the engagement. Provider access is reviewed when functions change.
4. Categories of personal data
4.1 The Account and transaction outcome follows this position: Data may include account identifiers, contact information, order and billing metadata, Token ledger entries, prompts, uploaded reference files, Generated Output, technical logs, cookie choices, fraud signals, support correspondence and privacy-request records.
4.2 Requests relating to categories of personal data may require identity verification proportionate to the sensitivity of the data. A response explains the action taken, any lawful limitation and the available complaint route.
4.3 Reasonable verification may be required for categories of personal data, especially where value, Account control or sensitive data is involved. Verification is proportionate to the risk and information requested.
Data categories
| Category | Examples | Source | Purpose |
| Account and identity | Name, email, Account ID, organisation, login records | User; Account administrator | Create, authenticate and administer the Account |
| Transaction and payment | Order, amount, currency, method type, status, limited card metadata | User; payment service provider | Authorise, fulfil, reconcile, refund and defend disputes |
| Token and fulfilment | Token credit, consumption, restoration, job and output-access events | Service systems | Deliver purchased services and evidence performance |
| Prompts and uploads | Prompt text, reference images, settings, safety results | User | Run the requested generation and enforce safety rules |
| Generated Output | Created image, metadata, download and deletion events | Service systems | Deliver files, support users and investigate failures |
| Technical and usage | IP address, device, browser, logs, cookie choices, security signals | Device; service providers | Security, diagnostics, consent and performance |
| Support and rights | Messages, attachments, complaint and privacy-request records | User; representative | Resolve issues and comply with legal duties |
5. Sources of personal data
5.1 To keep the Service predictable, Data is obtained from users, authorised account administrators, devices and browsers, payment and fraud providers, hosting and artificial-intelligence infrastructure, analytics tools used with consent, and public or third-party sources used to investigate abuse or rights complaints.
5.2 Flash Gen uses aggregation or de-identification for sources of personal data where this can achieve the purpose with less exposure of identifiable information. Re-identification or unrelated use is prohibited by internal access controls.
5.3 The treatment of sources of personal data is recorded so that support, billing and enforcement remain consistent. A corrected error is reflected in the Account or transaction history.
6. How we use personal data
6.1 The practical and contractual position is this: Personal data is used to create and secure accounts, process orders, credit Tokens, execute generation jobs, deliver files, provide support, prevent fraud, enforce policies, maintain service quality, comply with law and send consent-based marketing.
6.2 If how we use personal data concerns another person included in a prompt or upload, the user must have authority to submit that data. The operator may restrict the material while rights, safety or legality are assessed.
7. Lawful bases for processing
7.1 In operational terms, Contract supports account, payment, fulfilment and support processing; legal obligation supports tax, accounting and lawful-request handling; legitimate interests support security, abuse prevention and service administration; consent supports non-essential cookies and direct marketing where required.
7.2 Security for lawful bases for processing combines technical controls, provider assurance, logging and incident response. A material personal-data breach is assessed for regulatory and individual notification duties.
7.3 No delay in enforcing lawful bases for processing is a permanent waiver. A later response remains available where the underlying breach, error or risk continues.
Lawful bases
| Processing activity | Lawful basis | Notes |
| Account, order, Token and generation fulfilment | Contract | Necessary to provide the requested paid or Account service |
| Tax, accounting and lawful authority requests | Legal obligation | Records retained and supplied where law requires |
| Security, fraud prevention and policy enforcement | Legitimate interests | Balanced against user rights and limited to proportionate controls |
| Non-essential analytics and marketing cookies | Consent | Activated only after consent where required and withdrawable |
| Direct electronic marketing | Consent or legitimate interests where lawful | Unsubscribe and objection are always provided |
| Establishing or defending legal claims | Legitimate interests or legal obligation | Limited to relevant evidence and retention periods |
8. Payments and checkout
8.1 Payment-card data is entered into secure fields operated by the payment service provider. Flash Gen receives transaction status, amount, currency, method type, limited card metadata, fraud results and references needed for fulfilment, reconciliation, refunds and disputes.
8.2 The legal basis for payments and checkout is reviewed when the purpose changes. Consent is not substituted for contract or legal obligation merely because it is easier to obtain, and consent-based use stops after valid withdrawal.
8.3 If part of the rule on payments and checkout is unenforceable, it is adjusted only to the minimum extent necessary and the remaining provisions continue.
9. Cookies and similar technologies
9.1 The controlling rule is as follows: Strictly necessary technologies support login, checkout security, consent storage and service continuity. Functional, analytics and marketing technologies are governed by the Cookie Policy and are activated only under the applicable consent rules.
9.2 For cookies and similar technologies, the operator limits collection to information reasonably connected with the stated purpose and restricts access by role. Data is deleted, aggregated or isolated when the purpose and applicable retention period end.
10. Sharing of personal data
10.1 For the Flash Gen service, Data may be shared with payment, hosting, cloud, artificial-intelligence processing, customer-support, security, analytics, communications, professional-adviser and public-authority recipients where the function and legal basis require it.
10.2 The processing record for sharing of personal data identifies the purpose, data category, recipient function, lawful basis and retention trigger. This allows privacy requests and incidents to be handled against a defined data lifecycle.
10.3 Records supporting sharing of personal data are retained only for the applicable business, legal and evidential period and are protected under the Privacy Policy.
11. International transfers
11.1 This section allocates responsibility clearly. Some service providers may process data outside the United Kingdom. Transfers are supported by adequacy regulations, approved contractual safeguards or another lawful mechanism, together with risk-based technical and organisational protections.
11.2 Where international transfers involves a service provider, contractual controls require confidentiality, security, purpose limitation and deletion or return at the end of the engagement. Provider access is reviewed when functions change.
11.3 A business Account may allocate internal roles for international transfers, but the registered Account holder remains responsible for authorised access and accurate instructions.
12. Data retention
12.1 The Account and transaction outcome follows this position: Data is kept only for defined business, legal, security and evidential periods. Retention considers account status, transaction and tax obligations, chargeback windows, rights claims, security needs, user deletion controls and backup cycles.
12.2 Requests relating to data retention may require identity verification proportionate to the sensitivity of the data. A response explains the action taken, any lawful limitation and the available complaint route.
Retention
| Data category | Retention period | Trigger / criterion |
| Account profile | Active Account plus 24 months | Closure or last meaningful activity |
| Orders, invoices and refund records | 6 years | End of the financial year containing the transaction |
| Token ledger and fulfilment evidence | 6 years | Transaction or final dispute resolution |
| Prompts and Generated Output | Up to 90 days after job completion, unless retained by user or required for a dispute | Job completion, deletion request or case closure |
| Security and access logs | 12 months | Log creation, extended where an incident remains open |
| Support and complaint records | 24 months after closure | Final response or Account closure, whichever is later |
| Cookie-consent records | 3 years after the recorded choice is replaced | Consent update or withdrawal |
| Marketing preference and suppression record | Until withdrawal; suppression record up to 6 years | Opt-out or last relevant communication |
13. Data security
13.1 To keep the Service predictable, Controls include access restriction, encryption in transit, credential protections, logging, environment separation, provider due diligence, incident response and recovery measures. No online system is risk-free, so users must protect passwords and report suspected compromise promptly.
13.2 Flash Gen uses aggregation or de-identification for data security where this can achieve the purpose with less exposure of identifiable information. Re-identification or unrelated use is prohibited by internal access controls.
13.3 Users should raise concerns about data security promptly and preserve relevant confirmations, errors and communications so the issue can be resolved on reliable evidence.
14. Your privacy rights
14.1 The practical and contractual position is this: Subject to applicable conditions, individuals may request access, correction, erasure, restriction, portability or objection and may withdraw consent. They may also complain to the Information Commissioner’s Office without first contacting Flash Gen.
14.2 If your privacy rights concerns another person included in a prompt or upload, the user must have authority to submit that data. The operator may restrict the material while rights, safety or legality are assessed.
14.3 Any discretionary accommodation for your privacy rights is assessed consistently but does not create an automatic entitlement for materially different circumstances.
15. Marketing communications
15.1 In operational terms, Marketing is sent only where a valid permission or other lawful basis exists. Every electronic marketing message provides an unsubscribe route; service, security and transaction messages continue where necessary to administer the Account.
15.2 Security for marketing communications combines technical controls, provider assurance, logging and incident response. A material personal-data breach is assessed for regulatory and individual notification duties.
16. Automated decision-making and profiling
16.1 Fraud, security and content-safety tools may score transactions or activity and may temporarily block a payment or generation request. Significant adverse decisions receive proportionate human review where required by law.
16.2 The legal basis for automated decision-making and profiling is reviewed when the purpose changes. Consent is not substituted for contract or legal obligation merely because it is easier to obtain, and consent-based use stops after valid withdrawal.
16.3 The user remains responsible for downstream use connected with automated decision-making and profiling, including context, disclosures, third-party rights and compliance after an output is downloaded.
17. Third-party services and links
17.1 The controlling rule is as follows: External websites, payment interfaces and integrations operate under their own privacy terms. Users should review those terms before providing data, particularly when exporting Generated Output or connecting third-party services.
17.2 For third-party services and links, the operator limits collection to information reasonably connected with the stated purpose and restricts access by role. Data is deleted, aggregated or isolated when the purpose and applicable retention period end.
17.3 A restriction concerning third-party services and links can remain in place while a payment, safety or rights investigation is active and is reviewed when material new evidence becomes available.
18. Changes to this Policy
18.1 For the Flash Gen service, The Policy may be updated to reflect changes in law, providers, processing or product functions. Material changes are communicated through the website, Account or email where appropriate.
18.2 The processing record for changes to this policy identifies the purpose, data category, recipient function, lawful basis and retention trigger. This allows privacy requests and incidents to be handled against a defined data lifecycle.
19. How to contact us or submit a request
19.1 This section allocates responsibility clearly. Requests should identify the right being exercised, the relevant Account email and enough context to locate records. The operator normally responds within one month, subject to lawful extensions for complex or numerous requests.
19.2 Where how to contact us or submit a request involves a service provider, contractual controls require confidentiality, security, purpose limitation and deletion or return at the end of the engagement. Provider access is reviewed when functions change.
19.3 The operator will not impose a new price or recurring charge merely because how to contact us or submit a request requires verification, correction or support.
20. Governing law and statutory safeguards
20.1 The Account and transaction outcome follows this position: This Policy is administered under United Kingdom data-protection law and does not limit rights granted by the United Kingdom General Data Protection Regulation or the Data Protection Act 2018. Mandatory local rights remain available where they apply.
20.2 Requests relating to governing law and statutory safeguards may require identity verification proportionate to the sensitivity of the data. A response explains the action taken, any lawful limitation and the available complaint route.
20.3 Communications about governing law and statutory safeguards are sent to the Account email or another verified contact, and users must keep that route secure and current.
Schedule 1 – Practical Retention Guide
This guide translates the retention table into practical lifecycle outcomes. A longer period applies only where law, fraud, security or a live claim reasonably requires it.
| Scenario / step | Practical rule |
| Account data | Kept while active and normally for 24 months after closure to support recovery, complaints and security. |
| Payment and tax data | Kept for six years where needed for accounting, tax and legal claims. |
| Prompt and output data | Normally available for up to 90 days after completion unless the user retains it, deletes it earlier or a dispute requires preservation. |
| Security logs | Normally retained for 12 months and longer only where an incident remains open. |
| Support records | Normally retained for 24 months after the final response or Account closure. |
| Deletion request | Identity is verified, live data is removed where the right applies, and lawful retention copies are isolated until expiry. |
Flash Gen · Privacy Policy · v1.0 · effective 21 July 2026 · Published on the website; subject to update; the current published version governs.