Legal
Privacy Policy
How AIIP processes personal data and customer content for its professional photography platform and public website.
Effective date: 12 September 2026Last updated: 14 September 2026
1.Introduction
This Privacy Policy explains how AIIP (“AIIP”, “we”, “us”, or “our”) processes personal data in connection with our professional photography SaaS platform, our public website at https://getaiip.com, and related communications.
AIIP is intended for professional and business users. It helps photographers manage work around their photography business — including Client Galleries, website and marketing workflows, and authorized third-party integrations.
This Policy describes our current product and data practices. It does not describe planned features that are not yet operational.
2.Who is responsible
For questions about this Policy or AIIP’s processing of personal data, contact us at privacy@getaiip.com.
Postal address:
AIIP
Boekweitstraat 21, 9734 AW Groningen, Netherlands
Depending on the context, AIIP may act as a controller (for example for account administration, security, support, website operation, and product administration) or may process certain customer-provided content on behalf of the photographer or customer (for example Client Gallery information and photographs you upload).
If you upload or provide information about your own clients, you may also have independent controller obligations under applicable data protection law. This Policy does not constitute legal advice and does not transfer those obligations away from you.
3.Categories of personal data
Depending on how you use AIIP, we may process the following categories of personal data:
Account and workspace data. Name, email address, authentication and account identifiers, workspace or tenant information, photographer profile information, and subscription or license references.
Client data. Where you use Client Gallery or related features: client names, email addresses, other contact details you provide, and gallery or client-relationship information.
Photo and media data. Photographs and gallery media you provide, related processing metadata where actually used by the feature, and AI-derived analysis results. Current gallery workflows are JPEG-oriented. AIIP’s implemented import workflow does not currently ingest RAW files.
During import, EXIF or similar camera metadata may be read where present. Under the current implementation, that camera metadata is not maintained as a dedicated long-term metadata catalogue.
Integration data. Where you connect a third-party service: OAuth connection information; Google Ads account and campaign identifiers together with reporting metrics retrieved by the current read-only Google Ads integration (including campaign name and status, date, impressions, clicks, cost/spend, conversions, conversion value, CTR and average CPC); Google Analytics / GA4, Google Search Console and Google Business Profile data accessed by the relevant integration; and social-media metrics where an authorized integration is enabled. AIIP does not claim access to private social messages or arbitrary social content beyond what an enabled integration is designed to retrieve.
Security and technical data. Authentication and security information, audit and usage information, and — on the public marketing website — hashed IP and user-agent-derived signals used for privacy-preserving visit analytics where implemented. Original photographs may also be stored in connected systems such as WordPress Media or gallery filesystem storage, depending on your configuration.
AI-derived data. Classifications, selections, recommendations, analysis results, embeddings or other derived representations, and similar AI-assisted outputs generated in the course of providing AIIP.
4.Purposes of processing
We process personal data to:
- provide and operate AIIP’s functionality;
- manage accounts, workspaces and authorized users;
- store, display and deliver customer content, including Client Galleries;
- analyze photographs and generate AI-assisted results where those features are used;
- synchronize authorized third-party integrations;
- provide advertising and analytics insights from connected services;
- maintain security, prevent abuse and investigate incidents;
- troubleshoot, support and communicate with customers;
- maintain and improve AIIP’s own product intelligence; and
- comply with legal obligations.
Product improvement vs model training. AIIP may use user decisions, corrections, selections, feedback and similar signals to improve AIIP’s own product intelligence and decision-making. AIIP does not use customer photographs or customer data to train third-party foundation models, and does not claim to train its own foundation model on customer content.
We do not sell customer content. We do not use customer photographs for advertising purposes unless a specific, authorized feature is designed to do so.
5.AI processing
AIIP may use AI services to analyze photographs and/or generate AI-assisted results. Where vision analysis is enabled, image bytes may be transmitted to an AI vision provider. AIIP’s current active AI provider for this processing is OpenAI.
AIIP does not use customer photographs or customer data to train third-party foundation models. AIIP may use user feedback, decisions and corrections to improve AIIP’s own product intelligence.
Google Ads advertising and reporting data retrieved through AIIP’s current Google Ads integration is not sent to an LLM provider.
6.Google services and OAuth
You may authorize AIIP Studio to connect to certain Google services, including Google Ads, Google Analytics / GA4, Google Search Console and Google Business Profile, depending on the features you enable.
Google Ads connection. When a photographer connects Google Ads from AIIP Studio, AIIP uses Google OAuth 2.0. After the photographer authorizes the connection, AIIP receives OAuth credentials (access and refresh tokens). Those credentials are stored server-side in AIIP’s encrypted credential vault, are associated with the photographer’s AIIP workspace, and are not stored in or exposed to browser clients.
AIIP requests the Google Ads authorization scope https://www.googleapis.com/auth/adwords. Using the Google Ads API, AIIP currently retrieves reporting information such as accessible customer/account identifiers, campaign identifiers, campaign name and status, date, impressions, clicks, cost/spend, conversions, conversion value, CTR and average CPC. Retrieved reporting information is transformed into AIIP analytics evidence associated with the workspace and used to provide paid-acquisition and business-intelligence insights inside AIIP.
Current Google Ads access is read-only. AIIP does not currently create, modify, pause, delete, or otherwise manage Google Ads campaigns, ads, ad groups, budgets, billing settings, or Google Ads user access or permissions. AIIP only accesses information covered by the requested OAuth scope and the implemented Google Ads API reporting functionality.
Google Ads advertising and reporting data retrieved through the current Google Ads integration is not sent to an LLM provider.
Disconnecting Google Ads. When you disconnect Google Ads, AIIP revokes the OAuth authorization and removes or revokes the stored OAuth credentials for that connection. Previously ingested Google Ads reporting analytics evidence associated with the workspace may remain in AIIP after disconnect and continues to follow AIIP’s applicable retention and deletion lifecycle described in this Policy. Disconnecting the integration therefore does not necessarily mean that all historical Ads reporting evidence is immediately deleted.
7.Third-party services
To provide AIIP we use carefully selected service providers. Personal data is shared with them only where required for the relevant functionality, where you authorize a connection, or where we are legally required to do so.
Relevant categories include:
- AI providers — currently OpenAI, for photograph analysis and AI-assisted results where enabled;
- Google — for authorized Google Ads, Analytics, Search Console and Business Profile integrations;
- Microsoft Clarity — for website/product analytics where enabled;
- WordPress — where you connect a WordPress site for media or publishing workflows;
- Hosting / infrastructure — currently Contabo VPS;
- Email / SMTP — for transactional and contact email (provider depends on deployment configuration);
- Social network APIs — where you authorize a social integration and metrics are retrieved.
Payment processing (for example Stripe) is planned but is not currently operational. AIIP does not currently store credit-card details.
8.International transfers
AIIP is based in the Netherlands. Some service providers may process personal data outside the European Economic Area, including in the United States.
Where personal data is transferred outside the EEA, AIIP will use appropriate safeguards required by applicable data-protection law.
9.Retention
Active accounts. Account and workspace data is retained while the account remains active, or as otherwise needed to provide the service and meet legal obligations.
Customer content. Customer content (including photographs and Client Gallery information) is retained while required to provide the service. After account termination, AIIP aims to initiate deletion of customer content after a policy grace period of 30 days, unless a longer period is required for legal, security or dispute-related reasons. This is a policy target; not every deletion path may yet be fully automated.
Backups. Backup copies may persist for a limited period as part of normal backup and recovery processes.
Security and audit data. Certain security, audit and operational records may be retained longer where reasonably necessary for security, fraud prevention, dispute resolution, legal claims or legal obligations. Audit records may therefore outlive ordinary customer-content deletion.
OAuth credentials. When you disconnect an integration, AIIP removes or revokes the stored OAuth credentials for that connection according to the implemented integration lifecycle. Previously ingested reporting or analytics evidence from that integration may remain associated with the workspace and continues to follow the retention and deletion practices described in this section, rather than being erased solely because the connection was disconnected.
10.Account termination and deletion
When an account is terminated, AIIP will handle deletion of customer data according to its deletion process and retention obligations. Termination does not mean that every category of data is erased instantly and irreversibly in all systems.
In particular, customer content, operational account data, security/audit records, legal records and backups may follow different retention timelines, as described above.
12.Your rights
Subject to applicable conditions and exceptions under GDPR and other data-protection law, you may have the right to:
- access your personal data;
- rectify inaccurate personal data;
- request erasure;
- request restriction of processing;
- object to certain processing;
- receive personal data in a portable format;
- withdraw consent where processing is based on consent, without affecting the lawfulness of processing before withdrawal; and
- lodge a complaint with a supervisory authority (in the Netherlands, the Autoriteit Persoonsgegevens).
Not every right applies to every processing activity. To exercise your rights, contact privacy@getaiip.com.
13.Children
AIIP is intended for professional and business users and is not directed at children. You must be at least 16 years old to use AIIP.
14.Changes to this Policy
We may update this Privacy Policy from time to time. The “Last updated” date at the top of this page will change when we do. Where required, we will provide additional notice.
15.Contact
For privacy requests or questions: privacy@getaiip.com
AIIP
Boekweitstraat 21, 9734 AW Groningen, Netherlands