My Account
Close

Contacts

USA, New York - 1060
Str. First Avenue 1

800 100 975 20 34
+ (123) 1800-234-5678

info@vidsparks.com

Privacy Policy

VidSparks | Privacy Policy | v1.0 | Effective 21 July 2026

FieldValue
OperatorLOGIC OCTAVE LTD
Company number15587296
Registered office20 Wenlock Road, London, England, N1 7GU
Trading name / brandVidSparks
Websitehttps://vidsparks.com
Contact emailinfo@vidsparks.com
Support / complaintsinfo@vidsparks.com; Monday to Friday, 09:00-17:00 UK time, excluding public holidays
Governing lawEngland and Wales
Document versionv1.0
Effective date21 July 2026
Important: This Policy explains how VidSparks uses personal data for accounts, one-time Token Pack payments, artificial intelligence video generation, security and support. It applies to website visitors, registered users, payers and people who contact us. It does not transfer responsibility for personal data that users place in their Inputs.

1. Introduction and scope

1.1 LOGIC OCTAVE LTD, trading as VidSparks, is committed to handling personal data lawfully, fairly and transparently. This Policy covers data collected through https://vidsparks.com, the Account interface, checkout, generation workflows, support communications and related security systems.

1.2 The Policy applies when you visit, register, buy a Token Pack, submit an Input, receive an Output, communicate with us or are identified in a fraud, rights or abuse report. It also explains the choices and legal rights available under applicable UK data protection law.

1.3 Users decide what lawful material to upload. Where an organisation uses VidSparks to process personal data on its behalf, that organisation may be a separate controller and must give its own notices, obtain permissions and comply with obligations relating to the people represented in Inputs or Outputs.

2. Data controller and contact

2.1 LOGIC OCTAVE LTD, company number 15587296, is the controller for the Account, transaction, security, support and website data described in this Policy. Our registered office is 20 Wenlock Road, London, England, N1 7GU. Privacy enquiries and rights requests should be sent to info@vidsparks.com.

2.2 We do not appoint a separate public Data Protection Officer where the legal threshold is not met. Responsibility for privacy governance remains with the Operator and is coordinated through the privacy contact above. We may use specialist advisers and processors without transferring our accountability as controller.

2.3 If you act for another person or organisation, we may ask for evidence of authority before disclosing data or changing an Account. This protects the Account holder and does not prevent a person from using an authorised representative where applicable law permits.

3. Age position

3.1 The Service is intended for adults aged 18 or over. We do not knowingly offer Accounts or payment functionality to children. A person must not upload a child image, voice or other personal data unless the intended use is lawful, proportionate and supported by the permissions and safeguards required for that context.

3.2 If we learn that an Account holder is under the minimum age, we may suspend access, request age evidence and delete data that is not required for security, legal claims or compliance. A parent or guardian who believes that a child has provided personal data should contact the privacy address with enough information for us to locate the relevant record.

4. Categories of personal data

The table below describes the principal data groups. A particular user may provide only some of them, and we seek to minimise collection to what is reasonably needed for the relevant function.

CategoryExamplesSourcePurpose
Account and identityName, Account email, login identifier, age confirmation, country, organisation and verification resultDirectly from the user; security or verification providerCreate and protect the Account; communicate; apply eligibility and risk controls
Transaction and paymentOrder reference, amount, currency, Token Pack, payment status, limited card descriptor, billing country, fraud signalsPSP, acquiring partner and userProcess payment; fulfil Tokens; reconcile; prevent fraud; handle refunds and disputes
Inputs and OutputsPrompts, uploaded images, audio, reference media, generation settings, generated files and moderation signalsUser and generation systemsPerform generation; deliver Output; enforce safety; provide support
Technical and usageIP address, device, browser, timestamps, session identifiers, pages, model selection, Token consumption and error logsAutomatically from the website and ServiceOperate, secure, diagnose and improve the Service; measure consented analytics
Support and rightsMessages, attachments, complaint details, identity evidence, rights request and resolution historyUser, representative or rights holderRespond, investigate, comply with law and maintain an audit trail
Marketing preferencesConsent status, campaign source, email engagement and suppression statusUser and consented communication toolsSend requested marketing and respect opt-out choices

5. Sources of personal data

5.1 We receive data directly when you register, pay, generate, upload, download, submit a support request, change consent or exercise a right. We also create operational data such as Account identifiers, Token ledger entries, timestamps, moderation outcomes and technical logs as the Service is used.

5.2 Payment and fraud information may come from the PSP, bank, card network, device intelligence service or acquiring partner. Limited information may come from a rights holder, regulator, law-enforcement body, public register or another user who reports conduct affecting the Service.

5.3 We do not seek special category data. You should avoid placing health, biometric, political, religious, sexual-orientation or similarly sensitive data in prompts or uploads unless there is a clear lawful basis and the use is genuinely necessary. We may remove or restrict such material where risk is disproportionate.

6. How we use personal data

6.1 We use data to register and authenticate users, maintain balances, process one-time purchases, route Generation Requests, display progress, make Outputs available, diagnose errors, provide support and administer refunds, cancellations and complaints. These activities are necessary to supply the contract or take requested steps before it is formed.

6.2 We also use data to prevent fraud and abuse, protect systems, enforce the Acceptable Use Policy, investigate harmful synthetic media, preserve evidence, comply with tax and accounting duties, respond to lawful requests and establish or defend legal claims. Access is limited according to role and operational need.

6.3 With consent where required, we use non-essential cookies or similar technologies for analytics and marketing. We may use aggregated or de-identified information to understand demand, capacity and feature performance, provided the resulting information does not identify a person.

7. Lawful bases for processing

Processing activityLawful basisNotes
Create and administer an AccountContractNeeded to provide access, authentication, Token balances and communications requested by the user
Process a Token Pack payment and deliver TokensContract; legal obligationNeeded to complete the order and retain required accounting and tax evidence
Generate and deliver OutputContractInputs and settings are processed to perform the requested computational service
Fraud prevention, security and abuse investigationLegitimate interests; legal obligation where applicableProtects users, payment partners, rights holders and the integrity of the Service; safeguards are applied
Customer support, complaints and legal claimsContract; legitimate interests; legal obligationAllows issues to be resolved and evidence to be maintained proportionately
Non-essential analytics and advertising technologiesConsentActivated only after the applicable consent choice and withdrawable through preference controls
Direct marketing by emailConsent or another basis permitted by electronic marketing lawEvery message provides an unsubscribe route; suppression records are retained to respect the choice

7.1 Where legitimate interests is used, we consider the purpose, necessity and impact on individuals and apply measures such as access controls, minimisation, retention limits and objection rights. We do not rely on legitimate interests where the interests or fundamental rights of an affected person override the proposed use.

7.2 Consent is specific and may be withdrawn at any time without affecting processing already carried out lawfully. Withdrawal does not require deletion of transaction or security records that must be retained on another lawful basis. Contract processing may be necessary to provide a requested feature; without the required data, that feature cannot operate.

8. Payments and checkout

8.1 Payments are processed through an independent PSP and acquiring chain. Full card numbers, card security codes and authentication credentials are entered into the PSP environment and are not intended to be stored by VidSparks. We receive only the information needed to identify the transaction, confirm status, deliver Tokens and manage risk.

8.2 The PSP may act as an independent controller for regulatory, fraud and payment-network purposes and may provide its own notice at checkout. We may exchange Account, device, amount, billing location, authentication and dispute information with the PSP where necessary to authorise a transaction, prevent misuse or respond to a retrieval or chargeback.

8.3 We do not require a shipping address for ordinary digital delivery. A billing country, postcode or address fragment may still be requested by the PSP for authentication, tax or fraud prevention. You should not send payment card details through email or support attachments.

9. Cookies and similar technologies

9.1 We use browser storage and comparable technologies for session security, authentication, load management, checkout state and consent preferences. These strictly necessary functions may operate without consent where the law permits because the requested Service could not function securely without them.

9.2 Analytics, performance and marketing technologies are enabled only in accordance with the choices presented through the consent interface. The Cookie Policy describes categories, representative technologies, duration, provider roles and how to change preferences. Withdrawing consent does not disable essential Account or payment functions.

10. Sharing of personal data

10.1 We share data with processors and service providers that support hosting, content delivery, artificial intelligence model execution, storage, email, support, security, analytics selected by consent and payment processing. Each recipient receives only the data reasonably needed for its role and is subject to contractual or legal duties appropriate to that role.

10.2 We may disclose data to professional advisers, auditors, insurers, banks, card networks, regulators, courts or law-enforcement bodies where necessary and lawful. We may also share information with a rights holder or affected person where needed to address an infringement or safety report, taking care not to disclose more than the circumstances justify.

10.3 If the business or Service is reorganised, financed, sold or transferred, relevant data may be disclosed under confidentiality and transferred with appropriate safeguards. The recipient must use the data consistently with this Policy or provide a new notice where the purpose materially changes.

11. International transfers

11.1 Some hosting, generation, security, communications or payment providers may process data outside the United Kingdom. Before making a restricted transfer, we use a lawful transfer mechanism such as UK adequacy regulations, an approved contractual safeguard, binding rules or another mechanism permitted by UK data protection law.

11.2 Where appropriate safeguards are used, we assess the transfer context and apply supplementary measures where needed, including encryption in transit, access limitation, data minimisation and contractual controls. An exception is used only where its legal conditions are satisfied and the use is necessary and proportionate.

11.3 You may request further information about the relevant transfer mechanism by contacting the privacy address. We may redact confidential commercial or security details, but will provide a meaningful explanation of the protection used for the category of transfer concerned.

12. Data retention

Data categoryRetention periodTrigger / criterion
Account profile and Token ledgerAccount lifetime plus 24 monthsMeasured from closure; longer only for unresolved disputes, fraud or legal claims
Transaction, tax and refund recordsUp to 6 years after the relevant financial periodSupports accounting, tax, contract and dispute obligations
Inputs and generated OutputsNormally up to 30 days after generation or earlier user deletionOperational storage may be shorter; safety evidence may be retained separately where necessary
Security, authentication and technical logsNormally 12 monthsExtended for a documented incident, abuse investigation or legal claim
Support and complaint records3 years after resolution or Account closureAllows continuity, quality control and defence of claims
Marketing recordsUntil opt-out or 24 months of inactivityA minimal suppression record may be kept longer to prevent further marketing
Privacy rights records3 years after completionDemonstrates handling and protects against repeated unauthorised requests

12.1 Retention periods are applied by category rather than by retaining every item indefinitely. At the end of the period, data is deleted, anonymised or isolated from ordinary use unless a specific legal hold applies. Backup copies may persist for a limited cycle and are protected from routine access until overwritten.

12.2 Inputs or Outputs reported for serious abuse may be retained longer in a restricted evidence set where necessary to protect a person, respond to a regulator, enforce rights or defend a claim. We consider necessity, scope and access before extending retention beyond the normal operational period.

13. Data security

13.1 We use technical and organisational measures appropriate to the risk, including encrypted transport, access control, authentication safeguards, logging, provider due diligence, environment separation, vulnerability management and incident response. No online system is risk-free, so users must also protect credentials and devices.

13.2 Access to personal data is limited to personnel and providers who need it for operations, support, security, finance or legal compliance. Higher-risk actions may require verification or additional authentication. We review material incidents and take containment, remediation and notification steps required by law.

13.3 You should report suspected compromise to info@vidsparks.com without delay, using a secure device where possible. Do not include passwords, authentication codes or full card details. We may temporarily lock an Account or generation function while investigating a credible security report.

14. Your privacy rights

14.1 Depending on the circumstances, you may request access, correction, erasure, restriction, portability or objection, and may have rights relating to certain automated decisions. You may withdraw consent at any time. These rights are subject to legal conditions, exemptions and the rights of other people.

14.2 Send a request to the privacy contact and describe the Account or data concerned. We may request proportionate identification and clarification. We normally respond within one month, subject to any lawful extension for complexity or multiple requests. We do not charge unless the law permits a reasonable fee for a manifestly unfounded or excessive request.

14.3 You may complain to the UK Information Commissioner or another competent supervisory authority. We encourage you to contact us first so the issue can be investigated, but doing so is not a condition of using a regulatory right or legal remedy.

15. Marketing communications

15.1 We send promotional email only where a lawful electronic-marketing basis applies. Marketing content is identified, includes the Operator details and provides an unsubscribe route. Service messages about security, purchases, Token delivery, legal changes or support are transactional and may continue even after marketing opt-out.

15.2 You can unsubscribe through the message link or by contacting us. We may retain a minimal suppression record so the preference is respected. Cookie-based advertising or campaign measurement follows the consent choices described in the Cookie Policy and can be changed through the preference interface.

16. Automated decision-making and profiling

16.1 Automated systems may score transactions, devices, content or Generation Requests for fraud, security, policy and safety risk. These systems may block a payment, delay Token delivery, reject prohibited content or refer a case for manual review. They are used to protect users, payment partners and the Service.

16.2 We do not intend to make solely automated decisions producing legal or similarly significant effects without an applicable lawful basis and safeguards. Where such a right applies, you may request human review, express your view and contest the decision through the support route.

17. Third-party services and links

17.1 The Service may link to third-party websites, model information, payment pages or social platforms. Those services operate under their own terms and privacy notices. We are not the controller of an unrelated third-party site merely because a link is provided.

17.2 When a third-party integration is embedded, information such as IP address, browser data or selected content may be transmitted as needed for that function. Non-essential embedded technologies are controlled through consent where required. Users should review the provider notice before sending sensitive or confidential material.

18. Changes to this Policy

18.1 We may update this Policy to reflect law, guidance, service features, providers or security practices. The current version and effective date are published on the website. Material changes will be highlighted through the website, Account or email where reasonably practicable.

18.2 A change in wording does not retrospectively legitimise incompatible processing. If a new purpose is materially different, we will identify an appropriate lawful basis and provide additional notice or seek consent where required before beginning that use.

19. How to contact us or submit a request

19.1 Email privacy and rights requests to info@vidsparks.com or write to 20 Wenlock Road, London, England, N1 7GU. Include your Account email, the right or issue concerned and enough detail to locate the relevant data. For security, use the Account email where possible and do not send full card details or passwords.

19.2 We may separate a privacy request from a refund, cancellation or content complaint because different legal tests and records apply. The teams handling those matters may coordinate so you receive a coherent response without unnecessary repetition or disclosure.

19.3 This Policy is governed by the laws of England and Wales. That choice does not displace any mandatory data-protection, electronic-communications or consumer right that applies to you in another jurisdiction, nor any right to complain to a competent supervisory authority.

Schedule 1. Practical Retention Guide

SituationTypical retention treatment
You close the AccountAccess ends immediately or on confirmation. Profile and Token-ledger data moves to restricted retention for up to 24 months; transaction records remain for the applicable financial period.
You delete an OutputThe accessible copy is removed from ordinary storage. Short-lived backups or security evidence may remain until the relevant cycle or investigation ends.
A payment is disputedTransaction, authentication, fulfilment and communication evidence is retained until the dispute, appeal and related limitation period are complete.
You unsubscribeMarketing stops after processing. A minimal suppression entry remains so the opt-out is not accidentally reversed.
You report harmful contentThe minimum evidence needed to investigate may be isolated, access-restricted and retained longer than ordinary generated content.

The periods above are operational standards, not promises to retain data for the full period. Data may be deleted earlier where it is no longer needed, provided legal, security and dispute obligations are satisfied.

VidSparks | Privacy Policy | v1.0 | Effective 21 July 2026. Published on the website; subject to update; the current published version governs.