This explains what Mise en Scène does with personal data — yours, and the data your business puts into the platform. It is written to be read, not to be survived. Where something is uncomfortable, such as the fact that nothing is deleted automatically, we say so rather than hide it in a clause.
If you only read one section, read section 7 on model training and section 10 on how long we keep things.
1. Who is responsible for your data
The controller of the personal data described here is [[ OWNER: legal entity name, e.g. “Mise en Scène S.L.” ]], registered at [[ OWNER: registered address in Spain ]], tax ID (NIF) [[ OWNER: NIF ]], registered in [[ OWNER: Registro Mercantil details, or “not yet registered” ]].
For anything about your data, write to [[ OWNER: privacy contact email — hello@miseen.studio unless you want a separate one ]]. We have [[ OWNER: appointed / not appointed ]] a Data Protection Officer.
This page is also the information required of an information society service provider under Article 10 of Spanish Law 34/2002 (LSSI-CE).
2. Two different roles — read this first
Mise en Scène is a business tool. We handle personal data in two quite different ways, and your rights differ depending on which one applies.
- We are the controller for data about the people who use the product: account holders, workspace members, billing contacts, people who write to us. This policy is our notice to those people.
- We are a processor for the content our customers put into their workspace — product photos, brand documents, actor likenesses, voice samples, reviewer email addresses. The customer decides why that data is there and for how long; we only act on their instructions. If your employer, agency or client uploaded data about you, they are the controller and you should contact them first. We will help them answer you.
Business customers who need a written Data Processing Agreement under Article 28 GDPR can request one at the address above. [[ OWNER: Confirm a DPA exists and where it lives before publishing this sentence. ]]
3. What we actually store
This is the real list, taken from the database schema rather than a template.
- Account. Email address, display name and sign-in method. Authentication is handled by Supabase Auth; we do not store your password.
- Workspace. Workspace name, the members in it and their roles, plan, credit balance and settings.
- Invitations. The email address of anyone you invite — as a team member, or as an external reviewer who never creates an account — plus the invitation token, who sent it, and whether it was accepted. External reviewers who comment are stored with the email address they were invited under.
- Content you upload. Brand documents, product images, logos, fonts and reference material, along with the filename, file type, size and who uploaded it.
- Likeness data. If you add an actor, we store the source photograph, the generated character sheets, a face thumbnail, a written physical description of the person, and the demographic fields you supply (gender, age range, ethnicity). We also store an immutable consent record containing the time of acceptance, the version of the terms accepted, your IP address and your browser user-agent string.
- Voice data. If you clone a voice, we store the consent recording of the spoken authorisation phrase, the written attestation, the time, your IP address and user-agent, and the identifier of the cloned voice held at our voice provider. This record cannot be edited after the fact, by design.
- Work product. Projects, prompts, job records, generated images, video and audio, review comments and annotations, and search embeddings derived from them.
- Billing. Your plan, credit ledger, and the customer and subscription identifiers issued by Stripe. We never see or store card numbers — card details go straight to Stripe.
- Operational records. Audit events, usage events, error reports, and — for one public, unauthenticated endpoint — a stored IP address used purely to rate-limit abuse.
4. Face and voice data is special-category data
Photographs of a person and a cloned voice can identify that person. We treat likeness and voice data as sensitive and we only process it on the basis of explicit consent (Article 9(2)(a) GDPR), captured and stored at the moment of upload. That is why the product makes you tick a consent box and records it.
You may not upload a photograph or voice of a person who has not authorised it. The full rules are in the actor terms. Either you or the person depicted can ask us to delete it at any time.
We do not use face or voice data for biometric identification, and the terms forbid you from doing so either.
5. Why we process it, and on what legal basis
| Purpose | Legal basis |
|---|
| Creating and running your account and workspace, and delivering the generation, editing and review features you ask for | Performance of a contract — Art. 6(1)(b) |
| Taking payment, managing plans and credits, and issuing invoices | Performance of a contract — Art. 6(1)(b); legal obligation for tax records — Art. 6(1)(c) |
| Keeping the service secure: authentication, audit logs, rate limiting, error monitoring, fraud and abuse prevention | Legitimate interests — Art. 6(1)(f). Our interest is running a service that is not abused or broken; the data used is minimal and operational. |
| Support and answering messages you send us | Performance of a contract — Art. 6(1)(b); legitimate interests — Art. 6(1)(f) |
| Understanding which features are used, to decide what to build | Legitimate interests — Art. 6(1)(f) |
| Storing and using a person’s likeness or voice | Explicit consent — Art. 9(2)(a), recorded per upload |
| Marketing emails, if we send any [[ OWNER: confirm whether you send marketing email at all ]] | Consent — Art. 6(1)(a), withdrawable at any time |
6. We do not make automated decisions about you
The product uses AI models heavily to generate content, but no automated process makes a decision about a person that produces legal effects or similarly significantly affects them, in the sense of Article 22 GDPR. We do not profile you and we do not score you.
7. Do you train AI models on our content?
Short answer: we do not train our own models on your content. The longer, honest answer:
- We train no general model. Nothing you upload feeds a model that we own, sell or share with other customers.
- One exception, and it is yours. If you explicitly ask us to train a product LoRA, we send the product images from your own workspace to fal.ai to fit a small adapter. That adapter belongs to your workspace and is used only for your generations. It is started by you, never automatically.
- Third-party model providers. Your prompts and reference images are sent to the AI providers listed below in order to produce the output you asked for. Whether a given provider retains those inputs, and for how long, is governed by that provider's own terms and our contract with them. [[ OWNER: Confirm the no-training / zero-retention position with each provider in writing and state it here — this is the first question every serious client asks ]].
8. Who we share data with
We do not sell personal data and we do not share it for advertising. We use the service providers below. Each one is listed because code in this product actually sends data to it.
| Provider | What it does | What it receives | Where |
|---|
| Vercel | Hosting and content delivery | All requests to the site, including IP address | Deployed to the Paris (cdg1) region; Vercel is a US company |
| Supabase | Database, authentication, file storage and invitation email | Everything stored by the product | AWS eu-west-1 (Ireland) |
| Stripe | Payments and subscriptions | Name, email, billing details and payment method | US / global |
| Anthropic (Claude) | Text and vision AI — briefs, prompts, chat, quality checks | Prompts, briefs, product descriptions and images sent for analysis | US |
| Google (Gemini) | Image generation, speech and text | Prompts and reference images | US / global |
| OpenAI | Image generation and editing | Prompts and uploaded images | US |
| fal.ai | The main media generation gateway; routes to many underlying model vendors | Prompts, uploaded and generated images, video and audio | US |
| HeyGen | Avatar video, voice cloning and video translation | Voice recordings, video and text to be spoken | US |
| BytePlus (Ark) | Seedance and Seedream image and video models | Prompts, reference images and video | Singapore / Asia-Pacific endpoint |
| Higgsfield | Additional image and video models, and the ads pipeline | Prompts and reference images | Not verified |
| Atlas Cloud, PiAPI | Alternative routes to the same video models. Off unless a workspace opts in | Prompts and reference images | Not verified |
| Voyage AI | Turns your outputs into embeddings so search works | Output text and image URLs | US |
| Inngest | Runs long jobs like video renders reliably | Job payloads, including prompts and asset URLs | US |
| Sentry | Error monitoring | Error reports, technical request context and IP address | Depends on the Sentry region chosen — [[ OWNER: confirm and state EU or US ]] |
| Slack, Notion, Shopify, Meta, TikTok, Google Ads | Optional integrations you connect yourself | Only what that integration needs, and only if you connect it | Depends on the provider |
We may also disclose data where the law requires it, or to protect our rights or someone's safety.
9. Sending data outside the EEA
Our database and file storage sit in Ireland and the site is served from Paris. But most AI model providers are outside the EEA, so producing an image or a video means sending your prompt and reference material to the United States, and in the case of Seedance and Seedream models to a Singapore endpoint.
Where a provider is certified under the EU–US Data Privacy Framework, that transfer relies on the European Commission's adequacy decision of 10 July 2023. Where it is not, we rely on the European Commission's Standard Contractual Clauses (Article 46(2)(c) GDPR) together with a transfer impact assessment. [[ OWNER: Confirm, provider by provider, which mechanism actually applies and keep the signed clauses on file. The Data Privacy Framework is under appeal at the Court of Justice (Case C-703/25 P), so keep SCCs in place as a fallback even for certified providers. ]]
You can ask us for a copy of the safeguards used for any specific transfer.
10. How long we keep it
We would rather tell you the truth than quote a retention schedule we do not run:
- Nothing expires on its own. There is no automatic deletion job. Your projects, generated outputs, uploads and account data stay until someone removes them. That is deliberate — creative work disappearing on a timer would be worse than keeping it — but it means retention is on request, not on a clock.
- Deleting inside the product is reversible. Projects, outputs and clients you delete go to Trash and can be restored. They are not erased from storage at that point.
- Deleting an actor is not reversible. Removing an actor deletes the record permanently.
- Erasure on request. Ask us to delete an account, a workspace or a specific person's likeness or voice and we will do it manually, across storage as well as the database, within one month (Article 12(3) GDPR).
- What we keep afterwards. Invoices and payment records, for the period Spanish tax and commercial law requires. Consent records for likeness and voice, because they are the evidence that the upload was authorised — kept for as long as the generated material may be in circulation, then deleted on request. Security and audit logs, kept in a reduced form. [[ OWNER: Set the exact retention periods you want for invoices, consent records and logs, with your accountant. ]]
11. Keeping it safe
Every table is protected by row-level security in the database, so one workspace cannot read another's data even if the application layer were wrong. Data is encrypted in transit and at rest by our infrastructure providers. Administrative access is limited and audited. Sensitive operational tables are not readable by any customer-facing role at all.
No system is perfect. If we suffer a breach that is likely to put your rights at risk, we will notify the Spanish Data Protection Agency within 72 hours and tell you where the law requires it.
12. Your rights
Under the GDPR you can ask us to:
- tell you what data we hold about you, and give you a copy (access);
- correct anything wrong (rectification);
- delete it (erasure);
- pause our use of it while a dispute is resolved (restriction);
- hand it to you or another provider in a machine-readable form (portability);
- stop processing based on legitimate interests (objection);
- withdraw consent at any time, which is as easy as giving it, and does not undo what was lawful before.
Write to [[ OWNER: privacy contact email ]]. We answer within one month. There is no charge unless a request is clearly excessive.
If you are unhappy with our answer you can complain to the Spanish Data Protection Agency, the Agencia Española de Protección de Datos, C/ Jorge Juan 6, 28001 Madrid — www.aepd.es — or to the supervisory authority where you live or work.
13. Providing your data
You do not have to give us anything. But an email address and payment details are necessary to create an account and pay for it, so without them we cannot provide the service. Everything else is optional.
14. Children
Mise en Scène is a business product and is not intended for anyone under 18. In Spain the age at which a person can consent to their data being processed is 14 (Article 7, Organic Law 3/2018). If we learn that we hold data about a child without proper authorisation, we delete it.
15. Cookies
We use a small number of strictly necessary cookies and no tracking cookies at all. The detail is on the cookies page.
16. Changes to this policy
If we change this policy we will update the date at the top, and tell account holders by email when the change is material — for example a new category of data, a new purpose, or a new provider receiving your content.