Controller and contact
POLTEX GLOBAL INC controls MotionArt and is the controller or equivalent for ordinary Service use. Its official company and direct contact information is:
POLTEX GLOBAL INC3431 Guider Ave Unit 6ABrooklyn, NY 11235United States+1 347 737 6583Volodymyr PolovkoNo EEA Article 27 representative, UK representative, or data protection officer is identified or appointed by this disclosure. The Operator must still document its MiniMax data-processing agreement, subprocessor list and notices, data locations, content-use settings, deletion flow, EEA/UK transfer safeguards, and retention schedule; optional replay must remain off in consent jurisdictions until a compliant consent control is live. These remaining safeguards and counsel review are required before a privacy-compliant launch.
1. Scope and who controls data
This Policy explains how the person or entity that controls MotionArt (the “Operator”) processes personal data for its website, product-photo-to-ad-video generation, accounts, private history, credits, payments, analytics, moderation, support, and rights-reporting features (the “Service”). It applies to registered users, guests, support requesters, rights holders, and people whose authorized likeness or voice appears in submitted media.
For ordinary Service use, the Operator decides the purposes and means of processing and is the controller or equivalent. Providers process data under their terms and the Operator’s instructions where applicable. Google and checkout providers may be independent controllers for information submitted directly to them. If a signed business data-processing agreement expressly makes the Operator a processor for specified customer data, that agreement controls the roles for that data.
2. Data we process and where it comes from
- Account data: email address, internal user ID, password hash, Google account ID when used, verification status, registration country code, accepted Terms version and time, credits, account dates, and status.
- Product and generation content: descriptions, instructions, settings, uploaded product photos, logos and other visible brand assets, generated videos and previews, file type and size, hashes, model, quality, duration, task and file identifiers, status, and credit use. Media may contain an authorized adult’s likeness, voice, or other personal data.
- Moderation data: automated decisions, reason codes, policy and model identifiers, scores and timing, person or face detections, and apparent-age estimates or ranges. Face detection is used for safety review, not to identify a person.
- Authentication, security, and device data: sessions, verification and reset records, IP address, user agent, login activity, rate limits, pseudonymous guest identifiers, request logs, and security or administrator events.
- Transactions: selected package, price, currency, taxes when supplied, payment provider, order and payment identifiers, status, callbacks, gift-card fingerprints, refunds, and credit-ledger entries. MotionArt does not receive full card or wallet credentials entered on a provider page.
- Support and rights reports: email address, case and access identifiers, category, subject, messages, referenced jobs or media, status, replies, and assignment records.
- Analytics: sanitized page path, coarse events, referrer and allowed campaign parameters, browser, device, operating system, language, screen data, performance, IP-derived coarse location, and a pseudonymous analytics identifier when configured.
Data comes from you, your organization or authorized agent, your browser or device, the Service’s systems, and authentication, generation, moderation, payment, email, analytics, and security providers. A rights report may provide information about another user. Do not submit confidential or personal data that is unnecessary for the requested operation.
3. Purposes and European legal bases
Where the GDPR or UK GDPR applies, the Operator uses data as follows:
- Contract: create and secure an account; accept a generation request; send authorized content to providers; deliver, store, restore, and delete requested clips; administer credits, purchases, refunds, and support.
- Legitimate interests: secure and debug the Service; prevent fraud, counterfeiting, infringement, exploitation, and abuse; maintain limited operational analytics; improve reliability; establish or defend legal claims; and administer a business, after balancing those interests against individual rights.
- Legal obligation: keep required tax and transaction records, respond to valid legal process, protect legal rights, make legally required reports, and meet consumer, privacy, and security duties.
- Consent: run optional non-essential cookies, replay, or similar analytics where consent is required, and process special-category data where explicit consent is the valid and documented condition. Consent may be withdrawn prospectively.
Some account, generation, security, and transaction data is necessary to provide a requested feature or enter a contract. Without it, that feature cannot operate. The Operator must document its lawful-basis and legitimate-interest assessments before launch and will not use consent as a substitute where consent is not freely given.
4. How AI video generation processes content
For the current 10-second image-to-video feature, MotionArt sends the product description and the first uploaded product photo to the MiniMax API, together with model, duration, and resolution instructions. MiniMax returns a task identifier and makes the generated video temporarily available for MotionArt to copy into its private storage. Additional uploaded photos are accepted by MotionArt but are not currently sent to MiniMax for that generation. This behavior must be updated in this Policy if multi-image or clip-assembly processing changes.
MotionArt does not itself train an AI model on customer descriptions, uploads, or outputs. MiniMax’s published API terms currently say that it may use client input and generated content to provide, maintain, develop, and improve its services, comply with law, enforce policies, and keep services safe. Its published privacy policy does not give a fixed content-retention period. Do not upload confidential assets or personal data unless you accept that provider processing. The Operator must verify and contractually document MiniMax’s actual training/content-use controls, retention, deletion, security, audit, and assistance obligations before launch; this Policy does not promise protections that are not yet documented.
5. Automated moderation
Automated systems may inspect description text and images, detect people and faces, estimate apparent age, apply safety classifiers, and allow or block a generation. A blocked request may be kept as a zero-credit safety record, and authorized reviewers may see purpose-limited evidence. These systems may be wrong and do not guarantee detection.
A moderation decision controls access to a generation feature; it is not used to decide employment, credit, housing, insurance, health care, education, or another third party’s legal rights. You may request human review through Contact support.
6. Providers, processors, and disclosures
The Operator may provide only the data needed for the listed purpose to:
- MiniMax (Nanonoble Pte. Ltd. and its affiliates and subprocessors) for AI video generation, safety, task status, and temporary provider video delivery. MiniMax states that API personal data is stored in a United States cloud data center and may be processed by its vendors.
- Modal-hosted moderation services, where enabled, to safety-check description text and the source photo before generation.
- Google for optional OAuth authentication.
- Resend or a configured SMTP provider for sign-in, account, deletion, support, and transactional email.
- NOWPayments, RuKassa, and Rewarble for the payment, settlement, and gift-card methods that are actually made available.
- ipwho.is for a one-time registration-country lookup; MotionArt stores the resulting country code rather than a separate raw registration-IP field.
- the Operator’s hosting and self-hosted PostgreSQL, MinIO-compatible storage, and Umami services for application delivery, database records, encrypted private media, analytics, and optional replay.
- professional advisers, auditors, insurers, transaction successors, courts, regulators, law enforcement, rights holders, or affected people when reasonably necessary and lawful.
MotionArt does not sell personal data, share it for cross-context behavioral advertising, or use it for targeted advertising. It does not disclose customer content to data brokers. Providers’ own websites and checkout pages are governed by their separate notices. The Operator must maintain a current provider and subprocessor inventory and provide any legally required change notice before launch.
7. Retention and deletion
- Generation content: encrypted prompts and successfully captured uploads, outputs, and private history currently have no automatic time-based expiry. They remain until an available customer or administrator deletion process removes them, subject to legal preservation and deletion retries.
- MiniMax copies: provider tasks and files follow MiniMax’s retention and deletion practices. MotionArt account deletion does not yet prove immediate erasure from MiniMax. Provider-side deletion timing and propagation must be verified before launch.
- Account deletion: a verified request blocks access immediately and normally schedules erasure after a seven-day recovery period. Direct identity and generation ciphertext are then erased; pseudonymous financial, credit, generation, moderation, deletion, and security evidence may remain where needed for accounting, abuse prevention, legal claims, or system integrity.
- Sessions and tokens: browser login sessions expire no later than seven days. Sign-in codes normally expire after ten minutes and password-reset links after thirty minutes.
- Support: support cases are normally assigned a two-year retention date, although linked conversations may be erased with the account where applicable.
- Analytics and logs: session replay, if enabled with any required consent, is retained by Umami for up to 30 days. Aggregate analytics, operational logs, and immutable security events currently lack a published automatic deletion period.
- Transactions: payment, tax, accounting, anti-fraud, and chargeback records remain for the period required by applicable law and legitimate claims.
- Backups: residual copies may remain in protected backups and provider systems until their normal overwrite or deletion cycle unless law requires preservation.
Deletion may be delayed to verify a requester, protect another person’s rights, complete a retry, or meet a legal duty. Pseudonymized records are not represented as anonymous. [[DOCUMENT AND IMPLEMENT FIXED LOG, ANALYTICS, BACKUP, MINIMAX, AND LEGAL-HOLD SCHEDULES BEFORE LAUNCH]].
8. Cookies, browser storage, Umami, and replay
MotionArt uses necessary authentication and security cookies. It uses session storage for payment-return state and local storage for an unregistered support requester’s private case-access token. Removing these values may sign you out, remove checkout context, or prevent access to a guest support case.
Self-hosted Umami may collect cookie-free pageviews, sanitized routes, coarse events, campaign attribution, device data, and performance measurements. Ordinary analytics events are designed to exclude descriptions, emails, raw user IDs, filenames, media URLs, and job identifiers. Optional replay and heatmaps are more sensitive and may capture visible text, non-password form values, images, fonts, and canvas on configured public routes. Support and contact routes are excluded; password fields are masked; and URLs are sanitized.
The replay recorder honors configured Do Not Track and Global Privacy Control signals and does not start on a signaled browser. Where consent is legally required, optional replay, heatmaps, and non-essential storage must remain disabled until the visitor opts in and must stop after withdrawal. [[CONSENT BANNER/PREFERENCE CENTER AND REGIONAL DEFAULTS — REQUIRED BEFORE ENABLING OPTIONAL RECORDING IN THE EEA, UK, OR OTHER OPT-IN REGIONS]].
9. International processing
Data may be processed outside your country, including in the United States. MiniMax states that its API personal data is stored in a U.S. cloud data center and that it uses contractual protections consistent with EU standards; the Operator has not yet documented the specific cloud vendor, certification, subprocessor locations, or transfer instrument for this Service.
For restricted EEA transfers, the Operator must use an adequacy decision or an Article 46 safeguard such as the European Commission’s Standard Contractual Clauses, complete a transfer assessment, and add supplementary measures where needed. For restricted UK transfers, it must use UK adequacy regulations, the International Data Transfer Agreement, the UK Addendum, or another lawful safeguard and complete the required data-protection test. You may request information about the safeguards through Contact support. [[EXECUTED MINIMAX DPA, EU SCCs/TRANSFER ASSESSMENT, UK ADDENDUM OR IDTA/TEST, AND SUBPROCESSOR NOTICE PROCESS — REQUIRED BEFORE RESTRICTED TRANSFERS]].
10. EEA, UK, and Swiss rights
Depending on the law and circumstances, you may ask to access data, receive a copy, correct it, erase it, restrict processing, obtain portable data, object to legitimate-interest processing, or withdraw consent. You may also complain to the data-protection authority where you live or work and seek a judicial remedy. Consent withdrawal does not affect earlier lawful processing.
Use account controls or submit a request through Contact support. The Operator may verify identity or authority, ask for information needed to locate the record, protect other people’s rights, and apply lawful exceptions. It will respond without undue delay and ordinarily within one month where the GDPR or UK GDPR applies.
11. United States state privacy notice
During the preceding 12 months, MotionArt may have collected the categories described above: identifiers and customer records; commercial and transaction information; Internet and device activity; approximate location; audio, visual, and other user content; account credentials; and moderation inferences. It collects them from the sources in section 2, uses them for the purposes in section 3, and discloses them to the provider categories in section 6 for those business purposes. It does not knowingly sell or share these categories for cross-context behavioral advertising and does not knowingly sell or share personal data of people under 18.
Subject to state-law scope, thresholds, and exceptions, residents may have rights to confirm processing; know, access, or obtain a portable copy; correct; delete; opt out of sale, targeted advertising, or qualifying profiling; limit specified sensitive-data uses; use an authorized agent; appeal a refusal; and receive equal service without unlawful discrimination. Submit a request through Contact support. To appeal, reply to the decision or open a new privacy case marked “Appeal” and identify the earlier case. The response will explain the outcome and, where required, how to contact the relevant state attorney general.
MotionArt treats a recognized Global Privacy Control signal as an opt-out request where law requires. Because MotionArt does not currently sell data or use targeted advertising, there is no such processing to stop; the signal also suppresses the optional replay recorder on that browser. The Operator may authenticate the preference to an account where the law and technical context permit.
12. Children and people in uploaded media
The Service is for users 18 or older and prohibits uploading or depicting a minor. Do not submit a child’s personal data. If the Operator learns that a child used the Service or that prohibited child data was submitted, it may block access, preserve only evidence required by law, delete other data, and report suspected exploitation to competent authorities.
An adult whose likeness, voice, or personal data was submitted by another user may report unauthorized processing through Contact support. Provide only the minimum job or media reference needed to locate the material. The Operator may verify identity and balance the request against another person’s rights and legal duties.
13. Security and breach response
MotionArt uses measures designed for the data it processes, including TLS, application encryption for retained prompts and private media, private object storage, scoped credentials, access controls, audited administrator access, rate limits, and deletion workflows. No online service can guarantee complete security or continuous availability. The Operator will notify affected people and authorities of a breach when legally required.
14. Changes and contact
This Policy may be updated prospectively as features, providers, or law change. A new effective date and version will be posted, and material changes will receive additional notice or consent where required. Earlier consent is not agreement to an unrelated new purpose.
For privacy rights, deletion, appeals, unauthorized likeness reports, or questions, use the private Contact support form and select “Privacy or deletion” or the appropriate safety category. Do not include passwords, payment credentials, or media unless authorized support staff request the minimum needed through the private case.
This Policy does not waive mandatory rights. It is launch-oriented drafting, not a substitute for provider contracts, operational controls, records of processing, impact and transfer assessments, or counsel review.