Privacy Policy

Last updated: 12 August 2026

This policy describes how Viewroom collects, uses, and protects your personal data and your works. It applies to viewroom.art and to the Viewroom service.


Our commitments

Viewroom is a tool built by an artist for artists. Three commitments shape how the service treats what you upload to it:

  1. Your works belong to you. Every image, text, or document uploaded to Viewroom remains your exclusive property. Viewroom claims no rights over your works — no reproduction, no representation, no modification, no licence. The service acts solely as a hosting and sharing tool under your control.

  2. No AI trained on your works. Viewroom uses some AI tooling, internally, to speed up the processing of technical data — for example, extracting information from a filename or suggesting metadata. That said, no work uploaded to Viewroom is used to train an AI model, whether internal, partner, or third-party.

  3. Your data stays your data. Viewroom never sells your personal data or your works. There are no advertising partnerships, no resale of user lists, no secondary commercial exploitation of what you upload.


1. Data controller

The controller of personal data processing is Florian Pierre Bernard Zumbrunn, sole proprietor, publisher of the Viewroom site (see Legal Notice for full contact details).

Special case — Studio subscription: for the managed artists' data that a Studio client enters in their artist spaces (see section 2.1), the Studio client is the controller and Viewroom acts as processor, in accordance with the Terms of Sale.

Contact for any question relating to your data: contact@viewroom.art

For personal data relating to the account holder and the use of Viewroom, Viewroom determines the purposes described in this policy. Where a User adds or imports other persons' data to pursue the User's own purposes, the User determines those purposes and Viewroom processes the data solely to provide the contact book and import under the User's documented instructions. The allocation of roles depends on the facts of each processing activity.

Viewroom's commitments when acting as processor for the contact book and import are detailed in the Data Processing Addendum; those applicable to the artist spaces of the Studio subscription are set out in §10.3 of the Terms of Sale.


2. Data collected

2.1 Data you provide to us

  • Account creation: email address, password (stored as a hash, never in clear text), artist name or pseudonym.
  • Artist profile: biography, background, external links (website, Instagram, galleries), professional contact information you choose to enter.
  • Works: images, titles, dates, dimensions, techniques, descriptions, prices, status (available / sold / on consignment), any associated metadata.
  • Contacts: if you use the integrated contact book, the information of the people you add or import: name, relationship type, email, phone, company, address, city, country, free-text notes, sheet names and other cells you choose to submit.
  • AI-assisted contact import: Viewroom reads the CSV or XLSX, identifies its structure, suggests column mappings, displays a preview, checks duplicates and creates only the rows you confirm. The necessary content is temporarily sent to Amazon Bedrock. Calls must use a European AWS Region and an eu.* geographic inference profile, which may route processing across AWS Regions located in the European Union. AWS states that Bedrock inputs and outputs are not used to train models.
  • Import technical data: opaque identifiers, processing versions, counts, statuses, timestamps, durations, token volumes, estimated costs and error codes. These exclude filenames, cells, Contact fields, prompts and model outputs.
  • Managed artists' data (Studio subscription): if you use the Studio plan, the information you enter about the artists you manage — name, biography, background, works and their metadata, documents, contacts attached to an artist space. This data relates to third parties: as a Studio client, you warrant that you hold the necessary authorisations and take responsibility for informing the artists concerned (ToSale §10). These artists have no account on the Service and receive no communication from it.
  • Payment: no banking data is processed by Viewroom directly. Payments and billing are delegated to Stripe, through its Managed Payments service (the "Link" brand; seller of record / Merchant of Record: Sold through Link, LLC, United States), for Viewroom's paid subscriptions (Artist and Studio). Stripe applies PCI-DSS standards and collects/remits the applicable taxes (VAT in Europe, sales tax in the United States) on behalf of the publisher.

Viewroom does not reuse any contact value, cell, note, filename, prompt or model output for advertising, direct marketing, profiling, dataset creation, benchmarking, model improvement or AI training. Such content is used solely to perform the requested import.

2.2 Data collected automatically

  • Technical logs (IP address, browser type, request timestamps) — kept only for as long as strictly necessary for service security and debugging (30 days maximum).
  • Cookies — see section 6.

Viewroom uses PostHog for two separate processing activities:

  • browser product analytics, disabled until you accept "Analytics". Without consent, no ph_* cookie, user event or session recording is triggered. Withdrawal clears local identifiers and stops new events;
  • operational import counters, sent server-side under Viewroom's legitimate interest in reliability, security and cost control. They use a constant identifier without a user profile and contain no filename, cell, prompt, output or contact value. They place no cookie on your device.

PostHog traffic may pass through a managed reverse proxy operated by Cloudflare at metrics.viewroom.art. This proxy does not receive the import file or contacts; for operational counters, the request originates from the Viewroom server rather than the User's browser.

Viewroom also uses Sentry for technical error monitoring under its legitimate interest in service security. Default PII collection is disabled (sendDefaultPii: false), import-interface interactions are excluded and no import content should be attached. Error codes, technical stacks and minimized request metadata may nevertheless be processed.

No advertising tool, no social pixel (Google Analytics, Facebook Pixel, TikTok, LinkedIn Insight, etc.), no re-targeting is used on Viewroom.


3. Purposes and legal basis

Purpose Legal basis
Provide the service (hosting, display, sharing of your works) Performance of the contract (ToS / ToSale)
Analyze and import a contacts file at your request Performance of the contract (user-requested feature)
Measure import reliability, duration and cost with counters that have no user profile Legitimate interest in maintaining and securing the service
Account management and authentication Performance of the contract
Billing and management of paid subscriptions (Artist and Studio) Performance of the contract + legal obligation (accounting)
Hosting and management of a Studio client's artist spaces (managed artists' data) Performance of the contract — processing carried out as processor, on behalf of the Studio client acting as controller
Operational communication (confirmations, invoices, technical incidents) Performance of the contract
Product communication (new features, newsletter) Consent — one-click unsubscribe
Improvement of the service via anonymized statistics Legitimate interest
Service security, abuse prevention Legitimate interest + legal obligation

4. Retention period

  • Active account data: as long as the account is active.
  • Source file and temporary import artifacts: the parsed workbook, temporary cells, comprehension results, column mappings and preview are deleted after confirmation or cancellation and expire no later than 24 hours after upload finalization. An unfinalized upload expires after 10 minutes, and retrying does not extend the 24-hour period.
  • Technical import receipt: 30 days after confirmation. It only contains technical identifiers, versions, counts, statuses and timestamps, with no filename, cell, Contact field, prompt or model response.
  • Import technical traces: 30 days maximum. They are limited to versions, phases, counts, durations, tokens, costs and error codes; prompts, responses, filenames and cells are disabled at source.
  • After account deletion: effective deletion within 30 days, backups purged within 90 days at most.
  • Managed artists' data (Studio subscription): it follows the Studio account that administers it — retained as long as that account exists (including after the subscription has ended, the spaces then being frozen), deleted with it within the time limits above.
  • Billing data: 10 years (accounting obligation — Article L. 123-22 of the French Commercial Code).
  • Technical logs: 30 days.
  • Marketing / newsletter contacts: until unsubscribe, with annual purge of inactive accounts.

5. Your rights (GDPR)

In accordance with the General Data Protection Regulation (GDPR) and the French Data Protection Act, you have the following rights:

  • Access to your personal data;
  • Rectification of inaccurate or incomplete data;
  • Erasure ("right to be forgotten");
  • Restriction of processing;
  • Portability — full export of your catalogue (images + metadata) at any time;
  • Objection to processing based on legitimate interest;
  • Withdrawal of consent for processing that depends on it (newsletter, etc.).

To exercise these rights, write to contact@viewroom.art. A response is provided within 30 days.

Managed artists (Studio subscription): if your data was entered on the Service by a Studio client who manages your work, that client is the controller: your requests must be addressed to them. If you contact Viewroom directly, your request is forwarded to the Studio client concerned.

You may also lodge a complaint with the CNIL (French Data Protection Authority) — www.cnil.fr.

If your data appears in a Viewroom User's contact book, that User is your main contact when the User determines the contact book's purpose. Viewroom assists the User with requests relating to data processed on the User's behalf. You may also write to the address above: the request will be routed to the relevant account without requiring the source file or an unredacted screenshot.


6. Cookies

Without analytics consent, Viewroom uses only cookies strictly necessary for the operation of the service:

  • Session cookie — keeps you authenticated. Duration: session or 30 days if you tick "remember me".
  • Preference cookie — stores your display preferences (light/dark mode, language). Duration: 12 months.
  • CSRF security cookie — protects against cross-site request forgery attacks. Duration: session.

If you accept "Analytics", PostHog may place a first-party ph_* identifier for up to 13 months. It is not used for advertising and is cleared when consent is withdrawn. The server-side operational counters described above place no cookie. The Cookie Policy provides the full list and lets you change your choices.


7. Sub-processors and data transfers

Viewroom relies on the following sub-processors to deliver the service. Where processing takes place outside the European Economic Area, the applicable mechanism may be an adequacy decision or Standard Contractual Clauses with the required safeguards. Effective entities, locations and mechanisms are verified for each provider.

Sub-processor Role Data location
Vercel Inc. Site hosting, application execution and workflow; the import event log receives only opaque identifiers, states, indexes, timestamps and counters United States (global edge network, no persistence of user data on edge nodes); execution region depends on project configuration
Amazon Web Services EMEA SARL (Amazon Bedrock) AI-assisted analysis of contacts file structure, only when the user starts an import European Union geographic inference profile; processing may occur in the profile's European AWS Regions
Supabase, Inc. Database (catalogue, accounts, metadata, confirmed contacts and technical receipt without contact content) European Union — Frankfurt, Germany
Cloudflare R2 Storage of work images and private temporary storage of the source file and import artifacts European Union
Cloudflare, Inc. Managed reverse proxy for PostHog traffic (metrics.viewroom.art) — product analytics on consent only United States (under SCC)
Sold through Link, LLC (Stripe Managed Payments) Payments, billing, collection of applicable taxes — VAT or sales tax (Merchant of Record) United States
Resend Transactional emails (confirmations, invoices, notifications) United States
PostHog Consent-based product analytics and operational import counters without a user profile European Union
Sentry Error codes, technical stacks and minimized context; default PII disabled United States (under SCC)
Langfuse / ClickHouse Technical metadata per AI call; input and output recording disabled European Union (Langfuse Cloud, EU region)

8. Security

Viewroom applies the following measures:

  • Encryption of communications (HTTPS across the entire service).
  • Password hashing (modern algorithm such as bcrypt / argon2).
  • Encryption of backups at rest.
  • Access to data limited to what is strictly necessary — logged.
  • Regular backups, restoration procedure tested.

In the event of a data breach likely to entail a risk to your rights and freedoms, a notification will be sent to you as soon as possible, in accordance with Articles 33 and 34 of the GDPR.


9. Minors

Viewroom is not intended for persons under the age of 16. No account may be created by a minor without the consent of their legal representatives.


10. Changes

This policy may be updated. Any substantial change is subject to email notification to active users, at least 30 days before its entry into force.


11. Contact

For any question relating to this policy or your data:

  • Email: contact@viewroom.art
  • Mail: Florian Zumbrunn — 49 rue Eugène Berthoud, 93400 Saint-Ouen-sur-Seine, France