Skip to main content

Privacy Policy

Last Updated: August 6, 2026

Introduction

Flart Studio respects the privacy of visitors to flart.studio, customers who use our software, and people who communicate with us.

This Privacy Policy explains what personal information we process, why we process it, who may receive it, how long we retain it, and the rights available to you. It should be read together with our Terms of Service, Software License, and Refund Policy.

We do not sell personal information or use it for behavioral advertising or cross-site tracking.

Data Controller and Contact

The data controller is Anatoliy Kulbabskyy, operating as Flart Studio ("Flart Studio", "we", "us", or "our").

For privacy questions or to exercise your data-protection rights, contact privacy@flart.studio.

Information We Process

Depending on how you use our Services, we may process the following categories of personal information:

  • Account information: name, email address, username, authentication information, account status, and preferences.
  • Subscription and transaction information: products, subscriptions, licenses, entitlements, transaction references, and related business records.
  • Software delivery information: requested products and versions, download and update activity, delivery status, IP address, technical request information, and identifiers needed to provide and protect software delivery.
  • Communications: support requests, privacy requests, feedback, comments, attachments, and related correspondence.
  • Website and security information: IP address, browser and device information, requested pages, timestamps, session information, and security or abuse-prevention signals.
  • Installation diagnostics: installation or lifecycle identifiers, domain or hostname, product and platform information, software and environment versions, lifecycle activity, request IP address, and related delivery or entitlement context where available.

Installation Diagnostics

Commercial Software packages that include installation diagnostics automatically send a limited report when the Software is installed, updated, or an uninstall is requested. Installation diagnostics do not include account passwords or payment credentials.

Checkout Information

Checkout billing and payment information is provided directly to the third-party Merchant of Record described below. Flart Studio receives only the transaction, product, account, subscription, and entitlement information needed to provide the purchased Software and Services and maintain required business records.

Sources of Information

We obtain information directly from you, from your use of the Website and Services, from installed Flart Studio Software, and from service providers involved in checkout, delivery, security, and communications.

How We Use Information

We process personal information to:

  • provide and manage accounts, subscriptions, licenses, Software delivery, updates, and support;
  • process transactions and maintain business records;
  • authorize access under applicable subscription and license terms;
  • communicate about accounts, purchases, support, security, and requested Services;
  • maintain compatibility and installation diagnostics;
  • protect the Services, users, Software distribution, and infrastructure;
  • prevent and investigate fraud, abuse, unauthorized distribution, and security incidents;
  • enforce our agreements and establish, exercise, or defend legal claims;
  • comply with applicable law; and
  • improve the reliability, compatibility, and usability of our Services.

Legal Bases for Processing

Where the GDPR, UK GDPR, or comparable law applies, we rely on the following legal bases:

  • Performance of a contract or steps taken at your request: accounts, subscriptions, licenses, delivery, updates, support, and other requested Services.
  • Legal obligations: accounting, tax, regulatory, and other records or processing required by law.
  • Legitimate interests: operating and protecting the Services, customers, and business; service security; fraud and abuse prevention; installation diagnostics; compatibility analysis; Software attribution; enforcement of agreements; and the establishment, exercise, or defence of legal claims.
  • Consent: optional marketing communications or other processing where consent is required.

You may object to processing based on legitimate interests. We will assess the objection according to applicable law. Consent may be withdrawn at any time without affecting processing already performed or processing based on another lawful basis.

Required Information and Automated Processing

Some information is required to create an Account, complete a transaction, provide a download or update, respond to a request, or protect the Services. If required information is not provided, the relevant feature or Service may be unavailable.

We may automate routine Account, delivery, and security checks. We do not use profiling or solely automated decision-making that produces legal or similarly significant effects within the meaning of Article 22 GDPR.

Sharing of Information

We may disclose personal information to the following categories of recipients where necessary for the purposes described in this Policy:

  • hosting, content-delivery, security, communications, support, and other operational service providers;
  • checkout, payment, tax, fraud-prevention, and Merchant-of-Record providers;
  • professional advisers and parties involved in legal claims;
  • public authorities where disclosure is required by law;
  • parties involved in a merger, acquisition, reorganization, or transfer of the business; and
  • another recipient where you have authorized the disclosure.

Service providers acting on our behalf are permitted to process information only for the relevant service and are subject to applicable contractual and data-protection obligations. Some recipients independently determine how they process information within their own service boundary.

We do not sell, rent, or trade personal information.

International Data Transfers

Some service providers may process information outside your country or outside the European Economic Area. Where applicable law requires safeguards for an international transfer, we rely on a recognized mechanism such as an adequacy decision, Standard Contractual Clauses, an applicable Data Privacy Framework, or another lawful transfer mechanism.

Information about applicable transfer safeguards may be requested at privacy@flart.studio.

Data Retention

We retain personal information only for as long as necessary for the purposes described in this Policy, applicable legal obligations, dispute resolution, security, and legal claims. Our current retention periods are:

  • Account information: while the Account exists and up to 3 years after deletion, unless a longer legal period applies to particular records.
  • Subscription, transaction, and entitlement records: for the active relationship and applicable accounting, tax, limitation, and legal-claim periods.
  • Software delivery and attribution records: while needed to provide or protect the relevant artifact, then up to 24 months after the last relevant build or delivery, unless subject to a documented legal hold.
  • Download and update records: up to 18 months.
  • Installation and environment diagnostics: up to 18 months after the last relevant observation or lifecycle event.
  • Technical and security logs: normally from 30 days to 12 months, depending on their purpose and operational rotation.
  • Support and privacy correspondence: up to 5 years, or longer where required for an active dispute or legal claim.
  • Fraud, abuse, security, and legal-case evidence: for as long as reasonably necessary for the case, applicable limitation periods, or a legal hold.

Independent service providers apply their own retention periods within their service boundaries. When our retention period expires, we delete or irreversibly anonymize the applicable information unless continued retention is required by law or for a documented legal claim.

Cookies and Similar Technologies

We use cookies and similar technologies necessary for authentication, security, requested functionality, and user preferences. Third-party functional services may use their own technologies when they are displayed or requested.

We do not use advertising cookies, cross-site advertising trackers, or behavioral advertising profiles. If we introduce optional technology that requires consent, we will request the required choice before activating it for the affected user.

You can remove or block cookies using your browser. Blocking necessary cookies may prevent login, account, security, or other requested functionality from working.

Third-Party Services

We use third-party services only where needed to provide, protect, or support the Services:

  • PayPro Global operates the hosted checkout as Merchant of Record and processes payment, billing, tax, refund, and related checkout information under its own privacy terms.
  • hCaptcha may be used on selected forms to prevent automated abuse.
  • YouTube and Vimeo may process technical information when you choose to play a video hosted by them.

Provider privacy information:

Data Security

We use appropriate technical and organizational measures designed to protect personal information against unauthorized access, loss, misuse, alteration, or disclosure. No method of transmission or storage can guarantee absolute security. You are responsible for protecting your Account Credentials and notifying us if you suspect unauthorized access.

Your Rights

Depending on the law that applies to you, you may have the right to:

  • request access to personal information we hold about you;
  • correct inaccurate or incomplete information;
  • request deletion where continued processing is not required;
  • restrict processing in applicable circumstances;
  • receive portable data where the portability right applies;
  • object to processing based on legitimate interests;
  • withdraw consent for optional processing; and
  • lodge a complaint with an applicable data-protection authority.

To exercise a right, contact privacy@flart.studio. We may request information reasonably necessary to verify your identity and locate the relevant records. We will respond without undue delay and normally within one month, subject to any extension permitted by applicable law.

Public Information and Third-Party Links

Information you voluntarily publish in comments, public support discussions, or other public areas can be seen and reused by others. Avoid posting confidential information in public areas.

Our Website may link to third-party websites. Following a link takes you to that provider, whose privacy policy then applies. We are not responsible for the independent privacy practices of third-party websites.

Email Communications

We send transactional messages necessary for Accounts and requested Services. We send marketing emails only where permitted and, where required, with consent. You can unsubscribe from marketing using the link in the message or by contacting us.

Children's Privacy

Our Services are intended for adults and business or technical users and are not directed to children. If you believe a child has provided personal information improperly, contact privacy@flart.studio.

Changes to This Policy

We may update this Policy when our Services, processing, or legal obligations change. We will revise the "Last Updated" date and provide additional notice where required. Where a new purpose requires consent, we will request it before beginning that processing.