Privacy Policy
Version 2026-08-31 · in effect from 31 August 2026. Previous versions are listed at the end of this page.
This notice explains how Two Black Dogs B.V. ("we", "us", or "our") collects, uses, shares and protects personal data – both on this website and on the (IM)PERMANENT platform you sign in to. It is written to satisfy Articles 13 and 14 of the General Data Protection Regulation.
It replaces a notice dated January 2025 that described the contact form only. That notice stated that we did not transfer data to third parties and that we did not carry out profiling. Neither statement was correct, and both are corrected below.
1. Data Controller
The data controller responsible for your personal data is:
Two Black Dogs B.V.Sleutelstraat 15
2000 Antwerp
Belgium
For privacy-related inquiries, please contact us at: legal@im-permanent.com. We have not appointed a data protection officer.
2. What This Notice Covers
This notice covers two things:
- This website – the public marketing site, including its contact form.
- The (IM)PERMANENT platform – the signed-in application, the admin portal and the pipeline portal, including the archive records, imagery, 3D capture processing and recommendations they provide.
Your use of the platform is also governed by our Terms of Service.
3. What Data We Collect
If you use the contact form on this website:
- Name
- Email address
- Company or role (optional)
- Your message content
- A record that you gave consent, which version of this notice you were shown, and when. That record stores a one-way hash of your email address rather than the address itself.
If you hold a platform account:
- Email address, password (stored only as a hash), display name, avatar URL, locale, last-seen time, session and refresh tokens, role grants, and your organisation memberships.
- The archive records, items, boards, notes, tags and shares you create, and the files you upload. Uploaded images keep their EXIF metadata, which can include GPS coordinates, capture times and camera serial numbers. We do not currently strip it.
- Full-resolution capture imagery submitted for 3D reconstruction, and the job records describing that processing.
- Behavioural events – which items you view and open, which you favourite, which boards you add them to, which recommendations you click, and the text of the searches you run. Each event is stored against your account with a timestamp.
- The recommendation rows we compute from those events, with the score and the reason for each.
Whenever anyone uses either surface:
- Operational logs. Our application log records a pseudonymous account identifier, the request path and the outcome – never your IP address, email, request body or headers. Our load balancer, CDN and network logs do record IP addresses, and content-security-policy reports record the referring page and browser user agent.
4. Why We Process It, and On What Legal Basis
- Running your account – registration, approval, authentication, organisation membership, password reset and email change. Basis: performance of a contract, Art. 6(1)(b).
- Providing the archive – creating, curating, illustrating and sharing records, items, boards and notes, and storing the files you upload. Basis: performance of a contract, Art. 6(1)(b).
- 3D capture processing – turning capture sets into Gaussian splat reconstructions and derived assets. Basis: Art. 6(1)(b).
- Automated classification of imagery and search queries – classifying garments, generating similarity embeddings, removing backgrounds and objects, and interpreting what you typed into search. Basis: Art. 6(1)(b).
- Personalised recommendations – recording behavioural events and computing recommendations from them. Basis: our legitimate interests, Art. 6(1)(f) – specifically, making a large reference archive navigable so that the people who pay for it can find relevant pieces. We consider this a limited intrusion: the data is behaviour inside a professional research tool, it is never used to make any decision about you, it is never sold or shared for anyone else's purposes, and you can object at any time and we will stop – see section 10.
- Responding to your enquiry when you use the contact form on this website. Basis: your consent, Art. 6(1)(a), given by ticking the box on the form. Keeping the record that you consented is itself based on our legal obligation under Art. 7(1) to be able to demonstrate it.
- Operating, securing and administering the service – admin actions, fault diagnosis, abuse detection and the operational logs above. Basis: our legitimate interests, Art. 6(1)(f) in running a service that works and is not abused.
Where we rely on legitimate interests you may object under Art. 21 – see section 10. Where we rely on consent you may withdraw it at any time – see section 11.
5. Who Receives Your Data
We do not sell your personal data and we do not share it for anyone else's marketing. We do use service providers, and they receive personal data in order to provide those services. This is the complete list:
- Amazon Web Services – hosting, databases, file storage, search, logging and the email we send you about your account. Everything at rest sits in the Paris region (eu-west-3); the content-delivery network, the TLS certificate service and the current contact-form handler run in the United States.
- Amazon Bedrock (an AWS service) – four models. Claude Haiku 4.5 interprets your search queries; Claude Sonnet 4.6 and Titan Multimodal Embeddings analyse garment imagery; Titan Image Generator v2 performs object removal and in-painting on imagery.
- Thunder Compute (United States) – GPU instances that receive the full-resolution capture images for a reconstruction job.
- Resend (United States) – delivers contact-form submissions to us by email. It receives your name, email address, role and full message.
- Automattic / Gravatar (United States) – supplies profile avatars. It receives an MD5 hash of your email address, plus your IP address and the referring page, each time an avatar is displayed.
- Have I Been Pwned, via Cloudflare – when you set a password we send the first five characters of its SHA-1 hash to check it against known breaches. The password itself never leaves our systems.
- Google Workspace (United States) – hosts our mailboxes, so it receives any email you send us, including messages to legal@im-permanent.com.
- DuckDuckGo (United States) – when our system researches a garment in the archive it sends that garment's description to DuckDuckGo's image search to find reference pictures. The search terms are derived from the garment record, not from anything you typed and not from your account, so this is listed for completeness rather than because it receives data about you.
- Hugging Face – listed for completeness. We download machine learning model weights from it. It receives no data about you.
We may also disclose personal data where we are legally required to do so.
6. Transfers Outside the EU
Our databases and file storage are in the European Union and are not replicated outside it. Several of the recipients above are not, and these transfers are real:
- Resend – United States. It receives every contact-form submission.
- The contact-form handler itself – currently a server in the US East region, which processes and logs your submission before Resend receives it. We are moving this into the EU.
- Thunder Compute – the GPU provider does not tell us, and we cannot specify, which country a given instance runs in.
- Titan Image Generator v2 – US East. The model is not offered in our EU region, so imagery sent for object removal is processed in the United States.
- Gravatar – United States, on every avatar render.
- Google Workspace – United States, for email you send us.
- Content-delivery network access logs – US East. They record viewer IP address, URL and user agent.
- Have I Been Pwned – served from Cloudflare's global edge.
We do not currently have standard contractual clauses, an adequacy decision or a transfer impact assessment in place for these transfers. We are stating that plainly rather than implying a safeguard that does not exist. It is being worked on, and this section will be updated when it changes.
7. How Long We Keep It
We would rather tell you what actually happens than publish a retention schedule we do not enforce.
- Behavioural events – deleted after 90 days. This happens as part of an hourly maintenance job rather than as a separate scheduled task.
- Your account, content and uploaded files – kept until you delete them, or until you delete your account. No other time limit is currently defined.
- Recommendations – kept until they are recomputed, until you object, or until your account is deleted.
- Capture imagery and reconstruction job records – no time limit is currently defined.
- Contact-form messages – they live in our mailbox and with our email provider, neither of which is on a deletion schedule. The consent record we keep alongside them holds only a one-way hash of your email address, the date and the notice version, and is retained as evidence that consent was given.
- Operational logs – between 30 and 90 days depending on the log. Some database-level log groups currently have no expiry.
Establishing enforced retention periods for the entries above that have none is outstanding work, and we will update this section when they exist.
8. Automated Decision-Making and Profiling
We do carry out profiling, within the meaning of Art. 4(4), and the previous version of this notice was wrong to say otherwise.
For signed-in users we build a preference profile from your own behaviour – items you viewed, opened, searched for, favourited and added to boards – weight those signals, score the rest of the catalogue for similarity against them, and show you the highest-scoring items as recommendations. The score and the reason behind each recommendation are included if you ask us for a copy of your data.
We do not make any decision about you by automated means that produces legal effects or similarly significantly affects you, within the meaning of Art. 22. Accounts are approved by a person, not automatically. Nothing about your access, pricing or standing is decided by a model.
Automated classification is also applied to imagery – identifying garment attributes, generating similarity embeddings, removing backgrounds. That is applied to pictures of objects, not to people, and produces no decision about you.
9. Cookies and Similar Technologies
This website sets no cookies at all. It runs no analytics service, no advertising or tracking pixel, no session recording and no consent-management platform. We self-host our fonts so that loading a page does not call out to a font provider either.
The signed-in application sets one cookie, sidebar_state, which remembers for seven days whether you collapsed the navigation sidebar. It is strictly necessary to provide the interface you asked for and carries no identifier. Your session and refresh tokens are held in your browser's local storage, not in a cookie.
The behavioural events described in this notice are not collected by cookies or by any tracking technology in your browser. They are records the application writes on our own servers while you use it, on the basis of our legitimate interests under Art. 6(1)(f), which is why the control over them is an objection (section 10) and not a cookie banner.
10. Your Rights
Under the GDPR you have the following rights over your personal data:
- Access (Art. 15) and portability (Art. 20) – you can request a copy of the data we hold about you in a machine-readable format. If you have an account you can do this yourself: open your profile and use Download my data.
- Rectification (Art. 16) – you can correct inaccurate data, from your profile or by writing to us.
- Erasure (Art. 17) – you can delete your account and the personal data attached to it. Open your profile and use Delete my account, or write to us. A small number of records survive deliberately and we will tell you which: a log recording that the deletion happened (holding a one-way hash of your email address and row counts, no contents), and any copyright or IP attestation you signed, which we retain under Art. 17(3).
- Restriction (Art. 18) – you can ask us to limit how we process your data while a dispute is resolved.
- Objection (Art. 21) – where we rely on legitimate interests you can object. For recommendations this is a switch, not a request: open your profile and turn off Personalised recommendations. From that moment we stop recording behavioural events for you, and we delete the events and the recommendations we already hold for you. The objection is enforced on our servers, so it applies even to activity your browser had not yet sent us. If you turn it back on later, we start recording again from that point; we do not reconstruct the gap.
- Withdrawal of consent (Art. 7(3)) – see section 11.
- Complaint (Art. 77) – see section 12.
To exercise any right that is not a control in the app, write to legal@im-permanent.com. We will respond within one month.
11. Withdrawing Consent
Where we process your data on the basis of consent – today, that is the contact form on this website – you may withdraw it at any time by writing to legal@im-permanent.com. Withdrawing consent does not affect the lawfulness of processing carried out before the withdrawal. We will keep the record that consent was given and withdrawn, because Art. 7(1) requires us to be able to demonstrate it.
12. Right to Lodge a Complaint
If you believe your data protection rights have been infringed, you may complain to a supervisory authority. In Belgium this is:
Belgian Data Protection Authority(Gegevensbeschermingsautoriteit / Autorité de protection des données)
Drukpersstraat 35
1000 Brussels
Belgium
www.dataprotectionauthority.be
13. Changes to This Notice
We update this notice when what we do with personal data changes. Every version carries a version number and an effective date, and the consent we record when you use the contact form stores the version you were shown – so it stays possible to say what this page said at the moment you agreed to it.
- Version 2026-08-31 – 31 August 2026
- Complete rewrite. The notice now covers the signed-in platform as well as this website — accounts, uploaded imagery, 3D capture processing, behavioural events and recommendations — names every recipient and every transfer outside the EU, records a legal basis for each activity, and describes the objection control in the app. It corrects two statements in the previous notice that were untrue: that no data was transferred to third parties, and that no profiling took place.
- Version 2025-01 – January 2025
- The first notice. It covered the marketing contact form only, and stated that no data was shared with third parties and that no profiling took place. Both statements were incorrect: contact submissions were delivered through an email provider in the United States, and the signed-in platform computed recommendations from behavioural events. No copy of that notice was archived, so this entry describes it rather than reproducing it.