1. Who is responsible
The data controller for Oveloa account, billing, security and service-administration data is Chakker Digital (Mohamed Chakker), Norwegian organization number 938491275, reachable at privacy@oveloa.com, +47 47 21 81 57 and Grønnegata 78-88, 9008 Tromsø, Norway.
2. Controller and processor roles
Oveloa decides why and how account administration, billing, platform security, support and product operations data is processed, so Oveloa is the controller for those activities.
For business customers that upload property-production content containing personal data and instruct Oveloa to generate, review, store or deliver it, the customer normally remains the controller and Oveloa acts as processor. The Data Processing Terms govern that processing. The real roles depend on the facts and cannot be changed merely by naming them in a contract.
3. Data Oveloa processes
- Account data: email address, account identifier, authentication/session records and plan status.
- Property-production data: uploaded photographs, optional floor plans, room labels, chosen order, generated prompts, model settings, videos and project metadata.
- Collaboration data: Agency invitations, roles, activity, review-link recipients, reviewer names/emails, comments, timestamps and approval decisions.
- Billing data: Stripe customer/subscription/transaction identifiers, plan, invoice references, payment state, currency and summarized payout amounts. Oveloa does not store complete card details.
- Security and operations data: pseudonymous rate-limit identifiers, request metadata, generation status, provider usage, errors and support/privacy requests.
4. Where data comes from and what is required
Oveloa receives data directly from account holders, invited team members and reviewers; from Google when a user chooses Google sign-in; from Stripe for verified billing events; and from BytePlus for generation status and output. A business customer may also provide recipient information or property media concerning other people.
An email address and authentication data are required to create and secure an account. Billing details are required only for a paid plan. Property references and generation settings are required only when you ask Oveloa to create media. If required information is not provided, the related account, payment or generation function cannot be supplied.
5. Purposes and legal bases
Oveloa processes account, property-production, collaboration and subscription data as necessary to provide the service and perform its contract with you. Billing, tax and accounting records are processed to comply with legal obligations.
Security logs, fraud-prevention records, service diagnostics and limited operational analytics are processed for Oveloa's legitimate interests in protecting customers, preventing abuse, maintaining reliability and establishing or defending legal claims. Where consent is legally required, Oveloa will request it separately and you may withdraw it prospectively.
Oveloa does not currently include product analytics, advertising pixels or cross-site behavioral tracking in the application repository, and does not sell customer property media.
Oveloa does not make decisions based solely on automated processing that produce legal or similarly significant effects for users. Automated security and rate-limit checks may delay or block a request, but support can review account-impacting outcomes.
6. Processors and recipients
- Cloudflare: application hosting, edge execution, D1 structured records, R2 media storage and security controls.
- Supabase: account authentication and email-verification sessions.
- Google: optional Google sign-in selected by the user.
- Stripe: managed checkout, subscriptions, taxes, invoices, payment methods, refunds, fraud prevention and payment disputes.
- BytePlus ModelArk: supplied references and deterministic instructions needed to generate requested video output.
- Transactional email: Resend for account confirmation and password recovery.
Client-selected recipients also receive only the review or delivery information exposed by the scoped link the creator shares.
7. International data transfers
Some providers or support functions process data outside Norway or the EEA. Depending on the recipient and destination, Oveloa relies on an applicable adequacy decision, the European Commission's standard contractual clauses incorporated into a provider agreement, or another lawful transfer mechanism, together with supplementary safeguards where required. Contact the privacy address to request information about the safeguards relevant to your data.
BytePlus ModelArk generation is configured in the Asia-Pacific region. Property references and generation instructions are therefore transferred outside the EEA when you request a generation. BytePlus's published DPA incorporates controller-to-processor standard contractual clauses for restricted EEA transfers. Its terms also permit limited diagnostics, security and service-improvement processing. Oveloa does not use customer content to train its own model.
8. Retention and deletion
- Ordinary uploaded references: approximately 1 days.
- Accepted-generation source references used for revision: approximately 3 months.
- Generated MP4 files: approximately 7 days; history metadata may remain after the file expires.
- Review links expire on the creator’s selected schedule and may be revoked earlier.
- Account, billing, fraud-prevention and support records remain only as long as needed for service, legal, accounting, security or dispute purposes.
Use the support page to request media deletion, account deletion, access or correction. Deletion is verified before execution and may exclude records that must lawfully be retained.
9. Essential cookies and browser storage
Oveloa currently uses essential Supabase session cookies, a scoped review-access cookie when a protected recipient link is unlocked, and Stripe's checkout/payment storage when billing is opened. These are used for requested authentication, security and payment functions.
The browser stores harmless studio draft state, recent/pending generation identifiers and temporary account-navigation data locally. It does not store provider credentials or payment-card data.
No non-essential analytics or advertising tracker is currently installed, so Oveloa does not display a cosmetic consent banner. This assessment must be repeated before adding analytics, marketing pixels or session-replay tools.
10. Your privacy rights
Depending on applicable law, you may request access, correction, deletion, restriction, portability or objection, and may withdraw consent where consent is the legal basis. Requests can be opened from Support & data requests. Oveloa may verify identity before disclosing or deleting account information.
You may complain to Datatilsynet in Norway or another competent supervisory authority.
11. Security practices
Oveloa keeps provider credentials server-side, validates file content, restricts files and sizes, uses scoped signed URLs, server authorization, rate limits, idempotent billing/generation records, expiring review links and payment-webhook signature verification. No internet service can guarantee absolute security.
Report a suspected security issue privately to security@oveloa.com; do not include API keys, passwords or customer media in the first message.
12. Questions and changes
Privacy contact: privacy@oveloa.com. Material changes will be communicated as required before they take effect.