Privacy Policy & Data Protection Charter
Last Updated: September 2026 | Fully Compliant with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018 (DPA 2018).
1. Our Fundamental Commitment: Zero Biometric Data Retention
At Russella, we believe that sensitive biometric information should never leave the physical device of the user. Unlike cloud-based photo analysis services that transmit your face to remote servers for processing, storage, and training, Russella’s AuraFace AI operates exclusively client-side.
When you utilize our facial harmony tools, your images are executed within your local device’s memory using compiled WebAssembly (WASM) and WebGPU models. No raw photographs, facial vectors, or biometric templates are ever uploaded to, transmitted across, or stored upon Russella’s web servers. Discover the engineering architecture behind this privacy model on our About Us page.
2. What Data We Process and Where It Lives
| Category of Data | Storage Location | Retention Duration | Transmitted to Russella Servers? |
|---|---|---|---|
| User Uploaded Photographs | Local Device RAM only | Volatile; wiped upon tab close or page reload | NEVER (0% transmission) |
| Facial Coordinates (68/468 mesh) | Local Device Canvas Memory | Volatile; deallocated instantly after ratio calculation | NEVER (0% transmission) |
| Anonymous Technical Diagnostics | Server Access Logs | Maximum 30 days (for DDoS mitigation & security) | Only standard HTTP header info (IP, User-Agent) |
| Voluntary Contact Inquiries | Encrypted Mailbox | Retained until customer query resolution (max 12 mos) | Only details you submit via our Contact Us form |
3. Lawful Basis for Processing Under UK GDPR
Under Article 6 and Article 9 of the UK GDPR (Special Category Data relating to biometrics), we operate under the following lawful bases:
- Explicit Consent (Article 6(1)(a) & Article 9(2)(a)): By manually selecting an image or granting camera access, you provide unambiguous consent for your local browser sandbox to compute geometric points.
- Legitimate Interests (Article 6(1)(f)): Basic website telemetry and server firewall logging to defend against malicious traffic, security vulnerabilities, and network abuse.
- Contractual Necessity: Delivering customer support when you reach out directly to our team.
4. Cookies and Local Storage
Russella uses minimal, privacy-respecting cookies:
- Essential Cookies: Required for CSRF security protection, load balancing, and session maintenance.
- Analytical Cookies: Aggregated, privacy-friendly analytics with IP anonymization enabled by default. We never use third-party cross-site trackers or sell marketing behavioral data.
- Local Storage: Optional user preferences (such as light/dark mode toggles or saved metric histories) stored strictly in your browser’s localStorage that you can clear at any time.
5. Your Statutory Rights Under UK GDPR
As a data subject in the United Kingdom or European Economic Area, you possess comprehensive statutory rights:
- Right of Access & Portability: Request copies of any personal correspondence or account data we hold. (Note: Because we do not store facial images, we have zero biometric data to export).
- Right to Rectification & Erasure: Request the deletion of email exchanges or support tickets.
- Right to Object & Restrict Processing: Opt out of analytical cookies at any moment via browser settings.
- Right to Lodge a Complaint: You have the legal right to report concerns to the UK supervisory authority: the Information Commissioner’s Office (ICO) at ico.org.uk.
6. Related Legal Policies & Contacting our DPO
This Privacy Policy should be read in conjunction with our clinical and liability Disclaimer. For scientific methodologies and fact-checking standards, consult our Editorial Policy.
For any questions or formal Subject Access Requests (SARs), contact our Data Protection Officer:
Data Protection Officer (DPO)
Email: princexxxx698@gmail.com
Russella Ltd., 142 St. John Street, London, EC1V 4PW
Or message us directly via our Contact Us page.
