Privacy Policy
Last updated: March 2, 2026
1. Data Controller
SchemaGenAI is a product owned and operated by UpveoWorks.
Company Information:
Company Name: UpveoWorks
Product: SchemaGenAI
Contact Email: [email protected]
Website: upveoworks.com
UpveoWorks is the data controller responsible for the processing of your personal data collected through SchemaGenAI.
2. What Data We Collect
Contact Form Data:
- Full name
- Email address
- Subject of inquiry
- Message content
- Submission timestamp
- Source product (SchemaGenAI)
Account Data (for registered users):
- Email address
- Name
- Profile picture (if provided via OAuth)
- Subscription and billing information
- Usage data and project information
Technical Data:
- IP address
- Browser type and version
- Device information
- Cookies and similar technologies
3. How We Use Your Data
We process your personal data for the following purposes:
- Contact Inquiries: To respond to your questions, support requests, and feedback
- Service Provision: To provide and maintain SchemaGenAI services
- Account Management: To manage your account and subscription
- Payment Processing: To process transactions and prevent fraud
- Product Improvement: To analyze usage and improve our services
- Legal Compliance: To comply with legal obligations and protect our rights
- Marketing: With your consent, to send product updates and promotional materials
4. Legal Basis for Processing (GDPR)
- Consent: When you submit the contact form or sign up for marketing communications
- Contract Performance: To provide services you've subscribed to
- Legitimate Interest: To improve our services and ensure security
- Legal Obligation: To comply with applicable laws and regulations
5. Data Retention
We retain your personal data only as long as necessary:
- Contact Form Submissions: 2 years from submission date
- Account Data: Duration of your account plus 1 year after deletion
- Billing Records: 7 years (legal requirement)
- Technical Logs: 90 days
6. Data Sharing and Third Parties
We may share your data with trusted third-party service providers who assist us in operating our platform:
- Payment Processors: For secure payment processing and subscription management
- Cloud Service Providers: For data storage, hosting infrastructure, and computing services
- AI Service Providers: For automated schema generation and content processing
- Email Service Providers: For transactional and notification emails
- Security Service Providers: For spam prevention, bot detection, and platform security
- Legal Requirements: When required by law or to protect our rights
All third-party providers are carefully selected and contractually obligated to protect your data in compliance with applicable privacy laws. We do not sell your personal data to third parties.
7. Your Rights (GDPR & KVKK)
You have the following rights regarding your personal data:
- Right to Access: Request a copy of your personal data
- Right to Rectification: Correct inaccurate or incomplete data
- Right to Erasure: Request deletion of your data ("right to be forgotten")
- Right to Restriction: Limit how we use your data
- Right to Portability: Receive your data in a structured format
- Right to Object: Object to certain data processing activities
- Right to Withdraw Consent: Withdraw consent at any time
- Right to Lodge a Complaint: File a complaint with your local data protection authority
To exercise any of these rights, contact us at [email protected]
8. Data Security
We implement appropriate technical and organizational measures to protect your personal data, including:
- Industry-standard encryption for data transmission and storage
- Multi-layer access controls and authentication systems
- Regular security monitoring and vulnerability assessments
- Secure backup and disaster recovery procedures
- Staff training on data protection and security best practices
While we strive to protect your personal data, no method of transmission or storage is 100% secure. We continuously update our security measures to maintain the highest level of protection.
9. International Data Transfers
Your data may be transferred to and processed in countries outside the European Economic Area (EEA). We ensure appropriate safeguards are in place, including:
- Standard Contractual Clauses (SCCs) approved by the European Commission
- Adequacy decisions by relevant authorities
- Provider compliance with GDPR requirements
10. Cookies and Tracking
We use cookies and similar technologies for:
- Essential Cookies: Authentication and security (required)
- Functional Cookies: Remember your preferences and settings
- Analytics Cookies: Understand how you use our service and improve performance
- Security Cookies: Spam prevention and bot detection
You can control cookies through your browser settings or manage your preferences in our Cookie Policy page.
11. Children's Privacy
SchemaGenAI is not intended for children under 16 years of age. We do not knowingly collect personal data from children. If you believe we have collected data from a child, please contact us immediately.
12. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of significant changes by:
- Posting the updated policy on this page
- Updating the "Last updated" date
- Sending an email notification (for material changes)
13. Contact Us
For any questions about this Privacy Policy or our data practices, contact us: