Spectral Lens™  ·  Privacy Policy

Privacy
Policy.

How we collect, use, store, protect and share your personal data.

This Privacy Policy explains how Spectral Lens™ Ltd collects, uses, stores, protects and shares personal data across our website, store, Client Portal, creative production services, project delivery platform, agreements, media, downloads and communications.

Last updated: 26 August 2026

1. About This Policy

This Privacy Policy explains how Spectral Lens Ltd collects, uses, shares, stores and protects personal data when people use the Spectral Lens™ website, store, Client Portal, Media Library, project delivery systems, Real Estate upload service, Digital Products, Physical Products, secure downloads, agreements, messages and related Services.

It also explains AI-assisted production, technical security monitoring, visual session recording, cloud backup, international processing and the rights available to individuals.

2. Who We Are

Spectral Lens Ltd is a company registered in England and Wales under company number 11056390. Registered office: 124 City Road, London, England, EC1V 2NX. ICO registration reference: ZB678254. Privacy questions and rights requests may be sent to info@spectrallens.com.

3. Scope and Applicable Law

This Policy applies to website visitors, prospective and current Clients, Client representatives, Portal users, customers, suppliers, contractors, contributors, models, performers, property owners or occupants, event attendees and other individuals whose personal data is processed in connection with our Services.

We process personal data in accordance with applicable UK data protection law, including the UK GDPR, Data Protection Act 2018 and Data (Use and Access) Act 2025 as applicable, together with the Privacy and Electronic Communications Regulations where relevant.

4. Our Data-Protection Role

Spectral Lens is normally the controller of personal data used for enquiries, accounts, orders, contracts, communications, payments, security, legal compliance, relationship management and our own portfolio or marketing activity.

Where a Business Customer supplies personal data and instructs us to process it solely on that customer's behalf for a project, the Business Customer may be the controller and Spectral Lens may act as processor. A separate data-processing agreement may apply where required.

Third-party technology providers may act as our processors, subprocessors, independent controllers or another legally recognised role depending on the service and purpose.

5. Personal Data We Collect

Depending on your interaction with us, we may collect identity and contact data; account and Client Portal data; enquiry, project and property information; Client Materials; generated and edited Project Materials; contributor information; transaction and commercial records; agreements, approvals and licence information; technical and security records; communications; and cookie or device-storage information.

Technical and security records may include IP addresses or privacy-preserving hashes, device and browser information, timestamps, authentication events, pages or Portal functions accessed, system responses, download activity, agreement activity, file names, file types, file sizes, dimensions, file hashes, error records, suspected misuse indicators and other security events.

6. How We Collect Personal Data

We collect personal data directly from you; from Clients, agencies, employers, property professionals, event organisers or other authorised persons; automatically through website, Portal, authentication, security, logging, cookies and similar technologies; from payment, delivery, communications, storage, production, AI, media-processing, analytics, security and support providers; and from public or professional sources where reasonably necessary for a legitimate business, rights-check, fraud-prevention or legal purpose.

7. Purposes and Lawful Bases

We use personal data only where we have a lawful basis. Depending on the activity this may include performance of a contract, steps requested before a contract, legitimate interests, legal obligation, consent or another lawful basis.

Our legitimate interests may include operating and improving a creative business, secure delivery, maintaining account and system security, preventing and investigating misuse, keeping audit and contractual records, protecting intellectual-property and legal rights, managing Client relationships and defending legal claims. We consider necessity, proportionality and the rights of affected individuals before relying on legitimate interests.

8. Public Website Visitors

For ordinary public website visitors we may process basic technical logs, security information, cookie choices, analytics where enabled, enquiry information, purchase or order information where relevant, and communications submitted to us. A public visitor is not subject to the full Client Portal activity-recording environment unless they access an authenticated Portal or another secured account area.

Where optional analytics, marketing or embedded-media technologies require consent, they are controlled through the available cookie or preference mechanism. Strictly necessary security, authentication and service technologies may operate without optional consent where the law permits.

9. Client Portal Accounts and Authorised Access

The Client Portal is a private service environment. Account and project permissions determine what a User can access. Portal users may see project records, media, invoices, agreements, messages, account information, membership or entitlement information, transaction or spending summaries and other information made available to their authorised account.

Authorised Spectral Lens administrators may have broader administrative access because they create, manage, support, secure and deliver these records and Services. Portal users should not expect that information held in a business Client workspace is private from the authorised administrator of that workspace.

10. Security Monitoring and Visual Session Recording

Because the Client Portal contains private Client information and controlled access to files and project records, Spectral Lens uses technical monitoring to protect accounts, systems and Client information. When a User accesses the Client Portal, security records may include authentication events, IP and device information, pages and Portal functions accessed, timestamps, navigation activity, clicks or pointer movements, system responses, downloads, agreement actions, errors and visual session-replay information that may allow an authorised administrator to reconstruct activity occurring within the Portal.

The current Portal session recording is visual activity recording and does not record keystrokes. Login credential fields are visually masked in the replay. The Portal does not display full payment-card credentials, and payment-card details are handled through an independent payment provider rather than recorded in Portal session replay.

We use these records for account and information security, preventing and detecting unauthorised or abnormal access, fraud and misuse prevention, investigating suspicious activity, diagnosing technical or authentication issues, supporting Users, maintaining appropriate audit records and protecting the confidentiality, integrity and availability of the Portal and Client information.

Spectral Lens does not use Portal session recordings for advertising, marketing analytics, employee monitoring, commercial behavioural profiling or assessment of Client performance.

11. AI-Assisted Security and Technical Analysis

Automated and AI-assisted tools may be used to organise, summarise or highlight unusual technical, authentication or security events for review by authorised Spectral Lens administrators. These tools are used as investigative and support assistance. They do not make legal or similarly significant decisions about Portal users without meaningful human involvement.

Where an automated summary identifies a potential issue, administrators may review the underlying technical records before taking material action.

12. Portal Agreements, Downloads and Activity Records

The Client Portal may record invitations, account access, project associations, messages, approvals, document views, agreement acceptance, electronic signatures, downloads, timestamps, plan or entitlement changes and security events. We use these records to provide the Service, establish what was agreed or delivered, protect accounts, resolve disputes, prevent misuse and maintain legal and business records.

13. Payments, Billing and Spending Information

Payment-card credentials are normally collected and processed by an authorised payment provider and are not stored or displayed in full within the Spectral Lens Client Portal. We may receive and display transaction references, payment status, invoice status, subscription or membership information, project spending, aggregate spending information, limited billing details, refunds and dispute information needed to operate the account and provide support.

Users manage payment credentials and payment methods through the relevant payment provider where applicable.

14. Project Media and Client-Supplied Personal Data

Clients may supply photographs, footage, audio, property images, names, contact information, brand assets or other material containing personal data about other people. The Client is responsible for ensuring it has the lawful basis, authority, notices, permissions and releases appropriate to the intended project and processing.

We may return, delete, restrict or refuse material that appears unlawful, excessive, unsafe or outside the agreed scope.

15. Artificial Intelligence and Creative Technology

We may use AI, machine learning, generative media and automated technology for image-to-video generation, image or video generation, animation, virtual staging, visual effects, object removal or replacement, retouching, enhancement, upscaling, transcription, audio processing, drafting, summarisation, content organisation, project administration, technical analysis, quality control and workflow support.

Depending on the project, Client Materials, reference images, footage, audio, prompts, instructions, project codes, metadata, generated variants and outputs may be transmitted to third-party technology providers. We seek to minimise unnecessary personal data and to use privacy, account and provider controls that are appropriate to the project.

Some providers may process information outside the United Kingdom and may retain eligible inputs or outputs for security, moderation, evaluation, model improvement or other purposes under their applicable terms. Where a Client requires a strict no-training, named-provider, local-only, UK-only, EU-only or enhanced-confidentiality workflow, that must be agreed before materials are supplied and may affect tools, fees, timing or availability.

16. Special-Category, Biometric and Highly Sensitive Data

Please do not upload or send health information, racial or ethnic origin, political opinions, religious or philosophical beliefs, trade-union membership, genetic data, biometric identifiers, sexual-life or sexual-orientation data, criminal-offence data, identification documents, financial credentials or similarly sensitive material unless it is genuinely required, lawful and expressly agreed in advance.

Photographs, footage and voice recordings are not automatically biometric data. They may become biometric data where specific technical processing is used to identify or authenticate a person. Face-reference, voice-cloning, identity-matching and similar processing require specific review where appropriate.

17. Children and Young People

Our general website and Client Portal are not directed at children creating their own accounts. Projects may involve children where arranged by a parent, guardian, school, organisation, brand or other authorised Client. Appropriate safeguarding, notices, releases and authority must be in place. Identifiable child material will not knowingly be submitted for generative AI processing unless the project has been specifically reviewed and appropriately authorised.

18. Cookies, Storage and Similar Technologies

We use strictly necessary technologies to operate the website and Portal, authenticate users, secure accounts, remember essential settings, process orders and provide requested features. Optional categories may include preferences, analytics, marketing and embedded media. We request consent where required and provide a way to change available choices.

Where storage or access technology is used for a purpose that is strictly necessary for security, authentication, fraud prevention or delivery of a service requested by the User, an applicable legal exception may mean optional consent is not required. Where consent is legally required for a particular technology or purpose, we will seek it.

19. Marketing and Service Communications

We send service communications needed for enquiries, projects, accounts, security, orders, deliveries, agreements and support. We may send relevant business-to-business updates where permitted by law and use consent where required for consumer electronic marketing. You may opt out of marketing at any time; this does not stop essential service or security communications.

20. Who We Share Data With

We do not sell personal data. We may share personal data and Project Materials where reasonably necessary with categories of recipients including application hosting and infrastructure providers; cloud storage, backup and disaster-recovery providers; content-delivery and media-processing providers; AI and generative-media providers; email, communications and authentication providers; security and technical-support providers; payment, invoicing and accounting providers; production partners and subcontractors; printing, fulfilment and courier providers; professional advisers, insurers and auditors; and regulators, courts, law-enforcement bodies or public authorities where lawful and necessary.

We do not generally publish the names of all operational providers in this Policy. We maintain appropriate internal records and provide further information where required by law or reasonably necessary to address a data-protection request.

21. International Processing and Transfers

Some application infrastructure, cloud storage, backup, disaster-recovery, AI, media-processing, communications and support services may process or store personal data outside the United Kingdom, including in the United States, European Economic Area, Canada or other countries in which approved providers or their infrastructure operate.

Where we initiate a restricted transfer, we use a lawful transfer mechanism where required. This may include UK adequacy regulations, the UK Extension to the EU-U.S. Data Privacy Framework (UK-U.S. Data Bridge) where applicable, the UK International Data Transfer Agreement, the UK Addendum to approved EU Standard Contractual Clauses, binding corporate rules or another permitted mechanism. We also consider the nature of the data, destination, provider safeguards and practical risks.

22. Cloud Backup and Disaster Recovery

To protect business continuity, project integrity and recovery capability, Spectral Lens may maintain backup or disaster-recovery copies of project, account and operational data using approved cloud providers. Depending on the configured service, such backups may be stored in the United States or another permitted data region.

Backups are used for continuity, recovery, security, rights management and legal or operational protection. They are not used by Spectral Lens for unrelated advertising or sale of personal data. Deletion from active systems may occur before residual copies expire from routine backup cycles.

23. Storage and Security

We use reasonable technical and organisational measures appropriate to the nature of the data and Service. These may include access controls, authentication, permissions, private storage, encrypted network connections, signed upload and download links, logging, file verification, backups, role-based access and supplier security controls.

For relevant Real Estate and secure-delivery workflows, files may be uploaded directly to private object storage using time-limited signed links and may be checked for type, size, dimensions, integrity or hash values. No online, cloud or AI system can be guaranteed completely secure.

24. Retention

We keep personal data only for as long as reasonably required for the purpose for which it was collected, taking account of contract performance, Portal access, project delivery, security, accounting, legal obligations, rights management, complaints, disputes and data sensitivity.

Client, contract, licence, approval and project-administration records are normally retained for the relationship and for a period afterwards that is appropriate to legal, contractual and dispute requirements. Accounting and tax records are retained for the period required by law. Portal account and access records are retained while relevant and for a reasonable period afterwards for security, audit and support.

High-fidelity security and session-replay records are retained only for as long as reasonably necessary for security, troubleshooting, misuse detection, investigation and audit, with longer retention where a specific security incident, complaint, legal claim or legal hold requires it. Security and technical logs may be retained for a longer operational period where proportionate.

AI-provider inputs, prompts and outputs are retained according to project need, available deletion controls and the provider's applicable retention terms. Provider backups, anonymised data, legal records or prior model-training influence may persist after active deletion where applicable.

25. Deletion, Account Closure and Backups

A request to delete a Portal account or project file does not necessarily require immediate deletion of every related record. We may retain information needed for contracts, invoices, legal claims, security, rights management, suppression records, regulatory obligations or another lawful purpose.

Active copies may be removed before residual copies disappear from routine backups. Protected backup copies are not ordinarily restored except for continuity or disaster recovery.

26. Your Data-Protection Rights

Depending on the circumstances and lawful basis, you may have rights to access personal data, correct inaccurate data, request deletion, restrict processing, object to certain processing, receive certain data in portable form, withdraw consent where processing relies on consent, and request human intervention where a qualifying automated decision has legal or similarly significant effects.

Rights are not absolute and may be limited by exemptions, another person's rights, legal obligations, contractual records, security requirements or legal claims. We may need to verify identity and authority before responding.

27. Right to Object and Security Monitoring

You may object to processing based on legitimate interests. We will consider the objection and the circumstances. Where processing is necessary for the security, integrity and protection of a private account or system, we may have compelling legitimate grounds to continue the relevant processing, subject to applicable law and proportionality. You may object to direct marketing at any time, in which case we will stop using your personal data for that marketing purpose.

28. Data-Protection Complaints

You may make a data-protection complaint by emailing info@spectrallens.com or writing to Spectral Lens Ltd at the registered office. Please explain what happened, the data or project involved and the outcome sought. You may also complain to the Information Commissioner's Office. We would appreciate the opportunity to address the issue first, but this does not affect your right to contact the ICO.

29. Personal-Data Breaches

We maintain processes for identifying, assessing, recording and responding to personal-data breaches. Where required by law, we will notify the Information Commissioner's Office and affected individuals within the applicable time limits. Suspected loss, unauthorised disclosure, compromised credentials or misuse should be reported promptly to info@spectrallens.com.

30. Third-Party Links and Independent Services

Our website, Portal, store and communications may link to or integrate with third-party services. Their independent privacy practices apply where they determine their own processing purposes. We are not responsible for an external service's independent processing merely because a link or integration is available.

31. Changes to This Policy

We may update this Policy to reflect changes in law, technology, security, providers, Services or business operations. The current version will be published with a revised date. Where a material change introduces a new use of personal data affecting an active Client or User, we will provide additional notice before the new processing begins where required by law.

32. Contact

Spectral Lens Ltd, 124 City Road, London, England, EC1V 2NX. Email: info@spectrallens.com. Company number: 11056390. ICO registration reference: ZB678254.