Privacy Policy
Last updated: 2 June 2026
1. Introduction
At Vistta we are committed to protecting your privacy and your personal data. This Privacy Policy explains how we collect, use, store and protect your information when you use our virtual home staging platform.
This policy complies with the European Union General Data Protection Regulation (GDPR) and the Spanish Organic Law on the Protection of Personal Data and Guarantee of Digital Rights (LOPDGDD).
2. Data Controller
Controller: Vistta
Contact email: legal@visttahome.com
Address: Santa Cruz de Tenerife, Spain
3. Data We Collect
We collect the following categories of data.
3.1 Registration data
- Full name
- Email address
- Profile picture (if you sign up with Google)
3.2 Usage data
- Images you upload to the platform for processing
- Images generated by our AI system
- Style and configuration preferences
- Generation history
3.3 Technical data
- IP address
- Browser and device type
- Pages visited and time spent on the platform
- Cookies and similar technologies
4. Purpose of the Processing
We use your data for:
- Service delivery: Processing your images and generating AI transformations
- Account management: Creating and maintaining your user account
- Communications: Sending you information about your account, service updates and technical support
- Service improvement: Analysing the use of the platform to improve its operation
- Legal compliance: Meeting applicable legal obligations
5. Legal Basis for the Processing
The processing of your data is based on:
- Performance of a contract: To deliver the service you have contracted
- Consent: For the sending of commercial communications (where you have consented)
- Legitimate interest: To improve our services and prevent fraud
- Legal obligation: To meet applicable legal requirements
6. Processing of Images
The images you upload to Vistta are processed as follows:
- They are stored securely on encrypted servers
- They are processed by our AI systems to generate the requested transformations
- The original and generated images are associated with your account
- We do not share your images with third parties without your consent
- You can delete your images at any time from your account dashboard
Important: We do not use your images to train our AI models, nor do we share them publicly without your express authorisation.
7. Data Recipients
We may share your data with:
- Service providers: Companies that help us operate the platform (hosting, payment processing, AI)
- Authorities: When required by law or to protect our rights
Our service providers include:
- Supabase (authentication and database) — servers within the EU
- Google Cloud / Anthropic (AI processing)
- Payment providers (for processing transactions)
8. International Transfers
Some of our service providers may be located outside the European Economic Area. In those cases, we make sure adequate safeguards are in place to protect your data, such as the Standard Contractual Clauses approved by the European Commission, or equivalent certifications.
9. Data Retention
We retain your data for as long as necessary for:
- Account data: While your account is active
- Images: Until you delete them or cancel your account
- Billing data: For the period legally required (minimum 6 years)
- Usage data: Up to 24 months, in anonymised form, for statistical analysis
10. Your Rights
Under the GDPR you have the right to:
- Access: Request a copy of the personal data we hold about you
- Rectification: Correct inaccurate or incomplete data
- Erasure: Request the deletion of your data (the "right to be forgotten")
- Restriction: Restrict the processing of your data in certain circumstances
- Portability: Receive your data in a structured format and transfer it to another controller
- Objection: Object to the processing of your data for certain purposes
- Withdraw consent: Withdraw your consent at any time
To exercise these rights, contact us at legal@visttahome.com. We will respond to your request within a maximum of 30 days.
11. Security
We implement technical and organisational security measures to protect your data:
- Data encryption in transit (HTTPS/TLS) and at rest
- Secure authentication and access management
- Threat monitoring and detection
- Regular backups
- Data protection training for our staff
12. Cookies
We use cookies and similar technologies for:
- Essential cookies: Required for the operation of the service (authentication, security)
- Functional cookies: Remember your preferences
- Analytics cookies: Help us understand how the platform is used
You can manage your cookie preferences from your browser settings.
13. Minors
Vistta is not directed at children under 16. We do not knowingly collect data from minors. If we discover that we have collected data from a minor without verifiable parental consent, we will delete that information as soon as possible.
14. Changes to this Policy
We may update this Privacy Policy from time to time. We will notify you of significant changes via a notice on the platform or by email. We recommend reviewing this page regularly to stay informed about how we protect your data.
15. Complaints
If you believe that the processing of your data is not in line with the applicable regulations, you have the right to lodge a complaint with the Spanish Data Protection Agency (Agencia Española de Protección de Datos, AEPD) at www.aepd.es.
If you reside in another European Union Member State, you may also lodge a complaint with the supervisory authority of your country of residence.
16. Contact
For any query related to this Privacy Policy or the processing of your data:
Email: legal@visttahome.com
Data Protection Officer: legal@visttahome.com
Address: Santa Cruz de Tenerife, Spain