Topaz Labs Privacy Policy

Last updated: Sept 15, 2025

This Privacy Policy (“Policy”) describes and protects how Topaz Labs LLC (“Topaz” “us”, “we”, or “our”) collects, uses and discloses information related to users (referred to herein as “Customer”, “End User”, “you” or “your”) of the products and services offered by Topaz including, without limitation, our downloadable desktop software ("Software"), web-based applications ("Web Applications"), application programming interfaces ("API"), and on-premise deployments ("On-Premise Deployments") (collectively, the "Services"), as further described at https://www/topazlabs.com.

Topaz will not use, disclose, or share Your information with anyone except as described in this Policy or as otherwise required or permitted by applicable law. To the maximum extent permitted by applicable law, Topaz disclaims liability for disclosures made by third-party service providers, partners, or contractors acting on its behalf.

Your use of the Services is also subject to the End User License Agreement, available at https://topazlabs.com/eula, which is incorporated herein by reference and includes, by way of example, applicable terms governing limitations of liability, disclaimer, and indemnification. By accessing or using the Services, you (A) expressly accept and agree to the practices described in this Policy and (B) agree to the collection. use and disclosure of information in accordance with this Policy and/or, to the extent permitted by law, you waive and release Topaz from any claims arising out of third-party access, use, or misuse of your information outside Topaz’s reasonable control. If you submit any Personal Information relating to other people to us, you represent that you have the full authority to do so and have informed the other person about the contents of this Policy. If you do not agree with this Policy, please do not use the Services or provide us with any Personal Information (as defined below). This Policy does not apply to (1) websites, software applications, and other online properties and services that do not link to this Policy; and (2) any other collection, use or disclosure of data outside of the Services.

Personal Information. For purposes of this Policy, unless otherwise required by applicable law, “Personal Information” means any information that identifies, relates to, describes, or is reasonably capable of being associated, linked or linkable with a particular individual or household, including any information that is subject to applicable data protection laws.

Individual rights. Please see the Your Rights and Choices section below for a description of the choices we provide and the rights you have regarding your Personal Information. If you are a California resident, please also review the California Residents section below for information about the categories of Personal Information we collect and disclose and your rights under California privacy laws.

1. SCOPE

This Policy applies to our collection, retention, use, and disclosure of Personal Information related to purchasers and users of the Services. For clarity, information that has been de-identified, aggregated, or anonymized so that it cannot reasonably be linked back to an individual or household is not considered “Personal Information” under this Policy. Topaz may use and disclose such data without restriction, including for analytics, benchmarking, business intelligence, product improvement, and other commercial purposes, consistent with applicable law.

2. COLLECTION OF PERSONAL INFORMATION

The Personal Information we collect may vary depending on the nature of the Services provided or used and our interactions with individuals and Paz reserves the right to determine what information is reasonably necessary for the operation, security, and improvement of the Services, subject to applicable law.

2.1. Categories of Personal Information

While the Personal Information we collect may differ depending on the circumstances, we may collect the following categories of Personal Information (subject to applicable legal requirements and restrictions):

  • Name, contact information,other identifiers: identifiers such as name and email address.
  • Account and Profile Data: information such as your license tier, subscription plan, seat assignments, and other account settings.
  • Device information: Internet protocol (IP) address, web browser type, operating system version, phone carrier and manufacturer, application installations, device identifiers.
  • Communications: direct communications.
  • Usage, Billing, and Licensing data: internet or other electronic network activity information including, but not limited to, information regarding a consumer’s interaction with the Services, such as the number of images or frames processed, API calls made, timestamps, license keys, subscription status, and other metrics required to calculate fees and validate licenses.
  • Geolocation data: general location information (for example, your IP address may indicate your more general geographic region).
  • Audio, video and other electronic data: audio, electronic, visual, or similar information and media.
  • Profiles and inferences: inferences drawn from any of the information identified above to create a profile reflecting a user’s preferences, characteristics, predispositions, behavior, attitudes, intelligence, abilities, or aptitudes.

Topaz may also create derived data, statistical data, or technical logs from these categories of Personal Information for the purposes of analytics, auditing, and product improvement, and such derived data shall not be considered Personal Information once it has been reasonably de-identified or aggregated.

2.2. Sources of Personal Information

We may collect Personal Information about individuals:

  • Directly from you: such as when you make a purchase or contact us for support purposes.
  • Related to your use of our Services: including information we collect automatically when you use our Software, Web Applications, APIs, or On-Premise Deployments, or interact with us, or information we derive about you and your preferences or interests based on the Personal Information we collect and our interactions with you.

Where permitted by law, Topaz may also supplement the Personal Information you provide with information obtained from commercial sources, affiliates, or publicly available sources.

2.3. Information We Collect From You

We may collect Personal Information from you related to:

  • Purchases, orders and payments: when you purchase the Software or if you make additional purchases, we collect information in order to process your payment or to fulfill your order, including name, billing and shipping address and details, payment type, as well as credit card number or other payment account details.
  • Your communications and requests: when you email us or otherwise send us communications, we collect and maintain a record of your contact details, communications, and our responses.

Topaz may decline to respond to inquiries or support requests that do not contain sufficient identifying or contextual information, and you acknowledge that any information voluntarily provided in such communications may be used consistent with this Policy.

2.4. Information We Collect from Third Parties

We may collect Personal Information about you from third-party sources (which may be combined with other Personal Information we have collected about you), such as:

  • Third-Party Service Providers: we employ other companies and individuals to perform functions on our behalf. These third-party service providers have access to Personal information needed to perform their functions, but may not use it for other purposes.
  • Other: we may obtain Personal Information, such as demographic information or updated contact details, from third parties; we may also collect information from public records.
  • To the extent permitted by applicable law, Topaz is not responsible for the accuracy of Personal Information provided by third-party sources and has no obligation to independently verify such information.

2.5. Data Transmission for Locally Processed Services

You acknowledge that certain Services which run on your local hardware, such as On-Premise Deployments and the Command Line Interface (CLI), may be required to periodically transmit Usage, Billing, and Licensing Data to Topaz over the internet. This transmission is necessary to enable Topaz, without limitation, to provide the Services, ensure billing accuracy, validate licenses, and verify compliance with the End User License Agreement (EULA).

By using On-Premise Deployments or the CLI, you expressly consent to such transmissions, and you agree that failure to permit such transmissions may result in suspension, throttling, or termination of the Services.2.6 Retention. We retain Personal Information for as long as necessary to provide the Services, comply with our legal obligations, resolve disputes, enforce our agreements, or as otherwise permitted by law. Topaz reserves the right, to the maximum extent permitted, to determine appropriate retention periods based on the type of data, the purpose for which it was collected, and applicable legal requirements.

3. USE OF PERSONAL INFORMATION

We may use Personal Information for a variety of purposes, including, without limitation:

  • Sale of Services and processing of orders and payments: if you make a purchase, we collect information in order to process your payment and fulfill your order, including name, billing and shipping address and details, payment type, as well as credit card number or other payment account details.
  • Billing, Invoicing, and Account Management: To calculate and charge for Usage-Based Fees, manage subscriptions, process payments, generate invoices, and administer your account.
  • Providing support and services: including to provide our Services; to communicate with you about your access to and use of our Services; to respond to your inquiries; to provide troubleshooting, fulfill your orders and requests of products and services, and provide technical support; and for other customer service and support purposes.
  • Analyzing and improving our Services and operations: including better understand how users’ access and use our Services, to evaluate and improve our Services and business operations, and to develop new features, offerings and services; to increase our understanding of our customers; and for other research and analytical purposes. Where permitted by law, Paz may also use aggregated or de-identified data for analytics, benchmarking, and commercial research without restriction.
  • Securing and protecting our business: including to protect and secure our business operations, assets, Services, network and information and technology resources; to investigate, prevent, detect and take action regarding fraud, unauthorized access, situations involving potential threats to the rights or safety of any person or third party, or other unauthorized activities or misconduct.
  • Defending our legal rights: including managing and responding to actual and potential legal disputes and claims, and to otherwise establish, defend or protect our rights or interests, including in the context of anticipated or actual litigation with third parties.
  • License Enforcement and Compliance Auditing: To verify your compliance with the terms of our EULA, prevent unauthorized use, and conduct audits as permitted therein.
  • Auditing, reporting, corporate governance, and internal operations: including relating to financial, tax and accounting audits; audits and assessments of our operations, privacy, security and financial controls, risk, and compliance with legal obligations; our general business, accounting, record keeping and legal functions; and related to any actual or contemplated merger, acquisition, asset sale or transfer, financing, bankruptcy or restructuring of all or part of our business.
  • Complying with legal obligations: including to comply with the law, our legal obligations and legal process, such as warrants, subpoenas, court orders, and regulatory or law enforcement requests.
  • For our legitimate business interests: including where the interest of our business in conducting and managing our business to enable us to give you the best service/product and the best and most secure experience. We make sure we consider and balance any potential impact on you (both positive and negative) and your rights before we process your Personal Information for our legitimate interests. We do not use your Personal Information for activities where our interests are overridden by the impact on you (unless we have your consent or are otherwise required or permitted to by law). To the maximum extent permitted by law, Topaz retains sole discretion to determine when processing is necessary for legitimate interests. You can obtain further information about how we assess our legitimate interests against any potential impact on you in respect of specific activities by contacting us.
  • To perform any contracts between us and you: where it is necessary for the performance of a contract to which you are a party or to take steps at your request before entering into such a contract.
  • Cookies and Tracking Technologies. Topaz and its service providers may use cookies, log files, pixels, SDKs, and similar tracking technologies to operate, analyze, secure, and improve the Services, as well as for fraud prevention and compliance. You may disable cookies through your browser or device settings; however, certain features of the Services may not function properly if cookies are disabled.
  • 3A: FACIAL INFORMATION PROTECTION AND PRIVACY. Topaz Labs does not collect, store, retain, transmit, or otherwise process facial recognition data or biometric identifiers unless a user explicitly opts in to provide images for the purpose of improving our AI models. Such opt-in must occur through a clear, affirmative mechanism within the Services. Facial images submitted for enhancement through any of our Services are processed solely to fulfill the requested functionality (e.g., face refinement or enhancement) and are not analyzed, stored, or used for facial recognition, identification, profiling, marketing, or analytics. Any facial analysis performed is limited to temporary, in-memory processing and is automatically and irreversibly discarded once the enhancement task is complete. Facial analysis data is never written to persistent storage and is never shared with third parties. Images of faces may be stored only for the purpose of returning the original or enhanced image to the end user. These images may be deleted upon request at any time by the user. Topaz Labs does not and will not use facial images or data for user identification or tracking.

However, you acknowledge and agree that any data, including, without limitation, images, videos, and all other data, you submit for enhancement or processing may be cached or stored as necessary to provide the Services, enforce compliance, or resolve support issues, and you consent to such processing.

  • 3B: AI MODEL TRAINING.
  • Topaz Labs will not use Your media content (including images and videos) to train its artificial intelligence models without Your prior consent, which shall not be unreasonably withheld.

Notwithstanding the foregoing, Topaz may use de-identified, aggregated, or synthetic data derived from such media content solely for the purpose of improving its algorithms, provided that such data cannot reasonably be linked back to You.

4. DISCLOSURE OF PERSONAL INFORMATION

We may share or disclose the Personal Information we collect as follows:

  • Service providers: we may disclose Personal Information to third-party service providers who use this information to perform services for us, such as hosting providers, auditors, advisors, consultants, customer service and/or support providers. Topaz requires such providers to handle Personal Information consistent with this Policy; however, to the extent permitted by law, Topaz disclaims liability for acts or omissions of such providers outside Topaz’s reasonable control.
  • Legal compliance: we may be required to share Personal Information in response to a valid court order, subpoena, government investigation, or as otherwise required by law. We also reserve the right to report to law enforcement agencies any activities that we, in good faith, believe to be unlawful. In addition, we may share certain Personal Information when we believe that doing so is reasonably necessary to protect the rights, property, business operations, or safety of our company and/or others.
  • Business transfers: we may disclose and/or transfer Personal Information as part of any actual or contemplated merger, sale, transfer of assets, acquisition, financing and/or restructuring of all or part of our business, bankruptcy or similar event, including related to due diligence conducted prior to such event where permitted by law. You acknowledge and agree that your Personal Information may be included in the transferred assets and that the acquirer or successor may continue to use such information as described in this Policy, subject to applicable law.
  • Protect our rights: we may disclose Personal Information where we believe it necessary to respond to claims asserted against us, to enforce or administer our agreements and terms, for fraud prevention, risk assessment, investigation and/or to protect the rights, property or safety of us or our affiliates, clients, customers and/or others. Topaz reserves the right to pursue all remedies available, including disclosure of information, where it reasonably believes its rights or interests are threatened.
  • Your Consent: we may disclose Personal Information with your consent. Continued use of the Services following notice of an updated Policy shall be deemed consent to disclosures as described in the updated Policy.

4A. MEDIA CONTENT STORAGE AND RETENTION

Topaz Labs is committed to the security and responsible handling of the media content you process through our cloud-based Services.

  • Storage and Retention:
  • For the API Service: To facilitate Your access to processed content, input media and output content may be temporarily stored on our servers. This content is subject to automatic deletion after a limited period of time. You may also permanently delete this content at any time prior to its automatic deletion.

However, Topaz may retain residual copies in backup or archival systems for a limited period where required for compliance, auditing, or dispute resolution.

  • For Web Applications: The retention period for media content uploaded to our Web Applications is determined by your specific subscription plan. The exact terms of retention are presented to you at the time of purchase. Content may be deleted by you at any time. Topaz reserves the right, consistent with applicable law, to retain certain metadata or transactional records for billing, compliance, and legal purposes notwithstanding user deletion.

5. SECURITY

The security of your Personal Information is important to us. We have put in place safeguards to protect the Personal Information we collect from unauthorized access, use and disclosure. However, we cannot guarantee that unauthorized access, hacking, data loss, or other breaches will never occur. We urge you to take steps to keep your Personal Information safe, such as closing your web browser when finished using the Services. To the maximum extent permitted by law, Topaz disclaims liability for any unauthorized access, loss, or disclosure of Personal Information resulting from events outside its reasonable control, including without limitation network failures, third-party attacks, or your own failure to maintain the security of your devices and credentials.

6. CHILDREN'S PRIVACY

Our Services do not address anyone under the age of 13 and we do not knowingly collect or maintain Personal Information from children we actually know at the time of collection are under the age of 13. Should we discover that we have collected Personal Information online from a child who is under 13, we will promptly delete that Personal Information to the extent required by applicable law. If you have concerns regarding the collection of children’s Personal Information, please contact us at the information provided in the Contact Us section below. By using the Services, you represent and warrant that you are not under 13 years of age (or any higher age threshold required in your jurisdiction for consent), and you agree that Topaz shall not be liable for any misrepresentation of age or unauthorized use of the Services by minors.

7. YOUR RIGHTS AND CHOICES

Your rights with respect to your Personal Information may vary based on your jurisdiction. Subject to applicable law, you may request access to, correction of, or deletion of certain Personal Information by contacting us as described in the Contact Us section below. Topaz reserves the right to deny or limit such requests where permitted by law, including where they are unfounded, excessive, technically infeasible, or could adversely affect the rights and freedoms of others. European Union and United Kingdom. The following additional information and rights only apply to Personal Information associated with users who use the Services from the European Economic Area (“EEA”), including those based in the United Kingdom.

  • Data Controller. Topaz located at 14555 Dallas Parkway, Suite 350, Dallas, TX 75254, acts as the data controller for the Personal Information we process in connection with the use of the Services by users in the EEA. If you have any questions about how Topaz processes your Personal Information or would like to make use of your rights as a data subject, please contact us at privacy@topazlabs.com.

Information Rights under GDPR. Your rights with respect to your Personal Information include the following:

  • Request access to your Personal Information (commonly known as a “data subject access request”).

This enables you to receive a copy of the Personal Information we hold about you and to check that we are lawfully processing it.

  • Request correction of the Personal Information that we hold about you. This enables you to have any incomplete or inaccurate data we hold about you corrected, though we may need to verify the accuracy of the new data you provide to us.
  • Request erasure of your Personal Information (also known as the “right to be forgotten”). This enables you to ask us to delete or remove Personal Information where there is no good reason for us continuing to process, when you have successfully exercised your right to object to processing (see below), where we may have processed your information unlawfully or where we are required to erase your Personal Information to comply with local law. Note, however, that we may not always be able to comply with your request for erasure for specific legal reasons that will be notified to you, including, without limitation, where retention is required for compliance, billing, dispute resolution, or security purposes.
  • Object to processing of your Personal Information where we are relying on a legitimate interest (or those of a third party) and there is something about your situation which makes you want to object to processing on this ground as you feel it affects your fundamental rights and freedoms. In some cases, we may demonstrate that we have compelling legitimate grounds to process your information that override your rights and freedoms.
  • Request restriction of processing of your Personal Information. This enables you to ask us to suspend the processing of your Personal Information in the following scenarios:
  • If you want us to establish the data’s accuracy.
  • Where our use of the data is unlawful, but you do not want us to erase it.
  • Where you need us to hold the data even if we no longer require it as you need it to establish, exercise or defend legal claims.
  • You have objected to our use of your data, but we need to verify whether we have overriding legitimate grounds to use it.
  • Request the transfer of your Personal Information to you or to a third party. We will provide to you, or a third party you have chosen, your Personal Information in a structured, commonly used, machine readable format.
  • Not be subject to automated decision-making including profiling, where the decision would have a legal effect on you or produce a similarly significant effect. We do not carry out this type of automated decision making in the Software.
  • Withdraw consent at any time where we are relying on consent to process your Personal Information.

However, this will not affect the lawfulness of any processing carried out before you withdraw your consent. If you withdraw your consent, we may not be able to provide certain products or services to you. We will advise you if this is the case at the time you withdraw your consent. Withdrawal of consent shall not affect processing carried out prior to such withdrawal, and Topaz reserves the right to retain and process Personal Information where another lawful basis applies.

  • No Fee Usually Required. You will not have to pay a fee to access your Personal Information (or to exercise any of the other rights). However, we may charge a reasonable fee if your request is clearly unfounded, repetitive, or excessive. Alternatively, we could refuse to comply with your request in these circumstances. Where permitted by law, Topaz may also decline to act on such requests.
  • What We May Need from you. We may need to request specific information from you to help us confirm your identity and ensure your right to access your Personal Information (or to exercise any of your other rights). This is a security measure to ensure that Personal Information is not disclosed to any person who has no right to receive it. We may also contact you to ask you for further information in relation to your request to speed up our response. Failure to provide sufficient information may result in Topaz’s inability to fulfill your request.
  • Time Limit to Respond. We try to respond to all requests within one month. Occasionally it could take us longer than a month if your request is particularly complex or you have made several requests. In this case, we will notify you and keep you updated. Topaz may extend this period where necessary due to complexity or volume, consistent with applicable law.

Information Uses and Legal Bases. We will only use your Personal Information under the circumstances permitted by the law or you.

Pursuant to GDPR, we will use your Personal Information in one or more of the following circumstances:

INFORMATION USES INFORMATION PROCESSING LEGAL BASIS

Performance of any Contract between Us and You Where we need to perform the contract we are about to enter into or have entered into with you.

Providing Support and Services When it's necessary for us (or a third party) to process your Personal Information to:

  • comply with obligations under a contract with you. This includes our obligations under the EULA to provide the Software to you,
  • verify information before a new contract with you begins,
  • respond to your messages when you contact customer services, or
  • spot unusual data or behavior in our logs which might indicate a bug or other issue.

Improve our Software Where it is necessary for our legitimate interests (or those of a third party) to provide or improve the Software, including our interest to provide you improved Software, and where your interests and fundamental rights do not override those interests.

Communication Where it is necessary for our legitimate interests (or those of a third party) to communicate with you and your interests and fundamental rights do not override those interests.

Where we need your consent for the information use, we will seek your prior consent.

Comply with a request from law enforcement, courts or other competent jurisdictions When we must process your Personal Information to comply with a law and our legitimate interest. Our legitimate interest here includes assisting law enforcement authorities to prevent or detect serious crime.

Securing and Protecting Our

Business Where it is necessary for our legitimate interests to protect our intellectual property and original content as well as to investigate and protect our Software and our users against fraud and illegal activity.

To establish, exercise or defend legal claims Where it is necessary for our legitimate interests to seek legal advice and protect ourselves, our users or others in legal proceedings. For example, if we are involved in litigation and we need to provide information to our lawyers in relation to that legal case.

Legal Compliance Where it is necessary to meet our legal obligations. This might be an obligation under the law of the country/region you are in.

Canadian Residents

Where the Personal Information Protection and Electronic Documents Act (“PIPEDA”) applies, you have the right to:

  • Request access to your Personal Information. This enables you to receive a copy of the Personal Information we hold about you and to check that we are lawfully processing it.
  • Request correction of the Personal Information that we hold about you. This enables you to have any incomplete or inaccurate data we hold about you corrected, though we may need to verify the accuracy of the new data you provide to us.
  • Object to processing of your Personal Information where we are relying on a legitimate interest (or those of a third party) and there is something about your situation which makes you want to object to processing on this ground as you feel it affects your fundamental rights and freedoms. In some cases, we may demonstrate that we have compelling legitimate grounds to process your information that override your rights and freedoms.
  • Request restriction of processing of your Personal Information. This enables you to ask us to suspend the processing of your Personal Information in the following scenarios:
  • If you want us to establish the data’s accuracy.
  • Where our use of the data is unlawful, but you do not want us to erase it.
  • Where you need us to hold the data even if we no longer require it as you need it to establish, exercise or defend legal claims.
  • You have objected to our use of your data, but we need to verify whether we have overriding legitimate grounds to use it.
  • Withdraw consent at any time where we are relying on consent to process your Personal Information.

However, this will not affect the lawfulness of any processing carried out before you withdraw your consent. If you withdraw your consent, we may not be able to provide certain products or services to you. We will advise you if this is the case at the time you withdraw your consent.

  • Minimal Fee May Be Required. You may have to pay a minimal fee to access your Personal Information (or to exercise any of the other rights). We will provide you with the approximate cost before processing the request. We will confirm with you that you still wish to proceed with the request.
  • What We May Need from you. We may need to request specific information from you to help us confirm your identity and ensure your right to access your Personal Information (or to exercise any of your other rights). This is a security measure to ensure that Personal Information is not disclosed to any person who has no right to receive it. We may also contact you to ask you for further information in relation to your request to speed up our response.
  • Time Limit to Respond. We try to respond to all requests within 30 days. Occasionally it could take us longer than 30 days if your request is particularly complex or you have made several requests. In this case, we will notify you and keep you updated.
  • Right to Challenge Our Compliance. If for any reason, you are concerned about our compliance with this Policy or the principles established in PIPEDA, we encourage you to contact us at privacy@topazlabs.com.

United States Residents

US data protection laws (including the CCPA/CPRA and similar state laws) grant California, Colorado, Connecticut, Nevada, Utah, and Virginia residents’ certain data rights. These rights apply only to the extent required by applicable law and may be subject to exceptions, such as where retention is necessary for, without limitation, compliance, billing, auditing, security, or internal business purposes.

  • Right to Know and to Access. You have the right to request that we disclose certain information to you about our collection and use of your Personal Information over the past 12 months. This information is disclosed in the Collection of Personal Information section of this Policy. You also have the right to request access to Personal Information collected about you and information regarding the source of that information, the purposes for which we collect it, and the third parties and service providers with whom we share it. You may submit such a request as described below. To protect our customers’ Personal Information, we are required to verify your identify before we can act on your request. Topaz may decline to provide access when doing so would, amongst other things, adversely affect the rights of others, reveal trade secrets, or where another lawful exception applies.
  • Right to Portability. You have the right to request that we provide a copy of the Personal Information we have collected about you, in a portable and, to the extent technically feasible, readily usable format that allows you to transmit the data to another entity without hindrance. Once we receive your request and confirm your identity, we will provide you a copy of your data as required under the applicable data protection laws. We may provide this data to you via email to the email address you have provided with your request. Subject to, without limitation, technical feasibility and legal requirements.
  • Right to Delete. Subject to certain exceptions, you have the right to request that we delete any of your Personal Information. Once we receive your request and confirm your identity, we will review your request to see if an exception allowing us to retain the information applies. We will delete or deidentify Personal Information not subject to one of these exceptions from our records and will direct our service providers to take similar action. Topaz may retain Personal Information where required for, without limitation, compliance, billing, auditing, fraud prevention, security, or dispute resolution.
  • Right to Correct. Subject to certain exceptions, you have the right to request that we correct inaccurate Personal Information that we have collected about you. Once we receive your request and confirm your identity, we will review your request, taking into account the nature of the Personal Information and the purposes of the processing of the Personal Information to see if we can correct the data. We may also request additional information showing that the information you want to correct is inaccurate.

Corrections may be limited where requests are excessive, repetitive, or technically infeasible.

  • Right to Appeal. If we deny your request to exercise a privacy right, you may appeal our decision by contacting us at privacy@pazlabs.com with the subject line “Privacy Rights Appeal.” We will review and respond to your appeal within the timeframe required by applicable law. If you remain unsatisfied, you may also contact your state’s Attorney General.
  • Non-Discrimination. We will not discriminate against you for exercising any of your data privacy rights.
  • Exercising Your Rights. To exercise your rights described above, please submit a request by emailing us at privacy@topazlabs.com. Only you, or someone legally authorized to act on your behalf, may make a request to know or delete related to your Personal Information. You may also make a request to know or delete on behalf of your child. Certain data protection laws limit the ability to make a request to know to twice within a 12-month period, and allow us to charge a reasonable fee for responding to numerous requests from the same user. We cannot respond to your request or provide you with Personal Information if we cannot verify your identity or authority to make the request and confirm the Personal Information relates to you. Failure to provide sufficient verification information may result in denial of your request.

California Residents

  • Right to Opt-Out of Sale or Sharing of Personal Information. We do not sell or share your Personal Information with third parties, as those terms are defined under the California law.
  • California Shine the Light. Where applicable, California Civil Code Section 1798.83 allows California residents to request certain information regarding our disclosure of Personal Information to third parties for their direct marketing purposes. To make such a request please contact us using the information provided in the Contact Us section below.
  • Business and Employment-Related Data. This Policy applies to end-users of the Services. To the extent Paz processes information related to job applicants, employees, contractors, or B2B contacts, such processing is conducted in accordance with a separate privacy notice, provided at the time of collection.

The California Consumer Privacy Act of 2018, as amended by the California Privacy Rights Act of 2020 (“CCPA”), requires specific disclosures for each category of Personal Information that we collect and may provide to others. The table below summarizes our general data handling practices which are more fully described in Sections 2, 3, and 4 of this Policy. We do not collect Sensitive Personal Information.

Categories of Personal Information We Collect. The CCPA requires specific disclosures for each category of Personal Information that we collect. The table below summarizes our general data handling practices which are more fully described in Sections 2, 3, and 4 of this Policy.

CATEGORY OF PERSONAL INFORMATIONCATEGORIES OF SOURCES FROM WHICH PERSONAL INFORMATION WAS COLLECTEDBUSINESS OR COMMERCIAL PURPOSE FOR COLLECTING AND PROVIDING THE CATEGORY OF PERSONAL INFORMATIONCATEGORIES OF THIRD PARTIES AND OTHER ENTITIES TO WHICH WE PROVIDE PERSONAL INFORMATION
Name, Contact Information, and other Identifiers: identifiers such as name and email address
  • Directly from the user
  • From third-party data suppliers and business partners
  • To provide the user with and to improve the Software
  • To communicate with the user
  • To analyze and improve the business
  • To secure and protect the business
  • To defend the company’s legal rights
  • For auditing, reporting, corporate governance and internal operations
  • To comply with legal obligations
  • For legitimate business interests
  • With service providers
  • With government authorities as required by law or as necessary to protect the company’s rights
Device Information: Internet protocol (IP) address, web browser type, operating system version, phone carrier and manufacturer, application installations, device identifiers.
  • Directly from the user
  • From third-party data suppliers and business partners
  • To provide the user with and to improve the Software
  • To communicate with the user
  • To analyze and improve the business
  • To secure and protect the business
  • To defend the company’s legal rights
  • For auditing, reporting, corporate governance and internal operations
  • To comply with legal obligations
  • For legitimate business interests
  • With service providers
  • With government authorities as required by law or as necessary to protect the company’s rights
Communications: direct communications.
  • Directly from the user
  • To provide the user with and to improve the Software
  • To communicate with the user
  • To analyze and improve the business
  • To secure and protect the business
  • To defend the company’s legal rights
  • For auditing, reporting, corporate governance and internal operations
  • To comply with legal obligations
  • For legitimate business interests
  • With service providers
  • With government authorities as required by law or as necessary to protect the company’s rights
Usage data: internet or other electronic network activity information including, but not limited to, information regarding a consumer’s interaction with the Software, the time spent on the Software and other statistics.
  • Directly from the user
  • To provide the user with and to improve the Software
  • To communicate with the user
  • To analyze and improve the business
  • To secure and protect the business
  • To defend the company’s legal rights
  • For auditing, reporting, corporate governance and internal operations
  • To comply with legal obligations
  • For legitimate business interests
  • With service providers
  • With government authorities as required by law or as necessary to protect the company’s rights
Geolocation Data: general location information (for example, your IP address may indicate your more general geographic region).
  • Directly from the user
  • To provide the user with and to improve the Software
  • To communicate with the user
  • To analyze and improve the business
  • To secure and protect the business
  • To defend the company’s legal rights
  • For auditing, reporting, corporate governance and internal operations
  • To comply with legal obligations
  • For legitimate business interests
  • With service providers
  • With government authorities as required by law or as necessary to protect the company’s rights
Audio, Video, and other Electronic Data: audio, electronic, visual, or similar information such as, photographs and audiovisual recordings.
  • Directly from the user
  • To provide the user with and to improve the Software
  • To communicate with the user
  • To analyze and improve the business
  • To secure and protect the business
  • To defend the company’s legal rights
  • For auditing, reporting, corporate governance and internal operations
  • To comply with legal obligations
  • For legitimate business interests
  • With service providers
  • With government authorities as required by law or as necessary to protect the company’s rights
Profiles and Inferences: inferences drawn from any of the information identified above to create a profile reflecting a users preferences, characteristics, psychological trends, predispositions, behavior, attitudes, intelligence, abilities, or aptitudes.
  • Directly from the user
  • To provide the user with and to improve the Software
  • To communicate with the user
  • To analyze and improve the business
  • To secure and protect the business
  • To defend the company’s legal rights
  • For auditing, reporting, corporate governance and internal operations
  • To comply with legal obligations
  • For legitimate business interests
  • With service providers
  • With government authorities as required by law or as necessary to protect the company’s rights

Colorado, Connecticut and Virginia Residents

  • Right to Opt-Out. You have the right to out of the processing of the Personal Information for purposes of (i) targeted advertising, (ii) the sale of personal data, or (iii) profiling in furtherance of decisions that produce legal or similarly significant effects concerning the consumer. We do not process your Personal Information for (i) targeted advertising, (ii) the sale of personal data, or (iii) profiling in furtherance of decisions that produce legal or similarly significant effects concerning the consumer.
  • Right to Appeal. If you make a request to exercise any of the above data access rights and we are unable to comply with your request, you may request to appeal our decision. To appeal any data privacy request decision, please contact us by emailing privacy@topazlabs.com with the subject line “Data Access Request Appeal.” If after you complete the appeal process with us, you are still unsatisfied with our response, you may contact your Attorney General to file a complaint. Below are the contact information for the appropriate entity where you can inquire about filing an appeal:

Colorado residents:

Office of the Attorney General

Colorado Department of Law

Ralph L. Carr Judicial Building

1300 Broadway, 10th Floor

Denver, CO 80203 (720)

508-6000

https://coag.gov/

Connecticut Residents

Office of the Attorney General

165 Capitol Avenue

Hartford, CT 06106

Phone: (860) 808-5318

https://portal.ct.gov/AG

Virginia residents:

Office of the Attorney General

202 North 9th Street

Richmond, Virginia 23219 Phone:

(804) 786-2071

https://www.oag.state.va.us/

Nevada Residents

If you are a resident of Nevada, you have the right to opt-out of the sale of certain Personal Information to third parties who intend to license or sell that Personal Information. You can exercise this right by contacting us at privacy@topazlabs.com with the subject line “Nevada Do Not Sell Request” and providing us with your name and the email address associated with your account. Please note that we do not currently sell your Personal Information as sales are defined in Nevada Revised Statutes Chapter 603A. If you have any questions, please contact us as set forth below.

Utah Residents

If you are a resident of Utah, you have the right to out of the processing of the Personal Information for purposes of (i) targeted advertising and (ii) the sale of personal data. We do not process your Personal Information for (i) targeted advertising or (ii) the sale of personal data.

7A. INTERNATIONAL DATA TRANSFERS

If you are located in the European Economic Area (EEA), the United Kingdom, or Switzerland, your Personal Information may be transferred to and processed in countries that may not provide the same level of data protection as your home jurisdiction. Where required, Paz uses appropriate safeguards such as the European Commission’s Standard Contractual Clauses (SCCs), the UK Addendum, or other lawful transfer mechanisms. By using the Services, you acknowledge and consent to such transfers, subject to applicable law.

8. CHANGES TO THIS PRIVACY POLICY

We may update our Policy from time to time. If we make material changes to our privacy practices, an updated version of this Policy will reflect those changes. We will notify you of any changes by posting the new Policy on this page. If you continue to access or use the Services after being provided with the notice of updates, you acknowledge your acceptance of the updated Policy.

You are advised to review this Policy periodically for any changes. Changes to this Policy are effective when they are posted on this page.

Without prejudice to your rights under applicable law, we reserve the right to update and amend this Policy without prior notice to reflect technological advancements, legal and regulatory changes and good business practices provided that such updates do not materially diminish your statutory rights. Continued use of the Services after such updates shall constitute your acceptance of the updated Policy.

9. CONTACT US

If you have any questions about this Policy, please contact us at:

privacy@topazlabs.com

Topaz Labs LLC

14555 Dallas Parkway

Suite 350

Dallas, Texas 75254

(972) 246-8075

By contacting Topaz, you acknowledge and agree that (i) communications may not always be secure, (ii) Topaz may retain records of your communications for compliance, training, and dispute resolution purposes, and (iii) Topaz is not obligated to respond to inquiries that are abusive, repetitive, or outside the scope of its legal obligations.