β
Fully Compliant Platform
AIGC Compliance meets all major international regulatory requirements for data protection, content authenticity, and digital services.
Compliance Certifications
πͺπΈ
LSSI-CE
Compliant
GDPR Compliance (EU Regulation 2016/679)
-
β
Lawful Processing: We process personal data based on legitimate interests and user consent, with clear legal bases documented for each processing activity.
-
β
Data Subject Rights: Full implementation of access, rectification, erasure, portability, and objection rights through automated and manual processes.
-
β
Privacy by Design: Technical and organizational measures including pseudonymization, encryption (TLS 1.3), and data minimization principles.
-
β
-
β
Breach Notification: Procedures in place for 72-hour breach notification to supervisory authorities and affected data subjects.
-
β
Data Processing Agreements: Standard contractual clauses with all third-party processors (Supabase, Railway, Stripe).
-
β
Records of Processing: Comprehensive documentation of all processing activities maintained per Article 30.
-
β
Cookie Consent: Granular cookie consent mechanism with Essential, Analytics, and Marketing categories.
-
β
Data Retention: Automated deletion policies with maximum retention periods documented in our Privacy Policy.
-
β
International Transfers: All data processing occurs within EU/EEA with adequacy decisions or appropriate safeguards.
LSSI-CE Compliance (Spain Ley 34/2002)
-
β
Legal Identification: Complete operator identification including NIF 45544135H, registered address, and contact information.
-
β
Commercial Communications: Clear identification of promotional content with opt-in consent mechanisms.
-
β
Electronic Contracting: Transparent terms and conditions with double opt-in confirmation for service agreements.
-
β
Liability Framework: Service provider liability addressed with content moderation and takedown procedures.
LOPD-GDD (Spain Organic Law 3/2018)
Spanish implementation of GDPR with additional requirements:
-
β
Spanish DPA Registration: Notification to Agencia EspaΓ±ola de ProtecciΓ³n de Datos (AEPD) completed.
-
β
Digital Rights: Compliance with digital rights framework including digital disconnection and data portability enhancements.
-
β
Impact Assessments: Data Protection Impact Assessments (DPIA) conducted for high-risk processing.
EU AI Act Readiness
Fully compliant with the EU Artificial Intelligence Act (2024) - Article 52 Transparency Obligations:
-
β
Visible Watermarking (Article 52): All EU-processed images include clearly visible watermark "AI Generated" (customizable). This ensures end-users can identify AI-generated content without technical tools.
-
β
Technical Verification (C2PA): C2PA metadata embedded for cryptographic verification. Dual-layer compliance: visible (user-facing) + technical (forensic verification).
-
β
Transparency Requirements: Clear disclosure that content has been AI-generated through both watermarking and metadata, exceeding Article 52 requirements.
-
β
Risk Classification: Service classified as limited-risk AI system with appropriate transparency obligations.
-
β
Documentation: Technical documentation maintained for AI system capabilities and limitations.
-
β
Human Oversight: Human review processes for high-stakes content verification and dispute resolution.
C2PA Standards (Coalition for Content Provenance and Authenticity)
-
β
Content Credentials: C2PA 2.0 compliant using official c2pa-python 0.25.0 library. Cryptographic signing active with CAI test certificates (ES256 + DigiCert TSA). Production certificate in progress.
-
β
Tamper Detection: Cryptographic signing ensures any content modifications are detectable. Manifests validated successfully with CAI Reader.
-
β
Manifest Generation: Automatic generation of content provenance manifests with creation metadata, AI disclosure, and full action history.
Additional Security Compliance
-
β
PCI DSS: Payment card security handled through Stripe's certified infrastructure (PCI Service Provider Level 1).
-
β
ISO 27001 Alignment: Information security management practices aligned with ISO/IEC 27001 standards.
-
β
SOC 2 Type II: Infrastructure providers (Railway, Supabase) maintain SOC 2 Type II compliance.
π Compliance Documentation
For detailed compliance documentation, audit reports, or specific regulatory questions, please contact our compliance team:
π Continuous Compliance
We continuously monitor regulatory changes and update our compliance programs accordingly. Our last comprehensive compliance audit was completed in January 2024.