GDPR / EEA Supplemental Notice

This notice applies to users located in the European Economic Area (EEA) and supplements our Privacy Policy.

1. Legal Basis for Processing

We process certain personal data, including device-related identifiers and access logs, based on our legitimate interests (Article 6(1)(f) GDPR) in ensuring the security, integrity, and lawful operation of the service, preventing fraud and abuse, and protecting our legal rights. In some cases, processing may also be necessary to comply with legal obligations.

2. Device-Based Restrictions

In cases of serious or repeated violations of our Terms of Service, we may apply restrictions at the device level. These measures are implemented solely for security, abuse prevention, and service protection purposes.

3. Data Retention

When an account is deleted or access is restricted, certain data may be retained to the minimum extent necessary for fraud prevention, security monitoring, compliance with legal obligations, or the establishment, exercise, or defense of legal claims.

4. Data Subject Rights

EEA users have the right to request access to, rectification of, or erasure of their personal data, as well as to object to or restrict certain processing activities, subject to applicable legal limitations.

5. Contact

Requests can be submitted via our contact form: https://nekomimi.ai/contact/