Hanna Creative Co.
Website, Platform, and Business Contact Privacy Notice
Version 1.0 | Last Updated: August 20, 2026
This Privacy Policy describes how Hanna Creative collects, uses, discloses, retains, and protects personal data in connection with the Studio Halo platform and related business activities.
Hanna Creative Co., a Massachusetts corporation, operates the Studio Halo platform and offers services under the HALO SCORE brand.
Hanna Creative Co., a Massachusetts corporation ("Hanna Creative," "we," "us," or "our"), operates the Studio Halo platform and offers services under the HALO SCORE brand. This Privacy Policy explains how we process personal data when you visit a website or application that links to this Policy, create or use a Studio Halo account, connect business systems, communicate with us, participate in a beta or event, or otherwise interact with the Studio Halo services (collectively, the "Services").
This Policy should be read with the Studio Halo Terms of Service and AI, Data & Intellectual Property Rights Policy. Those documents govern contractual ownership, licenses, outputs, scoring, and permitted platform use. This Policy addresses personal data and does not transfer intellectual property rights.
The Services are designed primarily for business users in the interior design industry, including interior design professionals, firms, brands, manufacturers, showrooms, and agencies serving that industry. This Policy applies to personal data we process for our own business purposes and to personal data we process through the Services on behalf of customers. It does not apply to a third-party website, platform, service, or integration that has its own privacy notice.
The Services are not intended for children or for personal, family, or household use. Customers are responsible for providing any notices and obtaining any consents required for personal data they submit or connect to the Services.
The Services may be accessible from multiple countries. This Policy is intended to provide a general description of our personal-data practices wherever the Services are used, but accessibility alone does not mean that every Service or processing activity is intentionally offered in every jurisdiction. Additional notices, consent mechanisms, contractual terms, local representatives, transfer safeguards, or AI-transparency measures may apply where required. Nothing in this Policy limits non-waivable rights under applicable law.
2.1 Hanna Creative as Controller or Business. We determine the purposes and means of processing for account administration, billing, website and service operations, security, support, product communications, sales, and our own business records. For those activities, Hanna Creative acts as a controller, business, or similar responsible entity under applicable privacy law.
2.2 Hanna Creative as Processor, Service Provider, Contractor, or Subprocessor. When a customer submits personal data about its personnel, clients, prospects, contacts, vendors, or other individuals through the Services, Hanna Creative generally processes that data on the customer's behalf. Where a customer processes data on behalf of one of its own clients or another controller, Hanna Creative may act as the customer's subprocessor. The customer is responsible for its instructions, notices, consents, legal basis, authority to appoint Hanna Creative, and responses to individual requests. Schedule 1 to the Terms provides additional data-processing terms. We may direct a requester to the applicable customer when the customer or its client controls the data.
2.3 Hanna Creative as Independent Controller or Business for Independently Sourced Information. When Hanna Creative independently determines how to use professional, business, media, website, social-media, news-source metadata, or other information from public, licensed, commercial, or third-party sources, Hanna Creative may act as an independent controller, business, or similar responsible entity. We may process that information to operate the Halo Score, verify and normalize business information, maintain data quality, create industry-level reference benchmarks, conduct research, generate non-customer-specific insights, prevent misuse, and support the other purposes described in this Policy. Public availability does not mean that information is unrestricted; source terms, intellectual-property rights, privacy law, and other restrictions may limit collection, use, retention, display, or redistribution.
2.4 Legal Bases Where Required. Where a law such as the EU GDPR or UK GDPR requires a legal basis, we process personal data as necessary to perform a contract or take requested pre-contract steps; pursue legitimate interests such as operating, securing, supporting, and improving the Customer-specific Services, conducting proportionate business analytics, maintaining the integrity of the Halo Score, preventing misuse, and communicating with business contacts, where those interests are not overridden by applicable rights; comply with legal obligations; protect vital interests in limited circumstances; or rely on consent where appropriate. For independently sourced personal data, the applicable basis and required notice depend on the source, purpose, reasonable expectations, and jurisdiction. Consent may be withdrawn where it is the legal basis without affecting earlier lawful processing.
Depending on how you and your organization use the Services, we may collect the following categories of personal data:
The Services are not designed to collect sensitive personal data such as government identifiers, payment-card numbers, health data, biometric identifiers, precise geolocation, or information about children. Please do not submit sensitive personal data unless Hanna Creative has expressly requested and authorized it for a specific feature or agreement.
We collect personal data:
We may use personal data to:
The Services use automated, statistical, machine-learning, and generative-AI technologies to analyze business data and generate Halo Scores, classifications, summaries, trends, and recommendations. The current implementation uses third-party AI through API inference for classification and Customer-specific report generation. It does not train or fine-tune a Studio Halo model, create Customer embeddings, or maintain a vector or retrieval database. Data sources may refresh on different schedules. The Services support business brand analysis and are not designed to make legally binding or consequential decisions about natural persons.
We use Customer Data, including personal data, as necessary to provide and secure the applicable Customer's Services, troubleshoot, perform Customer-specific quality assurance, and generate Customer-specific outputs. We do not currently use Customer Data that identifies a Customer or its end users to train, fine-tune, or improve a model, scoring system, benchmark, or product made available to unrelated customers. Aggregate industry reference benchmarks currently used by Studio Halo are derived from independently sourced public or third-party reference data rather than Customer-connected analytics, search, or social data.
We use Anthropic's commercial Claude API for limited inference tasks, including classification and Customer-specific report generation. According to Anthropic's current commercial privacy materials, commercial API inputs and outputs are not used for model training by default and standard API inputs and outputs are automatically deleted from Anthropic's backend within 30 days, subject to stated safety, legal, and account-specific exceptions. Studio Halo's current use of Anthropic's Files API contains Hanna Creative report templates and prompt instructions rather than Customer Data. We do not represent that zero-data-retention terms apply unless separately confirmed for the account.
Authorized Hanna Creative personnel and service providers may access Customer Content, AI interactions, and customer-specific outputs where reasonably necessary for support, troubleshooting, security, misuse investigation, quality evaluation, legal compliance, or customer instructions. Access is subject to confidentiality and appropriate access controls. We do not represent that Customer Content is never accessed by people, but we do not conduct routine human review except as disclosed, authorized, or reasonably necessary for those purposes.
If Hanna Creative later proposes to use identifiable or customer-identifying non-public Customer Data for generalized model, scoring-system, benchmark, or cross-customer product improvement, that practice will require a separate affirmative authorization, Order, or other valid basis before it begins. A future policy update alone will not silently convert the current no-generalized-training practice into a broader training right.
6.1 Google-Connected Data. Studio Halo's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including applicable Limited Use requirements. Google-connected user data and data derived from it are used only to provide or improve the customer-facing features for which the Customer granted access; are not sold; are not used for generalized AI or machine-learning training or cross-customer benchmarking; and are transferred to service providers or accessed by people only in circumstances permitted by the applicable Google policy.
6.2 Customer-Connected Instagram Data. Customer-connected Instagram Business data is used to provide the connected Customer's own analytics, scoring, and reporting experience. We do not resell Customer-connected Instagram data as a standalone dataset. Collection is designed to stop when the Customer disconnects the source, deletes the relevant brand, or the source provider invalidates the access token. We also process deletion and disconnection requests in accordance with applicable law and source-provider requirements.
We may disclose personal data to the following categories of recipients for the purposes described in this Policy:
We may disclose Aggregated Data or De-Identified Data that does not reasonably identify an individual or customer, subject to applicable law and the AI and Data Policy.
Subprocessor and Service-Provider Transparency. Hanna Creative maintains a current Service Providers, Subprocessors & Data Sources Notice identifying material providers and their functions. Provider roles vary by service and data category, and not every listed provider is a processor of Customer Personal Data. Material subprocessor changes will be handled as described in Schedule 1 to the Terms, including notice and objection rights where applicable.
The current Studio Halo application does not deploy advertising pixels, analytics tags, session-replay tools, customer-data platforms, or integrated support-desk trackers. It uses first-party session and CSRF technologies required for authentication and security, an optional user-elected persistent-login cookie, and a first-party theme preference. The application currently requests Google Fonts from Google servers, which can disclose the visitor's IP address to Google. Stripe-hosted checkout occurs on Stripe's domain. Transactional email is delivered through SendGrid; any optional open/click tracking must be configured and disclosed consistently with applicable law before use.
Current cookie and similar-technology categories include strictly necessary first-party session and CSRF technologies; optional functional first-party technologies for persistent login and theme preferences; and the third-party Google Fonts request described above, which is not used for advertising.
Hanna Creative does not currently use personal data for cross-context behavioral advertising and the reviewed application does not deploy advertising pixels or ad-tech tags. Where applicable law requires consent before placing or accessing a non-essential cookie or similar technology, Hanna Creative will obtain that consent before activating the technology. Browser and product controls may be provided as appropriate. These statements will be updated before tracking practices materially change.
Some browsers transmit "Do Not Track" signals. Because there is no uniform standard, the Services may not respond to all such signals. We will recognize opt-out preference signals, including Global Privacy Control, where required by applicable law and relevant to our processing.
Hanna Creative does not currently sell personal data for money. Hanna Creative also does not currently "share" personal data for cross-context behavioral advertising or process personal data for targeted advertising as those terms are defined by applicable U.S. state privacy laws. Other jurisdictions may define sale, sharing, direct marketing, or targeted advertising differently. We will provide notices, consent or opt-out methods, and contract restrictions required by applicable law before materially changing these practices.
Disclosing personal data to service providers, processors, customer-directed integrations, or transaction counterparties for the purposes described in this Policy is not intended as a sale of personal data. Legal definitions vary by jurisdiction, and individuals may submit an opt-out request as described below if they believe a right applies.
We retain personal data for as long as reasonably necessary for the purposes described in this Policy, taking into account account status, source restrictions, legal requirements, security, and technical operations. Current application logs rotate daily and are retained for 14 days. Top-page snapshot records older than approximately 190 days are pruned weekly. Other active Customer Data is generally retained for the life of the Customer account or brand unless a shorter source-specific or legal rule applies.
On a connected-source disconnect or brand deletion, the current application is designed to destroy the locally stored OAuth credential and stop future scheduled collection for that source or brand. Brand deletion begins with an immediate soft-delete that makes associated records unavailable through the application, followed by administrative hard deletion according to Hanna Creative's operational retention process. Deleting an individual user login is not necessarily the same as deleting a Customer organization or brand, particularly where an organization has multiple Authorized Users. To request deletion of a brand or associated Customer-controlled data, use the brand/source controls or submit a privacy request. Backup copies, if maintained, and legal, billing, security, fraud-prevention, or dispute records may persist for limited periods where permitted or required.
11.1 Safeguards. We use reasonable administrative, technical, organizational, and physical safeguards designed to protect personal data. Verified current application controls include invite-only registration, email verification, bcrypt password hashing, expiring magic links, role-based customer permissions, HTTPS and TLS for third-party connections, CSRF protection, signature verification for Stripe webhooks, logical brand-level tenant segregation in a shared database, daily rotating logs, and Sentry configured with PII sending disabled and SQL parameter bindings excluded. Payment-card data is collected by Stripe-hosted checkout rather than Hanna Creative infrastructure. Additional organizational safeguards and incident-response measures are maintained or implemented as required by applicable law and contractual commitments. No system is completely secure.
11.2 Applicable Security and Local Requirements. Our security, retention, vendor-management, and incident-response practices are designed to address laws that apply to our processing and role. This includes applicable requirements of Massachusetts and Rhode Island law when protected information concerning residents of those states is processed, as well as comparable requirements in other jurisdictions. Operational compliance depends on the controls actually implemented and maintained; this Policy is not a certification that every law applies or that no security incident will occur.
11.3 Incident Response. We investigate suspected security incidents, take reasonable containment and remediation measures, and provide notices to customers, affected individuals, and regulators as required by applicable law and contract. Notification duties vary by jurisdiction, data type, and processing role; we apply the requirements that govern the affected information and our role.
You are responsible for protecting account credentials, using secure devices and networks, selecting appropriate administrators, and promptly notifying us of suspected unauthorized access.
Depending on where you reside, our role, and applicable exceptions, you may have rights to:
Jurisdiction-Specific Rights. Depending on the law that applies, additional rights may include restriction or objection to processing, withdrawal of consent, opt-out from certain profiling or direct marketing, appeal rights, and the right to complain to a data-protection authority or regulator. Under the EU GDPR and UK GDPR, where applicable, rights may include access, rectification, erasure, restriction, portability, objection, withdrawal of consent, and complaint to a supervisory authority. U.S. state rights apply only when the relevant statute, thresholds, data, role, and exceptions apply. We will provide supplemental notices or request methods where required.
To submit a privacy request, use the legal/privacy contact method designated on the Studio Halo website or within the Services and identify the request as a "Privacy Request." Describe the request and your relationship to Studio Halo. We may ask for information needed to verify identity and authority. An authorized agent may submit a request where permitted, subject to verification and proof of authority. We will respond within the time required by applicable law.
We may provide a supplemental state-specific notice or notice at collection when required by applicable law. The availability of a particular right depends on the law that applies, the nature of the data, Hanna Creative's role, and any statutory exception, including exclusions that may apply to business-contact or customer-controlled information.
To unsubscribe from marketing emails, use the unsubscribe link or contact us. You may still receive service, security, billing, and transactional messages. You may manage cookies using the methods described in Section 8.
13.1 Customer-Controlled Data. If your personal data was submitted to the Services by a Studio Halo customer, that customer may be the entity responsible for responding to your request. Please contact the customer directly. If you submit a request to us about customer-controlled data, we may refer the request to the customer and assist as required by our agreement and applicable law.
Customers must not use the Services to collect or process personal data in a way that violates privacy, marketing, communications, intellectual property, or other laws. Customers are responsible for their own privacy notices and consent mechanisms.
13.2 Indirectly Collected Information; Correction and Removal Requests. If Hanna Creative independently obtained professional, business, media, website, social-media, news-metadata, or other information about you from a public, licensed, commercial, or third-party source, you may request access, correction, deletion, objection, or source review through the legal/privacy contact method designated on the Studio Halo website or within the Services and identify the request as a "Data Correction or Source Challenge." Please identify the information, the relevant person or organization, the reason for the request, and supporting documentation. We may verify identity or authority, consult the source, correct or remove information where appropriate, and notify you of action taken as required by applicable law. We may retain information where permitted or required by law. Correcting source information may result in recalculation of a Halo Score or other output, but this process does not require disclosure of proprietary models, weights, source arrangements, methodologies, or trade secrets.
13.3 EEA/UK Indirect-Collection Notice. If the EU GDPR, UK GDPR, or a materially similar law applies to personal data we obtained indirectly, we will provide the information required by the applicable indirect-collection rule, including the categories and sources of the data, purposes, legal basis, recipients, retention criteria, and applicable rights, unless a lawful exception applies. Where legitimate interests are relied upon, we will assess necessity and balance those interests against the rights and reasonable expectations of affected individuals. A public-source label is not itself a substitute for that analysis.
The Services are not directed to children under 18, and we do not knowingly collect personal data directly from children. If you believe a child has provided personal data to us, use the legal/privacy contact method designated on the Studio Halo website or within the Services. We will investigate and delete the information where required.
Hanna Creative is based in the United States. Personal data may be processed in the United States and in other countries or regions where disclosed service providers or source platforms operate. If the EU GDPR, UK GDPR, Swiss data-protection law, or another transfer regime applies, Hanna Creative will use a lawful transfer mechanism appropriate to the actual parties, roles, and data flow, such as an adequacy mechanism, the EU Standard Contractual Clauses, the UK International Data Transfer Agreement or UK Addendum, or another recognized safeguard. Required transfer assessments, processor terms, local representatives, or data-protection contacts will be completed when the applicable facts require them; website accessibility alone does not automatically determine territorial scope. You may contact us for information about safeguards relevant to your data.
15.1 AI Transparency. Where applicable law requires individuals to be informed that they are interacting with an AI system, or requires AI-generated or manipulated content to carry a notice or machine-readable mark, Hanna Creative will provide or preserve the required transparency measure for the applicable Service. Article 50 of the EU AI Act applies to certain AI transparency obligations from August 2, 2026; the applicability of any specific obligation depends on the role, feature, output, and market in which the Service is offered.
The Services may link to or integrate with third-party websites and services. This Policy does not govern a third party's processing. Review the third party's terms and privacy notice before providing data or enabling an integration. We are not responsible for third-party privacy or security practices.
We may update this Policy to reflect changes in law, technology, the Services, vendors, or our practices. We will identify the updated date and provide additional notice of material changes where required. Changes ordinarily apply prospectively. We will not rely on a quiet or retroactive policy change to materially broaden the use of previously collected identifiable or confidential Customer Data for unrelated generalized AI training; where applicable law or our prior commitments require it, we will obtain affirmative consent or another valid authorization before the broader use.
Questions, concerns, and privacy requests may be directed to Hanna Creative through the legal/privacy contact method designated on the Studio Halo website or within the Services. If applicable law requires Hanna Creative to appoint a data-protection officer, EU/UK representative, or other local privacy contact, the applicable details will be published in this Policy or a jurisdiction-specific supplement.
| Legal entity | Hanna Creative Co. |
|---|---|
| Contact method | Use the legal/privacy contact method designated on the Studio Halo website or within the Services. A current business mailing address is available through that channel. |