Trust Center

Terms of Service

Effective date: 2026-10-01

Version: 2.0.1

These Terms of Service (the "Terms") govern your access to and use of the SplitLoom website at https://www.splitloom.app, the SplitLoom processing service, the Trust Center, support communications, and any outputs returned by the Service (together, the "Service"). By accessing or using the Service, you agree to these Terms.

If you use the Service on behalf of a company, brand, studio, organization, or other entity, you represent that you have authority to bind that entity, and references to "you" in these Terms mean both you personally and that entity.

If you do not agree to these Terms, do not use the Service.

1. Who we are

The Service is operated by Firmacor Systems Ltd ("Firmacor," "we," "us"), an Israeli company (Israeli company registration number 517299871), with its registered office at 5 Tuval Street, Tel Aviv-Yafo 6789717, Israel, c/o Naschitz Brandes Amir & Co. You can reach us at:

  • General support: support-splitloom@firmacor.com
  • Legal, privacy, security, and intellectual-property notices: legal@firmacor.com

2. What SplitLoom is

SplitLoom is a public web service that adapts a single transparent-background logo file into two transparent 1024 × 1024 PNG output assets - one optimized for white-shirt surfaces and one optimized for dark-shirt surfaces. The Service is designed to help apparel design, sample preview, and small-batch production workflows.

The Service is automated and deterministic. It assists, but does not replace, human judgment, legal clearance, brand review, printer specifications, manufacturing quality control, or any other review you may apply before relying on the outputs.

3. Free of charge

The Service is currently provided at no charge. We may introduce paid features in the future. If we do, we will post notice on the Trust Center with an effective date, and any new fees will apply only from that effective date forward.

4. Anonymous use

SplitLoom does not require account creation, sign-in, payment, or identity verification. Your use of the SplitLoom processing service is anonymous from our perspective: we receive only the request data needed to process your upload, as described in our Privacy Policy. We do not maintain accounts, profiles, or user records.

5. Eligibility and authorized use

You may use the Service only if you are legally able to enter into a binding agreement and only for lawful purposes. You must not be a child under the minimum applicable digital-services age in your jurisdiction (13 in the United States and the United Kingdom; 16 in the European Union/EEA, except where national law has set a lower age between 13 and 16).

You may use the Service only with content you own or are authorized to submit and process. You are responsible for ensuring that your use of the Service, and any output you rely on, complies with applicable law, contracts, platform rules, print-vendor requirements, export and sanctions restrictions, and intellectual-property obligations.

6. Acceptable use

You may not use the Service to:

  • upload content you do not own or are not authorized to use;
  • upload unlawful, infringing, deceptive, defamatory, abusive, harassing, hateful, or otherwise harmful content;
  • submit confidential, highly sensitive, or regulated data - including government identifiers, financial-account credentials, health data, biometric data, genetic data, data revealing religious, political, or ethnic affiliation, or children's data - that is not reasonably necessary for this type of image-processing service;
  • probe, scan, scrape, reverse engineer, decompile, disassemble, overload, or disrupt the Service or related infrastructure;
  • bypass or attempt to bypass technical limits, safety controls, access restrictions, rate limits, or anti-abuse measures;
  • submit malicious, exploit-oriented, corrupted, or hostile payloads (including oversized files, decompression bombs, and hostile SVG content);
  • use the Service to facilitate fraud, impersonation, counterfeiting, infringement, hate, harassment, or any unlawful activity;
  • use the Service in any way that could expose Firmacor to legal or regulatory liability.

We may refuse to process any request that, in our reasonable judgment, violates these Terms or threatens the Service.

7. Your content

You retain all rights you have in the content you submit to the Service.

You grant Firmacor a limited, non-exclusive, revocable license to receive your submitted content, hold it in transient runtime memory, reproduce it, transform it, and produce and return the requested adapted outputs - solely to perform the single processing request you made. That license terminates when the request completes.

We do not use your content (or the outputs) to train any model. We do not retain your content after the request completes. We do not share your content with any third party other than our hosting infrastructure provider acting as a processor on our behalf, as described in our Privacy Policy.

You represent and warrant that you have all rights, permissions, consents, and authority needed to submit that content and authorize its processing. Firmacor does not independently verify ownership, chain of title, trademark clearance, licensing scope, consent, or legal availability of any submitted logos, marks, or artwork.

Where these Terms state that we do not retain, store, or share content, they refer to content you upload to the SplitLoom processing service. We handle email you send us, including any attachments, as described in our Privacy Policy.

8. Generated outputs

For each valid input, the Service returns two transparent 1024 × 1024 PNG outputs - one optimized for white-shirt surfaces and one optimized for dark-shirt surfaces - together with a machine-readable processing report and manifest.

You own the outputs and may use them as you wish, subject to the rights chain of the input you submitted (we do not grant rights you did not already have). We claim no ownership in the outputs.

The outputs are produced automatically by deterministic image-processing logic. They may help with contrast, visibility, recentering, and apparel-adaptation workflows, but they are not guaranteed to be accurate in every case, production-ready or print-ready in every workflow, legally cleared, non-infringing, or brand-approved, or suitable for every garment, fabric, print method, substrate, ink system, or commercial context.

You are solely responsible for reviewing the outputs before relying on them in design, production, fulfillment, publishing, branding, or commerce.

9. Our intellectual property

Except for your rights in submitted content and resulting outputs, Firmacor and its licensors retain all rights, title, and interest in and to the Service, the SplitLoom website, the software and processing logic behind the Service, the SplitLoom and Firmacor names and logos, the visual design, the documentation, and all related intellectual property. These Terms do not transfer to you any ownership rights in the Service itself.

10. Service availability

The Service is provided "as offered" and "as available." It may be rate-limited, throttled, degraded, delayed, briefly unavailable, or overloaded. Requests may be rejected because of format, size, transparency, dimension, pixel-area, security, operational, abuse-prevention, or capacity limits, or because the Service is busy.

We may modify, suspend, or discontinue any part of the Service at any time, with or without notice, subject to applicable law. Support is offered on a best-effort basis through support-splitloom@firmacor.com.

11. Suspension and termination

We may block, throttle, restrict, or refuse access from sources that violate these Terms, abuse the Service, threaten its integrity, or create security, legal, or operational risk for us, our users, or third parties.

Because the Service does not maintain accounts, there is nothing for you to cancel. You may stop using the Service at any time by closing your browser or otherwise discontinuing access.

12. Communications from us

We do not send marketing emails, SMS, or push notifications. We do not maintain a marketing list and do not engage in outbound marketing. The only emails you may receive from us are direct replies to a support inquiry you initiate.

13. Privacy

Our handling of personal data is described in our Privacy Policy, which is published alongside these Terms on the Trust Center and forms part of the agreement between you and us. By using the Service, you acknowledge that you have read it.

14. Security

We use industry-standard TLS to protect data in transit between your browser and our servers. The Service is designed not to durably store uploaded artwork or generated outputs. Our backend uses defensive parsing for SVG and raster uploads to mitigate common attacks (such as XML external-entity attacks and image decompression bombs). API responses carry Cache-Control: no-store to prevent intermediate caching of result bundles. Our build-time audit forbids cookies and browser-side persistence in the public website code.

15. Disclaimers

To the maximum extent permitted by applicable law, the Service is provided "as is" and "as available," without warranties of any kind, whether express, implied, statutory, or otherwise. We disclaim all warranties of uninterrupted or error-free operation, merchantability, fitness for a particular purpose, non-infringement, title, accuracy, completeness, and output suitability.

Nothing in these Terms excludes or limits any right or remedy that cannot lawfully be excluded or limited under applicable law, including under European Union, United Kingdom, or other consumer-protection statutes.

16. Limitation of liability

To the maximum extent permitted by applicable law, Firmacor's aggregate liability for any and all claims arising out of or related to the Service - whether in contract, tort, statute, or otherwise - is limited to the greater of: (a) the total fees you paid us for the Service in the twelve months immediately preceding the claim, or (b) one hundred United States dollars (USD 100). For users of the Service at no charge, the cap is USD 100.

To the maximum extent permitted by applicable law, Firmacor and its operators, service providers, and licensors will not be liable for any indirect, incidental, consequential, special, exemplary, or punitive damages, or for any loss of profits, revenue, business, goodwill, data, production opportunity, or commercial opportunity arising out of or relating to the Service, even if advised of the possibility of those damages.

Nothing in this Section excludes or limits liability that cannot lawfully be limited under applicable law, including liability for gross negligence, willful misconduct, personal injury, or fraud where applicable.

17. Indemnification

To the maximum extent permitted by applicable law, you will defend, indemnify, and hold harmless Firmacor and its operators, service providers, and licensors from and against any claims, liabilities, losses, damages, judgments, costs, and expenses (including reasonable legal fees) arising out of or relating to:

  • your submitted content;
  • your use or misuse of the Service;
  • your violation of these Terms;
  • your violation of applicable law or the rights of another person or entity.

Nothing in this Section requires you to indemnify Firmacor for liability that cannot lawfully be allocated to you under applicable law.

18. Intellectual-property reporting

If you believe content submitted to the Service has infringed your copyright or other intellectual-property right, send a notice to legal@firmacor.com that includes:

  • identification of the copyrighted work or other right you claim has been infringed;
  • identification of the specific content or request you claim is infringing, with enough detail to enable us to identify it;
  • your full contact information (name, postal address, email, and telephone number);
  • a statement that you have a good-faith belief that the identified use is not authorized by the rights-holder, its agent, or the law;
  • a statement, under penalty of perjury where applicable, that the information in the notice is accurate and that you are authorized to act on behalf of the rights-holder;
  • your physical or electronic signature.

Because the Service is designed not to durably store user-submitted content, our response is principally preventative: we may decline to process future requests from the source you identify (to the extent we can identify it), and we may block access from sources that repeatedly submit infringing content. We may also refer matters to law enforcement or pursue any other remedy available to us.

19. Notice and action - illegal content

If you believe content submitted to the Service is illegal under applicable law (including, for users in the European Union, under the Digital Services Act), you may send a notice to legal@firmacor.com. We will review it promptly and respond in accordance with applicable law. Because the Service does not durably store user-submitted content, our response is principally preventative, as described in Section 18.

20. Feedback

If you send us feedback, suggestions, ideas, comments, or other input about the Service ("Feedback"), you grant us a perpetual, irrevocable, worldwide, royalty-free, sublicensable license to use the Feedback for any purpose, without obligation or attribution. This Section does not grant us any rights in your submitted content or outputs beyond those granted elsewhere in these Terms.

21. Governing law

These Terms are governed by the laws of the State of Israel, without regard to its conflict-of-law principles, except where the mandatory consumer-protection law of your country of residence grants you different or additional rights that cannot be displaced by contract.

22. Forum and no arbitration

Any dispute arising out of or relating to these Terms or the Service will be brought in the competent courts of Tel Aviv-Yafo, Israel, and you and we submit to the exclusive jurisdiction of those courts, except where the mandatory consumer-protection law of your country of residence grants you a right to bring proceedings in the courts of your country of residence.

We do not impose mandatory arbitration. There is no arbitration clause, no class-action waiver, and no pre-dispute waiver of court jurisdiction in these Terms.

23. European Union consumer rights

If you are a consumer resident in the European Union or the European Economic Area, nothing in these Terms limits any mandatory consumer-protection right you have under the law of your country of residence, including any right to bring an action in the courts of your country of residence. The European Commission's Online Dispute Resolution platform is available at https://ec.europa.eu/consumers/odr/; we do not commit to using that platform but you may use it to learn about your dispute-resolution options.

24. Changes to these Terms

We may update these Terms from time to time. The current version, with its effective date, is published on the Trust Center and is the operative version. For material changes, we will post a visible notice on the website for a reasonable period before the change takes effect. Your continued use of the Service after the effective date of the change indicates acceptance of the updated Terms, except where mandatory applicable law requires affirmative consent.

25. General

  • Entire agreement. These Terms, together with the Privacy Policy, constitute the entire agreement between you and Firmacor concerning the Service, and supersede any prior agreements between you and us on this subject.
  • Severability. If any provision of these Terms is held unenforceable, the remaining provisions remain in effect.
  • No waiver. Our failure to enforce any provision does not waive our right to enforce it later.
  • Assignment. You may not assign or transfer your rights under these Terms without our prior written consent. We may assign these Terms in connection with a corporate transaction or to an affiliate, with notice.
  • Electronic communications. You agree that we may communicate with you electronically through the Service or by responding to your email.
  • Survival. Sections concerning your content, our intellectual property, disclaimers, limitation of liability, indemnification, governing law, forum, and changes survive any cessation of your use of the Service.

26. Contact

For general support: support-splitloom@firmacor.com.
For legal, privacy, security, or intellectual-property notices: legal@firmacor.com.
Telephone: +972 55 999 6565.
Postal address: Firmacor Systems Ltd, 5 Tuval Street, Tel Aviv-Yafo 6789717, Israel, c/o Naschitz Brandes Amir & Co.

Privacy Policy

Effective date: 2026-10-01

Version: 2.0.1

This Privacy Policy describes how Firmacor Systems Ltd ("Firmacor," "we," "us") processes information in connection with the SplitLoom website at https://www.splitloom.app, the SplitLoom processing service, the Trust Center, and support communications (together, the "Service"). It does not govern third-party websites, platforms, or services that may link to SplitLoom or that you may use outside the Service.

1. Who we are

Firmacor Systems Ltd is an Israeli company (Israeli company registration number 517299871), with its registered office at 5 Tuval Street, Tel Aviv-Yafo 6789717, Israel, c/o Naschitz Brandes Amir & Co.

For privacy, legal, security, or intellectual-property questions and requests: legal@firmacor.com.

For general support: support-splitloom@firmacor.com.

Because this processing is limited and occasional, it falls below the thresholds that require a Data Protection Officer or an EU, UK, or Israeli representative, so none has been appointed. Direct any privacy matter to legal@firmacor.com.

2. Information we process

Depending on how you use the Service, we may process the following categories of information:

  • Uploaded image content - the transparent-background logo file you submit for processing. Held in transient runtime memory and a request-scoped temporary working directory during the processing of your single request. Not durably stored.
  • Generated output content - the two transparent 1024 × 1024 PNG files (white-shirt and dark-shirt variants), along with the processing report and manifest, that the Service returns to you. Held in transient runtime memory during the request and then returned to your browser. Not durably stored.
  • User-supplied filename - the basename of the file you uploaded (for example, mylogo.png). Used to name the output files and to label log entries.
  • Operational request metadata - request identifiers, timestamps, request paths, file sizes, processing times, response status codes, and error codes. Recorded in our backend logs.
  • Edge request metadata - your IP address, User-Agent string, and standard network metadata captured at the AWS CloudFront and AWS Lambda Function URL layers as part of normal infrastructure operation. If you enter the bare domain splitloom.app, our domain provider first receives the same technical data in order to redirect you to www.splitloom.app.
  • Inbound support correspondence - your email address, any name you provide, and the content of your message (including attachments), when you contact us at support-splitloom@firmacor.com or at another Firmacor email address.
  • Transient in-browser state - temporary state your browser holds while you are using the Service (such as object URLs for the result images and minimal application state). Held only in your browser tab; not transmitted to us.

We do not collect accounts, profiles, marketing-list emails, behavioral profiles, segments, scores, or other inferences about you. We do not knowingly process special-category (sensitive) personal data.

3. Sources

We obtain information from the following sources:

  • Directly from you - when you upload a file or send us an email.
  • Automatically from your browser and device - when you load the website or call our API, your browser sends standard HTTP request metadata (IP, User-Agent, request URL).
  • From our hosting and delivery infrastructure - Amazon Web Services (AWS) operates the static site delivery (CloudFront), the processing backend (Lambda), and the operational log capture (CloudWatch Logs). The processing backend produces the operational log records described in Section 7.

4. Purposes

We process the information described above to:

  • receive and validate the file you upload;
  • generate and return the requested adapted outputs;
  • operate, secure, monitor, troubleshoot, and improve the reliability of the Service;
  • detect and mitigate abuse, misuse, hostile payloads, and other operational and security risks;
  • respond to support inquiries you send to us and keep a record of that correspondence;
  • comply with applicable law and respond to lawful requests.

We do not use your information for marketing, advertising, profiling, behavioral analysis, model training, or any other purpose beyond what is described in this Policy.

5. Legal bases (EU / UK GDPR)

If the GDPR or UK GDPR applies to the processing of your personal data, our legal bases are as follows:

PurposeLegal basis
Receiving and processing your upload to return the adapted outputsArticle 6(1)(b) - performance of a contract / pre-contractual measures (you make a service request; we perform it)
Operational logging, reliability, security, and abuse-mitigationArticle 6(1)(f) - legitimate interests (operating a public web service requires basic operational telemetry; the data is minimal and the retention is short)
Edge metadata captured by our hosting and delivery infrastructure (AWS), and received by our domain provider (GoDaddy) for bare-domain redirectsArticle 6(1)(f) - legitimate interests (normal infrastructure operation)
Responding to support inquiries you initiateArticle 6(1)(b) / 6(1)(f) - performance of a contract and legitimate interests
Keeping support correspondence as ordinary business recordsArticle 6(1)(f) - legitimate interests
Complying with applicable law and lawful requestsArticle 6(1)(c) - legal obligation

No purpose described in this Policy relies on consent as the legal basis. We do not need or seek your consent for any of the processing described here, because none of it is consent-based under GDPR. If at any point we introduce a feature that does rely on consent (for example, optional analytics or marketing), we will request it separately and you will be able to withdraw it.

6. Zero durable retention for uploaded artwork and outputs

SplitLoom is designed not to durably retain uploaded source artwork or generated output assets after a request completes.

In ordinary operation, your uploaded file is held in Lambda function memory and in a request-scoped temporary working directory under Lambda's local /tmp storage. Both are cleaned up before the response is returned, including in failure paths. Generated outputs are assembled into the response in memory and are not written to any persistent store. The final zip response is delivered to your browser; we do not retain a server-side copy.

This zero-retention statement concerns durable server-side retention. It does not mean that no temporary technical handling occurs during processing - temporary in-memory buffers and request-scoped temporary files are part of normal request handling. It also does not apply to copies you keep yourself after downloading the result.

7. Logs, diagnostics, and edge access records

We log operational metadata for reliability, security, and abuse-mitigation. Logs do not contain raw uploaded image bytes, base64 request payloads, multipart bodies, or output image bytes. Our operational guidance and test suite enforce this rule.

Operational metadata in our backend logs may include items such as request identifiers, file names (basenamed; sanitized to alphanumeric characters and ./_/-), request size, response size, timing data, processing status, and error or rejection codes. We retain these logs for approximately 30 days.

Amazon CloudFront, which delivers the website, captures standard infrastructure-level access metadata (IP address, User-Agent, request URL, status, byte size, edge timestamp) as part of normal infrastructure operation, and our domain provider receives the same data for visits to the bare domain splitloom.app. We do not maintain our own access logs of the website, so we do not retain this data ourselves. The AWS Lambda Function URL that receives your uploads also captures access metadata, including your IP address and User-Agent string; our backend logs, described above, do not record them, and we do not retain them ourselves.

If you choose to email us, we receive your email address, any name you provide, and the content of your message (including attachments). We keep messages you send us for up to 24 months after our last exchange with you, unless we need to keep them longer to handle an ongoing matter or to establish, exercise, or defend a legal claim. You can request deletion via legal@firmacor.com, subject to legal hold and good-faith retention.

8. Browser storage and session behavior

SplitLoom does not use cookies, localStorage, sessionStorage, IndexedDB, or service workers. Our build-time audit script enforces this in the public website code.

The website creates only transient browser object URLs (URL.createObjectURL) to display and download the result images. These are revoked when you close the tab, refresh the page, navigate away, or click "go home" / "new project."

Because we do not use cookies or other non-essential browser storage, we do not display a cookie-consent banner and do not gather consent for cookies. There is no cookie-consent mechanism to manage.

9. Analytics, tracking, and advertising

We do not use first-party or third-party analytics, marketing pixels, advertising trackers, session-replay tools, or behavioral-advertising integrations. We do not track or measure individual user activity. Our operator-side server logs record only the structural metadata of each request (request identifier, byte sizes, processing time, response status), not the identity of the user who made it.

We do not sell or share personal information for advertising or any commercial third-party purpose.

10. Artificial intelligence and model training

The production SplitLoom Service does not use artificial-intelligence models, AI providers, or generative AI of any kind to deliver its output. The image-processing engine performs deterministic color and topology analysis (specifically, an OKLCH-based preservation-gated adaptive tournament).

We do not use your uploads or your outputs to train any model. We do not send your data to any external AI provider. We do not derive AI-based inferences about you.

If we add an AI feature in the future, we will update this Policy with an effective date and a visible site notice before the change takes effect.

11. Marketing communications

We do not maintain a marketing list, do not send marketing emails, do not send SMS or push notifications, and do not engage in any outbound marketing. The only emails you may receive from us are direct replies to a support inquiry you initiate.

12. Sharing and disclosures

We share information only with:

  • Service providers acting as processors on our behalf (see Section 13 - Subprocessors);
  • Legal and governmental recipients where disclosure is required or reasonably necessary to (i) comply with law, regulation, court order, subpoena, or other lawful process; (ii) prevent abuse, investigate incidents, or protect rights and the integrity of the Service; or (iii) respond to a verified claim of intellectual-property or other unlawful activity.

We do not sell personal information. We do not "share" personal information for cross-context behavioral advertising as defined under California law. We do not engage in targeted advertising. We do not run a data-broker business.

13. Subprocessors

We rely on the following subprocessors. Each acts as a processor on our behalf or as an independent service provider for narrowly-defined functions:

SubprocessorService providedCountry / RegionData processedTransfer mechanism (for EU/UK personal data)
Amazon Web Services, Inc. (AWS)Hosting, compute, storage, log retention, content delivery (CloudFront), and TLS certificate (ACM)United States (region us-east-1). Content delivery via the global AWS CloudFront edge network.Uploaded image content, generated output content, user-supplied filename, operational request metadata, and edge request metadata (see Section 2 - Information we process)AWS Data Processing Addendum incorporating the European Commission's Standard Contractual Clauses (Module 2, Controller-to-Processor) and the UK Addendum
Microsoft (Microsoft 365, Exchange Online)Handling email you send to usIsrael (current storage location)Your email address, name, and message contentAdequacy recognized for Israel by the European Commission (Commission Decision 2011/61/EU) and the United Kingdom; Microsoft's data-protection terms, incorporating the European Commission's Standard Contractual Clauses and the UK Addendum, for any transfer by Microsoft outside Israel
GoDaddy.com, LLC(a) DNS resolution for splitloom.app and www.splitloom.app, and redirecting splitloom.app to www.splitloom.app; (b) domain registration and DNS for firmacor.com (through which our Microsoft 365 mailboxes are provisioned)United States (GoDaddy headquarters); distributed for DNS resolution. Redirects via GoDaddy's forwarding service on a global network.Domain-name-system query data and domain registration records; technical connection data, including IP address, for visits to the bare domain splitloom.appGoDaddy's self-certification under the EU-US Data Privacy Framework and the UK Extension

We update this list when we add, remove, or change providers, and we re-version this Privacy Policy when we do.

We do not engage other subprocessors directly. Our hosting provider (AWS) maintains its own subprocessor management page that lists the providers AWS uses to operate its services, available at https://aws.amazon.com/compliance/sub-processors/. Microsoft publishes its data-protection terms at https://www.microsoft.com/licensing/terms/.

14. International data transfers

We are based in Israel, and the providers above process data in Israel, the United States, and other countries where their global networks operate. As a result, your personal data may be transferred to and processed in countries outside your country of residence.

  • Website connection data is processed by AWS at the CloudFront edge location that serves your request, usually one near you; the website itself is hosted in the United States.
  • Email you send us is currently processed by Microsoft in Israel.
  • EU and UK to Israel: the European Commission recognizes Israel as providing adequate protection (Commission Decision 2011/61/EU), and the United Kingdom has similarly recognized Israel as adequate. Any transfer by Microsoft outside Israel is covered by Microsoft's data-protection terms, which incorporate the EU Standard Contractual Clauses and the UK Addendum.
  • Transfers from Israel are made in compliance with the Israeli Privacy Protection (Transfer of Data to Databases Abroad) Regulations 2001.

The SplitLoom processing service is hosted in the United States (AWS region us-east-1). If you upload a file from the European Union/EEA, the United Kingdom, Israel, or another country, your request data is transferred to the United States for processing.

For transfers from the EU/EEA to the United States via our AWS hosting, we rely on the AWS Data Processing Addendum, which incorporates the European Commission's Standard Contractual Clauses (Module 2). For transfers from the United Kingdom to the United States, we rely on the UK Addendum to those Standard Contractual Clauses. Any transfer from Israel to the United States via our AWS hosting is covered by the same AWS contractual safeguards described above. For GoDaddy's DNS resolution and bare-domain redirects, we rely on the EU-US Data Privacy Framework and the UK Extension, under which GoDaddy is self-certified.

You can request more information about the transfer mechanisms used, or copies of the relevant clauses, by contacting legal@firmacor.com.

15. Your privacy rights - general

Subject to applicable law and to the practical limits of a stateless, no-account Service, you have the following rights:

  • Right to information. This Policy is the principal disclosure. You may also contact us with specific questions.
  • Right of access. You may ask us what information we hold about you and request a copy. Because we do not durably retain uploaded images or generated outputs, and because requests are processed anonymously, our ability to retrieve specific request-level data is limited; we can usually retrieve only support correspondence, log entries within retention, and structural metadata identifiable by time window.
  • Right to rectification. You may ask us to correct inaccurate information we hold.
  • Right to erasure ("right to be forgotten"). You may ask us to delete information we hold about you. Because uploaded images and outputs are not durably retained, this right has limited practical application to processing data; it applies most clearly to support correspondence. We may decline an erasure request to the extent retention is required by law or for legal-hold purposes.
  • Right to restrict processing. You may ask us to restrict processing of your information; in practice, our processing is limited to what's needed to perform the Service and to log operational metadata.
  • Right to data portability. You may request your information in a portable format where applicable; in practice, the limited per-user data available is your support correspondence and log entries that match your contact information.
  • Right to object. You may object to processing based on legitimate interests; we will review such objections promptly.
  • Right not to be subject to a decision based solely on automated processing. We do not make any automated decisions about you that produce legal or similarly significant effects (see Section 16 - Automated decision-making).
  • Right to lodge a complaint with a supervisory authority (described in the region-specific sections below).

To exercise any of these rights, contact legal@firmacor.com. We may need to verify your identity (or the connection between you and a specific request or correspondence) to act on a request.

16. Automated decision-making

We do not use automated decision-making (including profiling) to make decisions about you that produce legal or similarly significant effects. The image-processing engine performs deterministic image transformations and does not draw inferences about you as a person.

17. California users - CCPA/CPRA rights

This Section applies if you are a California resident.

Categories of personal information. The categories of personal information we collect about California consumers are identifiers (IP address; your email address and any name you provide, if you contact us; the basename of your uploaded file, if it contains a name), internet/network activity (request metadata), and the contents of support correspondence (if you contact us). The categories of sources are described in Section 3, the categories of recipients in Sections 12-13.

Sensitive personal information. We do not collect or process sensitive personal information (as defined under California law). See Section 23 for our affirmative posture.

Purposes. Described in Section 4.

Sale and sharing. We do not sell personal information. We do not share personal information for cross-context behavioral advertising. We do not have a "sale" or "share" to opt out of.

Targeted advertising. We do not engage in targeted advertising.

Your California rights include:

  • Right to know what categories of personal information we collect, the sources, the purposes, and the categories of recipients, and to request a copy of the specific pieces of personal information we collect about you.
  • Right to correct inaccurate personal information.
  • Right to delete personal information, subject to legal exceptions.
  • Right to opt out of sale or sharing. (We do not sell or share; this right is honored by default.)
  • Right to limit the use of sensitive personal information. (We do not process sensitive PI for purposes that would trigger this right.)
  • Right to non-discrimination for exercising these rights.
  • Right to designate an authorized agent to act on your behalf.

Opt-out preference signals. We honor recognized opt-out preference signals such as the Global Privacy Control where required.

To exercise any California right, contact legal@firmacor.com.

18. Other US states - privacy rights

If you are a resident of Colorado, Connecticut, Virginia, Texas, Utah, Oregon, Tennessee, Montana, Iowa, Delaware, New Jersey, New Hampshire, Minnesota, Maryland, Rhode Island, Indiana, Kentucky, Nebraska, Arkansas, or another US state with a comprehensive privacy law, you may have rights similar to those described for California - typically including the rights to access, correct, delete, port, opt out of sale and targeted advertising, and not be subject to profiling for decisions producing legal or similarly significant effects.

We do not sell personal information, do not engage in targeted advertising, and do not profile for decisions producing legal or similarly significant effects. We honor universal opt-out preference signals (such as the Global Privacy Control) where required.

To exercise rights or learn more, contact legal@firmacor.com.

19. EU / EEA users - GDPR rights

This Section applies if you are in the European Union or the European Economic Area.

Your rights under the EU General Data Protection Regulation are described in Section 15 (universal rights). In addition, you have the right to lodge a complaint with your national supervisory authority. A list of EU/EEA supervisory authorities is available on the European Data Protection Board's website at https://www.edpb.europa.eu/about-edpb/about-edpb/members_en.

As noted in Section 1, we have not appointed a Data Protection Officer and have not designated an EU Representative under Article 27 of the GDPR. Our processing is occasional in nature; you can reach us about any privacy matter at legal@firmacor.com.

20. UK users - UK GDPR rights

This Section applies if you are in the United Kingdom.

Your rights under the UK GDPR are described in Section 15 (universal rights). The supervisory authority for UK personal data is the Information Commissioner's Office (ICO), available at https://ico.org.uk/.

As noted in Section 1, we have not designated a UK Representative under the UK GDPR. Our processing is occasional in nature; you can reach us about any privacy matter at legal@firmacor.com.

21. Israeli users - Privacy Protection Law

This Section applies if you are in Israel.

Firmacor Systems Ltd is an Israeli company and is the controller of personal data processed through the Service. Your rights under the Israeli Privacy Protection Law (PPL), including the rights of access and correction, and the rights under PPL Amendment 13 (effective 14 August 2025), apply to processing we perform.

Although we are an Israeli company, the SplitLoom processing service is hosted in the United States (AWS region us-east-1), so personal data processed through it is transferred from Israel to the United States. This transfer is permitted under the Privacy Protection (Transfer of Data to Databases Abroad) Regulations 2001 (as amended) for service-provider relationships and is covered by the AWS contractual safeguards described in Section 14.

Email you send us is currently processed by Microsoft in Israel.

The relevant supervisory authority for Israeli users is the Privacy Protection Authority (PPA), available at https://www.gov.il/en/departments/the_privacy_protection_authority.

We have not appointed a Privacy Protection Officer (PPO) under Amendment 13. Our processing does not meet the mandatory-appointment thresholds for that role.

22. Children

SplitLoom is not intended for or directed to children under 13. We do not knowingly design the public Service to solicit personal information from children under 13. If you believe a child under 13 has provided personal information to us, contact legal@firmacor.com and we will take appropriate steps to address the matter.

23. Sensitive personal information

SplitLoom is not designed to receive or process sensitive personal information - including government-issued identifiers, financial-account credentials, precise geolocation, racial or ethnic origin, religious or philosophical beliefs, trade-union membership, genetic data, biometric data for identification, health data, or data concerning sex life or sexual orientation.

Our Terms of Service prohibit submitting such data through the upload flow. The upload flow is freeform in the sense that you choose what image file to submit, and SplitLoom does not inspect the image semantically; in the unlikely event that an uploaded image contains sensitive personal information, the transient handling of the upload (held in Lambda memory for the duration of one request and then discarded) minimizes the exposure. We do not use any sensitive personal information for purposes that would trigger California's "right to limit the use of sensitive personal information" or analogous rights elsewhere.

24. Security

We use industry-standard TLS to protect data in transit between your browser and our servers. The Service is designed not to durably store uploaded artwork or generated outputs. Our backend uses defensive parsing for SVG and raster uploads to mitigate common attacks (such as XML external-entity attacks and image decompression bombs). API responses carry Cache-Control: no-store to prevent intermediate caching of result bundles. Our build-time audit forbids cookies and browser-side persistence in the public website code, and our operational guidance and test suite forbid raw image bytes from appearing in logs.

We have not appointed a CISO, dedicated security team, or external auditor for SplitLoom; security questions and incident reports may be sent to legal@firmacor.com.

Incidents and notification. If we become aware of a security incident that materially affects personal data we process, we will notify the relevant supervisory authority where required by applicable law (in the EU/EEA, within 72 hours under GDPR Article 33 where the incident is likely to result in a risk to the rights and freedoms of natural persons; in the UK and other jurisdictions, in accordance with applicable equivalents). Where the incident is likely to result in a high risk to data subjects, we will also communicate the incident to affected individuals to the extent reasonably possible - bearing in mind that the Service is anonymous and we may not have direct contact details for affected users; in such cases we will publish a notice on the Trust Center.

25. Changes to this Policy

We may update this Policy from time to time. The current version, with its effective date, is published on the Trust Center and is the operative version. For material changes, we will post a visible notice on the website for a reasonable period before the change takes effect. We may also provide notice through other means where appropriate.

26. Contact

For privacy, legal, security, or intellectual-property notices and requests: legal@firmacor.com.
For general support: support-splitloom@firmacor.com.
Telephone: +972 55 999 6565.
Postal address: Firmacor Systems Ltd, 5 Tuval Street, Tel Aviv-Yafo 6789717, Israel, c/o Naschitz Brandes Amir & Co.