Skip to content
NTT DATA

Privacy

This notice covers Watermarking Studio's detection and marking tools. It is written in plain language; the contact block at the end is the authoritative point of escalation.

What we process

When you run a detection or marking job, the file you submit (image, audio, video, or text) is sent to our service and processed to read or embed a watermark. We only process what is needed to complete the job you asked for.

How long we keep it

It depends on what you asked us to do:

  • Detection: your file is processed in a temporary workspace and deleted before the response is returned. We never retain detection uploads. We do keep a technical detection log — a checksum of the file, the detection outcome and its metrics, and (when a watermark is found) its identifier — so watermark provenance can be traced.
  • Marking: the original file and the generated outputs (the marked file and its sidecar files) are kept so you can download and inspect the results. In hosted environments they are deleted automatically after the configured retention period; a registry entry is retained for provenance: checksums, the watermark identifier, timestamps, the original filename, and the marking options you selected (including any disclosure text or metadata fields you filled in) — never the file bytes themselves.

What we log

We log operational metadata (job status, timing, and error class such as “unsupported format” or “timeout”) plus a provenance record for each job: a checksum of the file, the outcome and its metrics, and any watermark identifier extracted or embedded; for marking jobs also the original filename and your chosen marking options. We never log or retain the file contents themselves.

Cookies

Watermarking Studio itself sets no cookies. Where a deployment is placed behind Microsoft Entra sign-in, the sign-in layer sets a small number of strictly necessary cookies: a short-lived Nonce cookie while you are being redirected to sign in, which protects that redirect from being forged, and a session cookie afterwards so that you stay signed in between requests. Both are strictly necessary — without them you could not sign in, or would be asked to on every page — so they are set without consent. Note that the first of them is set as soon as you reach a gated deployment, before and whether or not you sign in.

No analytics, advertising or tracking cookies are set. If that ever changes, this notice will be updated and a consent banner added before any non-essential cookie is set.

Your rights

Under the GDPR and equivalent regimes, you have the right to access, correct, erase, restrict, or object to the processing of your personal data, and the right to data portability and to lodge a complaint with a supervisory authority. For detection jobs we retain no uploads — only the technical detection log described above, and these rights apply to those log entries. For marking jobs they apply to the retained files and outputs described above — and in all cases to any contact information you share with us directly.

Contact

No data controller is configured for this deployment, so there is no contact point to publish here yet. This is a pre-launch environment; if you reached it unexpectedly, please contact whoever gave you the link.