0%

Privacy Policy

Home / Image gallery / Privacy Policy

Image Gallery — Privacy Policy

Last updated: 20 August 2026 This policy describes what data is processed by the ImageGallery Power BI visual and its associated services, developed by INVENIA SOLUTIONS SL (invenia), Tax ID ESB88009451, registered at C/ Bahía de Pollensa 5, 28042 Madrid, Spain ("invenia", "we"). Contact: support@invenia.es.

Summary

  • The visual collects no telemetry and no personal data, and does not send your report data to our servers except in the two export features described below, which are optional and which you switch on yourself.
  • The grid, the viewer, cross-filtering and the template designer run entirely inside Power BI and never leave it.
  • Three optional services touch our infrastructure, all with EU data residency: the image proxy (CORS), PowerPoint generation, and delivery of large PDF exports.

1. The visual inside Power BI

ImageGallery runs inside the Power BI sandbox. The grid, the viewer, cross-filtering and the template designer all work locally in your browser or in Power BI Desktop; none of that leaves Power BI. The visual includes no analytics, uses no cookies and transmits no usage data to invenia or to third parties. Licences purchased on Microsoft AppSource are validated by Microsoft; invenia receives no payment or account data from users. Gallery images are loaded by your browser directly from wherever they are hosted: those requests do not go through invenia.

2. Image proxy (CORS) — optional

If the server hosting your images does not allow direct browser access (CORS headers), the export can request images through our proxy on the Cloudflare network. In that case:
  • Only the public image URL is transmitted; never report data.
  • The proxy does not store images permanently. A technical cache of at most 24 hours reduces traffic; signed URLs (Azure SAS, S3 pre-signed links and the like) are not cached, so the image stops being served as soon as its signature expires.
  • The proxy keeps no logs of its own. Note, however, that the requested URL travels as a parameter and is recorded in the logs of our infrastructure provider (Cloudflare) for its standard retention period.
  • Processing takes place in European Union data centres.
  • You can avoid it entirely by enabling CORS on your image storage or by configuring your own proxy in the visual's settings.
It is used both with and without a licence, on purpose: restricting it to paying users would make the free export produce grey boxes whenever the origin server does not send CORS headers.

3. Cloud export services — optional

3.1 PowerPoint export

When exporting to PowerPoint, the visual sends our service:
  • Your corporate .pptx template, once, when the report author uploads it from the designer.
  • The URLs of the selected images.
  • The values of the report fields that the author mapped to the template placeholders. These are your report data, and they are needed to fill the placeholders — without them the slides would come out blank. No field you have not mapped is sent, nor any user, tenant or session identifier.
What is stored, and for how long:
  • The .pptx template is stored encrypted in the European Union (Cloudflare R2, EU jurisdiction) for as long as you keep using it. You can replace it from the designer, which deletes the previous one. If you stop using the service, write to us and we will delete it.
  • Images are downloaded, embedded in the file and discarded: they are not stored.
  • The generated file is kept only until you download it. The link works once and the file is deleted when served; in any case it is rejected and removed after 24 hours.

3.2 Delivery of large PDF reports

Power BI caps downloads originating from a visual at 30 MB. When the service is available, the PDF — which is generated in your browser — is uploaded to our service and delivered to you through a single-use link, with the same lifecycle as above: deleted on download and, in any case, after 24 hours. This means the contents of the PDF (your photos and the report text) pass through our infrastructure. If you would rather they did not, turn the export service off in the format pane: the visual falls back to Power BI's native download channel, with its 30 MB limit.

3.3 Isolation between customers

Each report generates a random 128-bit installation identifier stored inside the .pbix itself. The service namespaces everything it stores by that identifier, so one organisation's content is not reachable from another. That identifier is a random number: it does not identify any person or any organisation.

3.4 Self-hosted service

Enterprise customers can point the visual at their own proxy and their own export service from the format pane. In that case none of the above goes through invenia. We do not access the content except to provide the service or as required by law.

4. invenia's role under the GDPR

For content passing through the proxy or the export service, invenia acts as a data processor (Art. 28 GDPR) and your organization as controller. A Data Processing Agreement (DPA) is available to customers — request it at support@invenia.es. Our infrastructure sub-processor is Cloudflare, Inc., under a DPA with Standard Contractual Clauses, configured with EU data residency. For invoicing of direct licenses (embedded/Enterprise environments) we process, as controller, the necessary business contact details (name, email, company, tax data) on the basis of contract performance, retained for the periods required by commercial and tax law.

5. Your rights

You may exercise your rights of access, rectification, erasure, objection, restriction and portability by writing to support@invenia.es. You may also lodge a complaint with the Spanish Data Protection Agency (aepd.es) or your local supervisory authority.

6. Changes to this policy

Any changes will be published here with an updated date. Substantial changes affecting contracted customers will be communicated by email.