1. Controller
The controller responsible for your data is [Company name], [Legal form], [Address], email [Email], phone [Phone]. [If a data protection officer is appointed: name and contact.]
2. Data we process
Account data (all users)
- email address and password (stored only as a secure hash by our authentication provider);
- full name, your role (host or client) and, if you add one, a phone number and profile picture;
- the time you accepted the Terms of Service and Privacy Policy and which version you accepted;
- technical sign-in data: session tokens, sign-in times and security logs.
Host profiles
- headline, biography, city, country, hourly rate and currency, headshot, intro video link, years of experience, skills, languages and industries;
- whether the profile is published, and the rating calculated from reviews;
- days you block in your calendar, with an optional note.
Client (company) profiles
- company name, website, logo and industry.
Bookings and reviews
- booking requests: event name, location, start and end time, offer and currency, your message and the status (pending, accepted, declined, cancelled, completed);
- reviews: the star rating, the comment and the date, linked to the booking.
Visitors
- when you visit the site, our hosting provider processes your IP address, the page requested, the time and your browser’s user agent in server logs.
- if you sign in, a session cookie keeps you signed in (see the Cookie Policy). We use no analytics or advertising cookies.
3. Purposes and legal bases
| Purpose | Legal basis |
|---|---|
| Creating and running your account, signing you in | Contract, Art. 6(1)(b) GDPR |
| Showing a published host profile to clients and on public pages | Contract, Art. 6(1)(b) GDPR (the host chooses to publish) |
| Sending, answering and cancelling booking requests; showing a host’s busy days | Contract, Art. 6(1)(b) GDPR |
| Reviews and the public rating of hosts | Contract, Art. 6(1)(b) GDPR, and our legitimate interest in a trustworthy marketplace, Art. 6(1)(f) GDPR |
| Security, preventing spam and abuse (for example limits on requests), server logs | Legitimate interest, Art. 6(1)(f) GDPR |
| Service emails (confirming your email address, password reset) | Contract, Art. 6(1)(b) GDPR |
| Keeping records we are legally required to keep | Legal obligation, Art. 6(1)(c) GDPR |
We do not sell personal data and do not use it for advertising or automated decisions.
4. Who can see your data
- Everyone, including search engines: a published host profile, that is the host’s name, headshot or profile picture, headline, biography, city, country, rate, intro video, years of experience, skills, languages, industries, rating and reviews. Public reviews show the rating, comment and date, but never the client who wrote them. An unpublished profile is not public.
- Your booking counterparties: when a client and a host have a booking request between them (in any status), each can see the other’s name, profile picture and phone number, and the host can see the client’s company details. A client can also see the profile of a host they booked even after it is unpublished.
- Only the two participants: the booking itself (event details, times, offer and message) and the full review record.
- Only the host: the days the host blocked and their notes. A client sending a request sees only which days the host is busy, not why.
- Nobody else: your email address and phone number are never shown on public pages, and other users cannot see your account unless you have a booking with them.
5. Processors and other recipients
- Supabase (Supabase, Inc.) hosts our database, authentication and file storage, and sends our service emails [or: our email provider, [SMTP provider]]. Data region: [region].
- [Hosting provider] runs the website and processes the server logs described above.
- Video providers: if a host adds an intro video, their profile embeds a player from YouTube (in privacy enhanced mode, youtube-nocookie.com), Vimeo or Loom. The player loads from that provider when you view the profile, which then receives your IP address and may set its own cookies under its own privacy policy.
We have data processing agreements with our processors (Art. 28 GDPR). We disclose data to authorities only where the law requires it.
6. International transfers
Some providers are based in, or may access data from, countries outside the European Economic Area, such as the United States. Where this happens we rely on an adequacy decision (for example the EU-US Data Privacy Framework for certified companies) or on the European Commission’s Standard Contractual Clauses. [Confirm the mechanism for each provider.]
7. How long we keep data
- Account and profile data: until you delete your account, then within [30] days.
- Bookings and reviews: for as long as either participant’s account exists, and afterwards only as long as needed for legal claims or legal retention duties [period].
- Server logs: [7] days, unless needed to investigate a security incident.
- Backups: overwritten within [period].
8. Your rights
You have the right to:
- access the personal data we hold about you (Art. 15 GDPR);
- have incorrect data corrected (Art. 16);
- have your data erased (Art. 17);
- restrict processing (Art. 18);
- receive your data in a portable format (Art. 20);
- object at any time to processing based on our legitimate interests, for reasons arising from your particular situation (Art. 21);
- lodge a complaint with a data protection supervisory authority, in particular in the country where you live or work, or with the authority responsible for us: [Supervisory authority].
You can edit most of your data yourself in your dashboard. For everything else, write to [Email].
9. Security
Data is sent over encrypted connections. Access to data in our database is restricted by row level security rules, so each user can read only what section 4 describes.
10. Changes
We update this policy when our processing changes. The date at the top shows the current version.
11. Contact
Questions about privacy: [Email], [Address].