Privacy
⚠ DRAFT SHELL — to be completed and approved with the lawyer (GDPR).
The technical facts below are accurate today and written to be verifiable against the code.
1. Controller
[LAWYER: entity name, address, contact — after registration]
2. What we store
- Account: your email address and chosen handle.
- Money records: credit purchases (amount, time, payment reference — never card numbers; payment runs at our payment provider) and an append-only audit log, kept for accounting/legal retention. [LAWYER: retention period — fiscal 7y NL?]
- Project activity: the public ledger of project spends, tasks, updates — public by design; this transparency is the product.
- Forge chat: member-only messages, encrypted at rest (AES-256-GCM). Automated pattern checks surface deal-dodging signals to the project creator; messages are not otherwise read.
- Technical: IP-based rate-limit counters, held in memory only (~minutes).
3. What we don't do
- No third-party trackers, no ad tech, no analytics beacons.
- No sale of personal data.
- Cards/iDEAL are processed by our payment provider; card data never touches our servers.
4. Processors
Payment provider (Stripe), email delivery [LAWYER: name SMTP provider once chosen], hosting [Contabo, DE — confirm DPA], optional LLM inference relay (OpenRouter) for project compute.
5. Your rights
Access, rectification, erasure, portability, complaint at the Autoriteit Persoonsgegevens. [LAWYER: erasure vs public-ledger integrity and fiscal retention — define precedence]