Version 1.0 — DRAFT, NOT YET PUBLISHED. Pending review by counsel (CRP-01) before it replaces the current third-party policy.
Effective date: to be set on publication · Last revised: 25 September 2026
Before you read
This is the Privacy Policy referred to in Section 3 and Section 12 of our Terms and Conditions, and it forms part of them. It covers the Validating website, the Ideator web application, the Validator mobile application and the emails we send. Capitalised words that are not defined here have the meaning given in the Terms and Conditions.
We have written it to be read rather than to be survived. Where a section states a period, a provider or a legal basis, that is the real one, not an example. Where something is genuinely undecided we say so instead of writing a formula that covers every possibility.
Four things worth knowing before the detail. An Ideator never learns who a Validator is, and never sees the raw values of a Validator's income, exact age, gender or healthcare qualifications. We do not sell personal data; the only data that reaches advertising platforms is website measurement and remarketing data, and only if you accept advertising cookies — refusing them switches it off and never affects your use of the product. We do not use your content, your Responses or your Experiments to train an artificial-intelligence model, ours or anyone else's. And every automated decision that restricts your Account, withholds a payment or changes the Offers you receive can be reviewed by a person, on your request, with written reasons.
1. Who we are, and how to reach us
1.1 The controller of the personal data described in this policy is PHASE 2 B.V., a Dutch private limited company (besloten vennootschap met beperkte aansprakelijkheid) with registered office at De Boelelaan 1095a, Room 0A16, 1081 HV Amsterdam, the Netherlands, Chamber of Commerce (KvK) number 86210483, VAT identification number NL863896029B01. In this policy "Validating", "we", "us" and "our" mean that company.
1.2 Data protection contact: gabri@validating.studio. General contact: hello@validating.studio. We communicate in English and Italian. You are entitled to reach a human being and you may ask for one at any point.
1.3 We have not appointed a Data Protection Officer, because our processing does not meet the conditions in Article 37 of the General Data Protection Regulation. We will appoint one and publish the contact details here if that changes.
1.4 We are established in the European Union, so we do not need an Article 27 representative in the Union. Where we are required to designate a representative in another jurisdiction, the details appear in Section 16.
1.5 We are the controller for the personal data of Ideators, Validators and website visitors. There is one exception, in Section 4.6: where an Ideator puts a third party's personal data into the material of an Experiment, we process that data as processor on the Ideator's behalf, and the Ideator is the controller of it.
2. What this policy covers
2.1 It covers four places: validating.studio and its subdomains; the Ideator web application; the Validator mobile application on iOS and Android; and the transactional and marketing email we send. It applies wherever you are in the world.
2.2 It does not cover what happens on someone else's site or app when you follow a link from ours, and it does not cover a payment page operated by our payment provider, where that provider's own policy also applies alongside this one.
3. The short version
If you are an Ideator, we hold your account and billing data, the Experiments you create and the reports we generate for you. We keep them while your account exists, and we keep the financial records for seven years because Dutch tax law requires it.
If you are a Validator, we hold your account, the professional and demographic attributes you gave us so that we can match you to work, the Responses you submit, your Wallet and payout records, and internal signals about reliability and fraud. Your identity document is checked by our payment provider and never reaches us. Raw Responses are deleted two years after the Experiment they belong to is completed.
If you are only visiting the website, we set what is strictly necessary, and we set analytics and advertising cookies only if you agree to them. You can change your mind at any time, and how is in Section 19.
4. What we process
4.1 Everyone with an Account
- Identity and contact: email address, first name and surname, the country you tell us you are in, the language you use.
- Authentication: we do not store passwords. Sign-in is by magic link, and we keep the tokens and the session records that make it work.
- Device and technical: IP address, device and operating-system identifiers, app version, crash and error diagnostics, and the timestamps of what you do in the product.
- Communications: the email we send you and whether it was delivered and opened, the notifications we push to your device, and anything you write to support.
- Consent records: what you agreed to, when, and from which device — because we have to be able to show it.
4.2 Ideators
- The Experiments you build: the idea, the questions, the targeting you choose, the budget, and any file or link you upload.
- Results: the aggregated Responses, the verdict, the report we generate and any certificate issued.
- Billing: your billing name and address, VAT number where you give one, the invoices, the amounts, the discount or promotion codes applied, and refunds and chargebacks. Card details are handled by our payment provider and are never stored on our systems; we see the card type, the last four digits and the outcome.
- Workspace: the colleagues you invite and the role you give them.
4.3 Validators
- Matching profile: industry and sub-industry, job title and macro role, professional skills, interests, country, age range, gender, availability, and the professional materials you upload or link. We ask for these because they are what decides which Experiments you are offered; the more precise they are, the more paid work reaches you.
- Work: the Offers you were sent, which you accepted, refused or let expire, the Responses you submitted, the time you took, and the outcome of the quality checks.
- Money: your Wallet balance and its history, each payout, the payout account held with our payment provider, and the referral rewards described in Section 4.5.
- Identity verification: the outcome of the check, when it happened, and the country of the document. The document itself and the facial comparison are handled by our payment provider; we never receive or store either. Section 7 explains the consent this needs.
- Internal signals: your reliability score, and the fraud and abuse signals described in Section 8. These are internal. They are never disclosed to an Ideator or to any third party.
What an Ideator gets to see about you: nothing that identifies you. Responses are shown under a pseudonymous label. An Ideator receives anonymised match criteria, never the raw values of income, exact age, gender or healthcare qualifications, and never your reliability score.
4.4 What we do not process
In relation to Validators we do not process your emotional or psychological state, your private conversations, or data used to predict whether you would exercise collective rights or join a trade union. We do not process data revealing racial or ethnic origin, migration status, political opinions, religious or philosophical convictions, disability, health, sex life or sexual orientation. We use biometric data only for the one-to-one document check in Section 7, and for nothing else. Refusing an Offer, letting one expire, giving critical answers, reporting an Experiment, making a complaint or exercising a right under our Terms is never an input to any system we run and never counts against you.
4.5 Referrals
If you take part in a referral programme we process your personal referral code and link, the fact that an Account was created through them, the status and the amount of each reward, and — to detect self-referral and abuse — device, network and timing signals across the two Accounts. We show the person who referred you only the first name and initial, the registration date, the status and the amount. We show you only the first name of the person who referred you. Neither side sees the other's contact details, earnings or answers. Either of you may ask us to stop displaying your name to the other, without losing the reward. The full rules are in the Validator Referral Programme Terms.
When you send your referral link to someone, you are using their contact details, not ours: that is your decision and your responsibility, and we ask you not to send it to people who have not asked to hear from you.
4.6 Personal data inside an Ideator's Experiment
Where an Ideator puts a third party's personal data into the material of an Experiment, the Ideator is the controller of that data and is responsible for having a lawful basis and for having given that person the information the law requires. We process it as processor, on the Ideator's instructions, solely to deliver the Service, under our standard data processing terms, which are incorporated into the Terms and Conditions and are available on request from gabri@validating.studio. Where no such terms have been agreed, an Ideator must not include third-party personal data in Experiment material.
4.7 Visitors to the website
On the website we process the pages you visit, how you arrived, your approximate location derived from your IP address, and the identifiers set by the cookies and similar technologies described in Section 19. Analytics and advertising identifiers are set only where you consent. Advertising identifiers are used to measure our campaigns and, where you have consented, for remarketing — showing our advertisements to you on other sites and apps after you have visited ours. Section 10 lists the analytics, attribution and advertising providers involved.
5. Where the data comes from
Almost all of it comes from you: what you type, upload, accept or answer. Some is generated by our systems as you use the Service — timestamps, scores, logs. Some comes from our payment provider, which tells us the outcome of a payment, a payout or an identity check. Some comes from your device, through the app. And where you arrived through a referral link or an advertisement, we learn that from the link itself. We do not buy personal data, and we do not enrich your profile from data brokers or from public sources.
6. Why we process it, and on what legal basis
Under the GDPR we rely on one of four bases. Where we rely on consent you can withdraw it at any time, and withdrawing it does not affect what we did before. Where we rely on legitimate interests we have weighed ours against yours and you can object, as Section 15 explains.
- To create and run your Account, to deliver Experiments, to match Validators to work, to collect payment, to credit Wallets and to pay out — performance of the contract (Article 6(1)(b)).
- To prevent fraud and abuse, to keep the pool free of duplicate Accounts, to secure the Service, to check the quality of Responses, and to defend a legal claim — legitimate interests (Article 6(1)(f)): ours in running a marketplace people can trust, and every honest user's in not being crowded out by a dishonest one.
- To verify identity before a first payout, to keep accounting and tax records, and to answer a lawful request from an authority — legal obligation (Article 6(1)(c)).
- For analytics and advertising cookies, for marketing email where the law requires consent, for push notifications, and for the biometric document check — consent (Article 6(1)(a), and Article 9(2)(a) for the biometric check).
6.1 Marketing email to existing users about the Service is sent on the basis of our legitimate interest where the law allows it, and on consent where it does not. Every marketing email carries a one-click unsubscribe, and unsubscribing never affects the transactional email we must send you about your Account, your Offers or your money.
7. Special categories, and the one place we need your explicit consent
7.1 Identity verification happens once, late, at the point where it is the only thing standing between you and being paid. It is carried out by Stripe Identity using a government-issued document and, where required, a photograph of your face compared one-to-one with that document. The facial comparison is biometric data, which is a special category, so it needs your explicit consent — and we ask for it at that moment, not buried in your first session.
7.2 We do not receive or store your document or the biometric data. The comparison is made by the provider for the single purpose of confirming that the document belongs to you. It is not used to identify you in any other context, it is not shared with Ideators, and it is not used to build any profile.
7.3 If you do not consent, you cannot be paid out — but nothing else follows. Your Account stays open and the balance you have earned stays yours, available if you verify later. We will not close your Account and will not forfeit your balance for refusing.
7.4 Some attributes in a Validator profile are sensitive in ordinary language without being a special category in law — income band, exact age, gender. We treat them as sensitive anyway: they are used for matching, they are never shown to an Ideator in raw form, and they are not used for advertising.
7.5 We do not ask for health data. Where a Validator declares a healthcare qualification, we process it as professional information about what they are qualified to give an opinion on, not as data about their own health, and it is never disclosed to an Ideator in raw form.
8. Automated decisions, and what you can do about them
8.1 Five automated systems affect Validators, and we would rather list them than describe them in the abstract. Together with Section 42 of our Terms and Conditions and the AI Transparency Notice, this is the disclosure required by data protection law and by the rules on algorithmic management in platform work.
- Matching engine — decides which Validators receive an Offer for a given Experiment and in what order. Inputs: your declared industry and sub-industry, job title, skills, interests, country, age range and availability; the targeting the Ideator chose; your reliability score; whether you are currently eligible. Effect: how many Offers you receive, and for which Experiments.
- Profile quality check — assesses the substance and internal consistency of the professional materials you submit. Inputs: what you upload or link. Effect: whether your application is approved, deferred or refused.
- Response quality check — assesses whether a Response engages with the Experiment. Inputs: the content and structure of your answers, and the time you took. Effect: whether a Response is flagged for human review.
- Reliability score — aggregates your history into a single figure. Inputs: completion of accepted Offers, outcomes of quality checks, confirmed reports of misconduct. Effect: eligibility for Experiments restricted to higher-rated Validators, and therefore access to some better-paid work.
- Fraud and abuse detection — flags patterns indicating multiple Accounts, automated answers, manipulation or self-referral. Inputs: device, account, behavioural and payment signals. Effect: whether your Account or a referral reward is reviewed, restricted or suspended.
8.2 Human oversight is real, not nominal. These systems are monitored by people who have both the authority and the ability to override them.
8.3 Your rights here. Every decision that restricts, suspends or closes your Account, refuses or suspends a payment, withholds a referral reward, or changes the terms on which you receive Offers is reviewed by a qualified person on your request. Write to gabri@validating.studio. We will give you written reasons, consider anything you send us, and complete the review within 14 days. If the review shows the decision was wrong we reverse it immediately, restore what can be restored — including reinstating eligibility and releasing a suspended payment — and where you have suffered quantifiable loss as a direct result we will discuss appropriate compensation. You will never be disadvantaged for asking.
8.4 You may also ask us, at any time, to explain in plain language how these systems work in relation to you, including the main criteria and their relative importance. We maintain a data protection impact assessment covering this processing and keep it under review.
9. Artificial intelligence
9.1 We use a large language model, supplied by Anthropic, for three things: generating the report an Ideator receives from the aggregated Responses; running the Agentic and Hybrid panels, where the respondents are declared as machines and not passed off as people; and the quality checks in Section 8.
9.2 Your content is not training data. We do not use Experiments, Responses, profiles or any other personal data to train or fine-tune an AI model, ours or anyone else's, and our agreement with the provider excludes its use for training. The provider processes the data on our instructions, as a processor, and retains it only as long as needed to return the output.
9.3 A machine never has the last word on you. Where an automated check affects your Account, your approval or your money, Section 8.3 applies.
10. Who else processes your data
10.1 We use the providers below. Each processes personal data on our instructions, under a written data processing agreement, and none of them is permitted to use it for its own purposes — with one exception, stated plainly: the providers marked as advertising platforms below also use the measurement and remarketing data they receive for their own purposes, as controllers in their own right (jointly with us for the collection on our website), under their own privacy policies. This is the current list; we keep it here rather than in a document you have to ask for, and we update it when it changes.
- Supabase — database, file storage and authentication. Our primary database and storage are hosted in the European Union. Supabase Inc. is established in the United States.
- Railway — hosting of our backend services. United States.
- Vercel — hosting and content delivery for the website and the Ideator web application. United States.
- Cloudflare — image storage and delivery, and network protection. United States, with global edge delivery.
- Sanity — content management for our public pages, including this one. Norway (European Economic Area).
- Anthropic — the artificial-intelligence provider described in Section 9. United States.
- Stripe — payments, Connect payouts to Validators, and Stripe Identity verification. Stripe Payments Europe Limited is established in Ireland; Stripe, Inc. is established in the United States. For payments and payouts Stripe also acts as a controller in its own right for regulatory purposes, under its own privacy policy.
- Brevo — transactional and marketing email. France (European Union).
- Google, through Firebase Cloud Messaging — push notifications to the mobile application. Google Ireland Limited, with Google LLC in the United States.
- PostHog — product analytics, feature flags and A/B testing, and error diagnostics, inside the product and on the website. PostHog, Inc. is established in the United States and offers European hosting; the region we currently use is recorded in our processing register and stated on request.
- Google Analytics 4 — website analytics. Google Ireland Limited, with Google LLC in the United States. Only where you have consented to analytics cookies.
- Make — the automation platform that moves data between the systems above, for example to trigger an email when a reward is released. European Union.
- Google Tag Manager — loads and manages the analytics and advertising tags on the website, which fire only in line with your cookie choices. Google Ireland Limited, with Google LLC in the United States.
- Server-side Google Tag Manager, run by us on our own cloud infrastructure — receives measurement events from the website and forwards them to the analytics and advertising providers listed here, only in line with your cookie choices.
- Google Cloud — hosting and backend infrastructure, including our server-side tag manager. Google Ireland Limited, with Google LLC in the United States.
- Hyros — advertising attribution, for visitors to our website and for people who arrive from an advertisement. United States.
- Meta Platforms Ireland Limited (advertising platform) — advertising delivery, conversion measurement through the Meta pixel and the conversions API, Advanced Matching, which sends a hashed form of contact details such as your email address so that a conversion can be matched to an advertisement, and remarketing. Only where you have consented to advertising cookies and identifiers.
- Google Ireland Limited, through Google Ads (advertising platform) — conversion tracking, enhanced conversions, which likewise use hashed contact details, and remarketing. Only where you have consented to advertising cookies and identifiers.
- TikTok, LinkedIn, X, Reddit and OpenAI (advertising platforms) — conversion measurement for the campaigns we run on each of them, through the TikTok Pixel, the LinkedIn Insight Tag, the X Ads pixel, the Reddit Pixel and the OpenAI (ChatGPT) Ads measurement pixel; Reddit also uses its pixel data for ad targeting. Only where you have consented to advertising cookies and identifiers. Several of these providers are established in, or transfer data to, the United States; Section 11 explains the safeguards.
10.2 We also disclose personal data to our accountants, auditors and lawyers where they need it, and to a public authority or a court where the law obliges us. If we were ever part of a merger or a sale of the business, data would pass to the acquirer under the same protections, and we would tell you before anything changed for you.
10.3 We do not sell personal data for money, and we never have. Apart from what the advertising platforms in Section 10.1 do with measurement and remarketing data, with your consent and under their own policies, we do not disclose personal data to a third party for that party's own marketing.
11. Sending data outside Europe
11.1 Our primary database and file storage sit in the European Union. Several of the providers in Section 10 are established in the United States, so some processing takes place there or is accessible from there.
11.2 Every such transfer rests on one of these: an adequacy decision of the European Commission, including the EU–US Data Privacy Framework where the provider is certified under it; or the Commission's Standard Contractual Clauses, with the UK Addendum where UK data is involved; together with a transfer impact assessment which we keep on file and technical measures such as encryption in transit and at rest. You can ask us which mechanism applies to a given provider, and we will tell you.
12. How long we keep things
12.1 The rule behind the list: we keep personal data for as long as it is doing the job it was collected for, and then for as long as the law obliges us to keep it. After that we delete it or anonymise it irreversibly.
- Account and profile data — while your Account exists, and for 30 days after you close it, after which it is deleted or anonymised.
- Raw Responses — deleted two years after the completion of the Experiment they belong to.
- Aggregated and anonymised data, including Experiment results and reports — kept indefinitely, in a form that does not permit re-identification.
- Invoices, payouts, Wallet history, referral rewards and other accounting records — seven years from the end of the financial year, because Dutch tax law requires it. Closing your Account does not shorten this.
- Identity verification outcome — while your Account exists, and then for as long as anti-money-laundering and tax rules require. We hold no document and no biometric data to retain.
- Fraud and abuse signals, and records of measures taken — five years, because a banned Account that returns is the thing these records exist to catch.
- Support correspondence — three years from the last message.
- Consent records — five years after the consent ends, so that we can show what you agreed to and when.
- Server and security logs — twelve months.
- Analytics and advertising identifiers — no longer than thirteen months, and less where the cookie table in Section 19 says so.
12.2 Where a legal claim, an investigation or a dispute is live, we keep what is relevant to it until it is resolved, even if a period above has expired.
13. How we protect it
13.1 Encryption in transit and at rest. Row-level access control on every database table. No storage of passwords — sign-in is by magic link. Administrative access restricted to the people who need it and logged. Regular backups with tested restoration. Independent security testing before a production release. Providers selected against their own security posture, with a written agreement in each case.
13.2 No system is perfectly secure, and anyone who tells you otherwise is selling something. If a breach occurs that is likely to result in a risk to your rights, we notify the Dutch Data Protection Authority within 72 hours and we tell you without undue delay where the risk is high.
13.3 Your part matters too: use a device you control, keep access to your email secure, because the magic link goes there, and tell us at once if you think someone else has got into your Account.
14. Closing your Account, and what survives it
14.1 You can close your Account from the product or by writing to us. Deleting a Validator profile anonymises the personal data while preserving aggregated statistics that no longer identify you.
14.2 Three things do not disappear with your Account, and it is fairer to say so here than to surprise you later. The accounting records in Section 12.1 stay for seven years. A Wallet balance you have already earned is not forfeited — Section 40.11 of the Terms and Conditions explains what happens to it. And closing your Account does not by itself cancel a running Experiment, a subscription or an obligation to pay.
15. Your rights
15.1 Wherever you are, you can ask us to do the following, and we will not charge you or treat you differently for asking.
- Access — get a copy of the personal data we hold about you, and be told why we hold it, who we share it with and how long we keep it.
- Rectification — correct anything inaccurate, and complete anything incomplete. Most profile data you can correct yourself in the product.
- Erasure — have your data deleted, where we no longer need it and no law obliges us to keep it.
- Restriction — have us pause processing while a dispute about accuracy or legitimate interests is resolved.
- Portability — receive the data you gave us in a structured, commonly used, machine-readable format, or have us send it to another provider.
- Objection — object to processing based on our legitimate interests, and object at any time to direct marketing, which we will then stop.
- Withdraw consent — at any time, for anything we do on the basis of consent, including cookies, push notifications and the biometric check.
- Human review of an automated decision — as described in Section 8.3.
- Complain — to a supervisory authority, as described in Section 22.
15.2 How to exercise them: use the controls in the product where they exist, or write to gabri@validating.studio. We answer within one month, and we may extend that by two further months for a genuinely complex request — in which case we tell you inside the first month why. We may ask you to confirm who you are, but only with what is necessary, and never by asking you to send us an identity document by email.
15.3 Where a right cannot be granted in full — for example, erasure of a record we must keep for seven years — we say which part we cannot do and why, and we do the rest.
16. If you are outside the European Union
16.1 United Kingdom. The UK GDPR gives you the same rights as Section 15, and you may complain to the Information Commissioner's Office. Transfers of UK data rest on the UK Addendum to the Standard Contractual Clauses or on a UK adequacy regulation. We have not appointed a UK representative, because our offering is not directed specifically at the United Kingdom; if that changes we will appoint one and name them here.
16.2 Switzerland. The revised Federal Act on Data Protection gives you equivalent rights, and you may contact the Federal Data Protection and Information Commissioner.
16.3 Brazil. Under the LGPD you have the rights in Section 15 plus the right to information about the public and private entities with which we have shared your data, which Section 10 answers, and the right to ask for a review of an automated decision, which Section 8.3 answers. Our contact for LGPD requests is gabri@validating.studio.
16.4 Canada. Under PIPEDA you may access and correct your personal information and complain to the Office of the Privacy Commissioner of Canada. We rely on consent and on the reasonable purposes of running the Service.
16.5 Australia. Under the Privacy Act you may access and correct your personal information and complain to the Office of the Australian Information Commissioner.
16.6 Anywhere else. Where your local law gives you a right that Section 15 does not list, write to us and we will honour it to the extent the law requires.
17. If you are in the United States
17.1 This Section covers California and the other States with a comprehensive privacy law. The words below have the meaning those laws give them.
17.2 Categories we collect. Identifiers (name, email, IP address, account and device identifiers); commercial information (Experiments purchased, invoices, payouts); internet and network activity (how you use the product and the website); approximate geolocation derived from IP; professional and employment information (a Validator's industry, role, skills and qualifications); demographic information (age range, gender); financial information limited to payout and billing records held with our payment provider; audio, electronic and visual information only where you upload it as part of an Experiment; and inferences, limited to the reliability and quality scores in Section 8.
17.3 Sensitive personal information. We process a narrow set: account credentials in the sense of the sign-in mechanism, and, once, the biometric comparison for identity verification in Section 7, which the provider performs and we never receive. We do not use or disclose sensitive personal information for any purpose other than those permitted by Section 7027(m) of the CCPA regulations — in plain terms, to perform the service, to prevent fraud and to comply with the law. We do not use it to infer characteristics about you.
17.4 We do not sell personal information for money. We do "share" it for cross-context behavioural advertising, and engage in "targeted advertising", in the meaning those laws give the words: where you accept advertising cookies on our website, the advertising platforms in Section 10.1 receive online identifiers, your activity on our website and, for Meta Advanced Matching and Google enhanced conversions, hashed contact details, which they use to measure our campaigns and to show you our advertisements elsewhere. Under some of these laws that disclosure may also count as a "sale". You can opt out at any time through the "Do Not Sell or Share My Personal Information" link in the footer of every page, or by refusing advertising cookies in the cookie preferences panel, and we treat a Global Privacy Control signal as a valid opt-out with nothing further needed from you. None of this happens inside the mobile application, which uses no advertising identifiers. The Service is for adults, and we do not knowingly sell or share the personal information of anyone under 16.
17.5 Your rights: to know what we collect and why, to access a copy, to correct it, to delete it, to opt out of the sale or sharing of personal information and of targeted advertising as described in Section 17.4, to limit the use of sensitive personal information, to opt out of profiling in furtherance of a decision that produces a legal or similarly significant effect — which Section 8.3 already gives you by right of human review — and not to be discriminated against for exercising any of them. We do not offer financial incentives in exchange for personal information.
17.6 How to exercise them: gabri@validating.studio. We confirm receipt within 10 business days and respond within 45 days, extendable once by a further 45 where we tell you why. An authorised agent may act for you with written permission that we can verify. If we decline a request you may appeal, free of charge, by replying to our decision; we answer an appeal within 45 days and, where we still decline, we tell you how to contact your State's Attorney General.
17.7 California "Shine the Light": we do not disclose personal information to third parties for their own direct marketing, so there is nothing to disclose under that statute.
18. Children
18.1 The Service is for adults. You must be at least 18 to hold an Account, as a Validator or as an Ideator, and we do not knowingly collect personal data from anyone under 18. Where a verification document or any other signal shows that an Account holder is under the minimum age, we close the Account and delete the data, and we do not withhold a balance already earned from being paid to a lawful recipient.
18.2 If you believe a minor has given us personal data, write to gabri@validating.studio and we will delete it.
19. Cookies and similar technologies
19.1 We use four categories, and only the first is set without asking you.
- Strictly necessary — sign-in and session, security, load balancing, and remembering your cookie choice. These are set on the basis of our legitimate interest and cannot be switched off, because without them the Service does not work.
- Preferences — language and interface choices. Consent.
- Analytics — how the product and the website are used, so that we can fix what is broken. Consent. Identifiers kept no longer than thirteen months.
- Advertising, attribution and remarketing — measuring which campaign brought you here and, where you agree, showing you our advertisements on other sites and apps, through the providers named in Section 10. Consent. Identifiers kept no longer than thirteen months.
19.2 We ask for your choice on your first visit, through our consent management platform, which records what you chose and when. Refusing is as easy as accepting: there is a reject-all control at the same level as accept-all, and no pre-ticked boxes. The full, current list of cookies with their names, purposes and durations is available in the cookie preferences panel, because that list changes more often than this document does.
19.3 Changing your mind: reopen the cookie preferences panel at any time from the link in the footer of any page, or clear cookies in your browser. A Global Privacy Control signal from your browser is treated as a refusal of analytics and advertising cookies, and as an opt-out of sale and sharing under Section 17.4.
19.4 In the mobile application there are no advertising identifiers. We use the device's own identifier for push notifications, which you control in the operating system, and the in-product analytics in Section 10.
20. Email and notifications
20.1 There are two kinds. Transactional email is about your Account, your Offers, your money and the legal documents that govern them; you cannot unsubscribe from it while you hold an Account, because it is how we tell you things you need to know. Marketing email is everything else, and every one of them has a working one-click unsubscribe.
20.2 Push notifications are sent only if you allow them, and you can turn them off in the app or in your device settings without losing anything else.
21. Changes to this policy
21.1 We update this policy when what we do changes. The date at the top always tells you when it last changed. Where a change materially affects how we use your data — a new purpose, a new category of recipient, a longer retention period — we tell you by email and in the product at least 30 days before it takes effect, and where the change needs your consent we ask for it rather than assume it.
21.2 We keep the previous versions and will send you one on request, so you can see what changed.
22. If you want to complain
22.1 Tell us first, at gabri@validating.studio. We would rather fix it than read about it from a regulator, and we respond within 30 days.
22.2 You can complain to a supervisory authority at any time, whether or not you have contacted us. Ours is the Dutch Data Protection Authority (Autoriteit Persoonsgegevens), Postbus 93374, 2509 AJ Den Haag, the Netherlands, autoriteitpersoonsgegevens.nl. If you are in the European Economic Area you may instead complain to the authority where you live or work. Section 16 names the authority for the United Kingdom, Switzerland, Brazil, Canada and Australia.
22.3 You also have the right to an effective judicial remedy, and Section 22 of our Terms and Conditions explains where proceedings are heard — including the protection it preserves for consumers.