Legal draft

Privacy Policy

Draft privacy policy for ErgoBase.

DRAFT — pending legal review.

Draft notice

DRAFT — pending legal review. This page is not legal advice and must be reviewed by qualified counsel before launch.

Founder confirmation required: Controller entity, privacy contact, DPO if applicable, governing law, retention periods, and transfer mechanism.

Data we process

Account data: name, email, authentication identifiers, agency workspace membership, role, and usage metadata.

Financial workspace data: creator profiles, contracts, source-file metadata, imported financial rows, bank statement rows, expenses, adjustments, payout statements, export records, and audit events.

Support and contact data: contact-form submissions, support messages, and operational correspondence.

Data boundary

ErgoBase is not designed to ingest fan messages, fan notes, inbox content, scripts, vault/media content, sexual content, or creator-fan conversations.

Purposes and lawful basis

We process personal data to provide the service, secure accounts, maintain audit records, communicate with users, handle billing, and comply with legal obligations.

Founder confirmation required: Final GDPR lawful-basis mapping by data category.

Sub-processors

Current planned sub-processors include Clerk for authentication, Neon for Postgres database hosting, Cloudflare R2 for file storage, Resend for email delivery, Stripe for billing, Sentry for monitoring, Vercel for web hosting, and Render for API hosting.

Founder confirmation required: Final sub-processor list, regions, and DPA links summary.

Rights

Depending on jurisdiction, individuals may have rights to access, correct, delete, restrict, object, or port personal data.

Requests should be sent to Founder confirmation required: Privacy rights request contact email.