Legal draft
Privacy Policy
Draft privacy policy for ErgoBase.
Draft notice
DRAFT — pending legal review. This page is not legal advice and must be reviewed by qualified counsel before launch.
Founder confirmation required: Controller entity, privacy contact, DPO if applicable, governing law, retention periods, and transfer mechanism.
Data we process
Account data: name, email, authentication identifiers, agency workspace membership, role, and usage metadata.
Financial workspace data: creator profiles, contracts, source-file metadata, imported financial rows, bank statement rows, expenses, adjustments, payout statements, export records, and audit events.
Support and contact data: contact-form submissions, support messages, and operational correspondence.
Data boundary
ErgoBase is not designed to ingest fan messages, fan notes, inbox content, scripts, vault/media content, sexual content, or creator-fan conversations.
Purposes and lawful basis
We process personal data to provide the service, secure accounts, maintain audit records, communicate with users, handle billing, and comply with legal obligations.
Founder confirmation required: Final GDPR lawful-basis mapping by data category.
Sub-processors
Current planned sub-processors include Clerk for authentication, Neon for Postgres database hosting, Cloudflare R2 for file storage, Resend for email delivery, Stripe for billing, Sentry for monitoring, Vercel for web hosting, and Render for API hosting.
Founder confirmation required: Final sub-processor list, regions, and DPA links summary.
Rights
Depending on jurisdiction, individuals may have rights to access, correct, delete, restrict, object, or port personal data.
Requests should be sent to Founder confirmation required: Privacy rights request contact email.