1. Controller established in Latvia
The controller is [INSERT FULL REGISTERED LATVIAN LEGAL ENTITY OR SOLE-TRADER NAME], registration number [INSERT, IF ANY], legal or declared address [INSERT FULL LATVIAN ADDRESS], Republic of Latvia, operating under the Privé MGMT name (“Privé MGMT,” “we,” “us,” or “our”).
Privacy contact: apply@privecreators.com [CONFIRM OR REPLACE]. If appointment of a data protection officer is required under Article 37 GDPR, add the DPO’s direct contact details here. An EU representative is normally not required for a controller established in Latvia.
We process personal data under Regulation (EU) 2016/679 (GDPR), Latvia’s Personal Data Processing Law (Fizisko personu datu apstrādes likums), and other applicable Latvian and EU rules.
2. Scope of this Policy
This Privacy Policy explains how we collect, use, disclose, retain, and protect personal data when you browse privecreators.com, submit an application, communicate with us, or are considered for a potential business relationship. It should be read together with the Terms of Service and any privacy terms in a later signed services agreement.
3. Personal data we collect
| Category | Examples |
|---|---|
| Identity and contact | Name, email address, phone number, country or location, age confirmation, and communication details. |
| Professional/profile | Creator status, platform names or profile links, launch timeline, content experience, audience-size range, management status, goals, support needs, and current challenges. |
| Financial range | A broad self-reported monthly creator-revenue range. We do not request bank, card, or payout credentials through the Website. |
| Application content | Additional notes, your adult-content comfort response, and up to three optional non-explicit photographs you voluntarily upload. |
| Technical and security | IP address used temporarily for abuse prevention, request time, origin/host information, basic HTTP logs held by the hosting environment, anti-forgery token metadata, and error/security events. |
| Communications | Emails, responses, review notes, and records of legal-policy versions acknowledged. |
Only upload photographs of yourself that you have the right to provide. Do not provide passwords, login codes, government IDs, payment-card details, explicit or intimate media, information about minors, or unnecessary information about other people.
4. Why we process data and our legal bases
| Purpose | Data | GDPR legal basis |
|---|---|---|
| Receive, verify, review, and respond to your application | Identity, contact, profile, optional photographs, revenue range, goals, communications | Steps at your request before entering a contract (Article 6(1)(b)); and our legitimate interest in evaluating professional opportunities (Article 6(1)(f)) where applicable. |
| Operate, secure, troubleshoot, and prevent abuse of the Website | Technical, security, policy-version and limited request data | Legitimate interests in security, fraud prevention, service integrity, and evidence of compliance (Article 6(1)(f)). |
| Communicate about the application and possible relationship | Contact and communication data | Pre-contract steps (Article 6(1)(b)) and legitimate interests in business communications (Article 6(1)(f)). |
| Meet legal, regulatory, accounting, safety, and dispute obligations | Relevant application, communication, and technical records | Legal obligation (Article 6(1)(c)); legitimate interests in establishing, exercising, or defending legal claims (Article 6(1)(f)). |
| Send marketing, if introduced later | Email and preference records | Consent (Article 6(1)(a)) where required. The current application acknowledgement is not consent to unrelated marketing. |
Where we rely on legitimate interests, we consider necessity, proportionality, reasonable expectations, and potential impact. You may object as described below. Where data is required for an application, not providing it may prevent us from reviewing or responding.
5. Special-category and highly sensitive data
A creator’s public work or platform profile may reveal or allow inferences about sex life, sexual orientation, health, ethnicity, religion, or other information protected under Article 9 GDPR. We do not ask you to state these characteristics through the Website. Do not upload explicit content or unrelated sensitive information.
If review of a profile necessarily involves special-category data that you have manifestly made public, processing may rely on Article 9(2)(e) GDPR, where applicable, together with an Article 6 legal basis. Where another condition is required, we will seek explicit consent or use another lawful exception before processing. We will not infer protected traits for profiling, advertising, or automated eligibility decisions.
6. Sources of data
We collect data directly from you through the application form and communications. If you provide a public profile link, we may review information you have made publicly available on that profile for application assessment. We may also receive information from a representative you authorised or from service providers operating the Website. If we obtain material personal data from another source, we will provide any notice required by Article 14 GDPR.
8. International transfers
Some providers may process data outside the European Economic Area, United Kingdom, or your country. Where required, we use a lawful transfer mechanism such as an adequacy decision, approved Standard Contractual Clauses, the UK International Data Transfer Agreement/Addendum, or another legally recognised safeguard, together with supplementary measures where appropriate. You may request information about the applicable safeguard, subject to lawful redactions.
9. How long we retain data
| Record | Draft retention schedule |
|---|---|
| Unsuccessful or inactive applications | Up to 90 days after the last meaningful contact, unless you request earlier deletion or a longer period is necessary for legal claims, safety, or compliance. |
| Promising applications where you ask us to stay in touch | Up to 12 months, with a documented reason and an opportunity to object or request deletion. |
| Applications leading to a contract | Moved into the relevant client file and retained under the contract, accounting, tax, and legal-claims schedule. |
| Security/rate-limit records | The application code uses a short rolling window of up to 15 minutes for rate limiting; hosting logs may be retained separately by the hosting provider according to a configured schedule. |
| Consent/acknowledgement evidence and disputes | For the applicable statutory limitation period and as necessary to demonstrate compliance or resolve claims. |
Retention is reviewed against purpose, sensitivity, risk, legal obligations, and limitation periods. Data is deleted or anonymised when no longer required. Confirm these periods against actual mailbox, backup, and hosting configurations before launch.
10. Security
We use measures intended to protect data, including HTTPS enforcement, request-size limits, input validation, anti-forgery tokens, origin checks, rate limiting, a bot honeypot, restricted configuration files, encrypted email transport, and need-to-know access. No internet transmission, email system, or storage method is completely secure. Do not send credentials or explicit files by email. If we identify a qualifying personal-data breach, we will investigate and notify regulators and affected individuals where legally required.
11. Your data-protection rights
Subject to applicable law, you may have rights to access, rectify, erase, restrict processing, object to processing based on legitimate interests, receive portable data, withdraw consent without affecting prior lawful processing, and lodge a complaint with a supervisory authority. You also have the right not to be subject to a decision based solely on automated processing that produces legal or similarly significant effects.
To exercise a right, email apply@privecreators.com with “Privacy request” in the subject. We may request proportionate verification. We normally respond within one month under the GDPR, subject to lawful extensions. Requests are generally free, but manifestly unfounded or excessive requests may be refused or charged as permitted by law.
You may lodge a complaint with Latvia’s Data State Inspectorate (Datu valsts inspekcija), the Latvian supervisory authority under the GDPR and Personal Data Processing Law: Elijas iela 17, Rīga, LV-1050, Latvia; telephone +371 67223131; email pasts@dvi.gov.lv; website dvi.gov.lv. You may also complain to another competent supervisory authority where the GDPR permits.
13. Automated decision-making
We do not currently use solely automated decision-making or profiling to accept or reject applicants. Technical systems may automatically block suspected abuse or invalid requests, but substantive application decisions are intended to involve human review.
14. Children
The Website and application are for adults aged 18 or older. We do not knowingly collect personal data from children. If you believe a child has submitted data, contact us immediately so we can investigate and delete it where appropriate.
15. Changes to this Policy
We may update this Policy to reflect legal, technical, or operational changes. The effective date and version appear above. Material changes will be highlighted on the Website or application flow where appropriate. If a new purpose requires consent, we will seek it before that processing begins.
16. Latvia privacy contacts
Controller: [INSERT FULL REGISTERED LATVIAN LEGAL NAME]
Registration number: [INSERT, IF ANY]
Legal/declared address: [INSERT FULL LATVIAN ADDRESS]
Country: Republic of Latvia
Privacy email: apply@privecreators.com [CONFIRM OR REPLACE]
Data Protection Officer: [INSERT ONLY IF APPOINTED OR LEGALLY REQUIRED]
Latvian supervisory authority:
Data State Inspectorate (Datu valsts inspekcija)
Elijas iela 17, Rīga, LV-1050, Latvia
Telephone: +371 67223131
Email: pasts@dvi.gov.lv
Website: www.dvi.gov.lv