Personal data
Privacy Notice
Draft notice explaining who handles personal data, what data is used, why, for how long, with whom, and what rights people have.
Pre-publication draft: this document is not an approved public-beta contract. Publication and open registration remain disabled.
Document: privacy
Version: 2026-08-29-public-beta-draft-1
Effective date: 2026-08-29
Canonical localized-content SHA-256: b7b5f9ab559cc6cfe438b21a1e8128e6d265a871db43c7eac30d32d2b6abf3ea
Approved multilingual document SHA-256: 86e2001221c23591d35e3efb209c1f07c1bcd4a97fc92e5bcb291146652ec407
Privacy: privacy@gutmask.xyz
Controller and processing roles
Website, account, admission, licence, support, and hosted-service controller: Will be added later, established in Will be added later at Will be added later.
For customer runtime data processed only on documented customer instructions, the customer may be controller and the provider processor under the applicable Data Processing Addendum. The role follows actual purpose and control, not a label.
- Privacy contact: privacy@gutmask.xyz
- Legal contact: legal@gutmask.xyz
- The software licensor is not automatically controller or processor merely because it owns the software.
Data categories and sources
Data comes from the person, an authorized organization contact, the person's browser or device, security and service events, and identity or delivery providers used for the requested function.
GutMask does not request Google profile data for Google sign-in and does not use an IP address as proof of country, residence, authority, or licence eligibility.
- Account and identity: normalized email, local display name, email-verification state, adult attestation, authentication method, and security factors.
- Admission and licence: self-declared country and required subdivision, end-use attestations, Corporate holder type and authority, screening result, accepted document identities, licence and exact artifact entitlement.
- Service content: user-created GutMask data, files, messages, configuration, Portal/runtime events, and customer content needed for the requested hosted function.
- Operations and security: timestamps, IP and user-agent logs where required, session and audit records, abuse signals, delivery status, backup and restore evidence, and fault diagnostics.
- Support and rights requests: contact details, request text, redacted attachments, decisions, and fulfilment evidence.
- Preferences: language, theme, necessary session state, cookie choice, and optional first-party landing analytics only after opt-in.
Purposes and legal bases
Data is used only for stated purposes: account and contract formation, service delivery, security, support, legal compliance, rights requests, licence and jurisdiction controls, reliability, and optional measurement chosen by the visitor.
Where European data-protection law applies, each purpose uses the legal basis that actually fits it.
- Contract or steps requested before contract: account, legal confirmation, admitted service, licence, download, support, export, and deletion delivery.
- Legal obligation: records and action required by applicable consumer, tax, sanctions, security, or data-protection law.
- Legitimate interests: proportionate service security, fraud and abuse prevention, reliability, legal-claim defence, and minimal product improvement, after balancing individual rights.
- Consent: optional analytics or marketing only; it is off by default and can be withdrawn without affecting the account contract.
- Vital interests or public task are not ordinary GutMask bases and are used only if a specific situation and law support them.
- GutMask does not sell personal data and does not use it for third-party advertising or cross-site profiling.
Recipients, subprocessors, and international transfers
Access is limited to assigned service, privacy, security, and technical roles and to verified processors needed for hosting, mail, identity, DNS/security edge, backup, monitoring, or support. The current Subprocessors page identifies only providers proved active in the deployed contour.
Personal data is disclosed to authorities or other recipients only when required by law or necessary to establish, exercise, or defend legal claims.
- A processor receives a written purpose, confidentiality, security, deletion, assistance, and subprocessor duty.
- Processing outside the European Economic Area requires a valid mechanism, such as an adequacy decision or applicable standard contractual clauses, plus any required assessment and safeguards.
- Russia has no European Commission adequacy decision. Routine access from Russia to European customer personal data remains disabled until the exact transfer mechanism and safeguards are executed and disclosed.
- Global edge or identity providers may process technical request data in several countries; exact active facts remain a publication blocker until read back and listed.
- No planned provider, code capability, or marketing name is presented as an active recipient.
Retention and deletion
Data is kept only for the stated purpose and then deleted or irreversibly anonymized, subject to legal holds and bounded backups. Exact deployed schedules and backup deletion windows must be approved before publication.
Deletion from an active system may precede expiry of an encrypted backup copy; backup data is isolated, not used for ordinary processing, and removed by the documented rotation.
- Account and hosted content: while the account or requested service is active, then through the documented export/deletion process and any strictly necessary legal-claim period.
- Legal confirmations, licences, screening, and security audit: for the contract or licence life plus the documented period needed to prove compliance and resolve claims.
- Support and rights requests: while handled and for the bounded follow-up period published with the operational register.
- Optional first-party landing events: up to 90 days; the cookie preference: up to 365 days unless changed sooner.
- Raw credentials, private keys, and authentication tokens are not support records and must not be submitted in requests.
Individual rights
Depending on applicable law, a person may request access, correction, deletion, restriction, portability, or object to processing, and may withdraw consent at any time where consent is the basis.
Requests go to privacy@gutmask.xyz. Identity is verified proportionately before personal data is disclosed or changed; GutMask will explain a refusal and available appeal where required.
- Account export and deletion controls do not prevent a person from contacting the privacy channel.
- Objection to direct marketing, if ever introduced by separate opt-in, is honoured at any time.
- A person may complain to the Spanish Data Protection Agency or another competent supervisory authority, including the authority of habitual residence or work.
- There is no solely automated decision producing legal or similarly significant effects in the first public-beta admission design.
- Sanctions and jurisdiction screening uses bounded rules and human-reviewable outcomes; an unavailable result is not described as guilt or misconduct.
- Children are not the intended users; the service requires an adult attestation.
- Rights and mandatory time limits are not reduced by beta status or free access.
Security, incidents, and changes
GutMask applies access control, encryption where appropriate, audit, backup, release verification, and minimization measures proportionate to the current risk. No measure is described as absolute security or certification.
A material notice change is dated and published; where a new purpose needs consent or a new contract acceptance, it is collected separately before that purpose begins.
- Security reports: security@gutmask.xyz
- Privacy requests: privacy@gutmask.xyz
- A personal-data breach is assessed and notified to authorities or affected people where applicable law requires.
- This draft is not proof of deployed vendors, locations, transfers, or effective publication.