PRIVACY POLICY
1. DATA CONTROLLER
> Controller: FAKE_SOULMATE
> Contact: admin@fake-soulmate.org
> Jurisdiction: European Union
2. DATA WE COLLECT
We collect the following personal data:
> Account Data:
- > Username (required, publicly visible)
- > Email address (required, private)
- > Password (stored as secure hash, never in plain text)
- > Account creation date
> User-Generated Content:
- > Entity submissions (publicly visible, attributed to username)
- > Evidence submissions (publicly visible)
- > Comments (publicly visible, attributed to username)
- > Votes (aggregated, individual votes not publicly visible)
- > Reports (private, visible only to moderators)
> Technical Data:
- > IP addresses (for security and abuse prevention)
- > Browser type and version
- > Access timestamps
3. LEGAL BASIS FOR PROCESSING
Under GDPR Article 6, we process your data based on:
- > Contract (Art. 6(1)(b)): Processing necessary to provide the Service you requested when creating an account
- > Legitimate Interest (Art. 6(1)(f)): Security, fraud prevention, and platform integrity
- > Consent (Art. 6(1)(a)): Where you voluntarily submit content to the platform
4. HOW WE USE YOUR DATA
- > To provide and maintain the Service
- > To attribute content to your account
- > To communicate with you about your account
- > To enforce our Terms of Service
- > To prevent abuse and maintain security
- > To respond to legal requests
5. DATA RETENTION
> Active accounts: Data retained while account is active
> Deleted accounts: Account deactivated, username anonymized to "[deleted]"
> User-generated content: Retained for platform integrity after account deletion
> Technical logs: Retained for 90 days, then deleted
> Backup data: Retained for up to 30 days after deletion
6. YOUR RIGHTS (GDPR)
Under GDPR, you have the following rights:
> Right of Access (Art. 15):
You may request a copy of all personal data we hold about you.
> Right to Rectification (Art. 16):
You may request correction of inaccurate personal data.
> Right to Erasure (Art. 17):
You may request deletion of your personal data. Note: User-generated content may be retained with anonymized attribution for platform integrity.
> Right to Data Portability (Art. 20):
You may request your data in a machine-readable format.
> Right to Object (Art. 21):
You may object to processing based on legitimate interest.
> Right to Withdraw Consent (Art. 7(3)):
Where processing is based on consent, you may withdraw it at any time.
7. ACCOUNT DELETION
You can delete your account at any time:
- > Navigate to Account Settings
- > Click "Delete My Account"
- > Confirm with your password
Upon deletion:
- > Your account will be deactivated immediately
- > Your username will be replaced with "[deleted]" on all content
- > Your email will be disassociated from your content
- > Your content contributions will remain for platform integrity
8. COOKIES AND TRACKING
We use only essential cookies required for the Service to function:
- > Session cookie: Maintains your login state (expires on browser close or after inactivity)
- > CSRF token: Security measure to prevent cross-site request forgery
We do NOT use:
- > Third-party analytics cookies
- > Advertising or tracking cookies
- > Social media tracking pixels
9. THIRD-PARTY SERVICES
We use the following third-party services:
- > HTMX: Frontend library loaded from unpkg.com CDN (no personal data shared)
We do NOT share your personal data with advertisers or data brokers.
10. DATA SECURITY
We implement appropriate security measures including:
- > Secure password hashing (never stored in plain text)
- > HTTPS encryption for all connections
- > CSRF protection on all forms
- > Regular security updates
11. INTERNATIONAL DATA TRANSFERS
Your data is stored and processed within the European Union. If data is transferred outside the EU, we ensure appropriate safeguards are in place as required by GDPR Chapter V.
12. CHILDREN'S PRIVACY
The Service is not intended for users under 16 years of age. We do not knowingly collect data from children under 16. If you believe a child has provided us with personal data, please contact us immediately.
13. CHANGES TO THIS POLICY
> We may update this Privacy Policy periodically.
> Material changes will be announced on the platform.
> Continued use after changes constitutes acceptance.
14. COMPLAINTS
If you believe your privacy rights have been violated, you may:
- > Contact us at admin@fake-soulmate.org
- > Lodge a complaint with your local Data Protection Authority
15. CONTACT
> For all privacy-related inquiries:
> Email: admin@fake-soulmate.org
> Data Controller: FAKE_SOULMATE