Privacy Notice
1. Who controls your data
[LEGAL ENTITY, ADDRESS AND REGISTRATION DETAILS] is the controller for account, website and direct customer processing. Depending on the final service model, a family archive owner may independently control decisions about invitations or family material. Contact [PRIVACY EMAIL]. Data Protection Officer: [DPO OR “NOT APPOINTED”]. EU and UK representatives: [DETAILS IF ARTICLE 27 / UK GDPR REQUIRES].
2. Information we handle
- Account and identity: name, email, verification status, account identifiers, age/eligibility confirmation, roles, invitations and authentication events.
- Archive content: stories, answers, transcripts, questions, family relationships, dates, places, photographs, documents, correspondence, audio, video, captions, corrections and contributor attribution.
- Voice, image and generated-persona data: recordings, facial images, age-labelled portraits, voice characteristics, generated audio/image/video and consent records. If processed to identify a person, biometric templates can be sensitive data.
- Highly personal data: material may reveal health, disability, racial or ethnic origin, beliefs, politics, sexuality, abuse, criminal matters, children, finances or exact locations. Users should collect only what is necessary and restrict access.
- Non-user and witness data: information about relatives or other people supplied by a Life Subject, Steward or Contributor, including invitation contact details and testimony.
- Service and device data: IP address, device/browser, security logs, actions, timestamps, language, local-storage preferences, diagnostics and support communications.
- Transaction data: plan, invoices, tax location, payment status and limited payment metadata. Full card data should be handled by the payment processor.
3. Sources
We receive data from you; Life Subjects, Stewards, Witnesses and invited family members; devices and browsers; authentication, hosting, transcription, email, payment and support providers; and, only where authorised, public or archival sources. If someone adds information about you, we will provide notice where required and avoid revealing the contributor where doing so would unlawfully expose another person.
4. Purposes and legal bases
| Purpose | Typical EU/UK legal basis | Important limits |
|---|---|---|
| Create accounts, verify email, deliver archives and authorised conversations | Contract; steps requested before contract | Only role-authorised content is displayed. |
| Record, transcribe, organise, retrieve and present archive material | Contract; consent where content or local law requires | Special-category and biometric processing may require explicit consent. |
| Create synthetic voice, likeness or age presentation | Explicit, specific consent; exceptionally another documented lawful basis | Separate consent, clear labelling, withdrawal and authority checks. |
| Invite Witnesses, Stewards and Visitors | Contract or legitimate interests balanced against recipients’ rights | Minimal contact data, opt-out, no repeated unsolicited messages. |
| Security, fraud prevention, abuse reports and audit trails | Legitimate interests; legal obligation | Proportionate monitoring and access. |
| Billing, tax, consumer support and legal claims | Contract; legal obligation; legitimate interests | Financial retention follows law. |
| Product analytics and improvement | Legitimate interests for necessary, aggregated diagnostics; consent for non-essential tracking | Private archive content is excluded from general AI training by default. |
| Marketing | Consent where required; otherwise permitted legitimate interests | Unsubscribe at any time; no sensitive-content targeting. |
5. AI training and automated processing
Draft default: we do not use private archive content, voice, likeness or witness testimony to train a general-purpose or third-party AI model without a separate, specific opt-in. Service providers may process data only to provide the contracted function and may not train their models on it unless expressly disclosed and consented to.
Automated systems may transcribe, retrieve, summarise and generate presentation. They do not make decisions producing legal or similarly significant effects about users. Access and moderation decisions with significant impact should offer human review where required.
6. How and with whom we disclose data
- with authorised family members, Stewards, Witnesses and Visitors according to granular permissions;
- with contracted infrastructure, database, storage, authentication, email, transcription, AI, support, security and payment providers;
- with professional advisers, auditors, insurers and transaction counterparties under confidentiality;
- to comply with valid legal process, protect rights and safety, or investigate abuse, disclosing only what is necessary;
- during a corporate transaction, subject to notice and continued protection; and
- with others when the relevant person gives specific consent.
We do not sell personal information. We do not share it for cross-context behavioural advertising. If either practice changes, we will provide legally required notices, opt-outs and Global Privacy Control recognition before it begins.
7. International transfers and storage locations
Production hosting and subprocessor countries: [LIST ACTUAL COUNTRIES AND PROVIDERS]. For EEA/UK transfers, we will use adequacy decisions, approved standard contractual clauses and supplementary safeguards as appropriate. For Australian personal information, we will take reasonable steps under APP 8 before overseas disclosure and identify likely destination countries where practicable.
8. Retention
| Data | Draft retention rule |
|---|---|
| Active archive content | While the account/archive is active and according to the Life Subject’s stewardship instructions. |
| Deleted content | Removed from active systems promptly; encrypted backups expire within [PERIOD], unless law or a dispute requires retention. |
| Consent, authority and safety records | For the life of the representation plus [PERIOD] to demonstrate lawful use and honour restrictions. |
| Security and access logs | [PERIOD], longer only for investigation or legal obligation. |
| Billing and tax records | As required by applicable accounting and tax law. |
| Invitations not accepted | [SHORT PERIOD], then deleted or suppressed to honour opt-out. |
9. Security and breach response
Measures should include least-privilege role access, encryption in transit and at rest where supported, private storage, multi-factor options, secret management, logging, backups, vulnerability management, processor due diligence and incident response. We notify affected people and regulators of eligible breaches within legally required timeframes. No internet service can guarantee absolute security; keep an independent copy of irreplaceable material.
10. Your choices and rights
Depending on location and relationship, you may request access, a copy, correction, deletion, restriction, objection, portability, consent withdrawal, human review, or information about recipients and safeguards. You may opt out of marketing. We verify requests proportionately and may refuse or limit a request where an exception protects another person, legal claims, security, freedom of expression, archive integrity or a legal duty.
EEA/UK
You may exercise GDPR/UK GDPR rights and complain to your local supervisory authority. Consent withdrawal does not affect prior lawful processing. You may object to legitimate-interest processing and have an absolute right to object to direct marketing.
California and other US states
Where applicable, you may request to know/access, delete and correct; opt out of sale, sharing and certain profiling; limit certain uses of sensitive personal information; and appeal a refusal, without discrimination. Authorised agents may act as law permits. Current draft practice: no sale or cross-context behavioural-advertising sharing. Requests: [WEBFORM AND TOLL-FREE NUMBER/SECOND METHOD IF REQUIRED].
Australia
You may request access and correction and complain about APP handling. We will acknowledge and investigate privacy complaints through [PROCESS/TIMELINE]; if unresolved, you may contact the Office of the Australian Information Commissioner. Where practicable, you may interact anonymously or under a pseudonym unless identity is needed to provide secure archive access.
11. Living people, deceased people and family conflicts
Data-protection law often treats information about living people differently from information solely about the deceased, but archive material may affect living relatives and may remain protected by confidentiality, copyright, publicity, succession and local post-mortem laws. We apply permissions and recorded wishes regardless of whether a minimum privacy statute technically covers the deceased.
If a person disputes content about them, we may annotate, restrict or remove it after balancing accuracy, provenance, expression, historical value and safety. We may freeze access during authority or estate disputes.
12. Children
The Service is not directed to children under 13 in the US. We do not knowingly collect a child’s account data without verifiable parental permission where COPPA applies. EU/EEA national digital-consent ages vary. A parent/guardian must approve participation by minors, and sensitive recordings or synthetic likenesses require heightened review. Contact us to request removal of a child’s information.
13. Cookies, local storage and communications
See the Cookie Notice. Strictly necessary storage supports login, language, security and locally saved prototype data. Non-essential analytics or advertising technologies will not be activated in jurisdictions requiring consent until consent has been obtained. Marketing communications include an unsubscribe route; service and security notices may still be sent.
14. Changes
We will date updates and give advance notice of material changes where required. We will seek fresh consent before materially expanding the use of voice, likeness, sensitive archive content or AI training. Previous versions will be archived.
15. Contact and complaints
- Privacy requests: [PRIVACY EMAIL/FORM]
- Postal address: [ADDRESS]
- DPO: [DETAILS IF APPLICABLE]
- EU/UK representatives: [DETAILS IF APPLICABLE]
- California rights methods: [TWO METHODS IF REQUIRED]
- Australian privacy complaints: [PROCESS]