Privacy Notice

1. Who controls your data

[LEGAL ENTITY, ADDRESS AND REGISTRATION DETAILS] is the controller for account, website and direct customer processing. Depending on the final service model, a family archive owner may independently control decisions about invitations or family material. Contact [PRIVACY EMAIL]. Data Protection Officer: [DPO OR “NOT APPOINTED”]. EU and UK representatives: [DETAILS IF ARTICLE 27 / UK GDPR REQUIRES].

2. Information we handle

3. Sources

We receive data from you; Life Subjects, Stewards, Witnesses and invited family members; devices and browsers; authentication, hosting, transcription, email, payment and support providers; and, only where authorised, public or archival sources. If someone adds information about you, we will provide notice where required and avoid revealing the contributor where doing so would unlawfully expose another person.

4. Purposes and legal bases

5. AI training and automated processing

Draft default: we do not use private archive content, voice, likeness or witness testimony to train a general-purpose or third-party AI model without a separate, specific opt-in. Service providers may process data only to provide the contracted function and may not train their models on it unless expressly disclosed and consented to.

Automated systems may transcribe, retrieve, summarise and generate presentation. They do not make decisions producing legal or similarly significant effects about users. Access and moderation decisions with significant impact should offer human review where required.

6. How and with whom we disclose data

We do not sell personal information. We do not share it for cross-context behavioural advertising. If either practice changes, we will provide legally required notices, opt-outs and Global Privacy Control recognition before it begins.

7. International transfers and storage locations

Production hosting and subprocessor countries: [LIST ACTUAL COUNTRIES AND PROVIDERS]. For EEA/UK transfers, we will use adequacy decisions, approved standard contractual clauses and supplementary safeguards as appropriate. For Australian personal information, we will take reasonable steps under APP 8 before overseas disclosure and identify likely destination countries where practicable.

8. Retention

9. Security and breach response

Measures should include least-privilege role access, encryption in transit and at rest where supported, private storage, multi-factor options, secret management, logging, backups, vulnerability management, processor due diligence and incident response. We notify affected people and regulators of eligible breaches within legally required timeframes. No internet service can guarantee absolute security; keep an independent copy of irreplaceable material.

10. Your choices and rights

Depending on location and relationship, you may request access, a copy, correction, deletion, restriction, objection, portability, consent withdrawal, human review, or information about recipients and safeguards. You may opt out of marketing. We verify requests proportionately and may refuse or limit a request where an exception protects another person, legal claims, security, freedom of expression, archive integrity or a legal duty.

EEA/UK

You may exercise GDPR/UK GDPR rights and complain to your local supervisory authority. Consent withdrawal does not affect prior lawful processing. You may object to legitimate-interest processing and have an absolute right to object to direct marketing.

California and other US states

Where applicable, you may request to know/access, delete and correct; opt out of sale, sharing and certain profiling; limit certain uses of sensitive personal information; and appeal a refusal, without discrimination. Authorised agents may act as law permits. Current draft practice: no sale or cross-context behavioural-advertising sharing. Requests: [WEBFORM AND TOLL-FREE NUMBER/SECOND METHOD IF REQUIRED].

Australia

You may request access and correction and complain about APP handling. We will acknowledge and investigate privacy complaints through [PROCESS/TIMELINE]; if unresolved, you may contact the Office of the Australian Information Commissioner. Where practicable, you may interact anonymously or under a pseudonym unless identity is needed to provide secure archive access.

11. Living people, deceased people and family conflicts

Data-protection law often treats information about living people differently from information solely about the deceased, but archive material may affect living relatives and may remain protected by confidentiality, copyright, publicity, succession and local post-mortem laws. We apply permissions and recorded wishes regardless of whether a minimum privacy statute technically covers the deceased.

If a person disputes content about them, we may annotate, restrict or remove it after balancing accuracy, provenance, expression, historical value and safety. We may freeze access during authority or estate disputes.

12. Children

The Service is not directed to children under 13 in the US. We do not knowingly collect a child’s account data without verifiable parental permission where COPPA applies. EU/EEA national digital-consent ages vary. A parent/guardian must approve participation by minors, and sensitive recordings or synthetic likenesses require heightened review. Contact us to request removal of a child’s information.

13. Cookies, local storage and communications

See the Cookie Notice. Strictly necessary storage supports login, language, security and locally saved prototype data. Non-essential analytics or advertising technologies will not be activated in jurisdictions requiring consent until consent has been obtained. Marketing communications include an unsubscribe route; service and security notices may still be sent.

14. Changes

We will date updates and give advance notice of material changes where required. We will seek fresh consent before materially expanding the use of voice, likeness, sensitive archive content or AI training. Previous versions will be archived.

15. Contact and complaints