OIDCheck

Privacy Policy — DRAFT v0.2 (2026-07-17)

Draft version. Under legal review before official launch.

Controller: MY PATH S.R.L., Iași, Romania — privacy@oidcheck.eu

What we process, and why

DataPurposeLegal basis
Account email, name, organisation (OID)account, review authorship, claim verificationcontract (art. 6(1)(b))
Review author identity (never published)fraud prevention, legal compliance, DSA obligationslegitimate interest (6(1)(f)); legal obligation (6(1)(c))
Claim evidence documents (mandates)verifying organisation representativescontract / legitimate interest
Token ledger & payment recordsbilling, accountingcontract; legal obligation
Reports of illegal contentDSA notice-and-actionlegal obligation
Technical logs (IP, user agent)security, abuse preventionlegitimate interest
Organisation profile details (role contact email, description, topics)published by the organisation's verified owner on its own profilecontract
Organisation contact addresses found on the organisation's own public websitedelivering a one-time partnership invitation requested by a verified organisationlegitimate interest (6(1)(f))
Partnership request messages and their statusconnecting organisations that ask to be contactedcontract / legitimate interest
Invitation opt-out list (organisation and hashed address)honouring your choice not to receive invitationslegal obligation / legitimate interest

Organisation data (names, OIDs, countries, project participation) originates from public European Commission sources and concerns legal entities, not natural persons.

What we do NOT do

  • We do not publish review authors' identities.
  • We do not sell personal data or use it for advertising.
  • We do not list organisations' staff members on profiles.
  • We do not publish contact addresses we find ourselves. Addresses found on an organisation's own website are kept in an internal, non-public cache and used only to send a single invitation per request, with a strict opt-out. Contact details shown on a profile are the ones its verified owner chose to publish, and they are shown only to signed-in users.

Partnership invitations (unclaimed organisations)

When a verified organisation asks to contact an organisation that has not claimed its profile, we look up a contact address on that organisation's own public website, at that moment, and send one invitation email. The message itself is delivered only after the recipient claims its profile. We prefer role addresses (office@, info@). Limits: one invitation email per organisation per month; opt-out honoured permanently (link in every email); the address is never published or shared.

Account deletion

You can delete your account at any time from Account settings. This permanently deletes your login, profile and personal data. Published reviews remain on the platform — they are part of the reviewed organisation's public record and are anonymous — but the link between them and you is severed permanently at deletion: after that, the author cannot be re-identified by anyone, including us. Organisations you had claimed become unclaimed.

Retention

Account data: while the account exists + 3 years. Review authorship records: as long as the review is published + 5 years (defence of legal claims) — or until you delete your account, whichever comes first; deletion severs authorship irreversibly. Payment records: 10 years (Romanian accounting law). Claim documents: 2 years after decision. Internal contact cache: 90 days.

Recipients

Hosting and infrastructure: Supabase, Vercel (EU regions where available; transfers safeguarded by SCCs). Payments: Stripe. We disclose author identity only under a binding legal order.

Your rights

Access, rectification, erasure, restriction, portability, objection — privacy@oidcheck.eu. Complaints: ANSPDCP (dataprotection.ro) or your local supervisory authority.

Personal data inside reviews

Reviews must concern organisations, not private individuals. Moderation removes personal data before publication. If you find personal data about you in a published review, use oidcheck.eu/report — removal requests under GDPR are handled within 30 days.