Privacy Policy — DRAFT v0.2 (2026-07-17)
Draft version. Under legal review before official launch.
Controller: MY PATH S.R.L., Iași, Romania — privacy@oidcheck.eu
What we process, and why
| Data | Purpose | Legal basis |
|---|---|---|
| Account email, name, organisation (OID) | account, review authorship, claim verification | contract (art. 6(1)(b)) |
| Review author identity (never published) | fraud prevention, legal compliance, DSA obligations | legitimate interest (6(1)(f)); legal obligation (6(1)(c)) |
| Claim evidence documents (mandates) | verifying organisation representatives | contract / legitimate interest |
| Token ledger & payment records | billing, accounting | contract; legal obligation |
| Reports of illegal content | DSA notice-and-action | legal obligation |
| Technical logs (IP, user agent) | security, abuse prevention | legitimate interest |
| Organisation profile details (role contact email, description, topics) | published by the organisation's verified owner on its own profile | contract |
| Organisation contact addresses found on the organisation's own public website | delivering a one-time partnership invitation requested by a verified organisation | legitimate interest (6(1)(f)) |
| Partnership request messages and their status | connecting organisations that ask to be contacted | contract / legitimate interest |
| Invitation opt-out list (organisation and hashed address) | honouring your choice not to receive invitations | legal obligation / legitimate interest |
Organisation data (names, OIDs, countries, project participation) originates from public European Commission sources and concerns legal entities, not natural persons.
What we do NOT do
- We do not publish review authors' identities.
- We do not sell personal data or use it for advertising.
- We do not list organisations' staff members on profiles.
- We do not publish contact addresses we find ourselves. Addresses found on an organisation's own website are kept in an internal, non-public cache and used only to send a single invitation per request, with a strict opt-out. Contact details shown on a profile are the ones its verified owner chose to publish, and they are shown only to signed-in users.
Partnership invitations (unclaimed organisations)
When a verified organisation asks to contact an organisation that has not claimed its profile, we look up a contact address on that organisation's own public website, at that moment, and send one invitation email. The message itself is delivered only after the recipient claims its profile. We prefer role addresses (office@, info@). Limits: one invitation email per organisation per month; opt-out honoured permanently (link in every email); the address is never published or shared.
Account deletion
You can delete your account at any time from Account settings. This permanently deletes your login, profile and personal data. Published reviews remain on the platform — they are part of the reviewed organisation's public record and are anonymous — but the link between them and you is severed permanently at deletion: after that, the author cannot be re-identified by anyone, including us. Organisations you had claimed become unclaimed.
Retention
Account data: while the account exists + 3 years. Review authorship records: as long as the review is published + 5 years (defence of legal claims) — or until you delete your account, whichever comes first; deletion severs authorship irreversibly. Payment records: 10 years (Romanian accounting law). Claim documents: 2 years after decision. Internal contact cache: 90 days.
Recipients
Hosting and infrastructure: Supabase, Vercel (EU regions where available; transfers safeguarded by SCCs). Payments: Stripe. We disclose author identity only under a binding legal order.
Your rights
Access, rectification, erasure, restriction, portability, objection — privacy@oidcheck.eu. Complaints: ANSPDCP (dataprotection.ro) or your local supervisory authority.
Personal data inside reviews
Reviews must concern organisations, not private individuals. Moderation removes personal data before publication. If you find personal data about you in a published review, use oidcheck.eu/report — removal requests under GDPR are handled within 30 days.