Legal
Privacy Policy
This Policy explains how Infloowerz collects, uses, shares, secures and retains personal data.
Version 1.1.0 · Effective 11 July 2026
1. Data controller
The controller is [INSERT LEGAL ENTITY NAME], organisation number [INSERT ORGANISATION NUMBER], at [INSERT REGISTERED BUSINESS ADDRESS], Sweden. Privacy contact: [INSERT PRIVACY EMAIL].
2. Who this Policy covers
This Policy covers applicants, Founding List members, creators, account holders, purchasers, brands, visitors, reporters and people who contact us. It does not govern independent third-party platforms linked from Infloowerz.
3. Personal data we may collect
- Identity and contact data, including name, email address and country.
- Private date of birth, age-group status and, for applicants aged 13–17, parent or legal guardian name, email and verification status.
- Creator data, including handle, city, category, follower figures, social links, profile media, tier preferences and notes.
- Application and moderation data, including approval status, reviewer notes, reports, appeals and correspondence.
- Contract and consent records, including the legal version accepted, date, time and related technical records.
- Transaction data, including order, price, payment status, refunds and payment-provider references. We should not store full card details.
- Technical and usage data, including IP address, device/browser information, timestamps, security logs and cookie choices.
- Communication and support data.
- Public information from social-media profiles that you submit for review.
4. Why we use personal data
- To receive and assess applications and confirm eligibility.
- To create, operate and display approved creator profiles and placements.
- To administer the Founding List, Origin Halo queue and payments.
- To communicate about applications, account changes, purchases, security and support.
- To maintain evidence of agreements and legal acceptance.
- To prevent fraud, impersonation, abuse, illegal content and security incidents.
- To respond to reports, rights requests, complaints and legal obligations.
- To improve the website, subject to appropriate privacy choices.
- To send optional marketing only where a valid legal basis exists.
5. Legal bases
Depending on the activity, we rely on:
- Steps before and performance of a contract: applications, account administration, placements, payments and support.
- Legal obligations: accounting, tax, consumer, law-enforcement and regulatory requirements.
- Legitimate interests: platform security, fraud prevention, moderation, service improvement, evidence and protection of legal rights, balanced against individual rights.
- Consent: optional marketing and non-essential cookies where required. Consent can be withdrawn.
6. Date of birth, age group and guardian verification
Date of birth is private and must not appear on a public creator profile. It is collected to confirm the minimum age of 13 and determine whether the adult or guardian approval flow applies.
For applicants aged 13–17, we collect the minimum guardian contact data needed to request separate verification and approval. A minor's public profile, paid placement, payment and direct brand-contact features must not be activated until the guardian process is complete.
Access must be limited to authorised personnel. Where feasible, after age and guardian verification we should retain only the verification status and minimum evidence needed. We do not request a national identification number or identity-document copy as a default signup requirement.
7. Public and private information
May be public after approval
Creator name or display name, handle, country/city, category, public social links, follower information, approved profile media, tier, badge and globe placement.
Kept private
Date of birth, email address unless intentionally published, internal review notes, payment references, consent records, security information and private correspondence.
8. Sources of data
We collect data directly from you, from public profiles you identify, from payment and hosting providers, from security tools, and from people who send reports or rights claims. We do not treat public availability as permission to use data for any unrelated purpose.
9. Sharing and processors
We may share necessary data with:
- Hosting, database, security, email, analytics and customer-support providers.
- Payment processors and accounting providers.
- Professional advisers, auditors, insurers and authorities where justified.
- Successors in a lawful merger, financing, acquisition or restructuring, subject to safeguards.
- Other users only where information is intentionally made public through the service.
Providers acting as processors must be bound by appropriate data-protection terms. We do not sell personal data as a standalone product.
10. International transfers
Some providers may process data outside the EU/EEA. Where required, we will use an approved transfer mechanism, such as an adequacy decision or standard contractual clauses, and assess supplementary safeguards.
11. Retention
We retain personal data only for as long as needed for the stated purpose, legal obligations, disputes and security. Retention periods should be fixed in an internal schedule before launch.
- Unsuccessful or abandoned applications: normally a limited review and dispute period, then deletion or anonymisation.
- Active creator profiles: for the account/placement duration.
- Contract, payment and accounting data: for the legally required accounting and claims periods.
- Reports and moderation records: according to seriousness, legal obligations and appeal needs.
- Optional marketing data: until consent is withdrawn or the list is cleaned.
- Security logs: for a proportionate security period.
12. Security
We use proportionate technical and organisational safeguards, including access control, least-privilege permissions, secure transmission, backups, logging, provider review and incident procedures. No online system is entirely risk-free, but security must be built into the service and reviewed regularly.
13. Your rights
Subject to applicable law, you may request:
- Access to your personal data.
- Correction of inaccurate or incomplete data.
- Deletion in qualifying circumstances.
- Restriction of processing.
- Data portability where applicable.
- Objection to legitimate-interest processing.
- Withdrawal of consent without affecting earlier lawful processing.
- Information about safeguards for international transfers.
- Review of certain decisions where automated decision-making rules apply.
Contact [INSERT PRIVACY EMAIL]. We may need to verify identity in a proportionate way before completing a request.
14. Complaints
You may complain to the Swedish Authority for Privacy Protection (IMY) or, where applicable, another competent supervisory authority. We encourage you to contact us first so we can investigate promptly.
15. Cookies and similar technologies
Our Cookie Policy explains necessary, analytics and marketing technologies. Non-essential technologies should remain disabled until valid consent is obtained.
16. Children and young creators
Infloowerz applications are available from age 13. Applicants aged 13–17 use a protected guardian-verification flow. Their application remains pending and must not become publicly visible or paid until a parent or legal guardian has separately approved it.
Applicants under 13 are not eligible. If we learn that an ineligible child submitted personal data, we will investigate and delete or restrict it as appropriate, unless retention is legally required. Children's data receives heightened privacy and security protection.
17. Changes
We may update this Policy to reflect legal, technical or operational changes. Material changes will be communicated where required, and the current version and effective date will remain visible.
