GlamyBikini privacy notice
Version 1.0 draft. Effective [EFFECTIVE DATE].
Who we are
The controller is Carlos Brotas, trading as GlamyBikini, NIF 229701191, R. Hermano Neves 18, Telheiras, 1600-477 Lisboa. Contact: hello@glamybikini.com.
What we collect and why
| Who | Data | Why | Legal basis (GDPR) | Kept for |
|---|---|---|---|---|
| Models | Name, handle, email, phone (optional), country, bio | Run the license, credit you, contact you about features and brand interest | Contract (art. 6(1)(b)) | While the license is active, then 3 years |
| Models | Photos | Publish them as the license allows | Consent (art. 6(1)(a)) and contract | Until you withdraw |
| Models | ID check result (pass or fail), check date, Didit reference | Prove everyone we publish is 18 or older, and of age where they live | Legal obligation and legitimate interest (art. 6(1)(c), (f)) | While the license is active, then 3 years |
| Models | Signature record: typed name, time, IP address, device | Prove you agreed to the license | Legitimate interest (art. 6(1)(f)) | While the license is active, then 3 years |
| Brands | Contact name, email, company, website, message | Answer brand enquiries and broker intros | Legitimate interest (art. 6(1)(f)) | 2 years from last contact |
| Outreach | Instagram handle, date and status of our messages | Avoid contacting people twice, track replies | Legitimate interest (art. 6(1)(f)) | 1 year, or deleted on request |
| Visitors | Page views and clicks, with no cookies and no personal profiles | See which looks and brands people use | Legitimate interest (art. 6(1)(f)) | Aggregated statistics |
ID check and biometric data
Didit checks your ID document and matches it to a selfie. This involves biometric data, a special category under GDPR art. 9. Didit does this only with your explicit consent (art. 9(2)(a)), given in its flow. We never receive or store your document, selfie or face data. Didit's result includes your date of birth. Our server uses it once, to check it against the minimum age for your country of residence, and then discards it without storing it. We keep only a pass or fail result and a reference number. Didit processes data in the EU and deletes it automatically after 1 month. See Didit's own privacy notice for details.
Who else processes your data
| Provider | What for | Where |
|---|---|---|
| Didit | ID and age check | EU |
| Cloudflare (R2) | Photo storage | EU bucket location. Cloudflare is a US company, covered by the EU-US Data Privacy Framework and standard contractual clauses |
| Resend | Sending emails | EU sending region (Ireland). Resend is a US company, covered by standard contractual clauses |
| Hetzner Online GmbH | Website and database hosting | EU (Germany or Finland) |
| Umami (self-hosted) | Cookieless visit statistics | Our EU server |
| Instagram, Pinterest | Where we publish your licensed photos | Their own terms and privacy notices apply to what you post there |
We don't sell personal data. We give a brand a model's contact details only after the model agrees.
Your rights
You can ask us to access, correct, delete, restrict or port your data, and object to processing based on legitimate interest. You can withdraw consent at any time. Withdrawing doesn't make earlier processing unlawful. Write to hello@glamybikini.com. We reply within one month.
You can also complain to the Portuguese data protection authority, the Comissão Nacional de Proteção de Dados (www.cnpd.pt), or to the authority where you live.
Age
GlamyBikini is only for people 18 or older. Models must also be of age (the age of majority) where they live, if that is higher than 18. We don't knowingly collect data from anyone younger. If we learn that we did, we delete it and remove any published photos right away.
Changes
We will post any changes here and email models about changes that affect them.