EnglishPortuguêsEspañol

GlamyBikini privacy notice

Version 1.0 draft. Effective [EFFECTIVE DATE].

Who we are

The controller is Carlos Brotas, trading as GlamyBikini, NIF 229701191, R. Hermano Neves 18, Telheiras, 1600-477 Lisboa. Contact: hello@glamybikini.com.

What we collect and why

Who Data Why Legal basis (GDPR) Kept for
Models Name, handle, email, phone (optional), country, bio Run the license, credit you, contact you about features and brand interest Contract (art. 6(1)(b)) While the license is active, then 3 years
Models Photos Publish them as the license allows Consent (art. 6(1)(a)) and contract Until you withdraw
Models ID check result (pass or fail), check date, Didit reference Prove everyone we publish is 18 or older, and of age where they live Legal obligation and legitimate interest (art. 6(1)(c), (f)) While the license is active, then 3 years
Models Signature record: typed name, time, IP address, device Prove you agreed to the license Legitimate interest (art. 6(1)(f)) While the license is active, then 3 years
Brands Contact name, email, company, website, message Answer brand enquiries and broker intros Legitimate interest (art. 6(1)(f)) 2 years from last contact
Outreach Instagram handle, date and status of our messages Avoid contacting people twice, track replies Legitimate interest (art. 6(1)(f)) 1 year, or deleted on request
Visitors Page views and clicks, with no cookies and no personal profiles See which looks and brands people use Legitimate interest (art. 6(1)(f)) Aggregated statistics

ID check and biometric data

Didit checks your ID document and matches it to a selfie. This involves biometric data, a special category under GDPR art. 9. Didit does this only with your explicit consent (art. 9(2)(a)), given in its flow. We never receive or store your document, selfie or face data. Didit's result includes your date of birth. Our server uses it once, to check it against the minimum age for your country of residence, and then discards it without storing it. We keep only a pass or fail result and a reference number. Didit processes data in the EU and deletes it automatically after 1 month. See Didit's own privacy notice for details.

Who else processes your data

Provider What for Where
Didit ID and age check EU
Cloudflare (R2) Photo storage EU bucket location. Cloudflare is a US company, covered by the EU-US Data Privacy Framework and standard contractual clauses
Resend Sending emails EU sending region (Ireland). Resend is a US company, covered by standard contractual clauses
Hetzner Online GmbH Website and database hosting EU (Germany or Finland)
Umami (self-hosted) Cookieless visit statistics Our EU server
Instagram, Pinterest Where we publish your licensed photos Their own terms and privacy notices apply to what you post there

We don't sell personal data. We give a brand a model's contact details only after the model agrees.

Your rights

You can ask us to access, correct, delete, restrict or port your data, and object to processing based on legitimate interest. You can withdraw consent at any time. Withdrawing doesn't make earlier processing unlawful. Write to hello@glamybikini.com. We reply within one month.

You can also complain to the Portuguese data protection authority, the Comissão Nacional de Proteção de Dados (www.cnpd.pt), or to the authority where you live.

Age

GlamyBikini is only for people 18 or older. Models must also be of age (the age of majority) where they live, if that is higher than 18. We don't knowingly collect data from anyone younger. If we learn that we did, we delete it and remove any published photos right away.

Changes

We will post any changes here and email models about changes that affect them.