← Culture Dive

GDPR

How we comply, and what happens when you use your rights.

How Culture Dive complies with the GDPR

DRAFT FOR LEGAL REVIEW. This is not legal advice. It was written by reading the Culture Dive codebase and describes what the system actually does today, checked against the schema rather than against a template. No lawyer has reviewed it. Where a fact could not be established from the code it is marked [PLACEHOLDER: …] rather than guessed.

This page is deliberately separate from the Privacy Policy. That one tells you what we hold and why. This one tells you how the software enforces it, so that a claim you read there can be checked against something.


In short


The rights, and what happens when you use them

Access and portability — Articles 15 and 20

Profile → Your data → Download a copy.

You get a JSON file containing your profile, the workspaces you belong to and your role in each, invitations that were sent to your address, any staff access you hold, and the record of what you have done in the product.

Two things it deliberately does not contain, both worth stating:

Rectification — Article 16

Your name and job title are editable on the same page. Your email address is not: it is the thing you sign in with, and it is how an invitation was addressed to you. Ask us and we will change it.

Erasure — Article 17

Profile → Your data → Delete your account. You are asked to type DELETE, because it cannot be undone.

What happens, precisely:

Two things survive, and both are deliberate:

Invitations you sent to other people. Those are the record of somebody else being given access — their record, not yours. Deleting them to satisfy your request would erase a third party's history. They stay, and they no longer name you.

The row itself, emptied. Rather than deleting the database row, we clear everything in it that identifies you and mark it deleted. This is not a lesser outcome: what remains is an identifier with nothing behind it that names anybody. It is done this way because no part of the running application is permitted to delete user records at all — a deliberate restriction that predates this feature, and a good one, because it means no bug in the product can remove a person.

There is one case where deletion is refused: if you are the last super administrator, because the platform would be left with nobody able to administer it. You are told so, and told what to do about it.

Restriction and objection — Articles 18 and 21

Not self-served. Contact [PLACEHOLDER: data protection contact address — must be a monitored mailbox with a named owner].

Automated decision-making — Article 22

There is none about you. The product uses AI to analyse brands and public discourse. It does not make decisions about individuals, and nothing in it produces a legal or similarly significant effect on a person. Where AI produces analysis for a client report, a member of our staff reviews it before it is published.


Content about people who are not users

This is the part most privacy pages leave out, so it is stated plainly.

Culture Dive collects public material — social posts, news, and answers given by AI assistants — in order to analyse brands. That material can mention people who have never used this product and never agreed to anything.

If you believe you appear in material we hold and you want it removed, write to [PLACEHOLDER: data protection contact address] and say where. You do not need an account to ask.

[PLACEHOLDER: counsel to confirm the lawful basis recorded for this processing and the Article 14(5)(b) position on notifying people whose content is collected. No legitimate interests assessment has been carried out or written down.]


Where your data lives

WhatWhere
The databaseSupabase, eu-central-1 (Frankfurt)
The applicationFly.io, Frankfurt
EmailPostmark
PaymentsStripe
AI analysisOpenRouter, and the model providers behind it

No account data is sent to an AI model. The analysis operates on collected public content and on the questions we ask about brands; your name and email address are not part of it.

[PLACEHOLDER: for each provider above, counsel must establish and record the international transfer basis — adequacy, standard contractual clauses, or otherwise — and a data processing agreement must be executed with each.]


What we do not do


Retention

[PLACEHOLDER: a retention schedule per class of data is the single largest gap in this document and must be set before it is published. The mechanism to enforce it exists in the database; the policy does not. Founder and counsel to agree periods for: collected content, analysis records, the activity log, and invitations.]

Until that is set, we hold data for as long as the account exists. Deleting your account removes yours immediately, as described above.


Who to contact

ControllerAPC Labs SLU, Barcelona, Spain
Registration[PLACEHOLDER: company registration / NIF, from the incorporation documents]
Data protection contact[PLACEHOLDER: a monitored mailbox with a named owner]
Supervisory authorityAgencia Española de Protección de Datos (AEPD), Spain

You have the right to complain to the AEPD, or to the authority in the EU country where you live or work.