How Culture Dive complies with the GDPR
DRAFT FOR LEGAL REVIEW. This is not legal advice. It was written by reading the Culture Dive codebase and describes what the system actually does today, checked against the schema rather than against a template. No lawyer has reviewed it. Where a fact could not be established from the code it is marked [PLACEHOLDER: …] rather than guessed.
This page is deliberately separate from the Privacy Policy. That one tells you what we hold and why. This one tells you how the software enforces it, so that a claim you read there can be checked against something.
In short
- You can download everything we hold about your account, yourself, from your profile page.
- You can delete your account, yourself, from the same page. It takes effect immediately.
- Neither needs to go through us, and neither is a request we could quietly not action.
The rights, and what happens when you use them
Access and portability — Articles 15 and 20
Profile → Your data → Download a copy.
You get a JSON file containing your profile, the workspaces you belong to and your role in each, invitations that were sent to your address, any staff access you hold, and the record of what you have done in the product.
Two things it deliberately does not contain, both worth stating:
- Anybody else's activity. The record of actions inside a client organisation is readable by that organisation's staff, so an export that simply asked for "the audit log" would hand you your colleagues' actions. Every row in your file names you as the person who acted or the person acted upon, and this is enforced by an explicit filter rather than by relying on access rules.
- Material we collect about brands and public figures. That is not linked to any account, so it cannot be found by looking up yours. If you believe you appear in it, see *Content about people who are not users* below.
Rectification — Article 16
Your name and job title are editable on the same page. Your email address is not: it is the thing you sign in with, and it is how an invitation was addressed to you. Ask us and we will change it.
Erasure — Article 17
Profile → Your data → Delete your account. You are asked to type DELETE, because it cannot be undone.
What happens, precisely:
- Your name, email address and sign-in identity are removed. Your record stops naming you.
- Your memberships are deleted, so you lose access to every workspace immediately.
- Invitations sent to your address are deleted.
- Your sign-in account is removed so no new link can be sent to you.
- You are signed out at once.
Two things survive, and both are deliberate:
Invitations you sent to other people. Those are the record of somebody else being given access — their record, not yours. Deleting them to satisfy your request would erase a third party's history. They stay, and they no longer name you.
The row itself, emptied. Rather than deleting the database row, we clear everything in it that identifies you and mark it deleted. This is not a lesser outcome: what remains is an identifier with nothing behind it that names anybody. It is done this way because no part of the running application is permitted to delete user records at all — a deliberate restriction that predates this feature, and a good one, because it means no bug in the product can remove a person.
There is one case where deletion is refused: if you are the last super administrator, because the platform would be left with nobody able to administer it. You are told so, and told what to do about it.
Restriction and objection — Articles 18 and 21
Not self-served. Contact [PLACEHOLDER: data protection contact address — must be a monitored mailbox with a named owner].
Automated decision-making — Article 22
There is none about you. The product uses AI to analyse brands and public discourse. It does not make decisions about individuals, and nothing in it produces a legal or similarly significant effect on a person. Where AI produces analysis for a client report, a member of our staff reviews it before it is published.
Content about people who are not users
This is the part most privacy pages leave out, so it is stated plainly.
Culture Dive collects public material — social posts, news, and answers given by AI assistants — in order to analyse brands. That material can mention people who have never used this product and never agreed to anything.
- It is public content, collected for analysis of brands rather than of people.
- Quotations are capped at 125 characters as a standing rule.
- It is not linked to any account, which is why an account export cannot find it.
If you believe you appear in material we hold and you want it removed, write to [PLACEHOLDER: data protection contact address] and say where. You do not need an account to ask.
[PLACEHOLDER: counsel to confirm the lawful basis recorded for this processing and the Article 14(5)(b) position on notifying people whose content is collected. No legitimate interests assessment has been carried out or written down.]
Where your data lives
| What | Where |
| The database | Supabase, eu-central-1 (Frankfurt) |
| The application | Fly.io, Frankfurt |
| Postmark | |
| Payments | Stripe |
| AI analysis | OpenRouter, and the model providers behind it |
No account data is sent to an AI model. The analysis operates on collected public content and on the questions we ask about brands; your name and email address are not part of it.
[PLACEHOLDER: for each provider above, counsel must establish and record the international transfer basis — adequacy, standard contractual clauses, or otherwise — and a data processing agreement must be executed with each.]
What we do not do
- No analytics. No tracking pixels, no behavioural profiling, no third-party scripts.
- No email tracking. Open tracking and click tracking are switched off, and a test asserts they stay off.
- No advertising, and no sale or sharing of personal data.
- No cookie banner, because the only cookies set are the ones required to keep you signed in and to protect forms against cross-site submission. There is nothing to consent to.
Retention
[PLACEHOLDER: a retention schedule per class of data is the single largest gap in this document and must be set before it is published. The mechanism to enforce it exists in the database; the policy does not. Founder and counsel to agree periods for: collected content, analysis records, the activity log, and invitations.]
Until that is set, we hold data for as long as the account exists. Deleting your account removes yours immediately, as described above.
Who to contact
| Controller | APC Labs SLU, Barcelona, Spain |
| Registration | [PLACEHOLDER: company registration / NIF, from the incorporation documents] |
| Data protection contact | [PLACEHOLDER: a monitored mailbox with a named owner] |
| Supervisory authority | Agencia Española de Protección de Datos (AEPD), Spain |
You have the right to complain to the AEPD, or to the authority in the EU country where you live or work.