Privacy Policy
Last updated: [DATE] Effective date: [DATE]
DRAFT — This document is a working draft and has not been reviewed by legal counsel. Do not rely on this for legal compliance.
1. Introduction
ONTOUR Sports Ltd ("we", "us", "our") operates GafferLab (the "Service"). This Privacy Policy explains how we collect, use, share, and protect your personal data when you use the Service.
We comply with:
- UK General Data Protection Regulation (UK GDPR)
- Data Protection Act 2018
- EU General Data Protection Regulation (GDPR) for EU users
- California Consumer Privacy Act (CCPA) for California residents
Data Controller: ONTOUR Sports Ltd, 4 Lytton Road, Barnet, EN5 5BY, United Kingdom, ICO registration number: [ICO NUMBER — register at ico.org.uk] Data Protection Contact: [email protected]
2. Data We Collect
2.1. Information you provide
| Category | Examples |
|---|---|
| Account info | Email, password (hashed), display name, avatar URL |
| Payment info | Billing address, card details (processed by Stripe, not stored by us) |
| Content | Text prompts, uploaded media, generated videos/images/audio |
| Communications | Support tickets, feedback, email correspondence |
| Profile settings | Notification preferences, theme choices, language |
2.2. Information collected automatically
| Category | Examples |
|---|---|
| Usage data | Features used, credits consumed, render history, API calls |
| Device info | Browser type, OS, screen resolution, IP address |
| Cookies | Session tokens, preferences, analytics (see Cookie Policy) |
| Log data | Timestamps, error logs, request metadata |
2.3. Information from third parties
When you connect social accounts (Instagram, TikTok, Twitter/X, Google), we receive:
- Account identifier (username, user ID)
- Profile picture
- Access tokens (encrypted at rest)
- Permission scopes you granted
We do NOT receive your social account password.
2.4. Information we don't collect
- We do not collect special category data (health, biometric, political opinions, religion) unless you voluntarily include it in your content
- We do not collect data about minors under 16
- We do not sell your personal data to third parties
3. How We Use Your Data
We process your personal data for the following purposes:
| Purpose | Legal basis (UK/EU GDPR) |
|---|---|
| Providing the Service | Contract performance |
| Processing payments | Contract performance |
| Sending account notifications | Contract performance |
| Generating AI content (via third parties) | Contract performance |
| Marketing emails | Consent (opt-in) |
| Improving the Service | Legitimate interest |
| Security, fraud prevention | Legitimate interest |
| Complying with legal obligations | Legal obligation |
| Responding to support requests | Legitimate interest |
| Analytics (aggregated, non-personal) | Legitimate interest |
You may withdraw consent for marketing at any time without affecting the lawfulness of prior processing.
4. Third-Party Data Processors
We share your data with the following processors to deliver the Service. Each has been assessed for data protection compliance.
4.1. AI Processing
| Processor | Purpose | Data shared | Location | DPA |
|---|---|---|---|---|
| OpenAI, Inc. | GPT text generation, DALL-E 3 images, GPT-4o Vision | Prompts, images, request context | United States | [Link to OpenAI DPA] |
| ElevenLabs, Inc. | Voice synthesis, sound effects, music, transcription, dubbing, voice design | Text, audio files, voice selections | United States | [Link to ElevenLabs DPA] |
| Kling AI (Kuaishou Technology) | AI video generation | Text prompts, reference images | China / Singapore | [Link to Kling DPA] |
Important: Data processed by OpenAI, ElevenLabs, and Kling AI may be transmitted outside the UK/EU. We rely on Standard Contractual Clauses (SCCs) and other appropriate safeguards for international data transfers.
Important — AI training: We do not permit these providers to use your data to train their models. We configure zero-retention and no-training options where available.
4.2. Infrastructure
| Processor | Purpose | Data shared | Location |
|---|---|---|---|
| Amazon Web Services (AWS) | Hosting, S3 storage, Lambda rendering, CloudFront CDN | User content, generated files, logs | EU (Ireland, Stockholm) |
| Cloudflare | CDN, DDoS protection | IP addresses, request metadata | Global |
| Redis Labs (or self-hosted Redis) | Session cache, rate limiting | Session tokens, rate limit counters | EU |
4.3. Payment
| Processor | Purpose | Data shared | Location |
|---|---|---|---|
| Stripe, Inc. | Payment processing | Card details (tokenized), billing info, email | United States / Ireland |
| PostHog EU | Product analytics | Usage events, pseudonymous user id (no email/name) | EU (Germany) |
4.4. Social Media Publishing
| Processor | Purpose | Data shared | Location |
|---|---|---|---|
| Meta Platforms Ireland Ltd. | Instagram auto-publishing | OAuth tokens, post content | Ireland |
| TikTok Technology Ltd. | TikTok auto-publishing | OAuth tokens, post content | Ireland |
| X Corp | Twitter/X auto-publishing | OAuth tokens, post content | United States / Ireland |
When you connect a social account, data shared with that platform is subject to the platform's own privacy policy.
4.5. Authentication (future)
| Processor | Purpose | Data shared |
|---|---|---|
| Google LLC (planned) | Sign-in with Google | Email, name, profile picture |
| Apple Inc. (planned) | Sign-in with Apple | Email, name |
4.6. Sports Data
| Processor | Purpose | Data shared |
|---|---|---|
| ONTOUR (our own system) | Football fixture data | Account identifier |
| API-Football (via ONTOUR) | Fixture, stats, lineup data | No personal data |
5. Data Retention
We retain personal data only as long as necessary:
| Data type | Retention period |
|---|---|
| Account data | Duration of account + 90 days after deletion |
| User content (videos, images) | Duration of account + 30 days after deletion |
| Rendered outputs | 90 days from render date (unless downloaded) |
| Credit transaction history | 7 years (tax/accounting law) |
| Logs (security, errors) | 90 days |
| API usage logs | 180 days |
| Marketing data | Until you withdraw consent |
| Social OAuth tokens | Until you disconnect the account |
After retention expires, data is permanently deleted or fully anonymized.
6. Your Rights
6.1. Rights under UK/EU GDPR
You have the right to:
- Access: Request a copy of your personal data
- Rectification: Correct inaccurate data
- Erasure: Request deletion ("right to be forgotten")
- Restriction: Limit processing in certain circumstances
- Portability: Receive your data in a machine-readable format
- Object: Object to processing based on legitimate interest
- Withdraw consent: Where processing is based on consent
- Not be subject to automated decision-making: Including AI profiling
To exercise these rights, contact [email protected]. We will respond within 30 days.
6.2. Rights under CCPA (California residents)
California residents have the right to:
- Know what personal information is collected
- Know whether personal information is sold or disclosed
- Say "no" to the sale of personal information
- Access their personal information
- Request deletion
- Equal service and price even after exercising privacy rights
We do not sell personal information.
6.3. Right to complain
You can lodge a complaint with your local data protection authority:
- UK: Information Commissioner's Office (ICO) — ico.org.uk
- EU: Your national supervisory authority
7. International Transfers
We transfer personal data outside the UK/EU to:
- OpenAI (United States)
- ElevenLabs (United States)
- Kling AI (China/Singapore)
- Stripe (United States / Ireland)
- X Corp (United States)
For these transfers, we rely on:
- Standard Contractual Clauses (SCCs)
- UK International Data Transfer Agreement (IDTA)
- Adequacy decisions where available
Copies of relevant safeguards are available on request at [email protected].
8. Security
We implement technical and organizational measures to protect your data:
- Passwords hashed with bcrypt (cost factor 10+)
- API keys hashed with SHA-256, never stored in plaintext
- OAuth tokens encrypted at rest
- Database encrypted in transit (TLS) and at rest
- S3 objects private by default, signed URLs for access
- Rate limiting to prevent abuse
- Regular security audits and dependency updates
- Incident response plan for breach notification (within 72 hours per GDPR)
Despite our efforts, no system is completely secure. Users are encouraged to:
- Use strong, unique passwords
- Enable two-factor authentication (when available)
- Keep their devices and browsers updated
- Not share credentials
9. Cookies
We use cookies and similar technologies for:
- Essential: Session management, authentication (cannot be disabled)
- Preferences: Theme, language, UI state
- Analytics: Aggregated usage data (opt-in in EU/UK)
- Marketing: None currently
See our Cookie Policy for details and how to manage cookies.
10. Children's Privacy
GafferLab is not intended for users under 16. We do not knowingly collect personal data from children. If we become aware that a child has provided data, we will delete it promptly.
11. AI-Specific Disclosures
11.1. What AI features do with your data
When you use AI features, your inputs (prompts, images, audio) are sent to the relevant AI provider:
- Text prompts → OpenAI (for copy/Director) or stored internally
- Uploaded images → OpenAI Vision API (if analyzing) or stored
- Voice text → ElevenLabs for TTS
- Audio files → ElevenLabs for transcription/isolation/conversion
- Video prompts → Kling AI for generation
11.2. AI training
We have configured our AI providers to:
- OpenAI: API usage is not used for training (per OpenAI's API policy)
- ElevenLabs: Audio inputs are not used for training (per their commercial terms)
- Kling AI: We are reviewing their training data policy
11.3. AI outputs
Content generated by AI is delivered to you and stored in your account. We do not claim ownership. You are responsible for verifying AI outputs are appropriate before publishing.
11.4. AI limitations
AI systems can produce inaccurate, biased, or unexpected outputs. We disclaim liability for AI errors. Always review AI content before using commercially.
12. Marketing Communications
We may send you:
- Transactional emails (account, billing, security) — required
- Product updates (feature announcements) — opt-in
- Marketing (newsletters, promotions) — opt-in
You can unsubscribe at any time via email footer links or account settings.
13. Data Breach Notification
In the event of a personal data breach affecting your rights, we will:
- Assess the breach within 24 hours
- Notify the ICO within 72 hours (where required)
- Notify affected users without undue delay (where required)
- Provide guidance on steps to take
14. Changes to this Policy
We may update this Privacy Policy periodically. Material changes will be communicated via email or in-app notice at least 30 days before taking effect. Continued use after changes constitutes acceptance.
Previous versions are archived and available on request.
15. Contact
Data Protection Officer (or primary contact):
ONTOUR Sports Ltd 4 Lytton Road, Barnet, EN5 5BY, United Kingdom Email: [email protected] ICO Registration: [ICO NUMBER — register at ico.org.uk]
For data subject requests: [email protected] For general questions: [email protected]
Appendix A: List of Sub-Processors
(Updated quarterly)
| Sub-processor | Service | Purpose | Country | Transfer mechanism |
|---|---|---|---|---|
| OpenAI, Inc. | AI text/image/vision | Content generation | USA | SCCs + UK IDTA |
| ElevenLabs, Inc. | AI audio | Voice/audio generation | USA | SCCs + UK IDTA |
| Kling AI | AI video | Video generation | China/SG | SCCs + UK IDTA |
| Amazon Web Services | Cloud infrastructure | Hosting, storage, CDN | EU (Ireland) | Adequacy |
| Cloudflare | CDN/DDoS | Network security | Global | SCCs |
| Stripe | Payments | Transaction processing | USA/IE | Adequacy + SCCs |
| PostHog EU | Analytics | Product usage events | EU (Germany) | N/A (EU-hosted) |
| Meta Platforms | Instagram API | Auto-publishing | Ireland | Adequacy |
| TikTok Technology | TikTok API | Auto-publishing | Ireland | Adequacy |
| X Corp | Twitter API | Auto-publishing | USA | SCCs |
| ONTOUR | Sports data | Fixture feeds | UK | Adequacy |
Users are notified of material changes to sub-processors with 30 days' notice.