perso.social · Juridisch
Privacy Policy
How perso.social collects, processes, and protects your data.
Van kracht sinds 2026-07-03 · Taal: NL
Deze pagina wordt in het Engels weergegeven. De Engelse versie is de juridisch bindende versie. Er wordt een Nederlandse vertaling voorbereid.
Data Controller & Points of Contact (GDPR Art. 13(1)(a); DSA Arts. 11-12)
- perso.social is operated by ACGG Rent, S.L., a Spanish sociedad limitada and the sole data controller, with registered office (domicilio social) at Calle Francisco Ayala 27, 28522 Rivas-Vaciamadrid, Madrid, Spain; CIF B-56240385; registered with the Registro Mercantil de Madrid, Tomo 45565, Folio 30, Hoja M-801410; represented by Etienne Gillard. ACGG Rent, S.L. is established in Spain.
- perso is not directed to residents of the United Kingdom, the Channel Islands, the Isle of Man, or Gibraltar, and does not offer services to, or monitor the behaviour of, individuals located in those jurisdictions; account creation from a declared residence in any of them is refused. perso has therefore not designated a representative under Article 27 of the UK GDPR.
- For data-protection enquiries: dpo@perso.social
- DSA Single Point of Contact: dsa@perso.social
- General Legal Enquiries: legal@perso.social
- You have the right to lodge a complaint with the supervisory authority in your country of residence within the European Economic Area.
Identity Verification
When you choose to verify your identity, you complete the verification process directly with our verification provider. The provider checks your identity documents and performs liveness and fraud-prevention checks. We do not receive or store copies of your identity documents or biometric templates. From the verification outcome, we receive and store only a limited set of attributes linked to your account, such as: whether your verification was successful and which method was used; your verified legal name; a one-way identifier derived from your document number, which we use to prevent the same document from being used to open more than one account, to support account recovery, and to refuse recovery of an account that has been banned; whether your verification relied on certain trusted sources (for example, notified electronic identities) and an audit reference; confirmation that you are at least 18 years old; and your country of residence. Our verification provider sends us a technical payload that can include IP-based location and network metadata (for example, country and city derived from IP, and security signals). We do not read, use, or retain this information; it is not used for profiling, eligibility, or any other purpose, and no precise location data (such as GPS coordinates or IP-derived latitude/longitude) is stored. If you use a recovery email or have an institutional account, we also store an optional recovery email address that you provide, and for organisations, basic information about the organisation (such as its registration number) and the authorised representative. We use these attributes to confirm that each account is held by a real person, to prevent the same document from being used to open more than one account, to determine eligibility for certain features, and to comply with our legal, safety and platform-integrity obligations. They are stored separately from your public content at the application level and are accessible only to authorised personnel and services that need them for account integrity, safety, support or compliance purposes. We protect them using technical and organisational measures appropriate to their sensitivity, including encryption in transit, encryption at rest provided by our hosting provider, restricted access rights, key management for our de-duplication mechanism, and logging of administrative access. We keep your identity-verification attributes for as long as your account is active. If you delete your account, we delete or irreversibly anonymise these attributes, including the de-duplication identifier, as part of the account-deletion process. We do not retain identity-verification attributes after account deletion, except a limited accountability record of the verification decision and its reason, held for up to 12 months for security and audit purposes, with the email address redacted. In the future, we may retain a non-reversible technical identifier for a limited period solely to prevent abuse (for example, to prevent the same document from being used to open more than one account), and we will update this section before any such mechanism is enabled.
Press Verification
If you apply for a "verified journalist" badge, we ask you to provide your work email address, the name of your media organisation, and an optional link to a portfolio or recent work. At this stage, we do not collect or store images of press cards or other professional credentials as part of this process. We use this information only to assess your eligibility for a "verified journalist" badge and to prevent misuse of that status. Your work email address is stored in encrypted form and is accessible only to authorised personnel and services involved in verification and audit. These data are stored separately from your public content at the application level. In the future, we may offer you the option to upload a press card or similar professional credential as part of the verification process. If we introduce this feature, we will update this notice before we begin processing these images to explain what we collect, how long we keep it, and how we protect it, including the security measures that apply to any images you choose to upload.
Security and Technical Logs
For security, abuse-prevention and operational purposes, we create and retain logs about how our services are used. These logs can include information such as your IP address, your browser or device type and settings, the date and time of your requests, and how you interact with certain features (for example, account recovery and administrative tools). We use these logs to detect and prevent malicious or abusive activity, to investigate incidents, and to maintain the stability and security of the service. We keep this information for as long as necessary for these purposes and then delete it or irreversibly anonymise it.
Infrastructure and Hosting
perso's own application and database infrastructure is hosted on servers located in the European Union. In particular: application servers are located in France and operated by an EU infrastructure provider (OVHcloud); the primary database is a managed PostgreSQL database from Scaleway (an EU provider) in the Paris region (fr-par), where all connections between the application and the database use Transport Layer Security (TLS) with certificate verification and the database is encrypted at rest by the cloud provider at the storage-volume level (this provider-level encryption is distinct from application-level field encryption, which perso does not apply to identity attributes); the search index is Meilisearch, self-hosted by perso on its EU-based application infrastructure; email delivery uses an EU-based email service provider (IONOS); and key management uses a managed key service provided by Scaleway, used to generate and protect the key for the humanity-deduplication mechanism. perso does not currently use a separate caching layer (such as Redis) or a content delivery network. If perso later introduces such services, this section will be updated before they are used to process users' personal data. Third-party processors, including any processing outside the EU or EEA (such as identity verification, media-scanning, and any future analytics services), are addressed in the sub-processors section below and in perso's subprocessors and international-transfers documentation.
Media You Upload
Media you upload. When you post images or other media, we store them on European object storage (Scaleway, Paris region) with encryption at rest. Before your media is shown to anyone, it is automatically checked for known child sexual abuse material using Microsoft's PhotoDNA service through its European hash-matching endpoint. This check sends only a non-reversible mathematical signature of your image; the image itself is never sent to Microsoft. Your media is also automatically screened by a nudity-detection classifier. Media is not displayed until these checks complete, and any media the classifier flags is withheld from display until a member of our team has reviewed it.
Data Retention
perso keeps personal data only for as long as necessary. Account data is retained while your account is active and deleted within 30 days of account deletion via a cascading purge. Identity-verification attributes are retained while your account is active and are deleted or irreversibly anonymised, including the de-duplication identifier, as part of the account-deletion process; perso does not retain identity-verification attributes after account deletion, except a limited accountability record of the verification decision and its reason, held for up to 12 months for security and audit purposes, with the email address redacted. In the future, we may retain a non-reversible technical identifier for a limited period solely to prevent abuse (for example, to prevent the same document from being used to open more than one account), and we will update this section before any such mechanism is enabled. A verification-decision audit record is retained for 12 months from the decision, including past account deletion, for security and accountability purposes, with account-identifying fields redacted. Content data is retained while posted and deleted within 30 days of removal or of account deletion. Moderation audit logs are retained for as long as necessary for accountability under the Digital Services Act. Records of moderation decisions and appeals are retained without a deletion timeline, for the life of that accountability obligation, as the durable record supporting platform-safety and appeal decisions; other moderation audit logs are deleted or irreversibly anonymised once no longer necessary. Security and technical logs are retained for as long as necessary for security, abuse-prevention and operational purposes, then deleted or irreversibly anonymised. Contact-form and partnership-inquiry data is retained for up to 12 months: network identifiers are removed after 90 days and the records are deleted after 12 months. Where an organisation verification application is declined, the personal data of the authorised representative from that application is retained for 365 days from the decline and then deleted. Network identifiers (IP address and browser information) captured with an account-recovery attempt are removed after 30 days; the recovery-attempt record is retained without them as a security-audit record. CSAM evidence: where we detect or are notified of suspected child sexual abuse material (CSAM), we immediately remove or disable access to that content on our service but may retain associated hashes, metadata and a minimal evidentiary copy in a segregated evidence store for as long as necessary to comply with our legal obligations, cooperate with competent authorities and protect victims, and then delete it securely. Analytics data is pseudonymised and aggregated and retained no longer than necessary for the purposes described in this policy.
Lawful Basis for Processing
- Performance of a contract (GDPR Art. 6(1)(b)), together with the substantial-public-interest condition (GDPR Art. 9(2)(g)) for the special-category biometric data, for identity verification.
- Consent (GDPR Art. 6(1)(a)) for analytics and marketing cookies.
- Contract performance (GDPR Art. 6(1)(b)) for account operation and feature delivery.
- Legal obligation (GDPR Art. 6(1)(c)) for fraud prevention and law-enforcement requests.
- Legitimate interest (GDPR Art. 6(1)(f)) for service security and abuse prevention.
Your Rights
Under GDPR you have the right to access, rectify, erase, restrict, port, and object to the processing of your personal data. Erasure ("Right to be Forgotten", Art. 17) and portability (Art. 20) are exposed in-app under Settings → Legal → Data Export and Account Deletion.
Automated Decision-Making (GDPR Art. 22)
Most processing at perso does not involve solely automated decisions with legal or similarly significant effects. There is one exception, disclosed here with the safeguards that apply to it. To prevent the same document from being used to open more than one account, the outcome of your identity verification is automatically checked against a non-reversible de-duplication identifier derived from your identity document number. If it matches an already-verified account, your verification is automatically declined and a second account is not created. Because this is a solely automated decision that can significantly affect you (it can prevent you from opening an account), the GDPR Article 22(3) safeguards apply: you have the right to contest the decision, to obtain human review by a member of our team, and to express your point of view. To exercise these rights, email dpo@perso.social from the email address linked to your attempt, stating that you believe the duplicate decision is wrong and why (for example, that you are a different person who was matched in error). A human reviewer will re-examine your case, and if the decline was incorrect we will let you re-verify. Account matching decision. When you verify your identity, whether to recover an account or as part of opening a new one, the one-way identifier derived from your document number is automatically compared against existing accounts. If it does not match an account we can return to you, verification does not proceed. That is the case when no account exists for that identity, when the account was deleted, and when the account is one we have permanently closed. We do not tell you which of these applies, because the reason could reveal the status of an account that is not yours. Because this comparison is automated and can significantly affect you, the Article 22(3) safeguards apply: you can contest the outcome, obtain human review, and express your point of view. Write to dpo@perso.social. A person will review whether the match is correct. If your document was matched to an account that is not yours, we will clear the match so that you can verify and open your own account. We will not give you access to the matched account, and this review does not reconsider any decision we made about that account. Age determination. perso is only for adults. Before an approved verification is accepted, an automated check confirms that its age evidence positively establishes that you are 18 or older. If it does not, whether because the evidence shows you are under 18 or because it could not be read, your verification is automatically declined and no account is created. This check is deliberately strict: absent or unreadable age evidence is treated as not passing rather than guessed. We do not retain your date of birth. The one exception is narrow and temporary: if you contest an age decline and then verify again while that contest is open, we keep the date of birth read from that retry, together with the birthdate you tell us, solely so a person can compare them and judge whether the automated check misread your document. We keep those two dates only while your contest is open, and we delete them the moment it is resolved, whichever way it is resolved; what remains afterward is only the record that a decision was made and its reason. If your verification succeeds, we keep only the fact that the over-18 check passed; if it is declined and not contested, we keep only the decline and its reason category. Because this is a solely automated decision that can significantly affect you, the Article 22(3) safeguards apply: you can contest the outcome, obtain human review, and express your point of view. Write to dpo@perso.social and a person will review your case. If a person reviews your case and confirms from the evidence that you are over 18, we apply that confirmation so your next verification is accepted on the strength of it, and a correct outcome takes effect on your account rather than the same automated misreading repeating. If you are under 18, you are welcome to join once you meet the age requirement. Today, content moderation on perso is primarily human: posts and accounts may be reviewed and restricted or removed by our moderation team in accordance with our rules and the Digital Services Act (DSA). Where a moderation decision is based on an automated check (for example, to detect duplicate accounts), you have the safeguards required by Article 22(3) GDPR: you will be informed when an automated decision is made, you can contest it and express your point of view, and you can ask for a human to review the decision. In addition, uploaded images are checked using an automated hash-matching tool (PhotoDNA) to detect and block known child sexual abuse material (CSAM); this check is separate from ordinary moderation and exists solely to keep the service safe. Automated screening of uploaded media. Media you upload is automatically evaluated by a nudity-detection classifier before it can be shown to others. If the classifier flags your content, the content is withheld from display until a member of our team has reviewed it. This automated step does not by itself suspend your account or impose penalties; it gates visibility pending human review. You can contest a resulting moderation decision through our complaint and appeal process.
Sub-Processors
- Didit: identity verification. Acts as our data processor, on our documented instructions, for identity verification and de-duplication. We never receive your identity-document images, biometric templates, or document nationality; Didit processes biometric data only transiently during the verification session, and we configure the session for immediate deletion at the vendor once the verification outcome is returned. The verification payload may also contain technical and security signals, including IP-based location metadata. perso does not read, use, or retain these signals.
- OVHcloud (France): application server hosting.
- Scaleway (France, Paris region): managed PostgreSQL database, key management, and future object storage.
- IONOS (EU): email delivery.
- Microsoft (PhotoDNA Cloud Service): detection of known child sexual abuse material via perceptual-hash matching. Data: a non-reversible perceptual hash of uploaded media plus operational request metadata; no image content or account identifiers in the routine path. Location: Microsoft EU instance (processed within the EEA). Safeguard: processed within the EEA; for any incidental access from outside the EEA, perso relies on Microsoft's EU-U.S. Data Privacy Framework certification and, as a fallback, the 2021 Standard Contractual Clauses in Microsoft's DPA.
International data transfers
perso minimises transfers of personal data outside the EEA and relies on appropriate safeguards where any processing occurs outside it. Most of your personal data is processed inside the European Economic Area (EEA): perso's application servers, primary database, key management, search index, and email delivery are all operated within the EEA by EU-based providers, and your account and content data do not leave the EEA in the ordinary course of using perso. Our infrastructure providers operate within the EU/EEA. To detect known child sexual abuse material, we use Microsoft's PhotoDNA service running in a Microsoft European instance. This processing is designed so that image content and the mathematical signatures we generate from your images are processed within the European Economic Area using Microsoft's European hash-matching endpoint. As a safeguard for any incidental access from outside the EEA, we rely on Microsoft's participation in the EU-U.S. Data Privacy Framework and, as a fallback, the Standard Contractual Clauses in Microsoft's data protection terms. If you choose to take out a paid membership, certain subscription and entitlement data will also be processed by RevenueCat, Inc., a payment-management provider located in the United States. That processing is not active yet; before it begins, we will update this section to describe it and the safeguards that apply, and add the provider to our sub-processor list. If you would like more information about our international transfers or the safeguards we use, contact dpo@perso.social. The data controller, ACGG Rent, S.L., is established in Spain (EU). Where any authority makes a request for access to personal data, we assess it against EU law and challenge requests that are overbroad or unlawful.
Data Protection Contact
For data-protection enquiries: dpo@perso.social.
Supervisory Authority
Users in the European Economic Area have the right to lodge a complaint with their local supervisory authority.
United Kingdom, Crown Dependencies & Gibraltar: No Article 27 Representative
perso is not directed to residents of the United Kingdom, the Channel Islands, the Isle of Man, or Gibraltar, and does not offer services to, or monitor the behaviour of, individuals located in those jurisdictions; account creation from a declared residence in any of them is refused. perso has therefore not designated a representative under Article 27 of the UK GDPR.
Contact
- Privacy questions: dpo@perso.social.
- Data Controller: perso.social is operated by ACGG Rent, S.L., a Spanish sociedad limitada, with registered office (domicilio social) at Calle Francisco Ayala 27, 28522 Rivas-Vaciamadrid, Madrid, Spain; CIF B-56240385; registered with the Registro Mercantil de Madrid, Tomo 45565, Folio 30, Hoja M-801410. Represented by Etienne Gillard. ACGG Rent, S.L. is the sole data controller, established in Spain.
© 2026 perso