Privacy Policy

Last updated: 2026-08-01What personal data APERTURESyndicate OÜ collects, why, on what legal basis, who else sees it, and the rights you have over it.

Privacy Policy

Effective date: 31 July 2026 · Version 2.0

This policy tells you what personal data we process when you use APERTURESyndicate, why we process it, what legal basis we rely on, who else sees it, how long we keep it, and what you can do about it. It is the information notice required by Articles 13 and 14 of the General Data Protection Regulation (Regulation (EU) 2016/679, the "GDPR").

We have tried to write it so that you can actually read it. Where another document is the authoritative source — retention periods, the list of sub-processors — we link to it rather than repeat it, because duplicated facts drift apart.

We write these documents in good faith and keep them accurate to how the platform actually works. They have not yet been reviewed by qualified Estonian legal counsel.


1. Who is responsible for your data

The data controller is:

APERTURESyndicate OÜ Registry code 17384111 · VAT EE102972654 Priisle tee 8, Lasnamäe linnaosa, Tallinn, Harju maakond, 13914, Estonia Company Registration & Imprint

Contact for anything privacy-related: [email protected] — use the subject line "GDPR request". We accept requests in English or Estonian.

We have not appointed a Data Protection Officer. Article 37(1) GDPR requires one only where the controller is a public authority, where the core activity consists of regular and systematic monitoring of data subjects on a large scale, or where the core activity is large-scale processing of special-category or criminal-offence data. None of those apply to us: we are a micro enterprise, we do not carry out large-scale monitoring, and we do not build our business on special-category data. Privacy requests therefore go to the address above and are handled by the company directly. If that changes, we will appoint a DPO and publish the contact here.

2. What we process, why, and on what basis

This is the core of the notice. The retention column is drawn from the same source as our Data Retention Schedule — that document is authoritative and has the detail, including exceptions and legal holds. The recipients column gives categories; the named providers are listed in Data Processing & Sub-processors.

CategoryWhat it includesWhy we process itLegal basis (Art. 6)How longWho else sees it
AccountEmail address, nickname, internal account identifier, display name, avatar and banner, bio, links, language and theme settings, badges, followsTo create and run your account, show you to other users the way you chose, and let you use the productsContract — Art. 6(1)(b)While the account exists, then purged after ~30 daysEU hosting provider; CDN/edge provider
Authentication & securityPassword hash, two-factor (TOTP) secret in encrypted form, sessions and refresh tokens, sign-in events, IP addresses, user agent, rate-limit and abuse signalsTo sign you in, keep sessions valid, detect and stop account takeover, brute force, spam and denial-of-serviceContract — Art. 6(1)(b) for sign-in; legitimate interests — Art. 6(1)(f) for security and anti-abuse, our interest being to keep accounts and the platform safeServer logs and IP addresses 30 days; sessions until they expire or you sign outEU hosting provider; CDN/edge and security provider
PaymentsSubscription and plan records, invoices, payment status, billing country, VAT treatment, partial card metadata returned by the processorTo take payment, run subscriptions, issue invoices, handle refunds and meet accounting and tax dutiesContract — Art. 6(1)(b); legal obligation — Art. 6(1)(c) for accounting recordsInvoices and accounting records 7 years, as Estonian accounting law requiresPayment processor (Stripe); our accountant and the tax authority where required
Content you createPosts, profile content, uploaded images and audio, support requests and attachments, AI prompts and conversations, datasets, listening activity in ResonanceTo store, deliver and display what you create to the audience you chose, and to provide the product features you useContract — Art. 6(1)(b); consent — Art. 6(1)(a) where a feature is optional and you switch it on (for example AI training on your content)Until you delete it or close your account; then soft-deleted and purgedEU hosting and object storage; AI inference providers, only for the content you send to an AI feature; CDN for public media
Technical telemetryError reports and stack traces, performance timings, aggregate usage counters, device and browser typeTo find and fix faults, keep the service stable and understand which features are usedLegitimate interests — Art. 6(1)(f), our interest being a service that worksRaw events ~30 days; aggregates longer, in non-identifying formError-monitoring provider
SupportEmails you send us, the account they relate to, and our repliesTo answer you, follow up, and resolve disputesLegitimate interests — Art. 6(1)(f), our interest being to support and defend our service; legal obligation where the request is a statutory one~2 yearsOur email provider

Do you have to give us this data? To have an account, yes — an email address and credentials are necessary to conclude and perform the contract with us, and without them we cannot provide the Services. Everything else — profile details, uploads, optional features — is yours to give or withhold.

Cookies and similar technologies are covered separately in the Cookie Policy.

Product-specific detail. Resonance listening history and its privacy controls are described in the Resonance Privacy Addendum. How AI features use your data, and how to turn training off, is in AI Data & Training.

3. Your identifiers and what is public

Your nickname, avatar, banner, bio and links are visible to other users where you have chosen to publish them.

Your internal account identifier ("handle") is what our own services use to link your account across the platform. It is not a public identity, and we do not disclose it to third-party applications or to other services outside our own systems.

Your email address is never shown to other users.

4. Support requests

When you contact support from your account, the request and our replies are stored with your account so both sides can see the history. They travel over TLS and sit on encrypted storage, and they are readable by us — that is the point of asking us for help.

Only the people who handle support see them. Our replies are sent from a single support identity rather than from a named person's account, so nobody can impersonate a member of staff by writing to you directly.

You can close a request when it is resolved. Closing it does not delete it: the history is kept under the schedule in Data Retention, because a support conversation is often the evidence of what was agreed.

If you write to us by email instead, that email is handled the same way — see the "Support" row in the table above.

5. Who else receives your data

We do not sell your personal data, and we do not share it with advertisers or use it for advertising profiling.

Your data is shared only with:

  • Service providers acting on our instructions (processors) — hosting, storage, CDN, payments, AI inference, error monitoring, email delivery. Each is bound by a data-processing agreement under Article 28 GDPR. They are named, with their purpose and region, in Data Processing & Sub-processors.
  • Third-party applications you explicitly authorise. If you connect an application through our OAuth flow, it receives only the data covered by the scopes shown on the consent screen — typically nickname, email address, avatar and banner. You choose whether to approve it, and you can revoke access in your account settings. We never share passwords, two-factor secrets or session tokens.
  • Competent authorities, where we are required to disclose data by law or by a valid order, and where responding is necessary to establish, exercise or defend legal claims. We assess each request and disclose the minimum required.
  • A successor, if our business or part of it is transferred. You would be informed, and your rights would not be reduced.

6. Where your data is, and international transfers

Personal data is hosted within the European Union — our servers are in Finland and Germany.

Some providers process data outside the EU/EEA. Where that happens, the transfer is covered by one or more of the safeguards in Chapter V of the GDPR:

  • the EU Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914), supported by transfer risk assessments and additional technical and organisational measures where appropriate; and/or
  • an adequacy decision of the European Commission covering the recipient country or framework.

Which provider relies on which mechanism is set out per provider in Data Processing & Sub-processors. You can ask us for a copy of the relevant safeguards at [email protected].

7. Automated processing and profiling — what is actually automated

Some things here are decided by software, and you should know which.

Automated systems act on their own for infrastructure protection: rate limiting, spam and bot detection, fraud signals from our payment processor, and detection of anomalous account activity such as sign-in patterns consistent with credential stuffing. These systems can automatically slow a request, block traffic, require re-authentication, or temporarily lock an account. Recommendations and personalised feeds inside products such as Resonance are also generated automatically from your own activity.

Decisions that meaningfully affect you are made by people. Removing your content, restricting features, suspending or terminating your account, and refusing a refund are human decisions. Automated signals may raise the case; they do not close it.

Your rights here. Where a decision affecting you was reached with the help of automated processing, you can ask us to explain it, express your point of view, and have a person review it. Write to [email protected] with the subject line "Appeal". We do not carry out automated decision-making producing legal effects or similarly significant effects on you within the meaning of Article 22 GDPR; if that ever changes, we will say so here first.

8. Security

We apply technical and organisational measures proportionate to the risk: encryption in transit and at rest, hashed passwords, encrypted two-factor secrets, least-privilege access control, network isolation of our database layer, logging and monitoring, and vendor diligence before we engage a processor.

No system is perfect. If a personal data breach occurs that is likely to result in a risk to your rights and freedoms, we will notify Andmekaitse Inspektsioon within 72 hours of becoming aware of it, as Article 33 GDPR requires, and we will inform you directly where the risk is high.

Found a vulnerability? Please tell us — see Responsible Disclosure.

9. Your rights

Under the GDPR you have the following rights over your personal data.

Access — a copy of the data we hold about you and an explanation of how it is used.

Rectification — correction of inaccurate data. Most of it you can fix yourself in account settings; anything you cannot edit there, we correct on request.

Erasure — deletion of your account and personal data. This is a genuine hard deletion, carried through every service that held a copy, not just a hidden profile. Some records survive where the law requires — invoices in particular must be kept for 7 years — and we keep a minimal record that an erasure happened so we can prove we honoured it.

Restriction — pausing processing while a dispute about accuracy or about our legitimate interests is resolved.

Objection — you can object to processing based on legitimate interests, including profiling. We stop unless we can show compelling legitimate grounds that override your interests.

Portability — a copy of the data you provided to us, in a structured, commonly used, machine-readable format, and where technically feasible transmitted directly to another controller. Honest note: we do not yet have a self-service export button in the product. The right is real and we honour it — we produce the export manually when you ask, within the response time in Section 10. When self-service export ships, we will update this section.

Withdrawal of consent — where we rely on your consent, you can withdraw it at any time, as easily as you gave it. Withdrawal does not affect processing that already took place.

Complaint to a supervisory authority — see Section 11.

None of these rights is affected by exercising another, and exercising them is free.

10. How to exercise your rights

Write to [email protected] from the email address registered to your account, with the subject line "GDPR request", and say which right you want to exercise.

If we cannot tie a request to an account, we may ask for something further to confirm it is yours. We ask for the minimum needed and do not keep it afterwards.

We answer within 30 days of receiving the request. If the request is unusually complex or you have made several, we may extend this by up to 2 further months, and we will tell you within the first month if that happens.

Requests are free. We may charge a reasonable fee, or refuse, only where a request is manifestly unfounded or excessive — and we will explain why.

11. If you are not satisfied

Please come to us first at [email protected] — most complaints turn out to be something we can simply fix.

You also have the right to lodge a complaint with a supervisory authority under Article 77 GDPR. Ours is:

Andmekaitse Inspektsioon (Estonian Data Protection Inspectorate) Tatari 39, 10134 Tallinn, Estonia https://www.aki.ee/en · [email protected]

You may also complain to the supervisory authority of the EU member state where you live or work, or where the alleged infringement took place. Nothing here limits your right to a judicial remedy.

12. Children

The Services are for people aged 16 and over. We do not knowingly process the personal data of anyone under 16, and we do not direct any part of the platform at children.

If we learn that an account belongs to someone under 16, we close it and delete the associated personal data. If you believe a child under 16 has given us personal data, contact [email protected] and we will act.

Some content and features are additionally restricted to users aged 18 and over.

13. Marketing

We do not run a marketing newsletter and we do not have a marketing mailing list.

The email we send you is service email: account verification, security alerts, password and sign-in notices, billing and invoice messages, and notices about changes to these documents. That email is necessary to perform our contract with you and to meet our legal duties, so it is not something you can unsubscribe from while keeping an account — though you can close the account at any time.

If we ever introduce marketing email, it will be opt-in, based on your consent under Article 6(1)(a) GDPR, with a working unsubscribe link, and this section will be updated before the first message goes out.

14. Changes to this policy

We may update this policy — for example when we add a product, change a provider, or the law changes.

For any material change we will give you at least 30 days' notice by email to the address on your account or by a clear notice in the product, and we will update the "Effective date" at the top of this page. Minor corrections — typos, clarified wording, updated links — may be made without notice.

Previous versions are available on request at [email protected].

15. Language

This policy is published in English and in translation. The English version is the controlling version. If a translation and the English version differ, the English version applies. This does not affect any right you have under mandatory law to receive information in your own language.

Contact

PurposeContact
Privacy and data-subject requests[email protected] — subject "GDPR request"
General support[email protected]
Security vulnerabilities[email protected] — subject "SECURITY"
Websitehttps://aperturesyndicate.com

APERTURESyndicate OÜ · Registry code 17384111 · VAT EE102972654 Priisle tee 8, Lasnamäe linnaosa, Tallinn, Harju maakond, 13914, Estonia


Version history

  • v2.0 — 2026-07-31 — Full rewrite: controller identity and contact, category-by-category table with Article 6 legal bases, retention and recipient categories, international transfers and safeguards, the full set of data-subject rights with an honest note on portability, complaint route to Andmekaitse Inspektsioon, the reason no DPO is appointed, what is and is not automated, children, and language precedence. Removed the claim that chat is stored encrypted end-to-end, the description of the internal handle as public, and the promise of a newsletter that does not exist.
  • v1.0 — 2026-06-22 — Initial publication.
Privacy Policy | AS Docs