Your Data,
Protected
by Design.
We treat privacy the same way we treat delivery - with structural accountability. This policy explains exactly what we collect, why we collect it, and the rights you have at every step of the engagement.
Six commitments,
one clear standard.
The full policy is below. This summary captures the principles that govern every line of it - written in plain English, the way our engagements are structured.
What we collect
Account, engagement, billing, technical, and communication data - only what is needed to run a managed engagement.
How we protect it
AES-256 encryption at rest, TLS 1.2+ in transit, SOC 2-aligned access controls, and least-privilege internal access.
Why we hold it
Contract performance, legal obligations, fraud prevention, and improving the managed delivery framework.
Your rights
Access, rectification, deletion, portability, restriction, and objection - exercisable in a single email.
Where it lives
Primary data residency in the UK and EU. Sub-processors are bound by Standard Contractual Clauses.
What we never do
We do not sell personal data. We do not share it for advertising. We do not retain it beyond its purpose.
Information
we collect.
We collect only the data required to operate the managed engagement, fulfil legal obligations, and improve service quality. Each category below is tied to a defined purpose and lawful basis under GDPR Article 6.
Data minimisation
If a field is not strictly necessary for delivery, accountability, or legal compliance - we do not collect it.
Account information
- Full name, business name, and professional title
- Email address, telephone number, and country of residence
- Authentication credentials (password hashes - never stored in plain text)
- Profile picture and biographical content you choose to upload
Engagement information
- Project briefs, requirements, scope documents, and milestone records
- Timesheets, hour logs, deliverable URLs, and milestone approvals
- Messages exchanged on the platform between clients, developers, and OTF
- Dispute submissions, evidence files, and ruling records
Payment and tax information
- Billing address and tax registration numbers (VAT/GST/EIN as applicable)
- Bank or payout details - held by our PCI-DSS Level 1 payment processor, not by OTF
- Invoice history, payment status, and payout records
Technical information
- IP address, device identifiers, browser type, and operating system
- Pages visited, features used, and approximate session duration
- Cookie identifiers and session tokens (see Cookies section below)
Verification information (developers only)
- Government-issued ID for KYC checks during 5-stage vetting
- Portfolio links, code samples, and reference contact details
- Right-to-work and tax residency documentation as required by jurisdiction
How we use
your information.
Every processing activity at Open IT Freelancers is mapped to one of six defined purposes. Each purpose has a documented lawful basis and a defined retention period.
Operate managed engagements
Match developers and clients, run weekly cycles, track milestones, release payments, and resolve disputes - the core of every OTF engagement.
Enforce platform authority
Verify identity, prevent fraud, enforce contract terms, and protect both sides of the engagement under our managed delivery framework.
Improve product quality
Aggregate, anonymise, and analyse usage to refine the AI shortlist, the vetting workflow, and the platform experience overall.
Communicate with you
Send transactional emails (milestone notifications, dispute updates, payment receipts) and - only with consent - service updates.
Meet legal obligations
Comply with tax law, anti-money-laundering rules, KYC requirements, and any lawful request from a competent authority.
Measure delivery outcomes
Track the 98% delivery success rate and other quality metrics in aggregate - never to profile individuals beyond engagement context.
The legal basis
for processing.
Under GDPR and UK-GDPR, we must rely on a specific lawful basis for every processing activity. Below is the mapping we apply across the platform.
Operating your managed engagement, releasing payments, and delivering milestones.
Tax reporting, KYC/AML checks, and responses to lawful authority requests.
Fraud prevention, dispute investigation, platform security, and aggregate analytics.
Marketing communications, optional profile enrichment, and non-essential cookies.
Who we share with
and who we don't.
Data sharing inside Open IT Freelancers is governed by the principle of purpose limitation. Every recipient is listed; every purpose is documented.
Defined sub-processors & parties.
Counterparties in your engagement
The client sees the matched developer's professional profile and engagement data; the developer sees the client's project brief and milestone requirements.
Payment processors
Stripe, Wise, and regionally equivalent PCI-DSS Level 1 providers - only the minimum data needed to settle invoices and payouts.
Cloud infrastructure
AWS (eu-west-2, eu-west-1) and Cloudflare for hosting, storage, and edge delivery. Bound by SCCs and an executed Data Processing Addendum.
Identity & KYC verification
Third-party verification providers assist with government-ID checks and sanctions screening during the 5-stage vetting process.
Professional advisers
Auditors, legal counsel, and insurance carriers - only under professional confidentiality and strictly when required.
Legal authorities
Where compelled by a valid court order, regulator demand, or equivalent lawful process, and only to the extent required.
Lines we will not cross.
- We never sell personal data - under any definition, in any jurisdiction.
- We never share engagement content for advertising or retargeting.
- We never disclose dispute evidence to parties outside the dispute.
- We never let third parties fingerprint or track users across sites.
Sub-processor registry
A current register of sub-processors is available on request. Email privacy@openitfreelancers.com for a copy.
How long
we keep your data.
We retain personal data only for as long as it serves a defined purpose or until a statutory obligation expires - whichever is longer. After that, the data is permanently deleted or fully anonymised.
Account profile data
Lifetime of account + 30 daysDeleted permanently 30 days after account closure unless legally retained.
Engagement & milestone records
7 years post-engagementRequired for tax, accounting, and dispute audit purposes under UK/EU law.
Payment & invoice data
7 years (statutory)Held to satisfy HMRC, IRS, and equivalent international record-keeping rules.
KYC & identity verification
5 years post-relationshipRequired by AML legislation across operating jurisdictions.
Support & dispute correspondence
3 years from resolutionHeld to defend against potential claims and to improve dispute outcomes.
Marketing consents & logs
Until withdrawn + 12 monthsWithdrawal record retained briefly to evidence compliance with the request.
Web analytics (aggregated)
26 monthsStored in non-identifying form; cannot be linked back to individuals.
How we keep
your data secure.
We apply the same managed rigour to data security that we apply to engagement delivery - structural, continuous, and independently verified.
Encryption everywhere
AES-256 at rest, TLS 1.2+ in transit, and encrypted field-level storage for sensitive identifiers like KYC records.
Least-privilege access
Role-based access control, SSO with MFA for every staff member, and production access is time-boxed and audited.
Hardened infrastructure
Private VPCs, WAF at the edge, dependency scanning in CI, and automated patching on all production workloads.
Continuous audit
SOC 2-aligned controls, quarterly access reviews, immutable audit logs, and annual third-party penetration testing.
Monitoring & response
24/7 anomaly detection, runbooks for incident response, and a documented chain of escalation for any suspected breach.
Breach notification
If a qualifying incident occurs, affected users and the supervisory authority are notified within 72 hours under GDPR Art. 33.
Responsible disclosure: If you believe you have discovered a security vulnerability, please email security@openitfreelancers.com. We acknowledge reports within 48 hours and will coordinate remediation with you.
Your rights,
exercisable in one email.
Whether you sit under GDPR, UK-GDPR, or CCPA, we operate a single rights workflow. Requests are answered within 30 days - usually well inside two weeks.
Exercise a right
Email privacy@openitfreelancers.com from the email on your account. We will verify identity and respond under the applicable statutory timeframe.
Or open a structured requestRight of access
Request a copy of the personal data we hold about you, including the purpose of processing and the recipients.
Right to rectification
Ask us to correct inaccurate data or complete incomplete records. Changes propagate to all sub-processors.
Right to erasure
Request deletion of your data where there is no overriding legal obligation - the 'right to be forgotten'.
Right to restriction
Pause further processing of your data while a dispute, correction, or objection is investigated.
Right to portability
Receive your data in a structured, machine-readable format - or have us transmit it directly to another controller.
Right to object
Object to processing based on legitimate interest or direct marketing, at any time, free of charge.
Rights re: automated decisions
The AI shortlist is always reviewed by a human. You can request human review of any automated output at any point.
Right to withdraw consent
Where processing is based on consent, you can withdraw it at any time without affecting past lawful processing.
Cookies &
tracking technologies.
We use the smallest set of cookies needed to run the platform. Non-essential cookies are never set without your explicit consent, and can be revoked at any time from the cookie preference panel.
Strictly necessary
Always onAuthentication, session persistence, CSRF protection, load balancing.
Preferences
Consent-basedLanguage, region, interface density, recently viewed engagements.
Analytics
Consent-basedFirst-party, IP-anonymised traffic analysis to improve navigation and load times.
Marketing
Consent-basedOnly set if you have given explicit consent. Used to measure inbound campaign performance - never for retargeting across the web.
Manage your preferences
You can update cookie preferences at any time from the footer of the site or through your browser. Blocking strictly necessary cookies may prevent parts of the platform from functioning correctly.
International
data transfers.
Our primary processing is in the UK and EU. Because our managed network is global, some sub-processors operate in other jurisdictions. Every cross-border transfer is protected by an appropriate legal mechanism.
Adequacy decisions
Where available (e.g. UK โ EU), we rely on valid adequacy decisions.
Standard Contractual Clauses
For all other transfers, we execute the EU SCCs and the UK IDTA.
Transfer risk assessments
We conduct a TRA for each destination country and apply supplementary controls (encryption, pseudonymisation) as needed.
Data Privacy Framework
Where our US processors are certified under the EU-US DPF, we rely on it in addition to SCCs.
Changes to
this policy.
We revise this policy when the law evolves, when we launch new products, or when sub-processors change. Material changes are communicated in-product and by email to the primary contact on each account.
Notification standard
At least 30 days' advance notice for material changes. Immediate notification for security-critical updates, followed by documented context.
- 18 April 2026Current
Current policy - refactored into 10 sections, added explicit AI review disclosure, expanded international transfer coverage.
- 04 October 2025
Added EU-US Data Privacy Framework mechanism, clarified sub-processor disclosure process.
- 22 February 2025
Extended KYC retention to 5 years per updated AML legislation; clarified dispute evidence handling.
- 01 July 2024
Rewrite aligning with UK-GDPR post-adequacy and introducing the managed delivery data model.
Questions about
your privacy.
Open IT Freelancers Ltd is the data controller for personal data collected through the platform. For information exchanged inside an engagement, the client may act as a joint or independent controller for project content they contribute.
30d
Response SLA
72h
Acknowledgement
0
Data sales
AES-256
Encryption
Still curious?
Our privacy team is happy to walk you through how your data is handled on any specific engagement.
Talk to our team โQuestions about your data?
Exercise a right, ask about a sub-processor, or raise a concern. Our privacy team acknowledges every email within 72 hours.
- Access, rectification, deletion, portability
- Object to or restrict processing
- Request the current sub-processor list
- Raise a complaint with our DPO
Not satisfied with our response?
You always have the right to lodge a complaint with your local supervisory authority. We recommend contacting us first so we can resolve it directly - but escalation is your right.
- UK: Information Commissioner's Office (ICO)
- EU: Your local Data Protection Authority
- California: Attorney General / CPPA
- Other regions: Equivalent regulator
Our commitment: Privacy handled with the same managed rigour as delivery - transparent, accountable, enforceable.