Privacy Policy

Your Data,
Protected
by Design.

We treat privacy the same way we treat delivery - with structural accountability. This policy explains exactly what we collect, why we collect it, and the rights you have at every step of the engagement.

GDPR & UK-GDPR aligned
CCPA-ready rights
No sale of personal data
YOURDATAEncrypted๐Ÿ”Encryption๐Ÿ›ก๏ธAccess Control๐Ÿ“œLawful Basis๐Ÿ‘คYouData subject๐ŸขOTFData controllerโš–๏ธRegulatorGDPR/CCPAAES-256 Encryption at RestTLS 1.2+ in transitZero Personal Data SalesEver. No exceptions.
0Data brokers sold to
256-bitEncryption standard
30dRights response SLA
100%Transparent processing
At a glance

Six commitments,
one clear standard.

The full policy is below. This summary captures the principles that govern every line of it - written in plain English, the way our engagements are structured.

What we collect

Account, engagement, billing, technical, and communication data - only what is needed to run a managed engagement.

How we protect it

AES-256 encryption at rest, TLS 1.2+ in transit, SOC 2-aligned access controls, and least-privilege internal access.

Why we hold it

Contract performance, legal obligations, fraud prevention, and improving the managed delivery framework.

Your rights

Access, rectification, deletion, portability, restriction, and objection - exercisable in a single email.

Where it lives

Primary data residency in the UK and EU. Sub-processors are bound by Standard Contractual Clauses.

What we never do

We do not sell personal data. We do not share it for advertising. We do not retain it beyond its purpose.

Section 01

Information
we collect.

We collect only the data required to operate the managed engagement, fulfil legal obligations, and improve service quality. Each category below is tied to a defined purpose and lawful basis under GDPR Article 6.

Data minimisation

If a field is not strictly necessary for delivery, accountability, or legal compliance - we do not collect it.

01

Account information

  • Full name, business name, and professional title
  • Email address, telephone number, and country of residence
  • Authentication credentials (password hashes - never stored in plain text)
  • Profile picture and biographical content you choose to upload
02

Engagement information

  • Project briefs, requirements, scope documents, and milestone records
  • Timesheets, hour logs, deliverable URLs, and milestone approvals
  • Messages exchanged on the platform between clients, developers, and OTF
  • Dispute submissions, evidence files, and ruling records
03

Payment and tax information

  • Billing address and tax registration numbers (VAT/GST/EIN as applicable)
  • Bank or payout details - held by our PCI-DSS Level 1 payment processor, not by OTF
  • Invoice history, payment status, and payout records
04

Technical information

  • IP address, device identifiers, browser type, and operating system
  • Pages visited, features used, and approximate session duration
  • Cookie identifiers and session tokens (see Cookies section below)
05

Verification information (developers only)

  • Government-issued ID for KYC checks during 5-stage vetting
  • Portfolio links, code samples, and reference contact details
  • Right-to-work and tax residency documentation as required by jurisdiction
Section 02

How we use
your information.

Every processing activity at Open IT Freelancers is mapped to one of six defined purposes. Each purpose has a documented lawful basis and a defined retention period.

Operate managed engagements

Match developers and clients, run weekly cycles, track milestones, release payments, and resolve disputes - the core of every OTF engagement.

Enforce platform authority

Verify identity, prevent fraud, enforce contract terms, and protect both sides of the engagement under our managed delivery framework.

Improve product quality

Aggregate, anonymise, and analyse usage to refine the AI shortlist, the vetting workflow, and the platform experience overall.

Communicate with you

Send transactional emails (milestone notifications, dispute updates, payment receipts) and - only with consent - service updates.

Meet legal obligations

Comply with tax law, anti-money-laundering rules, KYC requirements, and any lawful request from a competent authority.

Measure delivery outcomes

Track the 98% delivery success rate and other quality metrics in aggregate - never to profile individuals beyond engagement context.

Section 04

Who we share with
and who we don't.

Data sharing inside Open IT Freelancers is governed by the principle of purpose limitation. Every recipient is listed; every purpose is documented.

We share with

Defined sub-processors & parties.

  • Counterparties in your engagement

    The client sees the matched developer's professional profile and engagement data; the developer sees the client's project brief and milestone requirements.

  • Payment processors

    Stripe, Wise, and regionally equivalent PCI-DSS Level 1 providers - only the minimum data needed to settle invoices and payouts.

  • Cloud infrastructure

    AWS (eu-west-2, eu-west-1) and Cloudflare for hosting, storage, and edge delivery. Bound by SCCs and an executed Data Processing Addendum.

  • Identity & KYC verification

    Third-party verification providers assist with government-ID checks and sanctions screening during the 5-stage vetting process.

  • Professional advisers

    Auditors, legal counsel, and insurance carriers - only under professional confidentiality and strictly when required.

  • Legal authorities

    Where compelled by a valid court order, regulator demand, or equivalent lawful process, and only to the extent required.

We never do

Lines we will not cross.

  • We never sell personal data - under any definition, in any jurisdiction.
  • We never share engagement content for advertising or retargeting.
  • We never disclose dispute evidence to parties outside the dispute.
  • We never let third parties fingerprint or track users across sites.

Sub-processor registry

A current register of sub-processors is available on request. Email privacy@openitfreelancers.com for a copy.

Section 05

How long
we keep your data.

We retain personal data only for as long as it serves a defined purpose or until a statutory obligation expires - whichever is longer. After that, the data is permanently deleted or fully anonymised.

Data category
Retention period
Reason
  • Account profile data

    Lifetime of account + 30 days

    Deleted permanently 30 days after account closure unless legally retained.

  • Engagement & milestone records

    7 years post-engagement

    Required for tax, accounting, and dispute audit purposes under UK/EU law.

  • Payment & invoice data

    7 years (statutory)

    Held to satisfy HMRC, IRS, and equivalent international record-keeping rules.

  • KYC & identity verification

    5 years post-relationship

    Required by AML legislation across operating jurisdictions.

  • Support & dispute correspondence

    3 years from resolution

    Held to defend against potential claims and to improve dispute outcomes.

  • Marketing consents & logs

    Until withdrawn + 12 months

    Withdrawal record retained briefly to evidence compliance with the request.

  • Web analytics (aggregated)

    26 months

    Stored in non-identifying form; cannot be linked back to individuals.

Section 06

How we keep
your data secure.

We apply the same managed rigour to data security that we apply to engagement delivery - structural, continuous, and independently verified.

Encryption everywhere

AES-256 at rest, TLS 1.2+ in transit, and encrypted field-level storage for sensitive identifiers like KYC records.

Least-privilege access

Role-based access control, SSO with MFA for every staff member, and production access is time-boxed and audited.

Hardened infrastructure

Private VPCs, WAF at the edge, dependency scanning in CI, and automated patching on all production workloads.

Continuous audit

SOC 2-aligned controls, quarterly access reviews, immutable audit logs, and annual third-party penetration testing.

Monitoring & response

24/7 anomaly detection, runbooks for incident response, and a documented chain of escalation for any suspected breach.

Breach notification

If a qualifying incident occurs, affected users and the supervisory authority are notified within 72 hours under GDPR Art. 33.

Responsible disclosure: If you believe you have discovered a security vulnerability, please email security@openitfreelancers.com. We acknowledge reports within 48 hours and will coordinate remediation with you.

Section 07

Your rights,
exercisable in one email.

Whether you sit under GDPR, UK-GDPR, or CCPA, we operate a single rights workflow. Requests are answered within 30 days - usually well inside two weeks.

Exercise a right

Email privacy@openitfreelancers.com from the email on your account. We will verify identity and respond under the applicable statutory timeframe.

Or open a structured request
01

Right of access

Request a copy of the personal data we hold about you, including the purpose of processing and the recipients.

02

Right to rectification

Ask us to correct inaccurate data or complete incomplete records. Changes propagate to all sub-processors.

03

Right to erasure

Request deletion of your data where there is no overriding legal obligation - the 'right to be forgotten'.

04

Right to restriction

Pause further processing of your data while a dispute, correction, or objection is investigated.

05

Right to portability

Receive your data in a structured, machine-readable format - or have us transmit it directly to another controller.

06

Right to object

Object to processing based on legitimate interest or direct marketing, at any time, free of charge.

07

Rights re: automated decisions

The AI shortlist is always reviewed by a human. You can request human review of any automated output at any point.

08

Right to withdraw consent

Where processing is based on consent, you can withdraw it at any time without affecting past lawful processing.

Section 08

Cookies &
tracking technologies.

We use the smallest set of cookies needed to run the platform. Non-essential cookies are never set without your explicit consent, and can be revoked at any time from the cookie preference panel.

Strictly necessary

Always on

Authentication, session persistence, CSRF protection, load balancing.

LifetimeSession / up to 12 months

Preferences

Consent-based

Language, region, interface density, recently viewed engagements.

LifetimeUp to 12 months

Analytics

Consent-based

First-party, IP-anonymised traffic analysis to improve navigation and load times.

LifetimeUp to 26 months

Marketing

Consent-based

Only set if you have given explicit consent. Used to measure inbound campaign performance - never for retargeting across the web.

LifetimeUp to 12 months

Manage your preferences

You can update cookie preferences at any time from the footer of the site or through your browser. Blocking strictly necessary cookies may prevent parts of the platform from functioning correctly.

PRIMARY DATA RESIDENCY - UK & EUUK / EUPrimaryUSSCCs + DPFAPACSCCsLATAMSCCsMEASCCsAll cross-border transfers protected by Standard Contractual Clauses
Section 09

International
data transfers.

Our primary processing is in the UK and EU. Because our managed network is global, some sub-processors operate in other jurisdictions. Every cross-border transfer is protected by an appropriate legal mechanism.

  • Adequacy decisions

    Where available (e.g. UK โ†” EU), we rely on valid adequacy decisions.

  • Standard Contractual Clauses

    For all other transfers, we execute the EU SCCs and the UK IDTA.

  • Transfer risk assessments

    We conduct a TRA for each destination country and apply supplementary controls (encryption, pseudonymisation) as needed.

  • Data Privacy Framework

    Where our US processors are certified under the EU-US DPF, we rely on it in addition to SCCs.

Section 10

Changes to
this policy.

We revise this policy when the law evolves, when we launch new products, or when sub-processors change. Material changes are communicated in-product and by email to the primary contact on each account.

Notification standard

At least 30 days' advance notice for material changes. Immediate notification for security-critical updates, followed by documented context.

  • 18 April 2026Current

    Current policy - refactored into 10 sections, added explicit AI review disclosure, expanded international transfer coverage.

  • 04 October 2025

    Added EU-US Data Privacy Framework mechanism, clarified sub-processor disclosure process.

  • 22 February 2025

    Extended KYC retention to 5 years per updated AML legislation; clarified dispute evidence handling.

  • 01 July 2024

    Rewrite aligning with UK-GDPR post-adequacy and introducing the managed delivery data model.

FAQ

Questions about
your privacy.

Open IT Freelancers Ltd is the data controller for personal data collected through the platform. For information exchanged inside an engagement, the client may act as a joint or independent controller for project content they contribute.

๐Ÿ”’UK-GDPRGDPRCCPADPF30d SLA72h ack

30d

Response SLA

72h

Acknowledgement

0

Data sales

AES-256

Encryption

Still curious?

Our privacy team is happy to walk you through how your data is handled on any specific engagement.

Talk to our team โ†’
Privacy team

Questions about your data?

Exercise a right, ask about a sub-processor, or raise a concern. Our privacy team acknowledges every email within 72 hours.

  • Access, rectification, deletion, portability
  • Object to or restrict processing
  • Request the current sub-processor list
  • Raise a complaint with our DPO
privacy@openitfreelancers.com
โš–๏ธ Your escalation route

Not satisfied with our response?

You always have the right to lodge a complaint with your local supervisory authority. We recommend contacting us first so we can resolve it directly - but escalation is your right.

  • UK: Information Commissioner's Office (ICO)
  • EU: Your local Data Protection Authority
  • California: Attorney General / CPPA
  • Other regions: Equivalent regulator
Open a structured request

Our commitment: Privacy handled with the same managed rigour as delivery - transparent, accountable, enforceable.

๐Ÿ”EncryptionAES-256 / TLS 1.2+๐Ÿ“œLawful BasisArt. 6 mapped๐ŸงญPurpose LimitedNo scope creep๐Ÿ‘คYour Rights30-day SLAโš–๏ธTransparentVersioned policy