This notice explains what PDC processes, what remains private, what a buyer may see, and which choices always stay separate.
Notice version
draft
Effective date
Not yet effective
Pilot mode
Not active
The short version
PDC helps you build a personal Capsule from data you deliberately add. Collection, Capsule visibility, temporary buyer preview, final project use, and release of sealed content are different decisions. One never silently authorizes another.
The pilot does not perform AI generation, voice cloning, face recognition, biometric identification, AI training, automatic data sales, payments, or automatic delivery to buyers.
Who is responsible
Controller
Not yet configured
Registered address
Not yet configured
Country and registration
Not yet configured
Privacy contact
Not yet configured
DPO position
Not yet configured
What we process and why
Account identity, session and security signals to provide and protect access.
Your profile, declarations, guided Q&A, preferences and boundaries to build the Capsule you request.
Provider records and files only for providers, categories and collection methods you select.
Voice, portrait or video only after the relevant high-risk collection choice; collection alone never permits synthesis or project use.
Consent, publication, preview, grant, access and revocation evidence so your choices can be verified.
Exports, encrypted backups, limited logs and operational evidence to deliver, secure and recover the service.
Legal bases depend on the operation: requested service or contract for core account functions, consent for optional collection and visibility, explicit consent where legally required for special-category data, legitimate interests for proportionate security, and legal obligations where applicable.
How data enters the Capsule
Sealed upload
Your browser encrypts the file before upload. PDC stores ciphertext and metadata; losing every local key copy may make the file unrecoverable.
Server connector
When you explicitly choose server collection, PDC receives readable data from that provider and stores only the authorized scope under the selected retention rule.
Guided capture
Text, audio, portrait and video are added through a specific module and remain private unless you later make a separate visibility or project choice.
Visibility, projects and sealed release
A Capsule is private by default. If owner-directed discovery is enabled, you choose the identity, items and permitted audience. Visibility means consultation only; it is not a licence, download right, AI permission or project approval.
A verified buyer must submit an approved project before requesting temporary access to named preview fields. You may refuse, grant preview only, conditionally approve the described use, or require final confirmation. Preview expires and has no download action by default.
Final project permission is purpose-specific and recorded separately. Sealed plaintext is never released automatically: any permitted release still requires the owner-controlled, grant-bound local unlock flow.
Recipients, providers and transfers
Service providers may process limited data for hosting, database, encrypted backup, transactional email, security monitoring and the provider connections you choose. Buyers receive only material made visible or previewed under the applicable control; no partner receives Capsule data automatically.
The production transfer position is not yet configured, so the real-pilot gate remains closed.
Retention and deletion
Raw collected artifacts
30 days unless a shorter category rule or earlier deletion applies
Capsule category data
The category-specific period shown when you consent, generally 90 to 365 days in the current configuration, subject to renewal or deletion.
Temporary buyer preview
The project-specific preview period, followed by expiry or earlier revocation.
Discovery access history
Up to 365 days
Local production backups
14 days; off-site copies follow the approved encrypted backup schedule
Account and consent evidence
Active while needed for the service; deletion removes active-system content while minimized legal, security and backup evidence follows the approved schedule.
Retention schedule version: draft.
Your controls and rights
Inside PDC you can withdraw collection consent, pause Capsule visibility, revoke active previews, review or revoke purpose-specific grants, leave the pilot, export your Capsule, submit a rights request, or request account deletion. Leaving the pilot does not silently rewrite a final project permission; that permission remains separately visible and manageable under its recorded terms.
You may request access, rectification, erasure, restriction, portability, objection where applicable, consent withdrawal, and human review. You may also complain to the competent supervisory authority.
Readiness signals, not automated decisions
Completeness, readiness and eligibility signals help organize the service. They do not authorize access or use, guarantee selection or compensation, penalize refusal, or make a legal or similarly significant decision about you. Buyer eligibility remains aggregate until a governed request reaches you.