Privacy Policy
How we collect, use, and protect your personal data.
Last updated: [EFFECTIVE_DATE]
1. Who We Are
We are [COMPANY_LEGAL_NAME], a data controller established in the Netherlands. Contact us at privacy@chipo.ai.
[COMPANY_LEGAL_NAME] ("Chipo", "we", "our", "us") is a private limited company registered in the Netherlands with the Dutch Chamber of Commerce (Kamer van Koophandel) under registration number [COMPANY_REGISTRATION_NUMBER]. Our registered address is [COMPANY_ADDRESS].
Chipo acts as the data controller for personal data processed through the Chipo platform and website. Where Chipo processes personal data on behalf of enterprise clients, it acts as a data processor under a separate Data Processing Agreement.
Our Data Protection Officer (DPO) can be contacted at privacy@chipo.ai. You may also write to us at the registered address above, marked for the attention of the Data Protection Officer.
2. Data We Collect
We collect account data, submitted content (voice/video/image/text), device data, payment data, analytics, and cookies.
We collect the following categories of personal data:
- Account data: name, email address, hashed password, preferred language, country of residence, and account role (contributor or enterprise).
- Submitted content: voice recordings, video recordings, images, and text submitted as part of data-collection tasks. This content may constitute special category data — see Section 3.
- Device and technical data: IP address, browser type, operating system, device identifiers, and log data generated when you access our platform.
- Payment data: bank account or mobile money details, Stripe Connect account identifiers, transaction history, and tax identification numbers where required for payouts. Full card numbers are never stored by Chipo; they are processed directly by Stripe.
- Analytics data: aggregated behavioural data (pages visited, task completion rates, session duration) collected via first-party analytics tools. We do not use third-party advertising trackers.
- Cookie data: see the Cookie Policy for full details.
- Consent records: a timestamped log of each consent decision you make on the platform, including the scope and purpose of consent.
3. Special Category Data
Voice and video recordings are processed as biometric data only when used for identification. We rely on your explicit written consent for this processing.
Certain data you submit — in particular voice recordings and video recordings — may qualify as special category data under Article 9 of the GDPR if they are used to uniquely identify you (biometric processing).
Chipo processes voice and video data as biometric data only in the following circumstances:
- When a task explicitly involves speaker identification or verification; or
- When an enterprise client's licensed use case involves biometric identification, and you have been informed of this use before submitting.
The lawful basis for such processing is explicit consent under Article 9(2)(a) GDPR. You will be presented with a clear, specific consent request before any such task. You may withdraw consent at any time, subject to the limitations described in Section 9.
Where voice and video recordings are used solely for linguistic, cultural, or contextual purposes (e.g., accent data, language diversity datasets) without any biometric identification component, they are treated as ordinary personal data and processed under Article 6(1)(b) (contract) or Article 6(1)(a) (consent).
4. How We Use Your Data
We use your data to operate the platform, review submissions, license datasets to enterprises, process payouts, prevent fraud, and comply with the law.
We use personal data for the following purposes:
- Platform operation: to create and manage your account, display tasks, accept submissions, and communicate with you about your account.
- Content review: to assess submissions for quality, compliance with task instructions, and policy compliance before approving earnings.
- Dataset licensing: to package and deliver licensed datasets to enterprise clients in accordance with the consent scope you provided. Your identity is not disclosed to enterprise clients.
- Payouts: to calculate earnings, initiate transfers via Stripe Connect, and maintain financial records.
- Fraud and security: to detect, investigate, and prevent fraudulent submissions, account misuse, or security incidents.
- Legal compliance: to comply with applicable laws including Dutch tax law, anti-money laundering regulations, and court orders.
- Platform improvement: to analyse aggregated usage patterns and improve our products and services.
5. Lawful Basis for Processing
We rely on consent (biometric data), contract (payouts), legitimate interests (analytics/security), and legal obligation (tax) as our lawful bases.
We process personal data only where we have a valid lawful basis. The primary bases we rely on are:
- Consent (Article 6(1)(a) and 9(2)(a)): for biometric processing of voice/video data, and for optional analytics cookies. You may withdraw consent at any time without affecting the lawfulness of prior processing.
- Contract (Article 6(1)(b)): for account creation, task participation, and payout processing — processing necessary to perform the agreement between you and Chipo.
- Legitimate interests (Article 6(1)(f)): for platform analytics, fraud prevention, and security monitoring. Our legitimate interests in operating a safe, functional platform do not override your fundamental rights.
- Legal obligation (Article 6(1)(c)): for financial record-keeping required under Dutch tax law and anti-money laundering regulations.
Where we rely on legitimate interests, you may object to the processing at any time (see Section 9).
6. Data Sharing
We share data with enterprise licensees (anonymised), Stripe, cloud providers, legal authorities, and potential business acquirers. We do not sell your data.
We do not sell personal data. We share data in the following circumstances:
- Enterprise licensees: packaged datasets are licensed to enterprise clients for AI training. Datasets do not include your name or contact details; they include submitted content, associated metadata (language, accent, country), and anonymised contributor identifiers.
- Stripe: payment data is shared with Stripe, Inc. to process payouts via Stripe Connect. Stripe's processing is governed by the Stripe Privacy Policy.
- Cloud infrastructure providers: data is hosted on cloud platforms. These providers act as sub-processors under data processing agreements that impose equivalent data protection obligations.
- Legal authorities: we will disclose personal data if required to do so by law, court order, or to protect the legal rights of Chipo or others.
- Business transfers: in the event of a merger, acquisition, or asset sale, personal data may be transferred to the acquiring entity, subject to the same protections described in this Policy.
7. International Transfers
Our primary processing is in the Netherlands (EU). Transfers outside the EEA are protected by Standard Contractual Clauses.
Chipo's primary data processing infrastructure is located in the Netherlands and within the European Economic Area (EEA). This means your data is, by default, processed within the EU under the full protection of the GDPR.
Where it is necessary to transfer personal data to countries outside the EEA (for example, to certain cloud sub-processors), we ensure adequate protection by relying on:
- Standard Contractual Clauses (SCCs) approved by the European Commission; or
- An adequacy decision by the European Commission confirming that the destination country provides an equivalent level of data protection.
Copies of the relevant transfer safeguards are available upon request at privacy@chipo.ai.
8. Data Retention
Account data is kept 90 days after closure. Biometric data is kept 3 years maximum. Financial records are kept 7 years per Dutch law.
We retain personal data for the minimum period necessary to fulfil the purposes for which it was collected:
- Account data (name, email, profile): retained for the duration of your account, then deleted or anonymised within 90 days of account closure.
- Biometric data (voice/video used for identification purposes): retained for a maximum of 3 years from the date of submission, or until you withdraw consent, whichever is earlier. Data already incorporated into licensed datasets cannot be recalled from enterprise clients' systems — see Section 9.
- Submitted content (non-biometric) (linguistic audio, images, text): retained for the duration of the applicable dataset licence. On account deletion, your personal identifiers are removed; the underlying content may remain in licensed datasets in anonymised form.
- Financial records (transaction logs, payout records, tax documents): retained for 7 years from the date of the transaction, as required under Dutch tax and accounting law (Boekhoudbesluit).
- Consent records: retained for the longer of 3 years or the duration of any dataset licence incorporating the consented data.
9. Your Rights (GDPR)
You have rights of access, rectification, erasure, restriction, portability, objection, and to withdraw consent. You may also lodge a complaint with the Autoriteit Persoonsgegevens.
As a data subject under the GDPR, you have the following rights:
- Right of access (Article 15): request a copy of the personal data we hold about you.
- Right to rectification (Article 16): request correction of inaccurate or incomplete personal data.
- Right to erasure (Article 17): request deletion of your personal data where no legitimate ground for continued processing exists. Note that data already incorporated into anonymised licensed datasets cannot be extracted or deleted from those datasets, as it is no longer linked to you.
- Right to restriction (Article 18): request that we restrict processing of your data in certain circumstances (e.g., while accuracy is disputed).
- Right to data portability (Article 20): receive your personal data in a structured, commonly used, machine-readable format, and transfer it to another controller.
- Right to object (Article 21): object to processing based on legitimate interests. We will cease processing unless we can demonstrate compelling legitimate grounds that override your interests.
- Right to withdraw consent: withdraw any consent you have given at any time. Withdrawal does not affect the lawfulness of processing before withdrawal.
To exercise any of these rights, contact us at privacy@chipo.ai. We will respond within one month (extendable by two further months in complex cases).
If you are not satisfied with our response, you have the right to lodge a complaint with the Dutch supervisory authority: Autoriteit Persoonsgegevens, autoriteitpersoonsgegevens.nl, Postbus 93374, 2509 AJ Den Haag.
10. Children
The platform is not for users under 16. Users aged 16–17 require verifiable parental consent.
The Chipo platform is not directed at or intended for children under the age of 16. We do not knowingly collect personal data from children under 16. If you are under 16, you may not create an account or use the Services.
Users aged 16 to 17 may use the platform only with verifiable parental or guardian consent. By creating an account, users aged 16–17 confirm that a parent or guardian has reviewed and agreed to this Privacy Policy on their behalf.
If we discover that we have collected personal data from a child under 16 without appropriate consent, we will delete that data promptly. If you believe a minor has submitted data without appropriate consent, please contact us at privacy@chipo.ai.
11. Changes to This Policy
We will give you at least 30 days' email notice before any material changes take effect.
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors.
For material changes — changes that affect your rights, the purposes for which we process your data, or our data sharing practices — we will notify you by email to the address associated with your account at least 30 days before the changes take effect. The updated effective date will be displayed at the top of this Policy.
For non-material changes (such as typographic corrections or clarifications that do not alter your rights), we will update this Policy without individual notice.
Your continued use of the platform after the effective date of a material change constitutes acceptance of the updated Policy. If you do not accept the changes, you may close your account before the effective date.
12. Contact
For all privacy questions and data subject requests, email privacy@chipo.ai.
For any questions, concerns, or requests relating to this Privacy Policy or our processing of your personal data, please contact our Data Protection Officer:
[COMPANY_LEGAL_NAME]
Attn: Data Protection Officer
[COMPANY_ADDRESS]
Netherlands
KvK: [COMPANY_REGISTRATION_NUMBER]
Email: privacy@chipo.ai
We aim to respond to all privacy-related enquiries within 5 business days and to complete subject access and rights requests within the statutory one-month period.
