Privacy Policy
Convenience translation. The legally binding version of this document is the German original; in case of any discrepancy the German version prevails.
Faceledger UG (haftungsbeschränkt) · Version: 2026-08-01.v1
Applies to the faceledger.ai platform. Section B is addressed to individuals (Supply), Section C to business users (Demand), Sections A and D to J to everyone.
A. Controller and Overview
Controller: Faceledger UG (haftungsbeschränkt), Kurhessenstraße 10, 60431 Frankfurt am Main, e-mail: privacy@faceledger.ai.
Data Protection Officer: reachable at privacy@faceledger.ai or by post at the controller's address with the addition "Data Protection Officer".
FaceLedger operates a licensing marketplace: verified adults provide a photo dataset of their appearance; verified companies license it for named advertising campaigns. The core of the service is the processing of photos of appearance, in part special categories of personal data (Art. 9 GDPR). This policy describes all processing activities, recipients, storage periods, and your rights.
B. Processing for Individuals (Supply)
B.1 Registration and Account
Processed: e-mail, password (hashed), pseudonym, real name, country, city, telephone number, optionally pronouns/gender identity; confirmation of legal age (logged). Purposes: account management, performance of the contract, age verification. Legal bases: Art. 6(1)(b) GDPR; for logging the confirmation of legal age, Art. 6(1)(c) and (f) GDPR (proof, protection of minors).
B.2 Appearance Characteristics
Processed: height, build, hair color/length, eye color, skin tone, beard, tattoos/piercings including retouching permission, distinguishing features. Purpose: description of the licensable dataset, filterability in the search for verified companies. Legal basis: Art. 6(1)(b) GDPR; the skin tone entry is additionally based on your consent (B.3), because it can allow inferences about origin. Deliberately no information is collected on ethnicity, religion, sexual orientation, or disability.
B.3 Photo Dataset (Special Categories)
Processed: up to 42 defined poses in up to five blocks, in accordance with your releases, as well as your showcase shots (one profile picture and up to five more, selected by you and technically downscaled). Purposes: (1) storage and human quality/content review, (2) display of only your showcase to verified companies in the protected search, whereby your complete dataset is not displayed there, (3) provision of the dataset to the licensing company after your acceptance, (4) generation of AI advertising material there within the scope of the license agreement. Legal basis: your explicit consent, Art. 9(2)(a), Art. 6(1)(a) GDPR (versioned consent text, logged; revocable at any time, consequences in the consent text and under H). The automatic quality check during capture is purely a brightness/resolution measurement; no AI-based analysis takes place.
B.4 Identity Verification (Soft KYC)
Processed: verification selfie, photo of the identity document, photo with a numeric code; verification result with reason from a closed list, time of verification, verifier. Purpose: verification of identity and legal age through human visual inspection, no automated facial comparison. Legal bases: Art. 6(1)(b) GDPR (access requirement of the platform contract), (c) (exclusion of minors), and (f) GDPR (legitimate interests: integrity of the marketplace, protection of companies and individuals against identity deception). Biometric processing within the meaning of Art. 9 GDPR does not take place, because the comparison is carried out exclusively by humans and without specific technical procedures (cf. Recital 51 GDPR). These records are made accessible to no company and are stored in a separate storage area accessible only to authorized verifiers.
B.5 Payout Verification and Payouts (Stripe Connect)
Before the first payout, Stripe Payments Europe Ltd. (Ireland), together with Stripe, Inc. (USA), carries out the anti-money-laundering verification (proof of identity, date of birth, bank details). Stripe is an independent controller for this purpose; Stripe's privacy notices apply in addition. FaceLedger receives the verification status and processes payouts via your Stripe account (Art. 6(1)(b) GDPR). FaceLedger does not store any bank or card data.
B.6 Requests, Licenses, Contracts
Processed: request parameters, acceptance/rejection, binding confirmation (timestamp, text version), generated license agreement (PDF, checksum), billing statements. Purposes: brokering, contract generation and documentation, payment processing, record-keeping. Legal bases: Art. 6(1)(b), (c), and (f) GDPR (legitimate interests: record-keeping and abuse prevention). Recipient upon acceptance: The licensing company receives your released photos, your age, and your real name, as an independent controller, bound to the purposes of the license agreement (§ 10 therein). Without your acceptance, no company obtains access.
B.7 Pool Consent and Showcase
Optional; the legal basis in each case is your consent (Art. 6(1)(a), for photos in conjunction with Art. 9(2)(a) GDPR), revocable at any time. Pool: storage of your dataset at the company beyond the end of the campaign for internal testing purposes. Showcase: public display of returned campaign assets only with the consent of both sides.
B.8 Consent Log
All consent events (granting/withdrawal, text version, text hash, language, source, timestamp, IP (truncated after 90 days), user agent) are logged in a tamper-evident manner and survive account deletion. Purpose: proof under Art. 7(1) GDPR, legal defense. Legal bases: Art. 6(1)(c) and (f), Art. 17(3)(e) GDPR. If a license agreement never comes about, we retain the log for three years from account deletion (Section G).
B.9 Data Export, Account Deletion
You can retrieve a complete data export (JSON) at any time (Art. 15, 20 GDPR) and delete your account. If there are neither active licenses nor open requests: without a contract history, complete deletion; with a contract history, deletion of photos, appearance, identity, and KYC data and pseudonymization of the profile. Contracts, billing statements, and the consent log we retain in accordance with Section G (Art. 6(1)(c) GDPR, §§ 257 HGB, 147 AO; Art. 17(3)(b) and (e) GDPR).
C. Processing for Business Users (Demand)
C.1 Organization and User Accounts: company, legal form/type, industry, size, country, website, billing address, VAT ID, billing e-mail; contact persons with name, position, e-mail; roles. Purposes: account management, verification, price calculation, invoicing. Legal bases: Art. 6(1)(b) GDPR (users), (f) (data of contact persons of legal entities, legitimate interest in B2B contract performance), (c) (mandatory tax information).
C.2 Verification: review of the organization's information; status verified/rejected. Legal basis: Art. 6(1)(b) and (f) GDPR (protection of individuals, marketplace integrity).
C.3 Payments: card payments via Stripe (authorization upon request, collection upon acceptance; subscription billing). FaceLedger does not store any card data. Legal basis: Art. 6(1)(b) GDPR.
C.4 Usage and Audit Data: access to datasets, downloads, deletion confirmations, and search operations are logged (action, actor, time, IP, user agent). Purposes: security, proof of license compliance, protection of individuals. Legal basis: Art. 6(1)(f) GDPR; balancing of interests in favor of record-keeping vis-à-vis the depicted individuals.
D. For Everyone: Website, Hosting, Communication
D.1 Server Logs: IP address, timestamp, requested resource, user agent, used for provision, stability, and security (Art. 6(1)(f) GDPR); deletion after 30 days at the latest, unless there is a security incident.
D.2 Cookies: Only technically necessary cookies are used (authentication/session, security). These are exempt from consent under § 25(2) no. 2 TDDDG; a consent banner is therefore not required. No tracking and no web analytics take place; no marketing cookies are set.
D.3 E-mail Dispatch: We send transactional and authentication e-mails via Plus Five Five, Inc. ("Resend"), San Francisco, USA. Resend is a processor for mail content and recipient data (deletion no later than 90 days after the end of the contract) and an independent controller for its account and usage data. The processing takes place predominantly in the USA; safeguards: EU Standard Contractual Clauses and certification under the EU-US Data Privacy Framework. Resend uses its own sub-processors (current list available from the provider); the binding to instructions under Art. 28 GDPR applies along the entire chain.
D.4 Contact: For inquiries to hello@faceledger.ai, we process your information in order to handle it (Art. 6(1)(b) or (f) GDPR).
D.5 Waitlist: e-mail address to provide information about the launch (Art. 6(1)(a)/(b) GDPR); deletion upon registration, objection, or after 24 months of inactivity.
E. Recipients
| Recipient | Role | Location/Safeguard |
|---|---|---|
| Supabase (database, file storage, auth) | Processor (Art. 28 GDPR, DPA) | EU region |
| Vercel (hosting) | Processor (DPA) | EU region; parent company USA → EU Standard Contractual Clauses/DPF |
| Stripe (payments, payout KYC) | partly processor, partly independent controller | Ireland/USA → EU-US Data Privacy Framework, supplemented by Standard Contractual Clauses |
| Plus Five Five, Inc. ("Resend", e-mail dispatch) | Processor (DPA); independent controller for its own account/usage data | USA → EU-US Data Privacy Framework + Standard Contractual Clauses |
| Verified companies (search) | independent controllers; before any license they see only your showcase shots and profile information | access only after verification; if established outside the EU/EEA/adequacy: additional safeguards or exclusion (Section F) |
| Licensing companies | independent controllers (only after your acceptance; scope: released photos, age, real name) | established according to the license agreement; contractual obligation to process in the EU/EEA or with appropriate safeguards (§ 10 of the license agreement) |
| Authorities, advisors | in the event of a legal obligation or legitimate interest | case-by-case |
F. International Data Transfers
Transfers to the USA take place only to recipients certified under the EU-US Data Privacy Framework (adequacy decision, Art. 45(3) GDPR) or on the basis of the EU Standard Contractual Clauses (Art. 46(2)(c) GDPR), in each case with supplementary measures. You can obtain a copy of the Standard Contractual Clauses used in each case upon request at privacy@faceledger.ai. The photo dataset and the KYC records are stored by FaceLedger exclusively in the EU. For processing by licensing companies, § 10 of the license agreement applies (EU/EEA, adequacy decision, or appropriate safeguards); with companies outside these states, EU Standard Contractual Clauses are additionally agreed before any provision; otherwise the provision does not take place.
G. Storage Periods
| Data | Period |
|---|---|
| Photo dataset | Duration of the account; immediately after account deletion; licensed blocks with a contract history: 3 years after the end of the last license (evidentiary purposes) |
| KYC records (selfie, ID photo, code photo) | Duration of the account; after account deletion: 3 years after the end of the last license, without ever having had a license: 30 days |
| Contracts, licenses, billing bases, consent log | 10 years from the end of the calendar year of the license's end (§§ 257 HGB, 147 AO; maximum limitation periods); consent log without ever having had a license agreement: 3 years from account deletion |
| Invoice/accounting records | 8 years (§ 147(3) AO) |
| Requests without conclusion of a contract | 12 months from change of status |
| Audit log | 24 months rolling; license-related entries 10 years |
| Server logs | 30 days |
| Waitlist | until registration/objection, max. 24 months |
H. Your Rights
You have the rights to access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction (Art. 18), and data portability (Art. 20 GDPR).
Right to object (Art. 21 GDPR): You have the right, on grounds relating to your particular situation, to object at any time to processing based on Art. 6(1)(f) GDPR (legitimate interests). We will then no longer process the data concerned, unless we can demonstrate compelling legitimate grounds for the processing that override your interests, rights, and freedoms, or the processing serves the establishment, exercise, or defense of legal claims.
Withdrawal of consent: at any time with effect for the future, as easy as granting it (account settings or e-mail); the lawfulness of processing carried out to date remains unaffected. The consequences of withdrawing the core consent, including the treatment of ongoing licenses, are explained in the consent text.
Right to lodge a complaint: with a data protection supervisory authority, in particular the Hessian Commissioner for Data Protection and Freedom of Information (HBDI), Gustav-Stresemann-Ring 1, 65189 Wiesbaden.
I. No Automated Decision-Making
No automated decision-making, including profiling, within the meaning of Art. 22 GDPR takes place. In particular, identity verification, photo releases, and blocking decisions are made by humans; FaceLedger does not use any AI on the platform, not even to assess persons or content. Service providers engaged by us may use AI technologies to operate their own services; in doing so, they may process personal data of our users only on our instructions; an AI-based assessment of users or platform content is not covered by this.
J. Obligation to Provide Data, Security, Changes
Provision: Without the data specified in B.1 to B.4, the platform cannot be used as an individual (contractual or consent requirement); there is no legal obligation to provide the data.
Security (Art. 32 GDPR): transport encryption, row-based access controls on all database tables, private storage areas with delivery only via short-lived signed links, a separate, access-restricted area for KYC records, logging of security-relevant access. We continuously develop these measures further.
Changes: This policy is updated when processing activities change; the version published on the platform applies. For version and status, see the header.