1. Controller
Controller within the meaning of Art. 4 (7) GDPR is:
rawlenses media, proprietor Filip Nies
Am Sonnenhang 20, 57223 Kreuztal, Germany
VAT ID: DE362309606
Email: hello@creatifs.com
We have not appointed a statutory Data Protection Officer as the mandatory thresholds under § 38 BDSG are not met. Data-protection inquiries reach the controller directly at the address above.
2. Categories of Data We Process
- Account data: name, email, password hash, role, workspace membership.
- Profile & business data: company name, VAT ID, address, IBAN, tax residency, company type.
- Creator directory data: publicly available social handles, portfolio media, niches, and self-declared availability, collected from public sources or provided by the Creator during application.
- Project data: briefs, quotes, contracts, signatures (with IP and user-agent), deliverables, messages.
- Payment data: Stripe customer ID, subscription status, invoice metadata. Card details are handled by Stripe and never reach our servers.
- Usage & log data: IP address, user-agent, timestamps, referrer, and technical error logs kept for security and abuse prevention.
- Communications: emails you send us and email delivery events (opens, bounces) reported by our email provider.
3. Purposes & Legal Bases
- Providing the Platform, account management, project workflows — Art. 6 (1) (b) GDPR (performance of a contract).
- Billing, invoicing, tax retention — Art. 6 (1) (b) and (c) GDPR (contract + legal obligation under § 147 AO / § 257 HGB).
- Signature audit trails (IP, user-agent, timestamp) — Art. 6 (1) (b) and (c) GDPR and § 2 No. 10 eIDAS.
- Publishing a Creator profile in the invite-only Creator network — Art. 6 (1) (a) GDPR (consent, given when the Creator connects Instagram and submits the profile for publication).
- Sending a personal invitation to a Creator and tracking its status — Art. 6 (1) (f) GDPR (legitimate interest in building a curated professional network; balancing test on file).
- Listing a Creator in the public directory before they sign up ("Not yet active on créatifs") — Art. 6 (1) (f) GDPR (legitimate interest in operating a B2B directory). Only public professional data is shown (handle, city, country, craft, focus, rounded follower band); no bio, image, email or exact follower count. Owners may object at any time (Art. 21) for permanent removal.
- Security, fraud and abuse prevention — Art. 6 (1) (f) GDPR.
- Marketing emails and product updates — Art. 6 (1) (a) GDPR (consent, revocable at any time) or § 7 (3) UWG for existing customers.
- Cookies and similar technologies that are not strictly necessary — § 25 (1) TTDSG (consent).
4. Recipients & Processors
We share personal data only with carefully selected processors under written agreements pursuant to Art. 28 GDPR:
- Supabase (via Lovable Cloud) — hosting, authentication, database, storage. Servers in the EU (Frankfurt).
- Cloudflare, Inc. — CDN, DNS, DDoS protection, R2 object storage and Stream video hosting for files and media you upload. EU-US Data Privacy Framework certified.
- Stripe Payments Europe, Ltd. (Ireland) — payment processing, Stripe Connect, Stripe Tax, subscription billing.
- Resend — transactional and lifecycle email delivery.
- Google Ireland Ltd. — OAuth sign-in (when you use "Continue with Google") and Google Maps / Places for location search and city autocomplete.
- Sentry / logging providers — error monitoring, where enabled.
- Meta Platforms Ireland — solely to fetch a Creator's own Instagram data via official APIs after that Creator has connected their account.
Contract counterparties (Booker / Creator) receive the personal data necessary to perform the project (name, contact details, invoice data, signature). Access to project data on the Platform is enforced by row-level security.
5. International Transfers
Where processors act outside the EU/EEA (e.g. Cloudflare or Stripe US infrastructure), transfers rely on the EU-US Data Privacy Framework or on Standard Contractual Clauses (Art. 46 (2) (c) GDPR) with additional safeguards. Copies are available on request.
6. Storage Periods
- Account and profile data: for the duration of your account plus up to 30 days after deletion for backup rotation.
- Invoices, contracts, signature audit trails, tax-relevant records: 10 years (§ 147 AO, § 257 HGB).
- Server and security logs: up to 90 days, longer if required for incident investigation.
- Marketing consent records: until consent is withdrawn plus 3 years to evidence lawful processing.
7. Creator Directory (Art. 13 GDPR)
The Creator network is invite-only and opt-in. A Creator is contacted with a personal invitation, connects their own Instagram account through Meta's official login dialog, and completes their profile themselves. Publication happens only after the Creator submits the profile and confirms publication — the legal basis is Art. 6 (1) (a) GDPR (consent).
Before an invitation is accepted we hold nothing more than a public handle and the invitation status, in order to send and track that single invitation. Consent can be withdrawn at any time by disconnecting Instagram, deleting the profile in the account settings, or writing to hello@creatifs.com. Withdrawal immediately unpublishes the profile; remaining data is removed within 7 days of a verified request.
8. Instagram Connection (Meta Platform Terms)
Creators connect their Instagram account through the official Instagram API with Instagram Login (permission: instagram_business_basic). Consent is given inside Instagram's own login dialog and is the legal basis (Art. 6 (1) (a) GDPR).
- We receive: account id, username, account type, media list (caption, media type, permalink, timestamp) and media links.
- Instagram-sourced media stays on Meta's own content delivery network. To keep the site fast, image requests pass through our Cloudflare image proxy, which resizes them on the fly and holds them only in a temporary edge cache — we never store Instagram images or videos in our database or object storage, and cached copies expire automatically.
- Separately, a Creator may upload their own files to their profile or workspace. Those uploads are stored by us (Cloudflare R2 / Stream) because the Creator chose to upload them; they are not Instagram data.
- Access tokens are stored encrypted, refreshed automatically and used only to keep the connected portfolio current.
- Disconnecting in Instagram (Settings → Apps and websites) triggers our deauthorize and data-deletion callbacks, which remove the connection, all Instagram-derived portfolio entries and unpublish the profile. You receive a confirmation code to check the status at creatifs.com/data-deletion.
- We do not sell Instagram data, do not use it for advertising or profiling, and do not share it with third parties.
9. Profile Promotion (optional consent)
Creators can separately allow us to feature their work in créatifs marketing. This permission is optional, is not part of the Terms of Use, and can be withdrawn at any time in the profile settings or by writing to hello@creatifs.com.
- Data processed: the work shown on the créatifs profile (posts from the connected social profile and own uploads), name, social handle, profile picture and the Creator's likeness where it appears in that work.
- Purpose: promoting the Creator and the créatifs platform on our own and third-party channels, including collaborator tagging on Instagram, newsletters, press and event material.
- Legal basis: consent, Art. 6 (1) (a) GDPR and § 22 KUG. Selection and publication may be automated and recurring.
- Recipients: the social and advertising platforms on which the material is published, and our newsletter and design service providers.
- Storage: for as long as the profile is active and the permission stays switched on. We log when the permission was given or withdrawn, and which version of the Profile Promotion Terms applied, to be able to prove it.
- Withdrawal: effective for the future; we stop new publications immediately and remove existing organic posts within 14 days where the platform allows it. Declining or withdrawing has no effect on the account, ranking or visibility.
10. Your Rights
Under the GDPR you have the right to:
- access your personal data (Art. 15);
- rectification (Art. 16);
- erasure ("right to be forgotten", Art. 17), subject to statutory retention;
- restriction of processing (Art. 18);
- data portability (Art. 20);
- object to processing based on Art. 6 (1) (f) at any time (Art. 21);
- withdraw consent at any time without affecting the lawfulness of prior processing (Art. 7 (3));
- lodge a complaint with a supervisory authority — for us the Landesbeauftragte für Datenschutz und Informationsfreiheit Nordrhein-Westfalen, Kavalleriestraße 2–4, 40213 Düsseldorf.
Signed-in users can exercise the rights of access and portability directly in the app: open your account settings and choose Download my data to receive a machine-readable copy of everything we store about your account. The same screen lets you delete your account permanently.
Requests: hello@creatifs.com. See also our Data Deletion instructions.
12. Automated Decision-Making
We use algorithmic search and ranking to display Creators, but we do not carry out automated decision-making within the meaning of Art. 22 GDPR that produces legal effects for you.
13. Security
We apply appropriate technical and organisational measures under Art. 32 GDPR: TLS in transit, encryption at rest for storage buckets, row-level security in the database, principle of least privilege for staff access, and audited third-party processors. No system is fully secure — we cannot guarantee that unauthorised access will never occur, but we treat every incident with priority and notify affected users and authorities where legally required.
14. Changes to this Notice
We update this Privacy Policy when our processing changes. Material updates are announced by email or in-app notice. The current version is always available at creatifs.com/data-protection.