How People Facing handles personal data.
Draft version 2026-09-08. We are building this policy section by section.
This draft uses bracketed placeholders for legal identity details until the operating company name, registration details, address, and contact emails are finalized.
1. Who We Are
"People Facing," "we," "us," and "our" mean the People Facing service operated by [LEGAL_ENTITY_NAME] from Lithuania, European Union.
Company registration number: [LEGAL_ENTITY_NUMBER]. Registered address: [REGISTERED_ADDRESS].
Your privacy is important to us. This Privacy Policy explains how we collect, use, disclose, transfer, retain, and otherwise process personal data, and it describes the rights available to you. We process personal data in accordance with this Privacy Policy and applicable data protection law.
Depending on the context, [LEGAL_ENTITY_NAME] may act as a data controller and, in some cases, as a data processor. A data controller determines the purposes and means of processing personal data. A data processor processes personal data on behalf of a controller.
We are committed to protecting personal data and processing it in accordance with applicable European Union and Lithuanian data protection laws, including Regulation (EU) 2016/679, the General Data Protection Regulation (GDPR), the Law on Legal Protection of Personal Data of the Republic of Lithuania, and guidance from competent authorities.
Terms used in this Privacy Policy should be understood consistently with the GDPR unless this Privacy Policy says otherwise.
If you have questions, concerns, or complaints about this Privacy Policy or how we process personal data, or if you want to exercise your rights under the GDPR, contact us at [PRIVACY_EMAIL].
Overview
People Facing provides AI-assisted public-source people research. The rest of this Privacy Policy explains the categories of personal data we process, why we process them, the legal bases we rely on, how long we retain them, who we share them with, and how data subjects can exercise their rights.
This page is a working draft for legal review. It should be treated as product copy in progress until approved by counsel.
2. How and for Which Purposes Do We Process Personal Data?
We process personal data only where we have a purpose and a legal basis to do so. The table below describes the main purposes for which we process personal data, the categories of data involved, the legal basis we rely on, and the retention period that applies.
| Why do we process personal data? | Which personal data do we process? | What is the legal basis? | How long do we keep it? |
|---|---|---|---|
| To create, authenticate, and manage user accounts. | Name, email address, password/authentication records, organization or workspace details, account status, session records, policy acceptance records, and account settings. | Performance of a contract with you (GDPR Art. 6(1)(b)); our legitimate interest in operating and securing the service (GDPR Art. 6(1)(f)). | For the lifetime of the account and 10 years after account deletion or expiration of the contract with you and/or the person you represent, unless a different period is required by law, legal claims, security, accounting, abuse prevention, or dispute-resolution purposes. |
| To provide the AI-assisted public-source research reports requested through the service. | User-submitted search details, the name and context of the searched person, public profile links supplied by the user, generated reports, source links, excerpts, confidence notes, report metadata, and case activity. | Performance of a contract with the user who requested the report (GDPR Art. 6(1)(b)); our legitimate interest in providing lawful public-source research services (GDPR Art. 6(1)(f)). | User-facing access to reports may expire after the period shown in the product. Backend report and service-delivery records may be retained until expiration of the contract and 10 years after expiration of the contract with you and/or the person you represent, unless a different period is required by law, legal claims, security, abuse prevention, or a valid deletion request. |
| To process publicly available information about searched persons when generating reports. | Publicly available information about the searched person, such as professional profile information, public web pages, public social or professional signals, media references, public source excerpts, profile images where enabled, and our report notes or assumptions about that person. | Our legitimate interest in conducting and providing public-source people research requested by a user, where that interest is not overridden by the rights and freedoms of the searched person (GDPR Art. 6(1)(f)). Where special categories of personal data are processed, we rely only on data manifestly made public by the data subject or another applicable GDPR Art. 9 exception. | User-facing access to searched-person report data may expire after the period shown in the product. Backend records may be retained until expiration of the contract and 10 years after expiration of the contract with the user and/or the person they represent, subject to applicable data subject rights, opt-out or suppression requirements, legal holds, abuse-prevention needs, and dispute-resolution requirements. |
| To respond to queries, support requests, privacy requests, complaints, and other communications. | Name, email address, company or organization, message content, attachments, request history, communications with us, and information needed to verify and respond to the request. | Our legitimate interest in responding to requests and operating our business (GDPR Art. 6(1)(f)); compliance with legal obligations where the request concerns privacy rights or legal claims (GDPR Art. 6(1)(c)). | 10 years, unless a longer period is required to establish, exercise, or defend legal claims. |
| To manage business relationships with customers, suppliers, partners, and representatives of legal entities. | Name, work email, phone number, role/title, company, authority to represent an organization, contract details, communication history, signatures, and related business records. | Performance of a contract or pre-contractual steps (GDPR Art. 6(1)(b)); our legitimate interest in maintaining business relationships (GDPR Art. 6(1)(f)); legal obligations where applicable (GDPR Art. 6(1)(c)). | Until expiration of the contract or business relationship and 10 years after expiration of the contract or business relationship with you and/or the person you represent, unless a longer period is required by law or for legal claims. |
| To process payments, credits, subscriptions, invoices, refunds, and fraud prevention. | Name, email address, billing details, purchase history, invoice records, credit activity, transaction metadata, payment provider identifiers, tax information, and fraud-prevention signals. | Performance of a contract (GDPR Art. 6(1)(b)); compliance with tax, accounting, and financial legal obligations (GDPR Art. 6(1)(c)); our legitimate interest in preventing fraud and securing payments (GDPR Art. 6(1)(f)). | 10 years after the payment with you and/or the person you represent, or as long as required by applicable tax, accounting, anti-fraud, anti-money-laundering, or limitation-period rules. |
| To send service updates and, where permitted, information about relevant products or services. | Name, email address, company, communication preferences, consent or opt-out records, purchase history, and similar-service usage information. | Your consent where required (GDPR Art. 6(1)(a)); our legitimate interest in communicating with existing customers about related services where permitted by law (GDPR Art. 6(1)(f)); applicable electronic communications rules. | 5 years, unless you withdraw consent or opt out earlier. We may keep a suppression record for as long as needed to respect your opt-out preference. |
| To manage our social media accounts and interactions. | Name, username, profile photo, public profile information, comments, messages, reactions, shares, event attendance information, message attachments, and the time and content of interactions. | Your consent or actions on the relevant social network (GDPR Art. 6(1)(a)); our legitimate interest in managing public communications and community interactions (GDPR Art. 6(1)(f)). | 10 years, subject to the retention and deletion controls of the relevant social network. |
| To protect the service, prevent misuse, investigate abuse, enforce our terms, and maintain audit records. | IP address, device and browser data, session logs, authentication events, rate-limit events, abuse indicators, policy attestation records, case activity, audit logs, and security investigation records. | Our legitimate interest in securing the service and preventing abuse (GDPR Art. 6(1)(f)); legal obligations where applicable (GDPR Art. 6(1)(c)). | 10 years, unless a different period is appropriate for the nature of the log or a longer period is needed for investigation, enforcement, dispute resolution, or legal compliance. |
| To establish, exercise, or defend legal claims and comply with legal proceedings. | Relevant account data, contract records, payment records, communications, reports, source evidence, documents, attachments, procedural documents, authority requests, court or regulator correspondence, and related records. | Our legitimate interest in protecting our rights and defending legal claims (GDPR Art. 6(1)(f)); compliance with legal obligations (GDPR Art. 6(1)(c)). | Until expiration of the contract and 10 years after expiration of the contract with you and/or the person you represent, or longer where necessary for the relevant proceeding, legal obligation, or limitation period. |
The retention periods above are draft placeholders unless shown as a fixed period. Before publication, we will align these periods with the General Document Retention Periods Index of the Republic of Lithuania, applicable tax and accounting rules, and relevant limitation periods under Lithuanian law.
3. How Do We Process Personal Data from Publicly Available Sources?
When providing AI-assisted public-source people research, we may process personal data about the person who requested a report and, where applicable, personal data about the searched person. Searched-person data is limited to information available from public sources or information provided by the user in connection with the research request.
Public sources may include professional profiles, public social media profiles, search engine results, public websites, public media references, public company or professional directories, public records where lawful to use, and other publicly accessible online sources.
In many cases, we do not obtain searched-person data directly from the searched person and may not have reliable contact details that would allow us to provide an individual notice. In those cases, providing individual notice may be impossible or would involve disproportionate effort. For that reason, and where permitted by GDPR Art. 14(5), we provide this public Privacy Policy as the notice explaining how searched-person data may be processed.
We process publicly available searched-person data to provide the public-source research report requested by a user, to check source relevance and attribution, to reduce false matches, to maintain service integrity, and to prevent misuse of the service. We do not intend to collect private credentials, non-public account content, restricted records, or information that the user is not authorized to access.
Where special categories of personal data are processed, we process them only where permitted by law, such as where the data has been manifestly made public by the data subject or where another GDPR Art. 9 condition applies. Before publication, we will document the safeguards, minimization rules, and product controls that apply to sensitive data, criminal-offence data, profile images, face-comparison features, and similar higher-risk processing.
Searched persons may contact us at [PRIVACY_EMAIL] to exercise applicable privacy rights, including access, objection, restriction, correction, erasure, or opt-out/suppression where available under applicable law.
5. How Do We Protect Personal Data?
We treat personal data with care and take appropriate steps to protect it. We secure access to our websites and applications using HTTPS technology. Access to personal data is protected by measures such as password protection, encryption, access controls, and other appropriate safeguards.
Personal data is processed in accordance with the GDPR, the Law on Legal Protection of Personal Data of the Republic of Lithuania, and other applicable legal requirements. During processing, we use legal, organizational, and technical measures intended to protect personal data from accidental or unlawful destruction, loss, alteration, unauthorized disclosure, unauthorized access, and other unauthorized processing.
We regularly monitor our systems and procedures to identify ways to strengthen security measures.
6. Do We Process Minors' Personal Data?
Our services are not intended for individuals under the age of 14. If we become aware that we have collected personal data from a user under the age of 14, we will take steps to delete such data from our databases.
If you are 14 years old or older but under 18, please review this Privacy Policy with a parent or guardian so that you understand how we process personal data and what rights you have.
Because People Facing processes publicly available information in response to user requests, public-source information may sometimes relate to a minor. We do not knowingly target minors for public-source research, and users must not use the service to research minors unless they have a lawful basis and the use is permitted by our Terms of Service and Acceptable Use Policy.
7. What Data Subject Rights Do You Have?
Depending on the circumstances and subject to the conditions and exceptions set out in the GDPR, you may exercise the rights described below. These rights may apply whether you are an account user, a customer representative, a person communicating with us, or a searched person whose personal data appears in a public-source research report.
Right to information and access. You have the right to clear, transparent, and easily accessible information about how we process personal data. You may also request confirmation of whether we process personal data about you and request a copy of that personal data.
Right to rectification. You have the right to ask us to correct inaccurate personal data or complete incomplete personal data. If you are an account user, you are responsible for keeping the personal data you provide to us accurate and up to date.
Right to erasure. You may ask us to delete personal data in the cases provided by GDPR Art. 17. In some cases, we may be required or permitted to continue processing certain data, for example where processing is necessary to comply with a legal obligation, establish, exercise, or defend legal claims, protect the service, or maintain a suppression record.
Right to restriction of processing. You may ask us to restrict processing of personal data in the cases provided by GDPR Art. 18. Where processing is restricted, we will store the affected data and process it only where permitted by law.
Right to data portability. Where processing is based on consent or contract and carried out by automated means, you may have the right to receive personal data you provided to us in a structured, commonly used, machine-readable format, and to transmit that data to another controller.
Right to object. You may object to processing based on legitimate interests, including processing of publicly available searched-person data. If you object, we will assess whether we have compelling legitimate grounds to continue processing or whether processing is needed to establish, exercise, or defend legal claims.
Right to withdraw consent. Where processing is based on consent, you may withdraw that consent at any time. Withdrawal of consent does not affect the lawfulness of processing carried out before the withdrawal.
Right to complain to a supervisory authority. If you believe that our processing of personal data does not comply with the GDPR, you may lodge a complaint with State Data Protection Inspectorate of the Republic of Lithuania or another competent supervisory authority. We ask that you contact us first so we can try to resolve your concern.
To exercise your rights, contact us at [PRIVACY_EMAIL]. For the protection of personal data, we may ask for additional information to verify your identity, authority, or relationship to the request before responding.
We will respond to data subject requests within one month after receiving the request. Where permitted by law, this period may be extended by up to two additional months if the request is complex or if we receive many requests. If we need an extension, we will inform you within one month and explain the reason.
9. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our service, processing activities, legal requirements, or business operations.
When we update this Privacy Policy, we will publish the updated version on this page and update the version or effective date. If changes are material, we may provide additional notice where required by law or where appropriate in the circumstances.
If you have questions about this Privacy Policy or how we process personal data, contact us at [PRIVACY_EMAIL]. People in the European Economic Area may also contact or complain to State Data Protection Inspectorate of the Republic of Lithuania.