• About
  • Pricing
  • Ready team blueprintsStart from a proven business outcome, then match real specialists.
  • Partnership
  • Signals
  • Insights
  • Login →Create account +Client Office →Team Studio →Pro Workspace →
    My account Upgrade $Support Sign out ×
Main/
InsightsArticles & newsSignalsPeople & project graphPartnershipCollaborate with usAboutWhat is Collty?PricingPlans and capacity
Login →Create account +Client Office →Team Studio →Pro Workspace →My account Upgrade $Support Sign out ×
PrivacyTermsCookiesGDPREU AI Act
Data protection operations

GDPR Compliance

This page describes Collty's implemented technical and operational data-protection controls, the evidence maintained for review, and the legal or contractual facts that remain subject to verification.

Control baseline

GDPR accountability and privacy by design

Technical status

Operational controls implemented

Legal status

Ongoing evidence and applicability review

Updated

July 29, 2026

01

Accountability by design

Versioned RoPA, DPIA, provider, transfer, retention, rights-request, incident and control records create an auditable operating history.

02

Protected rights workflow

Authenticated users can submit and track privacy requests. Deadlines, responses and state changes are recorded without storing requester email in the case table.

03

Verified facts stay separate

Contracts, processing regions, transfer safeguards, DPO status and EU-representative status remain pending until supporting evidence and legal review are complete.

Contents
  • 1. Scope and status
  • 2. Privacy architecture
  • 3. Records of processing activities
  • 4. Data-protection impact assessment
  • 5. Privacy rights and DSAR workflow
  • 6. Retention and controlled deletion
  • 7. Providers and international transfers
  • 8. Security incidents and breach response
  • 9. Roles, review and audit evidence

Collty uses this page as a public summary, not as a substitute for the Privacy Policy, a data processing agreement, regulator guidance or legal advice. The underlying protected registers contain more detail than is published here.

Read Privacy PolicyRead TermsEuropean Commission GDPR
01

Scope and status

Collty is building GDPR accountability into the product and its operating records. The platform distinguishes technical implementation, operational verification and legal determination. A control is not described internally as verified merely because a table, interface or policy exists.

StatusMeaning
ImplementedThe technical control and its protected evidence path exist and can be operated.
Partially implementedThe control exists but an enforcement, automation or evidence step remains.
Pending verificationA legal, organizational, contractual, regional or supplier fact still requires evidence.
Not requiredA documented assessment concluded that the control is not applicable in the reviewed context.

No unsupported certification claim

Collty describes technical and operational alignment. Formal legal compliance depends on the actual entity, establishment, contracts, processing, users and markets, and may require independent legal or regulatory assessment.

02

Privacy architecture

  • Private records are scoped by workspace, project and participant permissions.
  • Sensitive fields protected by Collty's secure-field layer use application-level AES-256-GCM authenticated encryption.
  • Keyed HMAC-SHA256 lookup values support exact matching of protected identifiers without exposing plaintext search data.
  • Protected governance tables use row-level security, revoked public and ordinary authenticated grants, and service-role-only access.
  • Privacy requests are linked to the authenticated auth user ID. The privacy case table does not require the user's email address.
  • Public discovery information is separated from private workspace data, direct messages, billing records and protected evidence.

Encryption complements rather than replaces authorization, secure transport, key management, audit logging, minimization, retention and incident response. No security system can eliminate every risk.

03

Records of processing activities

The versioned processing register records each identified processing purpose, controller or processor role, data-subject groups, personal-data categories, sources, recipients, legal-basis assessment, retention references, expected international transfers, accountable role and review state.

  • Account, identity and access administration.
  • Professional profiles, discovery and team assembly.
  • Workspace projects, tasks, chats, files and collaboration evidence.
  • Billing, subscriptions, invoices and financial analytics.
  • Security, fraud prevention, support and operational communications.
  • AI evaluation, feedback, outcomes, provenance and system monitoring.
  • Optional integrations enabled by the user or workspace.

The register is an operating dataset rather than a static document. New processing must be added and reviewed before it is treated as part of the approved inventory.

04

Data-protection impact assessment

Technical DPIA records currently cover Team Assembly, Signals applicant ranking, Team Intelligence and task allocation. Each assessment identifies intended processing, necessity, proportionality, data flows, risks to people, mitigations, residual risk, linked AI-system records and review dates.

  • Ranking bias, selection bias and proxy discrimination.
  • Incorrect exclusion or unsupported professional evidence.
  • Private-data leakage, excessive context and unauthorized access.
  • Over-reliance on recommendations or generated project actions.
  • Model error, drift, weak evidence and insufficient human review.
  • Misuse outside Collty's intended project-team and collaboration context.

Technical assessment completion is not recorded as legal approval. Any requirement for supervisory consultation remains a separate status and decision.

05

Privacy rights and DSAR workflow

An authenticated user can submit access, portability, rectification, erasure, restriction or objection requests in My Account. A protected case is created with the request type, authenticated user ID, encrypted details, status, one-month due date and audit history.

  • Open requests are unique per user and request type to prevent duplicate unresolved cases.
  • A user can withdraw an eligible open request from the same protected account area.
  • Additional identity or authority verification can be required when risk or account context makes it necessary.
  • An authorized operator can acknowledge, investigate, lawfully extend and close the case only through protected routes.
  • A completed, partially completed or rejected request requires a documented protected response.
  • Deletion and portability respect shared workspace rights, billing or tax duties, disputes, legal holds, security requirements and protected-backup rotation.

Response time

Collty's default deadline is one calendar month from receipt. A lawful extension can be recorded for complex or numerous requests, together with the case response and audit history.

06

Retention and controlled deletion

The retention matrix separates the trigger, active-system rule, backup rule, legal-hold rule, deletion method, accountable role and enforcement status for each data category.

LayerControl
Active systemsDelete, de-identify, restrict or retain according to the documented purpose and trigger.
Shared workspacesProtect the rights and records of other authorized participants when one account is removed.
Financial and dispute recordsRetain only where tax, accounting, fraud, claim or legal-hold requirements apply.
BackupsRemove through controlled backup rotation unless a documented legal hold requires preservation.
Derived analyticsRetain only in de-identified form when the data can no longer reasonably be linked to an individual.

The register explicitly identifies which policies are automatic, manual, hybrid or still pending verification. This prevents a written target from being mistaken for enforced deletion.

07

Providers and international transfers

The provider register covers infrastructure, database, AI, vector search, email, research, identity, analytics and optional communication integrations actually referenced by Collty. Current records include Supabase, Render, OpenAI, Jina AI, Qdrant, Resend, Exa, optional Anthropic shadow evaluation, Google services and optional Zoom integration.

  • Service purpose and whether the integration is optional.
  • Public privacy, security and DPA references where available.
  • Contract verification and documented-instruction status.
  • Processing-region verification.
  • Destination scope, transfer mechanism and transfer impact assessment status.
  • Review due date and active, optional or inactive state.

Collty does not publicly assert that a DPA is executed, a particular region is guaranteed or a transfer safeguard applies until the applicable account, contract and deployment evidence has been reviewed.

08

Security incidents and breach response

A suspected privacy incident creates an encrypted record containing severity, source, affected data categories, estimated people affected, confidentiality, integrity and availability impact, containment, corrective action and rights-risk assessment.

  • The system records detection time and starts a 72-hour supervisory-notification assessment clock.
  • The operator records whether authority notification and affected-person notification are required.
  • Containment, risk assessment, notification and resolution remain distinct states.
  • Every case change creates protected audit metadata without copying the encrypted incident narrative into the audit table.
  • Where notification is legally required, the operational timer supports action without replacing the responsible person's legal assessment.
09

Roles, review and audit evidence

Each processing, DPIA, retention and accountability record identifies an accountable role and review state. Privacy case and incident transitions create durable database audit entries. Admin reporting reads the protected registers on demand and does not run a background AI review or scan user content.

  • DPO necessity is recorded as a pending assessment until Collty's actual establishment, core activities and monitoring scale are confirmed.
  • EU-representative necessity is recorded separately and depends on establishment, offering and monitoring facts.
  • Entity name, legal address, appointed contacts and signed supplier evidence will be added when verified.
  • The public Privacy Policy and Terms are versioned and linked to the in-product rights workflow.
  • Operational records can be exported or reviewed by authorized personnel for legal, security or regulatory work.