Effective Date: April 6, 2026 | Version: 7.3 (GDPR & Career Opportunities Aligned)
⚠️ BETA VERSION - Operated by an individual entrepreneur (Belgium).
1. Who We Are
ProjKilo is a worldwide platform for permissionless work and project collaboration. We are committed to transparency and compliance with the EU General Data Protection Regulation (GDPR).
Data Controller: ProjKilo (Individual Operator) Jurisdiction: Belgium (EU) Contact:[email protected]
2. The Data We Collect (And Why)
2.1. Account & Security Data (Required)
To operate the service, we store:
Identity: First Name, Last Name, Email, Password (Hashed), and Profile Picture (if provided).
Security Logs: When you log in, we store your IP Address and User Agent in our secure Session table. This is used solely to prevent account takeovers and detect suspicious login patterns.
Eligibility: Date of Birth (to verify 16+ status).
2.2. Career Opportunities, Matching & Profile Data (Optional)
Public Profile: Bio, Skills, Interests, University, and Faculty. Note: Your profile defaults to INTERNAL (visible only to logged-in members).
Smart Recommendations: We use your stated skills and interests to power our matching engine, helping recommend relevant projects to you. This does not constitute "automated decision-making with legal effects" under GDPR Article 22.
Career Opportunities: If you explicitly opt-in, we allow verified businesses and recruiters (who may pay for platform access) to view your full profile and contact you for career opportunities. You may revoke this consent at any time.
To maintain a high-trust network, ProjKilo utilizes verification systems. Depending on the verification type requested:
Student Verification: If requested, photographic evidence (Student ID) is processed securely and DELETED within 30 days. We only retain the unique studentIdNumber in our database to prevent systemic fraud.
Government Digital Identity (Future Capability): If you choose to verify via an official provider (e.g., "EU-eIDAS"), ProjKilo will never store your biometric data. We will only store the cryptographic timestamp of verification and the issuer name (e.g., "EU-eIDAS") to assign your verified badge.
Certain data actions are recorded permanently to maintain the integrity, legal compliance, and safety of the platform. These records are explicitly exempt from the Right to Erasure:
Financial Contributions (AML Compliance): Money or resources given to a project are recorded in a permanent ledger. We retain snapshots of the contributor's Name, Email, and external transaction IDs (e.g., Stripe) to comply with Anti-Money Laundering (AML) laws and financial audits.
Moderation & Flags (DSA Compliance): If you report abusive behavior, or if you are reported, a snapshot of the involved users' names, emails, and the offending content is locked in our moderation ledger to protect the community and defend against legal claims.
Votes & Project Governance: Your participation in project governance is recorded to maintain the mathematical validity of decisions.
2.5. Feedback & IP Data
When you submit feedback, ideas, or feature requests via the Feedback tool, this data is classified as Non-Personal Data. Under our Terms of Service, this data is assigned to ProjKilo and is not subject to the Right to Erasure.
2.6. Location Data (Geospatial)
If you use the "Projects Near Me" feature or tag a project location:
We process search coordinates to find matches within a radius.
We do NOT track your real-time GPS movements. Location data (latitude/longitude) is static and only stored when you explicitly define a project's location or your user profile location.
2.7. Search & Behavioral Tracking
We operate a global search engine to help users find projects. How we process this data depends on your account status:
Guest Users (Anonymous): If you search without logging in, we record the search query text and filters applied to analyze global trends. This data is strictly anonymous. No IP addresses or session identifiers are attached.
Logged-in Users (Behavioral Profiling): If you are logged in, we link your search queries, filters, and the specific projects you click on from the results page to your account. We process this under Legitimate Interest to improve search relevance algorithms, power your "Recent Searches" history, and refine your smart recommendations.
Saved Searches: If you utilize the "Saved Search" feature to receive notifications, we store your search criteria under Contractual Necessity to fulfill your request.
2.8. Peer-to-Peer Arbitration (The Blind Queue)
To ensure absolute fairness, neutrality, and anonymity in our decentralized arbitration engine, we utilize randomized "Blind Queue" case assignments.
If you choose to recuse yourself from or skip a dispute case, the identifier of that case is temporarily held in your device's active memory (RAM) for the duration of your current session.
This ensures you are not immediately reassigned the same case. This data is processed ephemerally on our servers solely to fulfill your request to fetch a new randomized case.
It is strictly necessary for the core functionality of the platform, is not used for profiling or tracking, and is completely destroyed the moment you refresh your browser or end your session.
3. Privacy-First Analytics & Viral Growth
3.1. Visitor Analytics (Privacy-First)
Public Traffic Analytics: We do NOT store raw IP addresses for general public traffic. To count unique visitors securely, we generate a daily-rotating cryptographic hash (combining your IP, User-Agent, today's date, and a server secret). This visitorHash cannot be reversed to identify you. We only track aggregate metrics (e.g., total hits and country-level origins) against this anonymous hash.
Session Logs (Logged-in Security): We DO securely store your IP address and User-Agent in the Session table when you log in. This is strictly to protect your account from unauthorized access and takeover attempts.
3.2. Referral Links (Cookieless)
To attribute network growth, we utilize referral links (e.g., invite codes). We track the usage of these codes via stateless URL parameters on our servers. We do not drop third-party tracking cookies on your device to monitor your activity across the web.
4. Cookies & Local Storage
We use cookies strictly for essential functionality:
Authentication: To keep you logged in.
Preferences: To remember your language and theme settings.
We do not use third-party advertising cookies or cross-site tracking.
5. Who Sees Your Data & International Transfers
Internal Community: Standard platform members can see your basic profile (full name, profile image, and university) to facilitate collaboration on projects. However, verified recruiters and businesses will only be granted access to your profile and contact capabilities if you explicitly enable the "Career Opportunities" setting.
Public Web: We automatically truncate your Last Name (e.g., "Jane D.") for anonymous visitors to prevent scraping.
Meeting Rooms: ProjKilo project meeting rooms are strictly text-based. Audio and video streaming are not supported or recorded by our platform.
Sub-Processors: We use the following infrastructure to securely deliver our service:
Hetzner Online (Germany): Primary Database & Server Hosting (GDPR compliant).
Cloudflare (Global): CDN, DDoS Security, and Email Routing.
Cloudflare R2 (EU Jurisdiction): Secure Object Storage used strictly for encrypted database backups and user-uploaded profile/project images.
Stripe (Future Capability): Payment processing. We only retain external transaction IDs; full financial data is secured by Stripe.
6. Data Retention, Erasure & The "Ghost Protocol"
Account Deletion: You can delete your account in Settings. Profile data (Bio, Skills, Images) and personal search history are wiped within 48 hours.
The Ghost Protocol: To preserve project history, your past messages, project updates, and votes remain visible but are anonymized. Your name is replaced with "Former Member" and links to your profile are severed.
Legal Exemptions: As stated in Section 2.4, ledgers detailing financial contributions and moderation flags are retained permanently for legal compliance (AML, Fraud Prevention).
Backups: Encrypted database backups are stored in a strict EU jurisdiction and are automatically deleted after 30 days. If you delete your account, your data will naturally age out of our backups within this window.
7. Your Rights (GDPR)
You have the right to:
Access & Port: Download a copy of your data via Settings.
Rectify: Update your information at any time.
Erasure: Request the deletion of your account (subject to the Ghost Protocol and Legal Exemptions outlined in Section 6).
Object: Withdraw consent for non-essential processing (such as Career Opportunities).
Complain: Lodge a complaint with the Belgian Data Protection Authority (Gegevensbeschermingsautoriteit / Autorité de protection des données) if you believe your data is being mishandled.
ProjKilo is not intended for children under 16 years of age. We do not knowingly collect data from minors. If we discover a user is under 16, we will terminate the account and delete the data immediately.