Freelance Fast GDPR

GDPR Information

Last updated

This page gives GDPR-specific information for clients, freelancers, website visitors, chat users, and people mentioned in project briefs or support requests.

Controller details

Controller: ZHAR YURIY, Via Ronago, 49, 22029 Uggiate Trevano (CO), Italy. Italian tax code: ZHRYRY93D27Z138J. VAT number: 03969970130.

GDPR contact: elchemista@gmail.com. Formal PEC contact: yuriy.zhar@ultracert.it. Main infrastructure: Fly.io, Frankfurt am Main, Germany.

1. GDPR Roles

Freelance Fast generally acts as an independent controller for its website, chat intake, client consent flow, project review, freelancer profiles, deterministic project visibility, applications, billing status, support, security, and marketplace operations.

When a business client submits personal data belonging to its own staff, customers, suppliers, or other third parties in a project brief, that client remains responsible for having a lawful basis to share it and for limiting the information to what the project requires.

2. Categories of Data Subjects

  • Clients who contact the agent or create projects.
  • Freelancers who sign in, build profiles, receive opportunities, or apply.
  • Website visitors and people who use public pages.
  • People mentioned inside a project brief, message, attachment, or support request.
  • Admins and operators who review projects and manage the service.

3. Categories of Personal Data

  • Identity and contact data, including names, email addresses, phone numbers, Telegram identifiers, GitHub identifiers, and business contact details.
  • Project and conversation data, including messages, project requirements, cleaned briefs, anonymous public project text, classifications, summaries, tags, and metadata.
  • Freelancer profile and application data, including public GitHub-derived signals, preferences, proposals, prices, availability, and selected contact channels.
  • Authentication, session, security, audit, billing-status, support, accounting, and operational logs.
  • Cookie and local storage data used for sessions, remember-me sign-in, security, request logging, and interface preferences.

4. Purposes and Legal Bases

  • Project intake, account management, applications, handoff, and support: contract or pre-contract steps.
  • Security, abuse prevention, debugging, service integrity, deterministic project visibility, and operational analytics: legitimate interests.
  • Tax, accounting, authority requests, legal claims, and statutory records: legal obligations.
  • Optional communications, Terms acceptance in the chat flow, and non-essential cookies: consent where required.

5. AI-Assisted Processing and AI Act Boundary

Freelance Fast uses AI as a support tool for conversation, project cleanup, classification, safety routing, formatting, translation, public GitHub summaries, and descriptive drafting. The service is designed so AI assists people rather than replacing them.

AI is not used to score, rank, reject, approve, shortlist, or evaluate freelancers. Project visibility is based on explicit user-selected tags, preferences, budget range, availability, language, channel, and other deterministic database fields. Admins review projects before publication where practical, freelancers decide whether to apply, and clients choose who to contact.

Operators should understand the system's intended use, limits, hallucination risk, privacy limits, and the human oversight points before using AI-assisted workflows.

6. Processors and Third Parties

Freelance Fast may use processors and third-party services for hosting, database, storage, monitoring, security, messaging, authentication, email or notifications, payments, AI, and analytics. Known providers or categories include Fly.io hosting, Telegram messaging, GitHub sign-in/profile data, Stripe for subscriptions and billing, OpenRouter for AI routing and text-processing features, Google Analytics where analytics consent is accepted, and email or notification services where enabled.

Processors should be used under appropriate contractual terms. Subprocessors may be updated as the product changes, and material changes should be reflected in this page or the Privacy Policy.

7. Security Measures

  • Hosting in the Fly.io Frankfurt am Main region for the main application.
  • Signed sessions, CSRF protection, secure browser headers, and controlled sign-in flows.
  • GitHub sign-in for freelancers and scoped admin areas for operational review.
  • Admin review before projects become public or are sent broadly to freelancers.
  • Private client contact handoff only after client selection or operational replacement.
  • Operational logging, abuse-prevention checks, safety routing, and rate-limit signals.
  • Deletion, anonymization, and contact-field removal paths where technically possible.

8. International Transfers

Main hosting is in Germany. Some providers may process data outside the EEA. Where this happens, Freelance Fast relies on appropriate safeguards such as adequacy decisions, Standard Contractual Clauses, provider transfer mechanisms, or equivalent safeguards recognized by applicable law.

9. Retention and Deletion

Data is retained only as long as needed for service delivery, project operations, applications, billing, accounting, security, abuse prevention, legal obligations, or disputes. Chat messages and project records are kept for up to 1 year by default. Accounting, tax, invoice, Stripe payment, and legal records may be kept longer where required by law. Clients can request deletion in chat or by email. Freelancers can manage or request deletion of account data through the available account flow or by email.

On confirmed user deletion requests, Freelance Fast deletes or anonymizes the user's personal data, messages, projects, applications, profile, and sessions where technically possible, removes contact fields, clears session tokens where applicable, and keeps only records required for security, disputes, legal duties, accounting, or platform integrity.

10. Data Subject Rights

You can request access, rectification, erasure, restriction, portability, objection, or withdrawal of consent. Freelance Fast may ask for information needed to verify your identity and locate the relevant records. A response is normally provided within one month unless the request is complex or the law allows an extension.

If you believe your rights were not respected, you can lodge a complaint with the Garante per la protezione dei dati personali or another competent EU supervisory authority.

11. Records and Operational Compliance

Freelance Fast should maintain internal records of processing activities, processor terms, security measures, retention rules, breach response steps, and AI feature reviews. These internal records are not all public, but they are part of operating the service responsibly under GDPR.

12. Contact

GDPR questions and rights requests can be sent to elchemista@gmail.com. Formal PEC requests can be sent to yuriy.zhar@ultracert.it.