Privacy Policy

What personal data we collect, why, who we share it with, how long we keep it, and your rights.

Version 1.0 Effective 2026-08-18 US-FL

Remote Talent LLC, a Wyoming limited liability company with its mailing address at 924 N Magnolia Ave, Suite 202 Unit #5333, Orlando, FL 32803, USA ("Remote Talent", "we", "us") explains here how we handle personal data.

This policy covers the remotetalent.io website, the Remote Talent iOS application, and the services we provide (together, the "Platform").

1. Our role

Remote Talent supplies professional services to clients and performs them through independent contractors engaged as subcontractors. Because we are a party to both relationships rather than a platform standing outside them, we are a controller for most of the data we hold.

We are a controller for:

  • account, profile, and verification data of contractors and client contacts;
  • identity verification, sanctions, and anti-money-laundering data;
  • our contractual records — statements of work, work orders, timesheets, acceptance records;
  • billing, invoicing, and payment records, including amounts paid to contractors;
  • security, fraud-prevention, and audit records;
  • support and other correspondence.

We are a processor for personal data a client makes available to us so that services can be performed, and for personal data contained in deliverables. In that chain the client is the controller, we are the processor, and the contractor performing the engagement is our sub-processor. Our Data Processing Addendum at remotetalent.io/legal/dpa governs that processing.

Where you are a controller, you are responsible for having a lawful basis for the personal data you make available to us and for giving affected individuals any notice they are due.

2. What we collect

2.1 Before you have an account

If you request access, we collect your name, email address, country, company name, role description, and any referral code, together with a hashed IP address, your user agent, and the source of the request. We use this to assess and process access requests and to prevent abuse.

2.2 Account and profile

Email address and account type. For contractors: first, middle and last name, phone number and country code, date of birth, gender, nationality, street address, city, postal code, country, tax residence country, tax identification number, professional title, service category, short description, portfolio and LinkedIn URLs, and profile image.

For client contacts: company name, registration country, tax and VAT number, registered address, contact name, contact email, phone, role, and website.

2.3 Identity verification, address verification, and screening

To meet our legal obligations and manage fraud and financial-crime risk, we collect and generate:

  • identity document images and data, and a facial image;
  • facial geometry derived from that image for the purpose of matching your face to your document,

and a liveness check confirming a real person is present;

  • proof of address and the result of address verification, including whether a mismatch was

detected;

  • sanctions, politically-exposed-person, and adverse-media screening results, including a

risk score, the number of matches, and the date screened;

  • verification status, the date verified, and, where an application is declined, the **reason for

decline**.

Identity and biometric verification is performed by Didit. See Section 4 for how we treat biometric data, which is subject to additional protections.

2.4 Engagement and financial records

Contract terms, scope, rates, dates, signature status, signing links, and executed documents; timesheets and time entries, including approver name, approver email, and approver comments; approval tokens sent to approvers; invoices, invoice line items, amounts, taxes, fees, and payment dates; and supporting documents you upload.

Some of this is personal data about people who are not our users — a client's named signatory or timesheet approver, for example. We rely on the party who supplied it having a lawful basis to do so.

2.5 Payout details

Depending on the method you choose: bank account country, bank name, IBAN, account number, routing number, SWIFT/BIC, local bank details, Wise email address, Revolut tag, or cryptocurrency wallet address, network, and provider.

Account numbers, IBANs, routing numbers, and wallet addresses are stored encrypted.

2.6 Technical and device data

Device push-notification tokens and platform; log data including IP address and user agent; and cookie and consent data. Where we record your cookie consent, we store the policy version, your choices, the time granted, a hashed IP address, and your user agent.

2.7 Change history

We maintain an audit record of changes to key records. This retains before-and-after snapshots of the data that changed, which can include personal data, together with who made the change and when. It exists for security, dispute resolution, and regulatory accountability, and is not used for any other purpose.

3. Why we use it, and our lawful bases

PurposeLawful basis (UK/EU GDPR)
Providing the Platform and performing our agreementsPerformance of a contract
Identity verification, sanctions and AML screening, record-keepingLegal obligation; substantial public interest
Biometric verificationExplicit consent (Art. 9(2)(a)) — see Section 4
Invoicing, payment, tax, and accountingLegal obligation; performance of a contract
Fraud prevention, platform security, abuse preventionLegitimate interests
Assessing access requestsLegitimate interests; steps prior to a contract
Service communicationsPerformance of a contract
Optional analytics and error diagnosticsConsent
Establishing, exercising, or defending legal claimsLegitimate interests; legal obligation

Where we rely on legitimate interests, we have assessed that our interest is not overridden by your rights, and you may object as described in Section 8.

4. Biometric data

Our identity check captures a facial image and derives facial geometry from it to confirm that you are the person shown on your identity document, together with a passive liveness check.

  • Under UK and EU GDPR this is special category data, processed only on your explicit consent.
  • We ask for that consent on a dedicated screen before the camera opens — it is not bundled into

our other terms.

  • We do not sell, lease, trade, or otherwise profit from biometric data.
  • We do not use it to train any model, and we do not use it for any purpose other than verifying your

identity.

  • We permanently destroy biometric data when the purpose of collection has been satisfied, or within

three (3) years of your last interaction with us, whichever occurs first.

  • You may withdraw consent at any time. We cannot complete verification without it, so withdrawal

means we cannot continue to provide the Platform to you.

If you are in Illinois, this section is our written retention and destruction policy for the purposes of the Biometric Information Privacy Act. Equivalent rights apply under Texas CUBI and Washington's My Health My Data Act.

5. Automated decisions

Identity verification, address verification, and sanctions screening involve automated processing, and an application may be declined or an account restricted on the basis of the result.

You have the right to obtain human review, to express your point of view, and to contest a decision. Contact legal@remotetalent.io. Where the law prohibits us from explaining a decision — as it can with sanctions and financial-crime matters — we will say so.

6. Who we share it with

We do not sell personal data, and we do not share it for cross-context behavioural advertising.

RecipientPurposeLocation
SupabaseDatabase, authentication, file storage, serverless functionsIreland (eu-west-1)
DiditIdentity verification, biometric matching, proof of address, AML and sanctions screeningEU
DocumensoElectronic signature of contracts, timesheets, and terminationsEU
ResendTransactional emailUS/EU
WiseContractor payouts and local payment method dataEU/UK
RevolutContractor payoutsEU/UK
VatstackVAT number and company verificationEU
ApplePush notification deliveryUS

The current list is maintained at remotetalent.io/legal/subprocessors.

We also share: with the other side of an engagement, to the extent needed to perform it — a client is told the identity and relevant professional details of the contractor performing their engagement, and a contractor is told the client's identity and requirements; with professional advisers; with regulators, tax authorities, and law enforcement where legally required; and with an acquirer in a merger or sale of assets, under confidentiality.

7. International transfers

Our primary database and file storage are hosted in Ireland. We are established in the United States, and some processors operate outside the EEA and UK.

Where personal data leaves the EEA or UK, we rely on the European Commission's Standard Contractual Clauses and, for the UK, the International Data Transfer Addendum, together with additional safeguards where a transfer risk assessment indicates they are needed. You may request a copy of the relevant transfer mechanism at legal@remotetalent.io.

8. Your rights

Subject to local law, you may request access, correction, erasure, restriction, portability, and you may object to processing based on legitimate interests. You may withdraw consent at any time without affecting processing already carried out.

Deleting your account. You can delete your account from within the app, under Settings. Deletion removes your profile and account data. We retain what law requires us to keep — invoices, tax records, and AML records — for the periods in Section 9, and we retain anything needed to establish, exercise, or defend a legal claim.

To exercise a right, contact legal@remotetalent.io. We respond within one month, extendable by two further months for complex requests. We may need to verify your identity first.

You may complain to your local supervisory authority. In Ireland that is the Data Protection Commission; in the UK, the Information Commissioner's Office.

8.1 If you are in California

We collect the categories described in Section 2, including sensitive personal information: government identifiers, financial account details, and biometric information.

We do not sell personal information and do not share it for cross-context behavioural advertising. We use sensitive personal information only for the purposes permitted by the CPRA — providing the service, verifying identity, preventing fraud, and complying with law — and not to infer characteristics about you.

You have the rights to know, delete, correct, opt out of sale or sharing, and limit the use of sensitive personal information, and we will not discriminate against you for exercising them. An authorised agent may submit a request with written permission and verification.

8.2 Our representatives

We are in the process of appointing representatives in the European Union and the United Kingdom under Article 27 of the EU and UK GDPR. Until they are appointed and named here, please direct any matter you would raise with a representative to legal@remotetalent.io, and we will respond as if it had been raised with them.

9. How long we keep it

DataRetention
Account and profileWhile your account is active, then 30 days
Identity and AML records5 years after the relationship ends, as AML law requires
Biometric images and templatesPer remotetalent.io/legal/biometric-policy, then destroyed
Contracts, invoices, tax records7 years from the end of the relevant tax year
Audit and change history7 years
Consent records5 years after the consent is superseded or withdrawn
Access requests not converted to accounts12 months
Support correspondence3 years

Where periods conflict, the longest applicable legal requirement governs.

10. Security

Data is encrypted in transit and at rest. Payout account numbers, IBANs, routing numbers, and wallet addresses are additionally encrypted at the field level. Access is restricted on a need-to-know basis and database access is governed by row-level security. We keep audit records of changes to key data.

No system is perfectly secure. Where a breach is likely to result in a risk to your rights, we will notify you and the relevant supervisory authority as the law requires.

11. Children

The Platform is for business use by people aged 18 and over. We do not knowingly collect data from children. If you believe a child has provided us data, contact legal@remotetalent.io and we will delete it.

12. Changes

We will post any updated version here with a new effective date. Where a change is material we will notify you in advance through the Platform or by email.

13. Contact

legal@remotetalent.io · Remote Talent LLC, 924 N Magnolia Ave, Suite 202 Unit #5333, Orlando, FL 32803, USA

This is version 1.0 of the Privacy Policy, effective 2026-08-18. Published from the same source the Remote Talent iOS app reads, so the text here and the text you accept in the app are identical. Superseded versions are retained because acceptance records reference them.

Questions about this document: support@remotetalent.io