Privacy Policy
Effective August 24, 2026 · ACANTHUS
This policy explains how ACANTHUS (“we”) processes personal data when you use Acanthus. We act as a data controller for account data and as a data processor for conference content you upload (presenters, judges, scores).
1. What we collect
- Account data: name, email, hashed password, role.
- Conference data: conference name, awards, presenters, judge invites, scores, comments.
- Billing data: processed by Paddle.com as Merchant of Record; we receive only invoice metadata (transaction ID, tier, amount, country) and never full card numbers.
- Technical data: IP address, browser, basic usage logs for security and abuse prevention.
2. Why we use it (legal bases under GDPR)
- To provide the Service and your account — performance of contract.
- To process payments and send service emails — performance of contract.
- To secure the platform and prevent abuse — legitimate interests.
- To comply with tax, accounting and legal obligations — legal obligation.
3. Sharing
We share data with sub-processors strictly to provide the Service:
- Lovable Cloud / Supabase — hosting and database.
- Paddle.com — Merchant of Record: payment processing, billing, tax, invoicing, refunds and buyer support.
- Email delivery provider — transactional email (invites, receipts).
We do not sell personal data and we do not use it for advertising.
4. International transfers
Some sub-processors may process data outside your country. Where required, we rely on Standard Contractual Clauses or equivalent safeguards.
5. Retention
Conference data is retained while your account is active and for 30 days after you delete it (to allow recovery). Invoice data is retained as required by tax law (typically 7–10 years). You can request earlier deletion by contacting us.
6. Your rights
Subject to applicable law (including GDPR / UK GDPR / CCPA), you have the right to access, rectify, erase, restrict and port your personal data, to object to processing based on legitimate interests, and to lodge a complaint with your supervisory authority.
7. Cookies
We use only strictly necessary cookies (session, authentication, CSRF). We do not use advertising or third-party analytics cookies, so no consent banner is required under EU ePrivacy rules.
8. Security
Data is encrypted in transit (TLS) and at rest, access is governed by row-level security policies, and passwords are stored as salted hashes. No system is perfectly secure; you must keep your credentials safe.
9. Children
The Service is not intended for children under 16.
10. Contact / Data Processing Agreement
Privacy questions or DPA requests: reach us through the support options available in your account.