Privacy Policy

Effective August 24, 2026 · ACANTHUS

This policy explains how ACANTHUS (“we”) processes personal data when you use Acanthus. We act as a data controller for account data and as a data processor for conference content you upload (presenters, judges, scores).

1. What we collect

  • Account data: name, email, hashed password, role.
  • Conference data: conference name, awards, presenters, judge invites, scores, comments.
  • Billing data: processed by Paddle.com as Merchant of Record; we receive only invoice metadata (transaction ID, tier, amount, country) and never full card numbers.
  • Technical data: IP address, browser, basic usage logs for security and abuse prevention.

2. Why we use it (legal bases under GDPR)

  • To provide the Service and your account — performance of contract.
  • To process payments and send service emails — performance of contract.
  • To secure the platform and prevent abuse — legitimate interests.
  • To comply with tax, accounting and legal obligations — legal obligation.

3. Sharing

We share data with sub-processors strictly to provide the Service:

  • Lovable Cloud / Supabase — hosting and database.
  • Paddle.com — Merchant of Record: payment processing, billing, tax, invoicing, refunds and buyer support.
  • Email delivery provider — transactional email (invites, receipts).

We do not sell personal data and we do not use it for advertising.

4. International transfers

Some sub-processors may process data outside your country. Where required, we rely on Standard Contractual Clauses or equivalent safeguards.

5. Retention

Conference data is retained while your account is active and for 30 days after you delete it (to allow recovery). Invoice data is retained as required by tax law (typically 7–10 years). You can request earlier deletion by contacting us.

6. Your rights

Subject to applicable law (including GDPR / UK GDPR / CCPA), you have the right to access, rectify, erase, restrict and port your personal data, to object to processing based on legitimate interests, and to lodge a complaint with your supervisory authority.

7. Cookies

We use only strictly necessary cookies (session, authentication, CSRF). We do not use advertising or third-party analytics cookies, so no consent banner is required under EU ePrivacy rules.

8. Security

Data is encrypted in transit (TLS) and at rest, access is governed by row-level security policies, and passwords are stored as salted hashes. No system is perfectly secure; you must keep your credentials safe.

9. Children

The Service is not intended for children under 16.

10. Contact / Data Processing Agreement

Privacy questions or DPA requests: reach us through the support options available in your account.