Privacy Policy
What personal data we collect, why, who we share it with, how long we keep it, and your rights.
Remote Talent LLC, a Wyoming limited liability company with its mailing address at 924 N Magnolia Ave, Suite 202 Unit #5333, Orlando, FL 32803, USA ("Remote Talent", "we", "us") explains here how we handle personal data.
This policy covers the remotetalent.io website, the Remote Talent iOS application, and the services we provide (together, the "Platform").
1. Our role
Remote Talent supplies professional services to clients and performs them through independent contractors engaged as subcontractors. Because we are a party to both relationships rather than a platform standing outside them, we are a controller for most of the data we hold.
We are a controller for:
- account, profile, and verification data of contractors and client contacts;
- identity verification, sanctions, and anti-money-laundering data;
- our contractual records — statements of work, work orders, timesheets, acceptance records;
- billing, invoicing, and payment records, including amounts paid to contractors;
- security, fraud-prevention, and audit records;
- support and other correspondence.
We are a processor for personal data a client makes available to us so that services can be performed, and for personal data contained in deliverables. In that chain the client is the controller, we are the processor, and the contractor performing the engagement is our sub-processor. Our Data Processing Addendum at remotetalent.io/legal/dpa governs that processing.
Where you are a controller, you are responsible for having a lawful basis for the personal data you make available to us and for giving affected individuals any notice they are due.
2. What we collect
2.1 Before you have an account
If you request access, we collect your name, email address, country, company name, role description, and any referral code, together with a hashed IP address, your user agent, and the source of the request. We use this to assess and process access requests and to prevent abuse.
2.2 Account and profile
Email address and account type. For contractors: first, middle and last name, phone number and country code, date of birth, gender, nationality, street address, city, postal code, country, tax residence country, tax identification number, professional title, service category, short description, portfolio and LinkedIn URLs, and profile image.
For client contacts: company name, registration country, tax and VAT number, registered address, contact name, contact email, phone, role, and website.
2.3 Identity verification, address verification, and screening
To meet our legal obligations and manage fraud and financial-crime risk, we collect and generate:
- identity document images and data, and a facial image;
- facial geometry derived from that image for the purpose of matching your face to your document,
and a liveness check confirming a real person is present;
- proof of address and the result of address verification, including whether a mismatch was
detected;
- sanctions, politically-exposed-person, and adverse-media screening results, including a
risk score, the number of matches, and the date screened;
- verification status, the date verified, and, where an application is declined, the **reason for
decline**.
Identity and biometric verification is performed by Didit. See Section 4 for how we treat biometric data, which is subject to additional protections.
2.4 Engagement and financial records
Contract terms, scope, rates, dates, signature status, signing links, and executed documents; timesheets and time entries, including approver name, approver email, and approver comments; approval tokens sent to approvers; invoices, invoice line items, amounts, taxes, fees, and payment dates; and supporting documents you upload.
Some of this is personal data about people who are not our users — a client's named signatory or timesheet approver, for example. We rely on the party who supplied it having a lawful basis to do so.
2.5 Payout details
Depending on the method you choose: bank account country, bank name, IBAN, account number, routing number, SWIFT/BIC, local bank details, Wise email address, Revolut tag, or cryptocurrency wallet address, network, and provider.
Account numbers, IBANs, routing numbers, and wallet addresses are stored encrypted.
2.6 Technical and device data
Device push-notification tokens and platform; log data including IP address and user agent; and cookie and consent data. Where we record your cookie consent, we store the policy version, your choices, the time granted, a hashed IP address, and your user agent.
2.7 Change history
We maintain an audit record of changes to key records. This retains before-and-after snapshots of the data that changed, which can include personal data, together with who made the change and when. It exists for security, dispute resolution, and regulatory accountability, and is not used for any other purpose.
3. Why we use it, and our lawful bases
| Purpose | Lawful basis (UK/EU GDPR) |
|---|---|
| Providing the Platform and performing our agreements | Performance of a contract |
| Identity verification, sanctions and AML screening, record-keeping | Legal obligation; substantial public interest |
| Biometric verification | Explicit consent (Art. 9(2)(a)) — see Section 4 |
| Invoicing, payment, tax, and accounting | Legal obligation; performance of a contract |
| Fraud prevention, platform security, abuse prevention | Legitimate interests |
| Assessing access requests | Legitimate interests; steps prior to a contract |
| Service communications | Performance of a contract |
| Optional analytics and error diagnostics | Consent |
| Establishing, exercising, or defending legal claims | Legitimate interests; legal obligation |
Where we rely on legitimate interests, we have assessed that our interest is not overridden by your rights, and you may object as described in Section 8.
4. Biometric data
Our identity check captures a facial image and derives facial geometry from it to confirm that you are the person shown on your identity document, together with a passive liveness check.
- Under UK and EU GDPR this is special category data, processed only on your explicit consent.
- We ask for that consent on a dedicated screen before the camera opens — it is not bundled into
our other terms.
- We do not sell, lease, trade, or otherwise profit from biometric data.
- We do not use it to train any model, and we do not use it for any purpose other than verifying your
identity.
- We permanently destroy biometric data when the purpose of collection has been satisfied, or within
three (3) years of your last interaction with us, whichever occurs first.
- You may withdraw consent at any time. We cannot complete verification without it, so withdrawal
means we cannot continue to provide the Platform to you.
If you are in Illinois, this section is our written retention and destruction policy for the purposes of the Biometric Information Privacy Act. Equivalent rights apply under Texas CUBI and Washington's My Health My Data Act.
5. Automated decisions
Identity verification, address verification, and sanctions screening involve automated processing, and an application may be declined or an account restricted on the basis of the result.
You have the right to obtain human review, to express your point of view, and to contest a decision. Contact [email protected]. Where the law prohibits us from explaining a decision — as it can with sanctions and financial-crime matters — we will say so.
6. Who we share it with
We do not sell personal data, and we do not share it for cross-context behavioural advertising.
| Recipient | Purpose | Location |
|---|---|---|
| Supabase | Database, authentication, file storage, serverless functions | Ireland (eu-west-1) |
| Didit | Identity verification, biometric matching, proof of address, AML and sanctions screening | EU |
| Documenso | Electronic signature of contracts, timesheets, and terminations | EU |
| Resend | Transactional email | US/EU |
| Wise | Contractor payouts and local payment method data | EU/UK |
| Revolut | Contractor payouts | EU/UK |
| Vatstack | VAT number and company verification | EU |
| Apple | Push notification delivery | US |
The current list is maintained at remotetalent.io/legal/subprocessors.
We also share: with the other side of an engagement, to the extent needed to perform it — a client is told the identity and relevant professional details of the contractor performing their engagement, and a contractor is told the client's identity and requirements; with professional advisers; with regulators, tax authorities, and law enforcement where legally required; and with an acquirer in a merger or sale of assets, under confidentiality.
7. International transfers
Our primary database and file storage are hosted in Ireland. We are established in the United States, and some processors operate outside the EEA and UK.
Where personal data leaves the EEA or UK, we rely on the European Commission's Standard Contractual Clauses and, for the UK, the International Data Transfer Addendum, together with additional safeguards where a transfer risk assessment indicates they are needed. You may request a copy of the relevant transfer mechanism at [email protected].
8. Your rights
Subject to local law, you may request access, correction, erasure, restriction, portability, and you may object to processing based on legitimate interests. You may withdraw consent at any time without affecting processing already carried out.
Deleting your account. You can delete your account from within the app, under Settings. Deletion removes your profile and account data. We retain what law requires us to keep — invoices, tax records, and AML records — for the periods in Section 9, and we retain anything needed to establish, exercise, or defend a legal claim.
To exercise a right, contact [email protected]. We respond within one month, extendable by two further months for complex requests. We may need to verify your identity first.
You may complain to your local supervisory authority. In Ireland that is the Data Protection Commission; in the UK, the Information Commissioner's Office.
8.1 If you are in California
We collect the categories described in Section 2, including sensitive personal information: government identifiers, financial account details, and biometric information.
We do not sell personal information and do not share it for cross-context behavioural advertising. We use sensitive personal information only for the purposes permitted by the CPRA — providing the service, verifying identity, preventing fraud, and complying with law — and not to infer characteristics about you.
You have the rights to know, delete, correct, opt out of sale or sharing, and limit the use of sensitive personal information, and we will not discriminate against you for exercising them. An authorised agent may submit a request with written permission and verification.
8.2 Our representatives
We are in the process of appointing representatives in the European Union and the United Kingdom under Article 27 of the EU and UK GDPR. Until they are appointed and named here, please direct any matter you would raise with a representative to [email protected], and we will respond as if it had been raised with them.
9. How long we keep it
| Data | Retention |
|---|---|
| Account and profile | While your account is active, then 30 days |
| Identity and AML records | 5 years after the relationship ends, as AML law requires |
| Biometric images and templates | Per remotetalent.io/legal/biometric-policy, then destroyed |
| Contracts, invoices, tax records | 7 years from the end of the relevant tax year |
| Audit and change history | 7 years |
| Consent records | 5 years after the consent is superseded or withdrawn |
| Access requests not converted to accounts | 12 months |
| Support correspondence | 3 years |
Where periods conflict, the longest applicable legal requirement governs.
10. Security
Data is encrypted in transit and at rest. Payout account numbers, IBANs, routing numbers, and wallet addresses are additionally encrypted at the field level. Access is restricted on a need-to-know basis and database access is governed by row-level security. We keep audit records of changes to key data.
No system is perfectly secure. Where a breach is likely to result in a risk to your rights, we will notify you and the relevant supervisory authority as the law requires.
11. Children
The Platform is for business use by people aged 18 and over. We do not knowingly collect data from children. If you believe a child has provided us data, contact [email protected] and we will delete it.
12. Changes
We will post any updated version here with a new effective date. Where a change is material we will notify you in advance through the Platform or by email.
13. Contact
[email protected] · Remote Talent LLC, 924 N Magnolia Ave, Suite 202 Unit #5333, Orlando, FL 32803, USA
This is version 1.0 of the Privacy Policy, effective 2026-08-18. Published from the same source the Remote Talent iOS app reads, so the text here and the text you accept in the app are identical. Superseded versions are retained because acceptance records reference them.
Questions about this document: [email protected]