1. Who is responsible and how to contact us
welance/directory is operated within the Welance network by welance Ventures GmbH (Germany) and welance Ventures Italia SRL (Italy), whose complete corporate details appear in the Imprint. The entities’ final roles as controller, joint controllers or processors for each operation must be confirmed in the controller arrangement before public launch.
Privacy and rights requests: [email protected], with “Directory privacy” in the subject. If a data protection officer or dedicated privacy address is appointed, this notice will be updated before launch.
2. Who this notice covers
- Visitors and people who create, paste, upload or share a brief.
- Clients and representatives of legal entities publishing opportunities.
- Independent professionals, team contacts, team members and people invited to a roster, including people whose details are supplied by a colleague.
- People applying, inviting, voting, arranging or attending a handshake call, contacting support or receiving operational email.
3. Data we process and where it comes from
- Identity and business data: name, professional role, email, telephone, VAT ID, entity/team VAT, verification result, language, location, availability, experience and team relationships.
- Brief and profile content: project text, title, budget, timeline, constraints, success measures, answers, links, files, portfolio/shipped-work material, disciplines and any personal data included in them.
- Marketplace activity: publication and moderation state, score and rule verdicts, matches, applications, direct invitations, votes, messages or notes, acceptance, booking slots, attendance, cancellation, no-show, refund/credit and reveal state.
- Payment data: checkout/payment identifiers, status, amount and limited billing metadata. Full card details are handled by the payment provider and are not stored by Welance.
- Technical and security data: IP address, timestamps, route/action, session and event identifiers, locale, browser/device information available in ordinary server logs, abuse signals and delivery logs. Email-recipient logs are intended to be masked.
- Device-only data: unfinished briefs, wizard history, bookmarks, VAT history, accent/language and UI state may be stored in localStorage or essential cookies in your browser. It leaves the device only when the corresponding feature sends it.
- Sources: you; a client, team contact or colleague who names/invites you; existing Welance working relationships; VIES or other official VAT sources; public professional material you ask us to review; and records generated by use of the service.
4. Why we process data and our legal bases
- Pre-contract and contract (GDPR Art. 6(1)(b)): create and improve a brief, register an entity or team, authenticate by magic link, publish, match, apply, invite, schedule a handshake, take payment and provide support.
- Legitimate interests (Art. 6(1)(f)): human vetting, quality and fraud checks, abuse prevention, limited operational analytics, service security, deduplication by VAT, dispute handling, protection of anonymity before reveal, and improving routing. We balance these interests against the affected person’s rights.
- Legal obligation (Art. 6(1)(c)): accounting, tax, sanctions/fraud duties, responding to lawful requests and preserving evidence where legally required.
- Consent (Art. 6(1)(a)) only where expressly requested, such as optional marketing or a future non-essential cookie. Service messages and processing necessary to perform the requested marketplace action do not rely on marketing consent.
- Data about a roster member supplied by another person is processed to verify the invitation and operate the requested team relationship; we contact the member and provide this notice at first communication.
5. AI scoring, suggestions and matching
Brief text and relevant answers are sent to Welance’s Perfect Brief service for rule-based and model-assisted scoring and suggestions. The service may route model requests through OpenRouter and a selected model provider. Request metadata may also be processed. Do not include secrets, credentials, special-category data, patient data or unnecessary personal data in a brief.
AI output may influence the score, questions, extracted filters and suggested teams, but publication is gated by disclosed rules and may receive human review. Matching and scoring are decision-support tools; they do not make a solely automated decision producing legal or similarly significant effects. A user can edit the extracted filters, challenge a result, improve the brief or request human review.
Welance does not authorize model training on submitted brief content. Provider retention, region and training controls must be contractually and technically verified before launch; the current OpenRouter account settings and selected downstream provider must be recorded in the processor register.
6. Visibility, anonymity and identity reveal
- Drafts kept only in the browser are not published. A submitted brief may be moderated, formatted, translated, scored, anonymised and shown to eligible matched teams.
- Before mutual acceptance, each side receives a deliberately limited view. Team names, individual identities and client contact details may be withheld or replaced by codenames, composition data or initials.
- After the product’s reveal condition is met, relevant identity and contact data is disclosed to the connected client/team so they can hold the handshake and decide whether to continue independently.
- Public profiles and published briefs can be accessed by other visitors and may be indexed unless explicitly technically excluded. The publication screen must accurately state the chosen visibility.
7. Recipients and service providers
- Matched clients, teams and invited roster members, according to the staged visibility rules.
- Authorized Welance personnel and vetted contractors who operate, review, support, secure or moderate the Directory.
- Directus/CMS and infrastructure or hosting providers used for application data and files.
- The Perfect Brief scoring service, OpenRouter and the selected model provider for requested AI processing.
- Stripe and its banking/payment partners for checkout, authorisation, capture, refund, credit and fraud prevention when live payments are enabled.
- Email/notification delivery, error monitoring and security providers actually enabled in the relevant environment.
- Professional advisers, auditors, insurers, authorities or transaction counterparties where necessary and legally permitted.
8. International transfers
Some providers, particularly AI, payment, monitoring or infrastructure providers, may process data outside the EEA. Welance must use an adequacy decision or appropriate safeguards such as the European Commission Standard Contractual Clauses, with transfer-risk and supplementary-measure assessment where required. The final provider/region/SCC matrix must be attached to the internal processing register before launch and is available on request.
9. Retention and deletion criteria
- Unsubmitted browser drafts remain until you clear them, start over, clear site data or the feature removes them; Welance cannot delete data that never left your device.
- Rejected, abandoned or unverified submissions: proposed default 90 days after last activity, unless needed for security or a dispute.
- Published briefs, team profiles, applications and interaction history: while active, then proposed 24 months after closure/last activity to preserve continuity and resolve disputes.
- Authentication, security and operational event logs: proposed 90 days; shorter where feasible, longer only for a documented incident.
- Payment, invoice and tax records: the statutory period applicable to the responsible Welance entity, commonly up to 10 years.
- Consent/terms evidence and legal claims: version, timestamp and necessary evidence for the applicable limitation period.
- Backups are deleted on their normal rotation. Data may be retained longer when required by law, legal hold, fraud prevention or an active dispute. Counsel and engineering must confirm these proposed periods before launch.
10. Cookies and storage on your device
The Directory uses essential session, language and security cookies and local browser storage for drafts, history, bookmarks and interface preferences. Essential storage supports a requested service and is not used for behavioural advertising. If analytics, advertising or other non-essential technologies are enabled, they require a separate, equally easy accept/reject choice and a cookie inventory; this notice alone is not consent.
11. Your choices and GDPR rights
- Request access, correction, deletion, restriction or portability where applicable.
- Object to processing based on legitimate interests, including direct marketing; marketing objections are free and take effect without undue delay.
- Withdraw consent at any time without affecting earlier lawful processing.
- Ask for human intervention and contest an AI-assisted score or match.
- Complain to the competent supervisory authority, including the authority where you live, work or believe an infringement occurred. German users may contact the competent German state authority; Italian users may contact the Garante per la protezione dei dati personali.
- We may need to verify identity and authority over the relevant VAT/entity before fulfilling a request. Normally we respond within one month, subject to GDPR extensions.
12. Security, children and sensitive information
We use access controls, server-side credentials, signed expiring sessions, data minimisation, staged identity reveal and operational monitoring. No online service is risk-free. Report suspected compromise promptly.
The Directory is a business service for adults authorized to represent a legal entity; it is not directed to children. Do not submit special-category data, criminal-offence data, health records, credentials, source-code secrets or third-party confidential material unless Welance has expressly agreed a suitable protected process.
13. Changes and questions
We will date each version. Material changes affecting existing processing will be communicated through the service or the registered email where appropriate; they will not be treated as retroactive consent. Questions and rights requests may be sent to [email protected].