Template. This document must be reviewed and completed by counsel before it is relied on. Questions: hello@humxn.io
01Scope of this policy
This Privacy Policy explains how HUMXN handles personal data collected through our website at humxn.io (the "Site"), including when you browse the Site, submit a dataset request, apply to join our expert network, or contact us.
Personal data processed inside the marketplace and registry on behalf of business customers is covered by the relevant member agreement and, where applicable, our Data Processing Addendum. Where we process personal data contained in datasets as a processor for a customer, that customer's privacy notice applies.
We do not sell personal data, and we do not use information submitted through the Site's forms to train AI models.
02Who is responsible for your data
The controller of personal data described in this policy is HUMXN Data Labs, [Registered address], company number [Company number]. You can contact us about privacy at privacy@humxn.io.
EU representative (if required under Article 27 GDPR): [EU representative name and address]. UK representative (if required under Article 27 UK GDPR): [UK representative name and address]. Data protection officer (if appointed): [DPO name and contact].
03Information you provide
When you submit a form on the Site we store the information you enter, together with context that helps us respond and understand which pages are useful:
- Contact details: name, work email address, company or organization, and role where provided.
- The content of your message, dataset request or expert application, including any professional background, areas of expertise, links or rates you choose to share.
- Submission context: the page you submitted from, the referring website, and any campaign tags (such as UTM parameters) in the link you followed.
- Correspondence: emails and messages you exchange with us after submitting a form.
04Information collected when you visit
We measure visits to the Site without cookies. When you load a page, our own server records the page viewed, the time, the referring site and basic device information derived from the browser's user agent.
Instead of storing your IP address, we compute a visitor identifier by hashing the IP address and user agent together with a secret value that changes every day. The identifier lets us count unique visits within a day, but because the secret rotates daily, it cannot be used to follow you across days, and the raw IP address is not stored.
At the time of the visit, our server also looks up the country and the name of the network the visit came from (for example, a company or an internet service provider) using a network-ownership database hosted on our own infrastructure. This lookup does not send your IP address to a third party.
We apply rate limiting to forms and endpoints to protect the Site from abuse. Rate-limit records are short-lived and deleted within about a day.
05Optional Google Analytics
If enabled, we use Google Analytics, provided by Google LLC and Google Ireland Limited, to measure aggregate use of the Site. Google Analytics may set cookies and process your IP address and device information. It is never loaded on private pages such as the members' dashboard.
Where required by law, Google Analytics is only loaded after you consent, and you can withdraw consent at any time. See our Cookie Policy for details and controls.
06How we use your data and our legal bases
If you are in the European Economic Area or the United Kingdom, we rely on the following legal bases under Article 6 GDPR and UK GDPR:
- Responding to inquiries and dataset requests, and taking steps at your request before entering into a contract: performance of a contract or pre-contractual steps (Art. 6(1)(b)), or our legitimate interest in answering business inquiries (Art. 6(1)(f)).
- Assessing expert applications and onboarding approved experts: pre-contractual steps (Art. 6(1)(b)).
- Following up about an inquiry and sending relevant business communications to business contacts: legitimate interests (Art. 6(1)(f)), or consent where the law requires it (Art. 6(1)(a)). You can opt out at any time.
- Cookieless visit measurement and understanding which content is useful: legitimate interests in operating and improving the Site (Art. 6(1)(f)).
- Google Analytics, where enabled: consent (Art. 6(1)(a)) where required by law.
- Protecting the Site against spam, fraud and abuse, and keeping it secure: legitimate interests (Art. 6(1)(f)).
- Complying with legal obligations, such as tax, accounting and responding to lawful requests: legal obligation (Art. 6(1)(c)).
- Establishing, exercising or defending legal claims: legitimate interests (Art. 6(1)(f)).
07Automated decision-making
We do not make decisions that produce legal or similarly significant effects about you based solely on automated processing. Expert applications are reviewed by people. We may use software, including AI-assisted tools, to help organize and summarize inquiries, but a person makes the decision.
08How long we keep data
We keep personal data only for as long as needed for the purposes described in this policy:
- Visit records (hashed daily identifiers, pages viewed, country and network name): deleted automatically after a fixed period, currently [180] days.
- Rate-limit records: deleted within about 24 hours.
- Inquiries and dataset requests: kept for as long as needed to handle them and manage our relationship with you, and then for up to [24 months] after the last contact unless a longer period is required by law.
- Expert applications that do not proceed: kept for up to [12 months] so we can reconsider them for future briefs, unless you ask us to delete them sooner.
- Records we must keep for legal, tax or accounting reasons: for the period required by law, typically [6–7 years].
10International transfers
Our primary hosting infrastructure is located in [Germany / the EU — confirm]. Some service providers may process personal data in other countries, including the United States.
Where personal data originating in the EEA, UK or Switzerland is transferred to a country that has not been found to provide an adequate level of protection, we rely on the European Commission's Standard Contractual Clauses, the UK International Data Transfer Addendum, adequacy decisions such as the EU-US Data Privacy Framework where the recipient is certified, or another lawful transfer mechanism, together with supplementary measures where appropriate. You can request a copy of the relevant safeguards by contacting us.
11How we protect data
We use technical and organizational measures designed to protect personal data, including encryption in transit, access controls based on least privilege, hashed storage of visitor identifiers, rate limiting and monitored backups. No method of transmission or storage is completely secure, and we cannot guarantee absolute security. More detail is available on our Security page.
12Your rights in the EEA and UK
If GDPR or UK GDPR applies to you, you have the following rights, subject to conditions and exceptions set out in the law:
- Access: to obtain a copy of the personal data we hold about you.
- Rectification: to have inaccurate data corrected and incomplete data completed.
- Erasure: to have your data deleted in certain circumstances.
- Restriction: to limit how we use your data in certain circumstances.
- Portability: to receive data you provided to us in a structured, machine-readable format, where processing is based on consent or contract and carried out by automated means.
- Objection: to object at any time to processing based on legitimate interests, and absolutely to direct marketing.
- Withdrawal of consent: where we rely on consent, to withdraw it at any time without affecting earlier processing.
- Complaint: to lodge a complaint with your local data protection supervisory authority, or in the UK with the Information Commissioner's Office. We would appreciate the chance to address your concern first.
13Your rights in California
If you are a California resident, the California Consumer Privacy Act, as amended by the California Privacy Rights Act (together, CCPA), gives you rights regarding your personal information, to the extent the CCPA applies to us.
In the preceding 12 months we have collected the following categories of personal information described in this policy: identifiers (such as name and email address), professional or employment-related information (such as company, role and expertise), internet or other electronic network activity (such as pages viewed and referring site), and approximate geolocation (country). We collect it from you directly and from your device, for the business purposes described above, and disclose it to service providers for those purposes.
We do not sell personal information, and we do not share it for cross-context behavioral advertising. We do not knowingly sell or share the personal information of consumers under 16. We do not use or disclose sensitive personal information for purposes that would give rise to a right to limit.
You have the right to know what personal information we collect, use and disclose; to request deletion; to request correction of inaccurate information; and not to be discriminated against for exercising these rights. You may use an authorized agent to make a request on your behalf. We will verify requests by matching information you provide against information we hold, and may ask the agent for proof of authorization.
14Children
The Site and our services are intended for businesses and professionals. They are not directed to children, and we do not knowingly collect personal data from anyone under 18. If you believe a child has provided us with personal data, contact us and we will delete it.
15Changes to this policy
We may update this policy from time to time. The date at the top of the page shows when it last changed. If we make material changes, we will take reasonable steps to let you know, such as a notice on the Site.
16Exercising your rights and contact
To make a request, email privacy@humxn.io and tell us which right you want to exercise. We will respond within the period required by applicable law, normally one month under GDPR and 45 days under the CCPA, and may extend that period where the law permits. We may need to verify your identity before acting on a request.
Privacy questions and requests: privacy@humxn.io. General inquiries: hello@humxn.io. Postal address: HUMXN Data Labs, [Registered address].

