Legal
Privacy Policy
Last updated: 14 September 2026
This Privacy Policy explains how Unidia LLC collects, uses, stores, discloses and otherwise processes personal information in connection with YOU™.
YOU™ is a registration, documentation and verification service for unique artistic, handmade and collectible Works.
This Privacy Policy applies to:
- YOU™ accounts;
- Work submissions;
- registration and verification services;
- personalised digital Certificates;
- qualified electronic timestamping;
- QR and NFC services;
- ownership and provenance records;
- support communications;
- purchases and transactions;
- public Registry and Verification Pages; and
- use of the YOU™ website and related services.
For the purposes of applicable privacy and data-protection law, references to “personal data” or “personal information” include information relating to an identified or identifiable individual where the relevant law applies.
1. Who is responsible for your data
The controller responsible for YOU™ is:
Unidia LLC EIN 30-1438835 131 Continental Dr Newark, Delaware 19713 New Castle County United States
Email: [email protected]
Where Unidia LLC is subject to the EU GDPR or UK GDPR, Unidia acts as the controller for the processing activities described in this Policy unless otherwise stated.
Certain third-party providers, such as payment processors or qualified trust service providers, may act as independent controllers or processors depending on the nature of the service they provide.
2. EU and UK representatives
Unidia LLC is established in the United States.
Where Article 27 of the EU GDPR requires Unidia to appoint a representative in the European Union or European Economic Area, the representative’s verified contact details will be published in this Policy and on the appropriate legal-information page.
Where the UK GDPR requires appointment of a representative in the United Kingdom, verified representative details will similarly be published.
We will not identify a person or company as a statutory privacy representative until a valid appointment has actually been completed.
Appointment of a representative does not remove Unidia LLC’s own responsibility for compliance with applicable data-protection law.
3. Data Protection Officer
Unidia LLC has not designated a Data Protection Officer unless and until applicable law requires such designation or Unidia voluntarily makes one.
If a Data Protection Officer is appointed, the relevant contact details will be published in this Policy.
Privacy requests may currently be sent to:
4. Personal data we collect
The categories of personal data collected depend on how you use YOU™.
We may collect the following categories.
4.1 Identity and profile data
This may include:
- full name;
- public creator name;
- artist name;
- studio or business name;
- username;
- country;
- account type;
- profile information;
- professional biography; and
- other information you choose to include in your account or public creator profile.
5. Contact information
We may collect:
- email address;
- billing contact details;
- postal address where required for billing or delivery;
- telephone number where required for a particular service; and
- communication preferences.
Not all of this information is publicly displayed.
6. Account and authentication data
We may process:
- account identifiers;
- account creation date;
- account status;
- login history;
- authentication events;
- password-reset events;
- security events;
- session information; and
- records relevant to preventing unauthorised access.
Passwords should be stored only in protected form appropriate to the authentication system and are not intended to be visible to YOU™ staff.
7. Work and registration data
When a Work is submitted, we may process information including:
- Work title;
- Work type;
- category;
- declared creation date;
- materials;
- dimensions;
- description;
- creator attribution;
- photographs;
- video;
- supporting evidence;
- sketches or source material where submitted;
- relevant correspondence;
- Registration ID;
- Registration Manifest;
- cryptographic hashes;
- registration status;
- review information;
- Certificate information;
- qualified timestamp information;
- QR information;
- NFC information;
- provenance information; and
- Ownership Transfer history.
The information required depends on the relevant YOU™ service and Work category.
8. Photographs and video
Photographs and video submitted for registration may contain personal data.
For example, a photograph may incidentally show:
- a person;
- a hand;
- a studio;
- a home interior;
- a location;
- a document; or
- other identifying information.
Users should avoid including unnecessary personal information in Work photographs and videos.
YOU™ does not require users to submit biometric data for the ordinary registration of a Work.
The term cryptographic fingerprint or hash used in technical descriptions refers to a mathematical data fingerprint and does not mean a human biometric fingerprint.
9. Supporting evidence
Users may choose or be required to submit supporting materials relevant to registration.
These may include:
- creation photographs;
- process photographs;
- invoices;
- correspondence;
- sketches;
- documentation;
- ownership evidence;
- competition or exhibition information; and
- other supporting records.
Users should submit only information reasonably necessary for the relevant registration or dispute.
Where supporting materials contain personal information about another person, the user should ensure that they have an appropriate legal basis or authority to provide it.
10. Transaction and billing data
When you purchase a service, we may process information including:
- order number;
- customer identity;
- purchased service;
- price;
- currency;
- applicable tax information;
- billing address;
- payment status;
- refund or payment-dispute information;
- invoice information; and
- transaction timestamps.
Full payment-card details are normally processed directly by the relevant payment provider and are not intended to be stored by YOU™.
Payment providers may process your information under their own privacy notices.
11. Ownership and provenance information
Where YOU™ provides Ownership Transfer or provenance functionality, we may process:
- identity of transfer participants;
- Work Registration ID;
- transfer date;
- transfer status;
- current ownership status;
- previous recorded ownership events;
- acceptance records; and
- related evidence where necessary.
Transfer records do not necessarily include purchase price or other commercial terms unless the relevant service expressly requires that information.
12. QR and NFC data
Where QR or NFC services are used, we may process:
- tag identifier;
- linked Registration ID;
- activation status;
- replacement events;
- scan events where technically collected;
- approximate technical information relating to a scan;
- tag status; and
- security events.
We do not intend to use NFC or QR functionality to continuously track the physical location of users.
If location or additional scan analytics are introduced in the future, this Policy and any required consent mechanism will be updated before that processing begins.
13. Device, technical and usage data
When you use the website or service, we may receive technical information such as:
- IP address;
- browser type;
- operating system;
- device information;
- session identifiers;
- login timestamps;
- pages or functions accessed;
- error logs;
- security events;
- referring page;
- approximate location derived from IP address; and
- cookie or similar identifiers.
We use this information only for the purposes described in this Policy and subject to applicable cookie and privacy requirements.
14. Communications and support data
When you contact us, we may process:
- your name;
- email address;
- message contents;
- support history;
- attachments;
- complaint information;
- legal notices;
- copyright claims;
- dispute correspondence; and
- information required to resolve the matter.
Do not send passwords or complete payment-card information through email or support forms.
15. Information received from other people
In some circumstances, we may receive information about you from another person rather than directly from you.
For example:
- an owner may initiate an Ownership Transfer;
- a gallery or representative may submit a Work on behalf of a creator;
- a complainant may identify a creator in an intellectual-property complaint;
- a buyer may identify a previous owner;
- a legal representative may contact us on your behalf.
Where applicable data-protection law requires us to provide notice concerning information obtained indirectly, we will do so subject to lawful exceptions.
16. Why we process personal data
We process personal data only where we have an appropriate purpose and legal basis.
Depending on the circumstances, the legal basis may include:
- performance of a contract;
- steps requested before entering into a contract;
- compliance with a legal obligation;
- legitimate interests;
- consent; or
- another basis permitted by applicable law.
17. Contractual processing
Where necessary to provide the YOU™ service requested by you, we may process personal data to:
- create and administer your account;
- accept a Work submission;
- conduct the Review Process;
- communicate concerning a registration;
- create a Registration Record;
- generate a Registration Manifest;
- obtain or process timestamps;
- generate a personalised digital Certificate;
- provide Verification Pages;
- provide QR or NFC services;
- process Ownership Transfers;
- provide provenance functionality;
- process payments;
- provide customer support; and
- administer purchased services.
For EU/EEA and UK users, this processing may rely on the contractual legal basis where the processing is objectively necessary to provide the requested service.
18. Public Registry as part of the requested service
A central function of YOU™ is the ability to create a verifiable record associated with a Work.
Where a user requests a service that includes a public Registry or public Verification Page, publication of specified registration information forms part of that requested service.
Depending on the service, the public record may include:
- public creator or artist name;
- Work title;
- Work category;
- selected Work photographs;
- materials;
- dimensions;
- Registration ID;
- Certificate status;
- registration status;
- registration date;
- timestamp information;
- selected provenance information; and
- other verification information specifically identified as public.
Users will be informed which information is intended to become public before or during registration.
Private account contact information is not made public merely because a Work has a public Verification Page.
19. Legitimate interests
Where permitted by applicable law, we may rely on legitimate interests for purposes including:
- protecting YOU™ against fraud;
- maintaining security;
- detecting account misuse;
- preventing duplicate or fraudulent registrations;
- preserving the integrity of Registration Records;
- maintaining an appropriate evidentiary history;
- establishing, exercising or defending legal claims;
- resolving disputes;
- improving service reliability;
- investigating technical problems;
- preventing abuse; and
- protecting users and third parties.
Where EU or UK law applies, we consider whether those interests are outweighed by the interests, rights and freedoms of the affected individuals.
20. Legal obligations
We may process personal data where necessary to comply with legal obligations, including those relating to:
- accounting;
- taxation;
- financial records;
- sanctions;
- fraud prevention;
- legal notices;
- court orders;
- regulatory requests;
- intellectual-property procedures; and
- other obligations imposed by applicable law.
21. Consent
We may rely on consent where consent is the appropriate legal basis.
Examples may include:
- optional marketing communications;
- non-essential cookies;
- certain analytics technologies;
- advertising technologies;
- optional publication not necessary for the requested service; or
- other optional processing.
Where applicable law requires consent, consent must be freely given, specific, informed and unambiguous.
You may withdraw consent at any time.
Withdrawal does not affect processing that was lawful before withdrawal.
22. Special categories of personal data
YOU™ is not designed to collect sensitive or special-category data such as:
- racial or ethnic origin;
- political opinions;
- religious beliefs;
- trade-union membership;
- genetic information;
- biometric data used for unique identification;
- health information; or
- information concerning a person’s sex life or sexual orientation.
Please do not submit such information unless it is genuinely necessary for a specific lawful purpose and you have an appropriate legal basis for doing so.
If such information is incidentally submitted, we may remove, restrict or otherwise handle it as required by applicable law.
23. Qualified Electronic Timestamp processing
Where YOU™ provides Qualified Electronic Timestamp functionality, certain registration data will need to be processed in connection with the qualified trust service.
YOU™ intends, where technically and legally appropriate, to minimise the personal information transmitted to the Qualified Trust Service Provider.
The data submitted may include:
- a cryptographic hash of the final Registration Manifest;
- transaction or request identifiers;
- timestamp request metadata;
- verification data;
- technical information required by the QTSP; and
- other data strictly necessary for provision and validation of the timestamp.
The exact processing depends on the QTSP selected and its technical implementation.
24. QTSP integration status
If no qualified timestamp provider has yet been technically connected to the production service, YOU™ will not state that personal data is currently being transmitted to a QTSP.
Before a QTSP integration is activated, YOU™ will document and, where legally required, disclose:
- the identity or category of the provider;
- the role of the provider;
- data transmitted;
- purposes of transmission;
- applicable legal basis;
- provider location;
- international transfer mechanism where applicable;
- applicable retention;
- relevant security measures; and
- other legally required information.
Original Work photographs will not be transmitted to a QTSP merely because qualified timestamping is required unless such transmission is technically necessary and properly disclosed.
Where timestamping can be performed using a cryptographic hash rather than the underlying content, YOU™ intends to use the more data-minimising approach where reasonably possible.
25. Hashes and personal data
A cryptographic hash is not automatically anonymous merely because the underlying content cannot ordinarily be reconstructed directly from the hash.
Where a hash remains linked or linkable to a person, account, Registration ID or other identifiable information, YOU™ treats it with appropriate protection.
The use of hashing does not by itself remove all obligations under applicable privacy law.
26. Public and private information
YOU™ distinguishes between information intended for public verification and information used internally.
Public information may include
Depending on the selected service:
- public creator name;
- artist or studio name;
- Work title;
- selected photographs;
- description;
- category;
- materials;
- dimensions;
- Registration ID;
- Certificate status;
- registration status;
- registration date;
- timestamp information; and
- selected provenance events.
Information not public by default may include
- email address;
- billing address;
- private telephone number;
- authentication data;
- payment details;
- private supporting evidence;
- internal review notes;
- fraud-prevention information;
- legal correspondence; and
- private account settings.
27. Public information may be copied by third parties
Information intentionally published through a public Registry or Verification Page may be accessible worldwide.
Public information may be:
- indexed by search engines;
- linked from other websites;
- archived;
- photographed or screenshotted;
- copied;
- quoted; or
- stored by third parties.
YOU™ can control information displayed through its own service but cannot guarantee deletion of independent copies lawfully or unlawfully made by third parties.
Users should therefore select a public creator identity and public content they are comfortable displaying internationally.
28. Removal from public view
Where legally and technically appropriate, YOU™ may restrict or remove information from public display without necessarily destroying the underlying Registration Record.
For example, a record may become:
- private;
- restricted;
- disputed;
- suspended;
- revoked; or
- archived.
Removing information from public display is distinct from erasing all underlying data from YOU™ systems.
29. Service providers
We may use service providers to support operation of YOU™.
These may include providers of:
- hosting;
- cloud storage;
- cybersecurity;
- email;
- customer support;
- payments;
- accounting;
- analytics;
- authentication;
- certificate generation;
- PDF generation;
- QR services;
- NFC services;
- shipping;
- qualified trust services;
- backups; and
- technical infrastructure.
Where required, processors act under contractual data-protection obligations.
Some providers may act as independent controllers for specific processing.
30. Other recipients
We may disclose information where necessary and lawful to:
- courts;
- regulators;
- tax authorities;
- law-enforcement authorities;
- competent government authorities;
- lawyers;
- accountants;
- professional advisers;
- insurers;
- payment providers;
- intellectual-property complainants or respondents;
- parties to a legal dispute; and
- parties involved in an Ownership Transfer.
Disclosure will be limited to information reasonably necessary for the relevant purpose where possible.
31. Business transactions
If Unidia LLC or YOU™ undergoes a:
- merger;
- acquisition;
- restructuring;
- financing;
- sale of assets;
- insolvency process; or
- transfer of the YOU™ business,
personal data may be disclosed or transferred as part of that transaction subject to applicable legal requirements.
Any successor will be required to handle personal data consistently with applicable law.
32. We do not currently sell personal information
YOU™ does not currently sell personal information for monetary consideration.
We also do not currently use personal information for cross-context behavioural advertising in a manner that we identify as “sharing” under the California Consumer Privacy Act.
If these practices change, this Policy and any legally required opt-out mechanisms will be updated before or when required by law.
33. Advertising and targeted advertising
YOU™ does not need advertising tracking in order to provide its core registration and certification service.
If YOU™ later introduces:
- personalised advertising;
- cross-site behavioural advertising;
- targeted advertising;
- advertising pixels; or
- comparable tracking technologies,
the relevant privacy and cookie disclosures and consent or opt-out mechanisms will be introduced as required by applicable law.
34. International operation of YOU™
Unidia LLC is based in the United States.
Your information may therefore be processed in the United States and in other countries where YOU™ or its service providers operate.
Different countries may provide different levels of legal protection for personal data.
Where EU, EEA or UK transfer restrictions apply, YOU™ will use a legally permitted mechanism.
35. Transfers from the EU and EEA
Where the EU GDPR applies and personal data is transferred to a country outside the EEA, YOU™ will rely on an appropriate transfer mechanism where required.
Depending on the recipient and circumstances, this may include:
- a European Commission adequacy decision;
- participation of an eligible US recipient in the EU-US Data Privacy Framework;
- Standard Contractual Clauses approved by the European Commission;
- supplementary contractual, organisational or technical safeguards; or
- another transfer mechanism permitted by Chapter V GDPR.
The existence of a US entity alone does not mean that the EU-US Data Privacy Framework automatically applies to that entity.
YOU™ will rely on the Framework only where the relevant recipient actually participates in and is covered by it.
36. Transfers from the United Kingdom
Where UK transfer restrictions apply, YOU™ will use a lawful transfer mechanism where required.
Depending on the circumstances this may include:
- UK adequacy regulations;
- an applicable UK-US adequacy mechanism;
- the UK International Data Transfer Agreement;
- the UK Addendum to EU Standard Contractual Clauses;
- other appropriate safeguards; or
- a lawful exception.
37. Transfer assessments and safeguards
Where required by law, YOU™ or its relevant provider may assess whether additional safeguards are necessary for an international transfer.
Safeguards may include:
- encryption;
- pseudonymisation;
- access restrictions;
- contractual commitments;
- data minimisation;
- security controls; and
- limits on onward transfers.
Information regarding applicable safeguards may be requested through the privacy contact details in this Policy, subject to protection of confidential security information.
38. Retention principles
YOU™ does not retain all personal information for the same period.
Retention depends on:
- why the data was collected;
- whether the account remains active;
- contractual requirements;
- Registry and Certificate integrity;
- fraud-prevention requirements;
- accounting and tax requirements;
- applicable limitation periods;
- disputes;
- intellectual-property claims;
- security requirements; and
- other applicable legal obligations.
We delete, anonymise, restrict or archive information when it is no longer reasonably required, subject to the considerations below.
39. Account data retention
Core account information is generally retained while an account remains active.
After account closure, account information that is no longer necessary may normally be deleted or anonymised within approximately 24 months, unless a longer retention period is reasonably necessary because of:
- an active Registration Record;
- an unresolved transaction;
- a legal dispute;
- fraud or security concerns;
- legal claims; or
- applicable law.
40. Financial and transaction records
Billing, accounting, invoice and transaction records may be retained for the period required by applicable accounting, tax and financial laws.
Depending on the applicable jurisdiction and record type, this may commonly be up to approximately seven years, or another legally required period.
41. Rejected or abandoned submissions
Rejected, incomplete or abandoned Work submissions may normally be retained for up to 12 months after the last relevant activity.
A longer period may apply where necessary for:
- a dispute;
- fraud prevention;
- repeat-abuse detection;
- intellectual-property claims;
- legal proceedings; or
- another lawful reason.
Where possible, unnecessary source materials may be deleted earlier.
42. Private supporting files
Private source photographs, documents, videos and supporting evidence are not necessarily retained for the entire life of a public Certificate.
Where such files are no longer required for:
- verification;
- dispute resolution;
- fraud prevention;
- contractual obligations; or
- legal claims,
YOU™ may delete or reduce the retained material while preserving the minimum information necessary for integrity of the Registration Record.
43. Approved Registration Records and Certificates
YOU™ is designed to provide durable registration and verification records.
Accordingly, certain information associated with an approved registration may need to be retained for a substantially longer period than ordinary account data.
This may include:
- Registration ID;
- Work identity;
- creator attribution;
- essential Work information;
- registration status;
- registration chronology;
- Certificate status;
- cryptographic hashes;
- qualified timestamp evidence;
- material corrections;
- dispute status;
- revocation status;
- Ownership Transfer events; and
- essential audit-history information.
Such information may be retained for as long as necessary to preserve the validity, verification capability and integrity of the Registration Record.
This does not mean that every item of personal information submitted by the user must be kept indefinitely.
YOU™ seeks to separate durable evidentiary information from personal data that is no longer necessary.
44. Why some Registry information may need long-term retention
If every historical record could be completely rewritten or erased whenever an account was closed, it could undermine the reliability of:
- existing Certificates;
- Ownership Transfers;
- provenance history;
- fraud prevention;
- disputed registrations; and
- verification of previously issued records.
YOU™ may therefore retain a limited archival record where necessary and lawful to preserve those functions.
The scope of retained information should remain proportionate to that purpose.
45. Support communications
Routine support communications may normally be retained for up to three years after resolution.
Communications relating to:
- contracts;
- payments;
- legal claims;
- copyright complaints;
- fraud;
- security incidents; or
- Registration Record integrity
may be retained for a longer period where reasonably necessary.
46. Security logs
Security and technical logs may normally be retained for up to 24 months.
Relevant logs may be retained longer where necessary for:
- investigation of an incident;
- fraud prevention;
- legal claims;
- cybersecurity analysis; or
- regulatory obligations.
47. Backups
Personal data may remain temporarily in encrypted or protected backup systems after deletion from active systems.
Backups are removed or overwritten according to normal secure backup rotation procedures.
Data retained solely in backup copies is not ordinarily restored for normal operational use unless required for disaster recovery, security or another legitimate purpose.
48. Your privacy rights
Depending on the law applicable to you, you may have the right to:
- obtain information about our processing;
- request access to your personal data;
- request correction of inaccurate data;
- request deletion;
- request restriction of processing;
- object to certain processing;
- receive portable data;
- withdraw consent;
- object to direct marketing;
- complain to a supervisory authority; and
- exercise other statutory privacy rights.
Not all rights apply in every circumstance.
49. Right of access
Where applicable, you may request confirmation whether we process your personal data and obtain access to relevant personal data and legally required information concerning that processing.
We may request reasonable information necessary to verify your identity before responding.
Access rights must not adversely affect the rights and freedoms of other people.
50. Correction
You may request correction of inaccurate personal data.
Where information forms part of a historical evidentiary record, correction may be implemented through a transparent amendment or additional audit event rather than silent deletion of the original historical event.
This distinction helps preserve both accuracy and record integrity.
51. Erasure
Where applicable, you may request deletion of personal data.
The right to erasure is not absolute.
We may retain information where continued processing is lawfully necessary, for example for:
- compliance with a legal obligation;
- establishment, exercise or defence of legal claims;
- fraud prevention;
- contractual obligations;
- protection of rights of other people; or
- another lawful basis.
Where complete deletion is not legally or technically appropriate, we may consider measures such as:
- removing information from public display;
- restricting processing;
- pseudonymisation;
- deleting unnecessary supporting material; or
- retaining only a minimal archival Registry record.
52. Public Registry and erasure requests
A request to close an account or delete ordinary account data does not automatically require destruction of every historical Registration Record.
Where a Registration Record has already generated:
- a Certificate;
- a qualified timestamp;
- an Ownership Transfer;
- provenance history; or
- another integrity-dependent record,
YOU™ will assess which information can be deleted and which limited information remains reasonably necessary.
The result may therefore be that:
- the account is deleted;
- contact details are deleted;
- private files are deleted;
- the public record is restricted or anonymised;
while a limited integrity record remains.
53. Restriction and objection
Where applicable, you may request restriction of particular processing or object to processing based on legitimate interests.
We will assess the request in accordance with applicable law.
An objection does not automatically require destruction of a Registration Record where overriding lawful grounds justify continued processing.
54. Data portability
Where legally applicable, you may request personal data you provided to us in a structured, commonly used and machine-readable format where the statutory requirements for portability are satisfied.
Portability does not require YOU™ to disclose:
- proprietary algorithms;
- internal security data;
- information concerning other individuals; or
- information outside the legal scope of the portability right.
55. Withdrawal of consent
Where processing is based on consent, you may withdraw consent at any time.
Withdrawal does not affect the lawfulness of processing performed before withdrawal.
If particular optional functionality depends on consent, withdrawing consent may mean that functionality can no longer be provided.
56. Marketing communications
Where required by law, promotional email communications will be sent only on an appropriate legal basis.
You may unsubscribe from marketing communications using:
- the unsubscribe function in the message; or
- the privacy/contact channel provided by YOU™.
Service communications concerning your account, purchases, Certificates, security or legal notices are not treated as optional marketing merely because they are sent by email.
57. Supervisory authority complaints
If EU or EEA data-protection law applies to you, you may have the right to lodge a complaint with a competent data-protection supervisory authority.
If UK data-protection law applies, you may have the right to lodge a complaint with the UK Information Commissioner’s Office.
We encourage users to contact us first where appropriate so that we can attempt to address the issue, but doing so does not remove a statutory right to complain directly to a competent authority.
58. Privacy requests
Privacy requests may be submitted to:
Please describe the request sufficiently for us to understand what you are asking.
We may request reasonable information to verify:
- your identity;
- your authority;
- the relevant account;
- the relevant Registration Record; or
- the scope of your request.
Do not send passwords or complete payment-card details.
59. Authorised representatives
Where applicable law allows another person to submit a privacy request on your behalf, we may require reasonable evidence that the representative has valid authority.
We may also verify your identity directly where permitted.
60. United States privacy rights
Residents of certain US states may have additional privacy rights where the relevant state law applies to Unidia LLC and the particular processing activity.
Depending on the applicable law, these rights may include:
- access or confirmation;
- deletion;
- correction;
- portability;
- opt-out of sale;
- opt-out of targeted advertising;
- opt-out of qualifying profiling;
- limitation of certain sensitive-data uses; and
- appeal of a privacy-request decision.
These rights vary by state and apply only where the relevant statutory requirements are satisfied.
61. California residents
Where the California Consumer Privacy Act, as amended, applies to Unidia LLC and a particular California consumer, applicable rights may include:
- the right to know;
- the right to access;
- the right to delete;
- the right to correct;
- the right to opt out of sale;
- the right to opt out of sharing for cross-context behavioural advertising;
- rights concerning certain sensitive personal information; and
- the right not to receive unlawful discriminatory treatment for exercising statutory privacy rights.
The inclusion of this section does not constitute a statement that Unidia LLC necessarily meets every statutory threshold for application of the CCPA in every period.
Where the CCPA applies, YOU™ will provide and honour the mechanisms required by that law.
62. Global Privacy Control and opt-out signals
YOU™ does not currently sell personal information or share it for cross-context behavioural advertising as described above.
If YOU™ later engages in processing for which applicable US law requires recognition of qualifying opt-out preference signals, such signals will be handled in accordance with applicable law.
This may include recognised mechanisms such as Global Privacy Control where legally required.
63. Non-discrimination
Where applicable US privacy law provides such protection, YOU™ will not unlawfully discriminate against a person because they exercised a statutory privacy right.
This does not prevent differences reasonably related to the value or functionality of a requested service where permitted by law.
64. Children and minors
YOU™ is not intended to provide independent contractual accounts to children under 16 without appropriate legal authorisation.
We do not knowingly seek to collect personal information directly from children for ordinary YOU™ registration services without legally valid involvement of a parent, guardian or other authorised person where required.
If you believe a child has provided personal information improperly, contact:
Age thresholds and consent requirements may differ by jurisdiction.
65. Cookies and similar technologies
YOU™ may use cookies and similar technologies for different purposes.
These may include:
Strictly necessary technologies
Used for:
- login;
- account security;
- fraud prevention;
- shopping-cart functionality;
- checkout;
- session management;
- user-requested preferences; and
- essential website operation.
Where permitted by law, these may be used without optional consent because they are necessary for the requested service.
Analytics and other optional technologies
Where YOU™ uses non-essential analytics, advertising or similar tracking technologies, they will be subject to any consent or opt-out requirement imposed by applicable law.
Additional information is provided in the Cookie Policy.
66. Cookie consent for EU/EEA and UK users
Where applicable European or UK rules require consent before storing or accessing non-essential technologies on a user’s device, YOU™ will request that consent before activating those technologies.
Rejecting optional cookies should not prevent access to the core YOU™ service where those cookies are not necessary to provide it.
Users should be able to change applicable cookie preferences through the relevant consent controls.
67. Security
YOU™ applies technical, organisational and administrative measures designed to protect personal data against:
- unauthorised access;
- unlawful disclosure;
- accidental loss;
- destruction;
- alteration;
- misuse; and
- other inappropriate processing.
Measures may include, where appropriate:
- access controls;
- role-based permissions;
- authentication controls;
- encryption in transit;
- protected storage;
- backups;
- logging;
- monitoring;
- software maintenance;
- vulnerability management; and
- separation of public and private information.
68. No security guarantee
No internet-connected information system can guarantee absolute security.
YOU™ therefore cannot guarantee that a security incident will never occur.
Users are responsible for:
- protecting their login credentials;
- using secure passwords;
- maintaining control of their email account; and
- notifying YOU™ promptly of suspected account compromise.
69. Security incidents
Where a personal-data breach occurs, YOU™ will investigate and take appropriate steps.
Where applicable law requires notification to a supervisory authority or affected individuals, notification will be made in accordance with the relevant legal requirements.
70. Automated tools and fraud detection
YOU™ may use automated or semi-automated tools to assist with:
- duplicate detection;
- security monitoring;
- unusual account activity;
- fraud detection;
- image or data consistency checks;
- scan anomalies; and
- technical risk detection.
Such tools may generate flags for further review.
71. Automated decision-making
YOU™ does not intend to make decisions based solely on automated processing that produce legal effects or similarly significant effects for an individual unless:
- applicable law permits the processing; and
- all required safeguards are implemented.
Where applicable law creates rights relating to solely automated decision-making, YOU™ will comply with those requirements.
Routine security blocking, spam detection or technical risk controls may be automated where legally permitted.
72. Human review
Material registration, moderation or dispute decisions may involve human review where appropriate.
An automated flag does not necessarily mean that a Work or account has been finally rejected.
Where an appeal or reconsideration procedure is required by law or provided by YOU™, information about that procedure will be made available.
73. Data minimisation
YOU™ aims to collect only data reasonably relevant to:
- registration;
- verification;
- certification;
- ownership;
- provenance;
- security;
- contractual performance; and
- legal compliance.
Users should avoid providing unnecessary personal information in:
- Work descriptions;
- photographs;
- videos;
- supporting documents; or
- support messages.
74. Accuracy
Users are responsible for providing materially accurate information.
YOU™ may allow users to correct or update information where appropriate.
Where information is part of an evidentiary audit trail, a correction may be recorded as a new event instead of silently overwriting the historical record.
75. Changes in processing purposes
If we intend to use personal data for a materially different purpose from the purpose for which it was originally collected, we will assess whether the new processing is lawful.
Where applicable law requires additional notice or consent before that processing, we will provide it.
76. Changes to this Privacy Policy
We may update this Privacy Policy where necessary because of:
- legal changes;
- regulatory guidance;
- new YOU™ functionality;
- new service providers;
- qualified timestamp integration;
- privacy practices;
- security changes; or
- changes to the business.
The latest update date will be displayed at the top of the Policy.
Where a change is material, we may provide additional notice through:
- the website;
- the user account;
- email; or
- another appropriate communication channel.
77. Policies related to this Privacy Policy
This Policy should be read together with the applicable:
- Terms of Service;
- No-Refund & Cancellation Policy;
- Cookie Policy;
- Acceptable Use Policy;
- Copyright & Dispute Policy;
- DMCA Policy; and
- any category-specific registration terms.
Where those documents concern personal-data processing, they should be interpreted consistently with this Privacy Policy and applicable privacy law.
78. Contact
For privacy questions or to exercise applicable privacy rights, contact:
YOU™ / Unidia LLC 131 Continental Dr Newark, Delaware 19713 New Castle County United States
Email: [email protected]
Please include sufficient information to allow us to understand your request.
Where your question concerns a Work or transaction, you may include the relevant:
- Registration ID;
- Certificate number; or
- order number.
Do not send:
- passwords;
- authentication codes;
- complete payment-card numbers; or
- other unnecessary sensitive information
by email.
79. Representative information to be completed before applicable launch
Where legally required, the following information must be added after an actual appointment has been completed.
EU GDPR Representative
Representative: [TO BE COMPLETED] Member State: [TO BE COMPLETED] Address: [TO BE COMPLETED] Email: [TO BE COMPLETED]
UK GDPR Representative
Representative: [TO BE COMPLETED] Address: [TO BE COMPLETED] Email: [TO BE COMPLETED]
These details must not be invented or published as completed appointments before the relevant representative has actually been appointed.