Skip to content
PersoTakt
How it works Sign in Get started ↗

PRIVACY NOTICE · DEVELOPMENT VERSION

Your identity deserves care.

This notice describes the current development build. Production verification providers, hosting, retention periods and international transfers must be finalized before public registration opens.

1. Controller and scope

Mikel Krasniqi operates PersoTakt. Contact hello@webtakt.ai for privacy questions. See the legal notice for the configured address. This notice covers accounts, persona profiles, licence requests, output review, platform payments and misuse reports.

2. What we process and why

Account data includes your name, email, password hash, date of birth, country and account type. Company representatives also provide company details. We use these to operate your account, check eligibility, prevent misuse and support requested services. Contract-related processing relies on Article 6(1)(b) GDPR; justified security and fraud-prevention processing on Article 6(1)(f). Any legally required records are retained under Article 6(1)(c).

Persona owners provide one catalogue portrait and seven private source photographs, a description, categories and rates. Catalogue publication and sharing source photos under an accepted licence are separate recorded permissions. Specific consent processing relies on Article 6(1)(a). You can withdraw photo permissions in your profile for future processing. Existing licence and statutory record obligations require separate assessment.

Requests contain the brief, parties, proposed tools, terms, fee and decisions. Finished output files and review notes record the agreed use. We keep account and administrative access restricted. A persona's personal email and date of birth are not shown in the catalogue.

The selected identity method is private manual review. When this service opens, you provide a marked ID copy, a selfie showing a one-time challenge and, for companies, evidence of business existence and representative authority. A human checks the name, adulthood and person/photo relationship; persona owners must also supply their complete photo pack. Copy permission and review records are separate from your likeness licence. Follow the upload instructions to hide unnecessary ID information. Evidence is encrypted and available only to authorized administrators. It is never included in a licensed photo pack or sent to requesters.

We do not use Stripe Identity, automated face matching or internet-wide face searches in this release. An ordinary photograph is not automatically biometric identification data. Manual review reduces impersonation risk but cannot guarantee that every forged document or invented image will be detected. Identity uploads remain closed in the public preview while the launch privacy rules are finalized.

Security records can include IP addresses, request times, errors and audit events. Report data includes a URL, description, optional contact email and review history. Avoid unnecessary sensitive information in briefs, payment notes or reports.

3. Recipients and transfers

The selected persona owner receives the requester identity and project brief after confirmed submission. Authorized requesters may receive source photos only within an accepted licence and agreed period after both parties confirm their direct payment arrangement. Report and verification records are restricted to administration.

When configured, payment processing is provided through a hosted checkout. Card details are entered with the payment provider, rather than this app. Its own processing is explained in the payment provider privacy notice. The active Hostinger VPS is in Germany (Frankfurt); provider backups are stored separately in France. Production identity intake remains closed. Email delivery, processor contracts, backup policy and any transfer safeguards still require approval before public operation. AI tools named by requesters are outside-platform recipients; source use must follow the accepted brief and their applicable obligations.

4. Cookies and device storage

Visiting the preview uses a necessary session cookie for navigation and request security, even without an account. Session records can include your IP address and browser's user-agent information. Ordinary request and security logs can include IP addresses, request times, page paths, response codes and errors. Closing account and report forms does not stop this basic visitor processing.

We also use necessary session and request-security cookies for sign-in and safe forms when those services open. The development build contains no analytics, advertising pixels, third-party fonts or tracking cookies. Additional optional storage requires a separate assessment before introduction.

5. Retention and deletion

Manual verification images, copied profile details, private review notes and references are scheduled for removal from active storage seven days after approval or rejection. Unanswered submissions expire after thirty days. Expired evidence cannot be opened; failed physical deletions are recorded for retry and administrator attention. Minimal review decisions, dates, adult results and necessary photo-pack references remain in the account without a permanent active ID copy.

Encrypted identity images are excluded from ordinary application archives. Encrypted copied profile and review fields are part of the database, so earlier copies can remain in local database dumps with fourteen-day retention and in thirty daily encrypted archive snapshots. These copies expire separately from active deletion. Whole-VPS provider backups include the identity-image directory despite its separate storage mount, and can retain those images after active deletion. Hostinger describes rotating slots for up to two daily and two weekly backups and a manual snapshot that expires after one day; this is not a guaranteed fourteen-day total-erasure deadline. See the provider's backup rules. The owner has not approved this longer backup retention for identity evidence. Real identity intake stays closed until that conflict is resolved and the actual copy-expiry policy is confirmed.

Any restored database, files or whole server must stay isolated from public intake and identity access until expired images and copied profile/review fields have been purged and missing-file handling has been checked. Restoring a copy must not restart an expired retention period. The production restore procedure still requires verification.

The remaining launch retention schedule is not finalized. In the development build, account, licence, audit and report records remain until an authorized deletion or review. Replaced private source files are retained only where an existing request freezes that exact file as agreement evidence. A production schedule must define justified periods for unused profiles, source files, outputs, security logs and backups, while keeping legally required accounting and dispute records. Do not upload real ID documents during development.

6. Your rights and complaints

Under the applicable conditions, you can request access, correction, deletion, restriction and data portability. You may object to processing based on legitimate interests and withdraw consent for future processing. Contact the controller above; withdrawing consent does not affect processing already lawfully performed. You may complain to a data protection supervisory authority, including the Bavarian State Office for Data Protection Supervision.

7. Updates

Development version dated 9 October 2026. Provider configuration, identity methods and production policies will be reviewed before launch.

PersoTakt

A real person behind every permission.

Legal noticePrivacyTermsWithdrawalReport misuse
© 2026 PersoTakt · A WebTakt project