🇪🇺 GDPR Compliance Policy
General Data Protection Regulation (GDPR) - Effective August 1, 2026
RateMyBody.net is headquartered in Finland and fully complies with the General Data Protection Regulation (GDPR) (Regulation (EU) 2016/679) and the Finnish Personal Data Act (Henkilötietolaki). This policy explains how we comply with GDPR and your rights as a data subject.
1. Data Controller Information
- Data Controller: RateMyBody.net (Operating Entity, Finland)
- Jurisdiction: Finland (EU)
- Supervisory Authority: Office of the Data Protection Ombudsman (Tietosuojavaltuutetun toimisto), Finland
- Data Protection Officer (DPO): Available via contact form or privacy@ratemybody.net
- Contact for Data Requests: privacy@ratemybody.net
2. Legal Basis for Processing (Article 6 GDPR)
We process personal data for the following lawful purposes:
| Processing Purpose | Legal Basis (GDPR Article 6) | Data Categories Involved |
|---|---|---|
| Account registration & authentication | Contract (Art. 6(1)(b)) - Service provision | Email, password, date of birth, username |
| Content moderation & safety | Legal Obligation (Art. 6(1)(c)) - CSAM prevention, law enforcement | Photos, videos, metadata, IP addresses |
| Fraud prevention & abuse detection | Legitimate Interest (Art. 6(1)(f)) - Platform security | IP addresses, device IDs, login patterns |
| Analytics & service improvement | Legitimate Interest (Art. 6(1)(f)) - Service optimization | Usage patterns, click data, session logs |
| Customer support | Contract (Art. 6(1)(b)) - Service support | Support tickets, correspondence, account info |
| Compliance with legal orders | Legal Obligation (Art. 6(1)(c)) - Law enforcement cooperation | All available data as requested |
3. Your GDPR Rights (Chapter III GDPR)
As a data subject under GDPR, you have the following rights:
3.1 Right of Access (Article 15 GDPR)
- You can request a copy of all personal data we have collected about you
- We will provide this in a structured, commonly-used format (e.g., CSV)
- You have the right to receive this information free of charge once per calendar year
- Additional requests may incur a reasonable administrative fee
- We must respond within 30 days of your request
- To request: Email privacy@ratemybody.net with subject "GDPR Article 15 - Right of Access"
3.2 Right to Rectification (Article 16 GDPR)
- If personal data we hold about you is inaccurate or incomplete, you can request correction
- You can correct your own account information (email, profile, etc.) via your account settings
- For corrections beyond your account, email privacy@ratemybody.net
- We will correct inaccurate data without undue delay
- To request: Use account settings or email privacy@ratemybody.net with subject "GDPR Article 16 - Right to Rectification"
3.3 Right to Erasure / "Right to be Forgotten" (Article 17 GDPR)
- You can request deletion of your account and all associated personal data
- This includes your profile, email, messages, and activity logs
- Important exception: Content you have publicly uploaded (photos, comments) may not be deleted if others rely on it. However, we will remove your identifying information
- We must respond to deletion requests within 30 days
- Important legal exception: Evidence of violations (particularly CSAM or child exploitation) is retained for law enforcement investigation in compliance with 18 U.S.C. §2258A
- To request: Email privacy@ratemybody.net with subject "GDPR Article 17 - Right to Erasure"
3.4 Right to Restrict Processing (Article 18 GDPR)
- You can request that we restrict processing of your personal data in certain circumstances (e.g., while disputing accuracy)
- When processing is restricted, we will only store your data and not process it further
- We will notify you before lifting any restrictions
- We may continue processing if you consent, or if it's needed for legal obligations or law enforcement
- To request: Email privacy@ratemybody.net with subject "GDPR Article 18 - Right to Restrict Processing"
3.5 Right to Data Portability (Article 20 GDPR)
- You can request that we provide your personal data in a structured, machine-readable format (e.g., JSON, CSV)
- This includes all data you have provided or generated during your account use
- You can use this to transfer your data to another service
- We must provide this within 30 days free of charge, once per calendar year
- To request: Email privacy@ratemybody.net with subject "GDPR Article 20 - Right to Data Portability"
3.6 Right to Object (Article 21 GDPR)
- You can object to processing based on legitimate interest (e.g., marketing, analytics)
- You can object to automated decision-making
- You can opt-out of certain types of processing (e.g., behavioral profiling)
- We must stop such processing unless we have compelling legitimate grounds or legal obligations
- To request: Email privacy@ratemybody.net with subject "GDPR Article 21 - Right to Object"
3.7 Right to Withdraw Consent (Article 7 GDPR)
- If you consented to processing, you can withdraw consent at any time
- Withdrawal does not affect the lawfulness of processing before withdrawal
- We will stop processing once we receive withdrawal, except where we have another legal basis
- To withdraw consent: Email privacy@ratemybody.net with subject "Withdrawal of Consent"
3.8 Right to Lodge a Complaint (Article 77 GDPR)
- If you believe we are violating your GDPR rights, you can lodge a complaint with your national data protection authority
- For users in Finland: Office of the Data Protection Ombudsman (Tietosuojavaltuutetun toimisto)
- Website: www.tietosuoja.fi
- Email: tietosuoja@om.fi
- Phone: +358 (0)29 566 6700
- For users in other EU countries, contact your national DPA
- You can file a complaint without first contacting us
- Filing a complaint does not prevent you from seeking other legal remedies
4. How to Exercise Your Rights
- Email privacy@ratemybody.net with:
- Your full name and account email address
- The specific right you are exercising (e.g., "Right of Access" or "Right to Erasure")
- A description of your request
- Your preferred method of receiving the response
- We will verify your identity to ensure the request comes from the data subject
- We will respond within 30 calendar days
- If your request is complex, we may request a 60-day extension (we will notify you)
- If your request is manifestly unfounded or excessive, we may refuse or charge a reasonable fee
Email: privacy@ratemybody.net
Postal Address: [Your Finland office address]
5. Data Protection Principles
We process personal data in accordance with GDPR principles:
- Lawfulness, Fairness, Transparency (Art. 5(1)(a)): We only process data lawfully, fairly, and transparently. This policy discloses all our practices
- Purpose Limitation (Art. 5(1)(b)): We collect data for specified, explicit purposes and do not use it for incompatible purposes
- Data Minimization (Art. 5(1)(c)): We collect only the minimum data necessary to provide our service
- Accuracy (Art. 5(1)(d)): We keep personal data accurate and up-to-date, and allow you to correct inaccuracies
- Storage Limitation (Art. 5(1)(e)): We retain data only as long as necessary (see Data Retention section of Privacy Policy)
- Integrity and Confidentiality (Art. 5(1)(f)): We protect personal data using technical and organizational security measures
- Accountability (Art. 5(2)): We are accountable for GDPR compliance and can demonstrate it
6. Data Retention Schedule (Article 5(1)(e) GDPR)
| Data Category | Retention Period | Reason |
|---|---|---|
| Account information (name, email) | Until account deletion | Service provision & legal obligations |
| IP addresses & device IDs | 6 months - 2 years | Fraud detection & abuse prevention |
| Content (photos, videos) | Until deletion by user | Service provision & user choice |
| Private messages | Until user deletes or account closes | User data control & service provision |
| CSAM/law enforcement evidence | 1 year minimum (18 U.S.C. §2258A) | Legal obligation - evidence preservation |
| Activity logs (non-content) | 90 days - 2 years | Security & abuse investigation |
| Support tickets & correspondence | 2 years after resolution | Dispute resolution & legal protection |
7. International Data Transfers
RateMyBody is based in Finland (EU). If you access the platform from outside the EU, your personal data will be transferred internationally. We ensure that any international transfers comply with GDPR:
- For transfers to non-EU countries, we use Standard Contractual Clauses (SCCs) or other GDPR-approved mechanisms
- We conduct Transfer Impact Assessments (TIAs) to ensure adequate safeguards
- We do not transfer personal data to countries without adequate protection unless you consent
- You have the right to be informed about cross-border transfers
8. Third-Party Data Sharing
We may share personal data with:
- Law enforcement: When required by law or in response to valid legal requests
- NCMEC (USA): CSAM reports in compliance with 18 U.S.C. §2258
- Finnish law enforcement (KRP): Criminal investigations involving Finland
- Service providers: Third parties providing technical services (hosting, email, etc.) under Data Processing Agreements
- Legal advisors: In compliance with legal professional privilege
We do NOT sell personal data to marketing companies or advertisers.
9. Data Protection by Design and Default (Article 25 GDPR)
We implement data protection through:
- Encryption: Sensitive data (passwords, payment info) encrypted in transit and at rest
- Access controls: Limited staff access to personal data; access logging
- Pseudonymization: Data anonymized where possible for analytics
- Security audits: Regular security testing and penetration testing
- Privacy notices: Clear, transparent information about data processing
- User controls: Users can manage their own data (update profile, delete content, export data)
10. Data Processing Agreements (Article 28 GDPR)
We have Data Processing Agreements (DPAs) with all third-party processors who handle personal data on our behalf, ensuring they:
- Process data only on our instructions
- Implement appropriate security measures
- Respect data subject rights
- Cooperate with supervisory authorities
- Delete or return data upon termination
11. Data Breach Notification (Article 33-34 GDPR)
In the event of a personal data breach:
- Supervisory authority: We notify the Finnish Data Protection Ombudsman within 72 hours of becoming aware
- Data subjects: If a high risk exists, we notify affected individuals without undue delay
- Notification contents: We provide information about the breach, affected categories, likely consequences, and measures taken
- Documentation: We maintain records of all breaches, even if notification was not required
12. Data Subject Rights Requests - Response Times
- Standard deadline: 30 calendar days from receipt of a clear request
- Extension: We may extend by up to 60 additional days if the request is complex (we will notify you)
- Acknowledgment: We acknowledge receipt of requests without undue delay
- Identity verification: We may request identification information to verify you are the data subject
- Manifestly unfounded requests: We may refuse requests that are manifestly unfounded or excessive, or charge an administrative fee
13. Your 18+ Status & GDPR
RateMyBody is an 18+ only platform. This means:
- We process personal data only from individuals aged 18 and over
- GDPR Article 8 (children's digital consent age) does not apply, as we have eliminated all processing of minor data
- We do not rely on parental consent under GDPR, as we accept no users under 18
- Any personal data found to belong to someone under 18 is immediately and permanently deleted
14. Contact Information for Data Protection Inquiries
- Email: privacy@ratemybody.net
- Subject line: "GDPR Request" or "Data Protection Inquiry"
- Response time: 30 calendar days
- Postal address: [Your Finland office address]
Finnish Data Protection Ombudsman (Supervisory Authority)
- Website: www.tietosuoja.fi (English version available)
- Email: tietosuoja@om.fi
- Phone: +358 (0)29 566 6700
15. Policy Updates
We may update this GDPR Compliance Policy to reflect changes in our practices or to comply with regulatory updates. We will notify you of material changes and, where required by GDPR, obtain your renewed consent for new processing activities.
Last Updated: August 1, 2026
Terms of Service | Privacy Policy | 18+ Only Policy | Legal Hub