Skip to content
RSXLegalrsxdev.rsxpages.com

RSX-PRV-01

Register

Privacy
policy.

What data the ID Portal, CDN, API, and Webhooks collect, why we hold it, how long we keep it, and your rights over it.

Effective
6 September 2026
Version
1.2
Applies to
All RSX users, developers, and visitors
Status
In force

01Who we are

1.1
RSX is a development brand operated from Silesia, Poland by a group of individuals working under the wider Whitehill Group banner, some of whom are based in the United Kingdom. Neither RSX nor Whitehill Group is an incorporated company.
1.2
Because there is no company to name, the controller of the personal data described in this policy is a natural person: paige@rsx.group, contactable at privacy@rsx.group. The other individuals who operate RSX process data under their direction.
1.3
Our main establishment is in Poland, so the EU GDPR applies to our processing. Where you are in the United Kingdom the UK GDPR also applies. Where the two differ, we apply whichever gives you more protection.
1.4
We have not appointed a Data Protection Officer, as we are not required to. Data protection matters are handled directly by privacy@rsx.group.

02What this policy covers

2.1
This policy covers personal data we process through the ID Portal, the CDN, the API, Webhooks, our websites, our documentation, and our support channels.
2.2
It does not cover:
  • ·applications built by other developers on the RSX Platform. They are separate controllers with their own notices, and section 5 explains the split;
  • ·personal data inside a file a user uploads. We host those bytes at that user’s instruction and do not read them; the person who uploaded the file is the controller of what it contains, and a request about it goes to them. Clause 2.3 explains what to do if you cannot reach them;
  • ·Discord, or any other third-party platform you use alongside ours. Their own policies apply;
  • ·sites we link to.
2.3
If a file stored on our systems contains your personal data and you cannot resolve it with the person who uploaded it, write to privacy@rsx.group or abuse@rsx.group. We will act where the content is unlawful, breaches the Content Policy, or where we are required to, using the process in section 6 of that policy.
2.4
Terms used here have the meanings given in the Terms of Service.

03What we collect

3.1
Account data, ID Portal. Collected when you register and while you hold an account: email address, username and display name, a hashed and salted password or an external authentication identifier, account status and roles, security settings including two-factor enrolment, and your preferences.
3.2
Linked account data. If you link a Discord or other third-party account, we store the platform’s user ID, the username and avatar reference at the time of linking, and the scopes you granted. We do not receive or store your password on those platforms.
3.3
Authentication and session data. Session and refresh token identifiers, issue and expiry times, sign-in and sign-out events, the IP address and user agent used, approximate location derived from IP at country level, and failed authentication attempts.
3.4
Developer and API data. Registered application details, hashed API keys and key metadata, and for each request: timestamp, endpoint, method, response status, latency, approximate payload size, rate-limit counters, IP address, and user agent. We do not retain full request or response bodies except where sampled for a specific investigation.
3.5
Webhook data. The endpoint URLs you register, signing secret metadata, and for each delivery: event type and ID, timestamp, response status, latency, and retry history. We log delivery outcomes rather than the full payload content, except where needed to diagnose a reported failure.
3.6
CDN data. When you upload a file we store the file itself and, about it: the filename you gave it, its size, a digest of its contents, the content type we derive from the bytes rather than from what you told us, the previews generated from it, the share links you create with their visibility and expiry, and the account that owns each. Upload sessions record their own progress so an interrupted upload can resume. For delivery we process request metadata at the edge, including IP address, user agent, and the ranges requested; we do not build a per-viewer record of who opened which file.
3.7
File contents. A file’s bytes are stored so we can serve them back. They are not read, indexed, classified, or profiled. The exceptions are set out in section 5 of the Content Policy: automated matching of images against hashes of known child sexual abuse material, and review by a person where content is reported, flagged, or the subject of a lawful order. Where a file contains somebody’s personal data, that is the uploader’s doing and the uploader’s responsibility, as clause 2.2 explains.
3.8
Technical and security data. Server and edge logs, request metadata processed by our infrastructure provider, bot and abuse detection signals, and records of enforcement action taken on an account.
3.9
Support and correspondence. Anything you send to our contact addresses, together with the address you sent it from and our replies.
3.10
We do not collect payment card details, government identity documents, biometrics, precise location, or special category data as defined by Article 9 GDPR. Do not send them to us.

04Why we use it, and our lawful basis

4.1
We process personal data only for the purposes below, on the lawful bases stated.
PurposeData usedLawful basis
Creating and running your account, authenticating you, and providing the Services you ask forAccount, linked account, authenticationContract, Art. 6(1)(b)
Issuing and validating API keys, applying rate limits, and delivering webhooksDeveloper, API, webhookContract, Art. 6(1)(b)
Storing your files, generating previews, serving them at the visibility you set, and counting them against your quotaCDN, file contentsContract, Art. 6(1)(b)
Scanning images against hashes of known child sexual abuse material, and reporting confirmed matchesFile contents, accountLegal obligation, Art. 6(1)(c); and substantial public interest, Art. 9(2)(g), for any special category data the material discloses
Acting on reports about content, reviewing what is reported, and deciding whether to remove itCDN, file contents, account, reporter's contact detailsLegal obligation, Art. 6(1)(c), and legitimate interests, Art. 6(1)(f): a lawful service and the rights of the person reporting
Keeping the platform secure: detecting abuse, credential stuffing, key leakage, fraud, and attacksAuthentication, API, technicalLegitimate interests, Art. 6(1)(f): securing our systems and protecting users
Enforcing our terms, investigating reports, and preventing evasion of enforcementAccount, technical, enforcement recordsLegitimate interests, Art. 6(1)(f): operating a safe platform
Diagnosing faults, monitoring capacity, and improving reliabilityAPI, webhook, technicalLegitimate interests, Art. 6(1)(f): a working service
Answering your support requests and data rights requestsSupport, accountContract, and legal obligation: Art. 6(1)(b) and 6(1)(c)
Service notices: security alerts, breaking changes, terms updatesAccount contactContract, and legitimate interests: Art. 6(1)(b) and 6(1)(f)
Optional product updates or announcements by emailAccount contactConsent, Art. 6(1)(a), withdrawable at any time
Meeting legal obligations and responding to lawful requestsAs requiredLegal obligation, Art. 6(1)(c)
4.2
Where we rely on legitimate interests, we have assessed that our interest is not overridden by your rights. You can ask for that assessment, and you can object under section 10.
4.3
We do not sell personal data, we do not share it for cross-context behavioural advertising, and we do not use it to build advertising profiles.
4.4
If we ever want to use your data for a new purpose that is not compatible with the above, we will tell you first and, where required, ask for consent.

05Webhooks and developer applications

5.1
When you connect a third-party application to your RSX account, we send that developer the data covered by the scopes you approved. From that point they are an independent controller for what they hold, and their own privacy notice governs it.
5.2
The Developer Terms require developers to publish a privacy notice, request minimum scopes, secure what they receive, delete it when you disconnect, and notify us of incidents within 48 hours. We enforce those obligations, but we cannot control what a developer does with data once delivered.
5.3
To see or remove your connections, open the ID Portal and revoke the application. Revoking stops further delivery immediately and obliges the developer to delete what they hold. To confirm deletion, contact the developer directly; tell us at privacy@rsx.group if they do not comply.
5.4
Webhook deliveries go only to endpoints registered by the developer. We log the outcome of each delivery as described in clause 3.5.
5.5
Where we operate a system inside another party’s product, the people who interact with it do not hold RSX accounts. Where we process an identifier supplied by that operator, we do so on their behalf and keep it only as long as the feature requires.

06Cookies and similar technologies

6.1
We use strictly necessary cookies and local storage only: your session token, cross-site request forgery protection, load balancing and bot-protection identifiers set by our infrastructure provider, and your interface preferences. These do not require consent because the Services cannot work without them.
6.2
We do not use advertising cookies, third-party trackers, social plug-ins, or cross-site analytics.
6.3
Where we measure traffic, we use aggregate, cookieless analytics that does not build a profile of you or track you across sites.
6.4
Blocking strictly necessary cookies in your browser will prevent sign-in from working.

07Who we share data with

7.1
We share personal data only with the categories of recipient below. We do not sell it.
RecipientRoleWhat they receive
CloudflareHosting, edge network, object storage, DDoS and bot protection, image and media processing, CSAM hash scanning, transactional email deliveryEffectively all traffic-borne data: request metadata, IP addresses, stored account and platform data, uploaded files and the previews derived from them, email address and message content for account, security, and service notices
Child protection bodies and law enforcementMandatory reporting of child sexual abuse materialThe material, the account behind it, and the records needed to identify it. Reported without notice to the account holder, as clause 12.3 of the Content Policy sets out.
The person who reported content, or who sent a legal noticeTelling a reporter what we decidedThe outcome of their report, and nothing that identifies the person who uploaded the content unless a court or an authority requires it
Discord, and other platforms you linkAccount linking, at your instructionOnly what the authorisation flow requires; we receive their identifiers, they receive no RSX data beyond the request itself
Other Whitehill Group membersThe wider group RSX operates within: shared administration, security, and support, including individuals in the United KingdomAccess on a need-to-know basis, under confidentiality obligations and the direction of the controller
Professional advisersLegal, accounting, insuranceOnly where necessary for a specific matter
Law enforcement, regulators, courtsLegal obligationOnly what a valid, specific, lawful request requires. See clause 7.3.
7.2
Processors act only on our documented instructions under a contract meeting Article 28 GDPR, with confidentiality, security, sub-processor, and deletion obligations. We review them before engagement.
7.3
We respond to lawful requests from authorities, but we check that each request is valid, specific, and proportionate, disclose only what is required, and tell you unless legally prohibited from doing so.
7.4
If the operation of RSX passes to a different operator, or to an entity later formed to run it, data may transfer with it. We will notify you before that happens and before any change of purpose, and this policy continues to apply until you are told otherwise.
7.5
We will publish material changes to our processors on this page at least 30 days before they take effect, so you can object.

08International transfers

8.1
Our infrastructure is configured to process and store data in the European Economic Area and the United Kingdom wherever the service allows it.
8.2
Some of the individuals who operate RSX are based in the United Kingdom and access data from there. That transfer relies on the European Commission’s adequacy decision for the United Kingdom and, in the other direction, on the UK’s adequacy regulations for the EEA.
8.3
Where a processor operates a global network and data may be handled outside the EEA or UK, the transfer is covered by the European Commission’s Standard Contractual Clauses, together with the UK International Data Transfer Addendum where relevant, plus encryption in transit and at rest and a transfer risk assessment.
8.4
You can request a copy of the transfer safeguards for a specific processor from privacy@rsx.group.

09How long we keep it

9.1
We keep personal data only as long as we need it for the purpose it was collected for.
DataRetentionThen
Account and profile dataFor the life of the accountDeleted within 30 days of account closure
Linked account recordsUntil you unlink, or the account closesDeleted within 30 days
Session and authentication recordsSession lifetimeDeleted on expiry or sign-out
Sign-in and security event history12 monthsDeleted
API request logs30 daysDeleted; aggregate, non-identifying counters may be kept
Webhook delivery logs14 daysDeleted
Uploaded files and their previewsFor as long as the account holds a link to them, with no time limit of our ownDeleted within 30 days of account closure, or when you delete the last link to them, whichever is first
File and share-link metadataAs aboveDeleted with the content
Upload sessionsUntil the upload completes or the session expiresDeleted; an incomplete upload's parts are discarded
CDN delivery logs30 daysDeleted; aggregate, non-identifying counters may be kept
Reports about content, and what we decided24 months from the decisionDeleted unless part of an open case or needed to show a pattern of repeat breach
Abuse and content-policy flags12 monthsDeleted unless part of an open case
Support correspondence24 months from last contactDeleted
Enforcement records (suspensions, terminations)Retained while needed to prevent evasion, reviewed every 3 yearsReduced to the minimum identifier set
Records needed for a legal claim, obligation, or investigationAs long as the obligation or claim period lastsDeleted
9.2
Deletion means removal from live systems immediately and from encrypted backups within 90 days, as backups rotate. Data in a backup is not used for any purpose while it waits to be overwritten.
9.3
We keep a minimal record of terminated accounts (an identifier, the date, and the ground) because we cannot enforce clause 7.3 of the Terms of Service without it. This is a legitimate interest and you may object under section 10.
9.4
Deleted files are not necessarily erased immediately. Identical content uploaded by two people is stored once, so deleting your link removes your access and your link but leaves the bytes in place while another account holds a live link to them. At that point the content is theirs, not yours, and nothing connects it back to you. Once no link of any kind points at it, it is erased.
9.5
Content that we are required to preserve for a law enforcement or child protection report is kept for as long as that requirement lasts, separately from the live systems, and is not restored to the account.

10Your rights

10.1
Under the EU and UK GDPR you have the right to:
  • ·Access: get a copy of the personal data we hold about you, and information about how we use it.
  • ·Rectification: have inaccurate data corrected and incomplete data completed.
  • ·Erasure: have data deleted where we no longer have grounds to keep it.
  • ·Restriction: have processing paused while a dispute about accuracy or grounds is resolved.
  • ·Portability: receive the data you gave us in a structured, machine-readable format, or have it sent to another controller where technically feasible.
  • ·Object: object to processing based on legitimate interests, including profiling, on grounds relating to your situation.
  • ·Withdraw consent: at any time, where we rely on consent. This does not affect processing already carried out.
  • ·Complain: to a supervisory authority, as set out in clause 15.3.
10.2
Exercise any of these by writing to privacy@rsx.group from the email address on your account, or through the ID Portal where the tool exists. Say which right you are exercising and which data it concerns.
10.3
We respond within one month. We may extend by up to two further months for complex requests, and will tell you within the first month if we do.
10.4
Requests are free. We may charge a reasonable administrative fee, or refuse, only where a request is manifestly unfounded or excessive, and we will explain why.
10.5
We may ask for information to confirm your identity, but only what is necessary and only where we genuinely cannot otherwise verify you. We will not create a new identity record from it, and we delete what you send once verification is complete.
10.6
Some rights are limited. We may keep data needed for a legal obligation, for the establishment or defence of a legal claim, or for the enforcement records in clause 9.3. Where we refuse a request, we will tell you the reason and how to challenge it.

11How we protect data

11.1
Technical measures: TLS for all traffic; encryption at rest for stored data; passwords stored using a modern memory-hard hashing algorithm with per-user salts; API keys stored only as hashes; signed and expiring session tokens; signed webhook payloads; network-level DDoS and bot protection.
11.2
Organisational measures: access on a least-privilege basis, granted per role and reviewed periodically; multi-factor authentication required for administrative access; audit logging of administrative actions; separation of production from development data; supplier review before engaging a processor.
11.3
No system is completely secure. You play a part too: use a unique password, enable two-factor authentication, and keep API keys off client devices.
11.4
If a personal data breach is likely to result in a risk to your rights and freedoms, we will notify our supervisory authority within 72 hours of becoming aware, and we will notify you without undue delay where the risk is high. Our notice will say what happened, what data was affected, what we have done, and what you should do.
11.5
Report a suspected vulnerability or breach to security@rsx.group. Section 12 of the Developer Terms sets out our disclosure terms.

12Age and minors

12.1
RSX accounts are for people aged 16 or over. The platform is a developer tool and is not directed at children.
12.2
We do not knowingly collect personal data from anyone under 16 in connection with an RSX account. If we learn that an account holder is under 16, we will terminate the account and delete the data, other than the minimal record needed to prevent re-registration.
12.3
If you believe someone under 16 holds an account, tell us at privacy@rsx.group and we will investigate promptly.
12.4
People who reach an RSX system without holding an account may be under 16. We do not collect account data from them. Where such a system processes an identifier supplied by the operator of the product it sits inside, we do so on that operator’s behalf, for the shortest period the feature requires, and we do not use it to build a profile.

13Automated decisions

13.1
We use automated systems to detect abuse: rate-limit breaches, credential stuffing, leaked keys, and spam patterns. These systems can automatically throttle traffic, revoke a key, or restrict an account.
13.2
We also match uploaded images against hashes of known child sexual abuse material. This compares a fingerprint of a file against a list; it does not read, classify, or score your content, and it produces no judgement about anything not on that list. A match is reviewed and reported as set out in section 12 of the Content Policy. No other automated system inspects the contents of your files.
13.3
Decisions to remove content, other than under the clause above, are taken by a person who has looked at the material. See section 5 of the Content Policy.
13.4
Automated action is limited to what is needed to stop immediate harm. A permanent termination is reviewed by a person before it is final, except where clause 7.3 of the Terms of Service applies and the evidence is unambiguous.
13.5
Where a decision that significantly affects you is made by automated means, you have the right to be told, to obtain human review, to express your view, and to contest it. Use appeals@rsx.group.
13.6
We do not use automated decision-making for profiling unrelated to security and enforcement, and we do not use it for marketing.

14Changes to this policy

14.1
We update this policy when our practices, our processors, or the law change.
14.2
For changes that materially affect how we use your data, we will give at least 30 days’ notice by email or in the ID Portal before they take effect. Where a change requires consent, we will ask for it rather than assume it.
14.3
Corrections and clarifications take effect when published. The version and effective date at the top of this page always reflect the current text.
14.4
Previous versions are available on request from privacy@rsx.group.

15Contact

15.1
RSX is an unincorporated group operating from Silesia, Poland, under the Whitehill Group banner. Controller: paige@rsx.group.
15.2
Privacy and data rights requests: privacy@rsx.group. Security: security@rsx.group. Content reports: abuse@rsx.group. Everything else: legal@rsx.group.
15.3
Complaining to a supervisory authority. You may complain to the data protection authority in the country where you live, where you work, or where you believe the problem happened. Our lead authority is the Polish Urząd Ochrony Danych Osobowych (ul. Stawki 2, 00-193 Warszawa, uodo.gov.pl). In the United Kingdom it is the Information Commissioner’s Office (ico.org.uk). We would rather you came to us first, at privacy@rsx.group, but you are not obliged to.

—Revision history

Every version this document has had. The last row is the version in force. Superseded versions are available on request from legal@rsx.group.

VersionEffectiveChange
1.010 August 2026First issue.
1.126 August 2026AI Portal section and its retention commitments removed.
1.26 September 2026CDN data and file contents added, with the lawful bases for scanning and acting on reports. UODO and ICO named.