RSX-PRV-01
RegisterPrivacy
policy.
What data the ID Portal, CDN, API, and Webhooks collect, why we hold it, how long we keep it, and your rights over it.
- Effective
- 6 September 2026
- Version
- 1.2
- Applies to
- All RSX users, developers, and visitors
- Status
- In force
01Who we are
1.1
RSX is a development brand operated from Silesia, Poland by a group of individuals working under the wider Whitehill Group banner, some of whom are based in the United Kingdom. Neither RSX nor Whitehill Group is an incorporated company.
1.2
Because there is no company to name, the controller of the personal data described in this policy is a natural person: paige@rsx.group, contactable at privacy@rsx.group. The other individuals who operate RSX process data under their direction.
1.3
Our main establishment is in Poland, so the EU GDPR applies to our processing. Where you are in the United Kingdom the UK GDPR also applies. Where the two differ, we apply whichever gives you more protection.
1.4
We have not appointed a Data Protection Officer, as we are not required to. Data protection matters are handled directly by privacy@rsx.group.
02What this policy covers
2.1
This policy covers personal data we process through the ID Portal, the CDN, the API, Webhooks, our websites, our documentation, and our support channels.
2.2
It does not cover:
- ·applications built by other developers on the RSX Platform. They are separate controllers with their own notices, and section 5 explains the split;
- ·personal data inside a file a user uploads. We host those bytes at that user’s instruction and do not read them; the person who uploaded the file is the controller of what it contains, and a request about it goes to them. Clause 2.3 explains what to do if you cannot reach them;
- ·Discord, or any other third-party platform you use alongside ours. Their own policies apply;
- ·sites we link to.
2.3
If a file stored on our systems contains your personal data and you cannot resolve it with the person who uploaded it, write to privacy@rsx.group or abuse@rsx.group. We will act where the content is unlawful, breaches the Content Policy, or where we are required to, using the process in section 6 of that policy.
2.4
Terms used here have the meanings given in the Terms of Service.
03What we collect
3.1
Account data, ID Portal. Collected when you register and while you hold an account: email address, username and display name, a hashed and salted password or an external authentication identifier, account status and roles, security settings including two-factor enrolment, and your preferences.
3.2
Linked account data. If you link a Discord or other third-party account, we store the platform’s user ID, the username and avatar reference at the time of linking, and the scopes you granted. We do not receive or store your password on those platforms.
3.3
Authentication and session data. Session and refresh token identifiers, issue and expiry times, sign-in and sign-out events, the IP address and user agent used, approximate location derived from IP at country level, and failed authentication attempts.
3.4
Developer and API data. Registered application details, hashed API keys and key metadata, and for each request: timestamp, endpoint, method, response status, latency, approximate payload size, rate-limit counters, IP address, and user agent. We do not retain full request or response bodies except where sampled for a specific investigation.
3.5
Webhook data. The endpoint URLs you register, signing secret metadata, and for each delivery: event type and ID, timestamp, response status, latency, and retry history. We log delivery outcomes rather than the full payload content, except where needed to diagnose a reported failure.
3.6
CDN data. When you upload a file we store the file itself and, about it: the filename you gave it, its size, a digest of its contents, the content type we derive from the bytes rather than from what you told us, the previews generated from it, the share links you create with their visibility and expiry, and the account that owns each. Upload sessions record their own progress so an interrupted upload can resume. For delivery we process request metadata at the edge, including IP address, user agent, and the ranges requested; we do not build a per-viewer record of who opened which file.
3.7
File contents. A file’s bytes are stored so we can serve them back. They are not read, indexed, classified, or profiled. The exceptions are set out in section 5 of the Content Policy: automated matching of images against hashes of known child sexual abuse material, and review by a person where content is reported, flagged, or the subject of a lawful order. Where a file contains somebody’s personal data, that is the uploader’s doing and the uploader’s responsibility, as clause 2.2 explains.
3.8
Technical and security data. Server and edge logs, request metadata processed by our infrastructure provider, bot and abuse detection signals, and records of enforcement action taken on an account.
3.9
Support and correspondence. Anything you send to our contact addresses, together with the address you sent it from and our replies.
3.10
We do not collect payment card details, government identity documents, biometrics, precise location, or special category data as defined by Article 9 GDPR. Do not send them to us.
04Why we use it, and our lawful basis
4.1
We process personal data only for the purposes below, on the lawful bases stated.
| Purpose | Data used | Lawful basis |
|---|---|---|
| Creating and running your account, authenticating you, and providing the Services you ask for | Account, linked account, authentication | Contract, Art. 6(1)(b) |
| Issuing and validating API keys, applying rate limits, and delivering webhooks | Developer, API, webhook | Contract, Art. 6(1)(b) |
| Storing your files, generating previews, serving them at the visibility you set, and counting them against your quota | CDN, file contents | Contract, Art. 6(1)(b) |
| Scanning images against hashes of known child sexual abuse material, and reporting confirmed matches | File contents, account | Legal obligation, Art. 6(1)(c); and substantial public interest, Art. 9(2)(g), for any special category data the material discloses |
| Acting on reports about content, reviewing what is reported, and deciding whether to remove it | CDN, file contents, account, reporter's contact details | Legal obligation, Art. 6(1)(c), and legitimate interests, Art. 6(1)(f): a lawful service and the rights of the person reporting |
| Keeping the platform secure: detecting abuse, credential stuffing, key leakage, fraud, and attacks | Authentication, API, technical | Legitimate interests, Art. 6(1)(f): securing our systems and protecting users |
| Enforcing our terms, investigating reports, and preventing evasion of enforcement | Account, technical, enforcement records | Legitimate interests, Art. 6(1)(f): operating a safe platform |
| Diagnosing faults, monitoring capacity, and improving reliability | API, webhook, technical | Legitimate interests, Art. 6(1)(f): a working service |
| Answering your support requests and data rights requests | Support, account | Contract, and legal obligation: Art. 6(1)(b) and 6(1)(c) |
| Service notices: security alerts, breaking changes, terms updates | Account contact | Contract, and legitimate interests: Art. 6(1)(b) and 6(1)(f) |
| Optional product updates or announcements by email | Account contact | Consent, Art. 6(1)(a), withdrawable at any time |
| Meeting legal obligations and responding to lawful requests | As required | Legal obligation, Art. 6(1)(c) |
4.2
Where we rely on legitimate interests, we have assessed that our interest is not overridden by your rights. You can ask for that assessment, and you can object under section 10.
4.3
We do not sell personal data, we do not share it for cross-context behavioural advertising, and we do not use it to build advertising profiles.
4.4
If we ever want to use your data for a new purpose that is not compatible with the above, we will tell you first and, where required, ask for consent.
05Webhooks and developer applications
5.1
When you connect a third-party application to your RSX account, we send that developer the data covered by the scopes you approved. From that point they are an independent controller for what they hold, and their own privacy notice governs it.
5.2
The Developer Terms require developers to publish a privacy notice, request minimum scopes, secure what they receive, delete it when you disconnect, and notify us of incidents within 48 hours. We enforce those obligations, but we cannot control what a developer does with data once delivered.
5.3
To see or remove your connections, open the ID Portal and revoke the application. Revoking stops further delivery immediately and obliges the developer to delete what they hold. To confirm deletion, contact the developer directly; tell us at privacy@rsx.group if they do not comply.
5.4
Webhook deliveries go only to endpoints registered by the developer. We log the outcome of each delivery as described in clause 3.5.
5.5
Where we operate a system inside another party’s product, the people who interact with it do not hold RSX accounts. Where we process an identifier supplied by that operator, we do so on their behalf and keep it only as long as the feature requires.
08International transfers
8.1
Our infrastructure is configured to process and store data in the European Economic Area and the United Kingdom wherever the service allows it.
8.2
Some of the individuals who operate RSX are based in the United Kingdom and access data from there. That transfer relies on the European Commission’s adequacy decision for the United Kingdom and, in the other direction, on the UK’s adequacy regulations for the EEA.
8.3
Where a processor operates a global network and data may be handled outside the EEA or UK, the transfer is covered by the European Commission’s Standard Contractual Clauses, together with the UK International Data Transfer Addendum where relevant, plus encryption in transit and at rest and a transfer risk assessment.
8.4
You can request a copy of the transfer safeguards for a specific processor from privacy@rsx.group.
09How long we keep it
9.1
We keep personal data only as long as we need it for the purpose it was collected for.
| Data | Retention | Then |
|---|---|---|
| Account and profile data | For the life of the account | Deleted within 30 days of account closure |
| Linked account records | Until you unlink, or the account closes | Deleted within 30 days |
| Session and authentication records | Session lifetime | Deleted on expiry or sign-out |
| Sign-in and security event history | 12 months | Deleted |
| API request logs | 30 days | Deleted; aggregate, non-identifying counters may be kept |
| Webhook delivery logs | 14 days | Deleted |
| Uploaded files and their previews | For as long as the account holds a link to them, with no time limit of our own | Deleted within 30 days of account closure, or when you delete the last link to them, whichever is first |
| File and share-link metadata | As above | Deleted with the content |
| Upload sessions | Until the upload completes or the session expires | Deleted; an incomplete upload's parts are discarded |
| CDN delivery logs | 30 days | Deleted; aggregate, non-identifying counters may be kept |
| Reports about content, and what we decided | 24 months from the decision | Deleted unless part of an open case or needed to show a pattern of repeat breach |
| Abuse and content-policy flags | 12 months | Deleted unless part of an open case |
| Support correspondence | 24 months from last contact | Deleted |
| Enforcement records (suspensions, terminations) | Retained while needed to prevent evasion, reviewed every 3 years | Reduced to the minimum identifier set |
| Records needed for a legal claim, obligation, or investigation | As long as the obligation or claim period lasts | Deleted |
9.2
Deletion means removal from live systems immediately and from encrypted backups within 90 days, as backups rotate. Data in a backup is not used for any purpose while it waits to be overwritten.
9.3
We keep a minimal record of terminated accounts (an identifier, the date, and the ground) because we cannot enforce clause 7.3 of the Terms of Service without it. This is a legitimate interest and you may object under section 10.
9.4
Deleted files are not necessarily erased immediately. Identical content uploaded by two people is stored once, so deleting your link removes your access and your link but leaves the bytes in place while another account holds a live link to them. At that point the content is theirs, not yours, and nothing connects it back to you. Once no link of any kind points at it, it is erased.
9.5
Content that we are required to preserve for a law enforcement or child protection report is kept for as long as that requirement lasts, separately from the live systems, and is not restored to the account.
10Your rights
10.1
Under the EU and UK GDPR you have the right to:
- ·Access: get a copy of the personal data we hold about you, and information about how we use it.
- ·Rectification: have inaccurate data corrected and incomplete data completed.
- ·Erasure: have data deleted where we no longer have grounds to keep it.
- ·Restriction: have processing paused while a dispute about accuracy or grounds is resolved.
- ·Portability: receive the data you gave us in a structured, machine-readable format, or have it sent to another controller where technically feasible.
- ·Object: object to processing based on legitimate interests, including profiling, on grounds relating to your situation.
- ·Withdraw consent: at any time, where we rely on consent. This does not affect processing already carried out.
- ·Complain: to a supervisory authority, as set out in clause 15.3.
10.2
Exercise any of these by writing to privacy@rsx.group from the email address on your account, or through the ID Portal where the tool exists. Say which right you are exercising and which data it concerns.
10.3
We respond within one month. We may extend by up to two further months for complex requests, and will tell you within the first month if we do.
10.4
Requests are free. We may charge a reasonable administrative fee, or refuse, only where a request is manifestly unfounded or excessive, and we will explain why.
10.5
We may ask for information to confirm your identity, but only what is necessary and only where we genuinely cannot otherwise verify you. We will not create a new identity record from it, and we delete what you send once verification is complete.
10.6
Some rights are limited. We may keep data needed for a legal obligation, for the establishment or defence of a legal claim, or for the enforcement records in clause 9.3. Where we refuse a request, we will tell you the reason and how to challenge it.
11How we protect data
11.1
Technical measures: TLS for all traffic; encryption at rest for stored data; passwords stored using a modern memory-hard hashing algorithm with per-user salts; API keys stored only as hashes; signed and expiring session tokens; signed webhook payloads; network-level DDoS and bot protection.
11.2
Organisational measures: access on a least-privilege basis, granted per role and reviewed periodically; multi-factor authentication required for administrative access; audit logging of administrative actions; separation of production from development data; supplier review before engaging a processor.
11.3
No system is completely secure. You play a part too: use a unique password, enable two-factor authentication, and keep API keys off client devices.
11.4
If a personal data breach is likely to result in a risk to your rights and freedoms, we will notify our supervisory authority within 72 hours of becoming aware, and we will notify you without undue delay where the risk is high. Our notice will say what happened, what data was affected, what we have done, and what you should do.
11.5
Report a suspected vulnerability or breach to security@rsx.group. Section 12 of the Developer Terms sets out our disclosure terms.
12Age and minors
12.1
RSX accounts are for people aged 16 or over. The platform is a developer tool and is not directed at children.
12.2
We do not knowingly collect personal data from anyone under 16 in connection with an RSX account. If we learn that an account holder is under 16, we will terminate the account and delete the data, other than the minimal record needed to prevent re-registration.
12.3
If you believe someone under 16 holds an account, tell us at privacy@rsx.group and we will investigate promptly.
12.4
People who reach an RSX system without holding an account may be under 16. We do not collect account data from them. Where such a system processes an identifier supplied by the operator of the product it sits inside, we do so on that operator’s behalf, for the shortest period the feature requires, and we do not use it to build a profile.
13Automated decisions
13.1
We use automated systems to detect abuse: rate-limit breaches, credential stuffing, leaked keys, and spam patterns. These systems can automatically throttle traffic, revoke a key, or restrict an account.
13.2
We also match uploaded images against hashes of known child sexual abuse material. This compares a fingerprint of a file against a list; it does not read, classify, or score your content, and it produces no judgement about anything not on that list. A match is reviewed and reported as set out in section 12 of the Content Policy. No other automated system inspects the contents of your files.
13.3
Decisions to remove content, other than under the clause above, are taken by a person who has looked at the material. See section 5 of the Content Policy.
13.4
Automated action is limited to what is needed to stop immediate harm. A permanent termination is reviewed by a person before it is final, except where clause 7.3 of the Terms of Service applies and the evidence is unambiguous.
13.5
Where a decision that significantly affects you is made by automated means, you have the right to be told, to obtain human review, to express your view, and to contest it. Use appeals@rsx.group.
13.6
We do not use automated decision-making for profiling unrelated to security and enforcement, and we do not use it for marketing.
14Changes to this policy
14.1
We update this policy when our practices, our processors, or the law change.
14.2
For changes that materially affect how we use your data, we will give at least 30 days’ notice by email or in the ID Portal before they take effect. Where a change requires consent, we will ask for it rather than assume it.
14.3
Corrections and clarifications take effect when published. The version and effective date at the top of this page always reflect the current text.
14.4
Previous versions are available on request from privacy@rsx.group.
15Contact
15.1
RSX is an unincorporated group operating from Silesia, Poland, under the Whitehill Group banner. Controller: paige@rsx.group.
15.2
Privacy and data rights requests: privacy@rsx.group. Security: security@rsx.group. Content reports: abuse@rsx.group. Everything else: legal@rsx.group.
15.3
Complaining to a supervisory authority. You may complain to the data protection authority in the country where you live, where you work, or where you believe the problem happened. Our lead authority is the Polish Urząd Ochrony Danych Osobowych (ul. Stawki 2, 00-193 Warszawa, uodo.gov.pl). In the United Kingdom it is the Information Commissioner’s Office (ico.org.uk). We would rather you came to us first, at privacy@rsx.group, but you are not obliged to.
—Revision history
Every version this document has had. The last row is the version in force. Superseded versions are available on request from legal@rsx.group.
| Version | Effective | Change |
|---|---|---|
| 1.0 | 10 August 2026 | First issue. |
| 1.1 | 26 August 2026 | AI Portal section and its retention commitments removed. |
| 1.2 | 6 September 2026 | CDN data and file contents added, with the lawful bases for scanning and acting on reports. UODO and ICO named. |