Skip to content
Crealenty policies

Privacy Notice

This notice explains what Crealenty handles, why it is used, who receives it, how long selected records remain, and the controls available to you.

Effective August 4, 2026
Version 2026-08-04

Controller and privacy contact

Nerdy Clock is the personal information controller and legal operator of this Crealenty pilot.

Operator address: Philippines

Privacy contact or data-protection representative: Data Protection Officer, crealenty_privacy@nerdyclock.com

Information we handle

The information involved depends on whether you browse publicly, join as talent, or manage a recruiter workspace.

  • Account and identity data, such as email, authentication identifiers, display name, role, preferences, active workspace, and policy acceptance. Acceptance evidence includes the policy versions and content digests, the exact public controller/contact snapshot, a server timestamp, browser information, request reference, and—when configured—a dedicated keyed hash derived from the connection address. Crealenty does not store the raw address in that record and cannot join this hash to browsing analytics.
  • Profile and portfolio data, including biography, location, categories, skills, rates, availability, links, media, embeds, custom presentation code, and visibility choices.
  • Marketplace and safety data, including job posts, applications, drafts, invitations, auditions, attachments, offers, bookings, reviews, shortlists, team membership, messages, blocks, reports, moderation actions, and related history.
  • Technical and usage data, including IP-derived abuse signals, hashed viewer identifiers, browser or device information, referrer, profile views, search appearances, timestamps, logs, and security events.

How we use and show information

We use information to create and secure accounts; operate discovery and hiring workflows; deliver messages and notices; apply limits; prevent abuse; investigate reports; maintain records; understand marketplace use; troubleshoot; and improve the pilot. We use consent where required and otherwise rely on the need to provide the requested service, protect legitimate safety and operational interests, or comply with law.

Published talent profiles, selected portfolio content, public reviews, and open jobs can be visible without signing in and may be indexed or copied by others. Drafts, private auditions, internal shortlist notes, team details, and other restricted workflow records are limited to authorized participants according to the product controls, but no system can promise absolute confidentiality.

Direct messages are stored by Crealenty and are not end-to-end encrypted. Message content may be processed for delivery, unread-message email notices, abuse prevention, support, report investigation, legal compliance, and enforcement. Avoid sending information that is not necessary for the collaboration.

Processors, recipients, and third parties

We disclose only what is reasonably needed to users involved in a workflow, to authorities when legally required, during a legitimate business transfer, or to provider categories that operate the service for us.

  • Cloud hosting, database, authentication, object storage, content delivery, backup, and search-index providers.
  • Email delivery and operational communications providers.
  • Security, logging, performance, error-monitoring, and analytics providers, if enabled for the deployment.
  • Services you or another user choose to embed or contact from a portfolio, such as supported video, audio, or social platforms. Those third parties receive requests under their own policies. Sandboxed portfolio code can make restricted HTTPS requests but cannot use camera, microphone, location, payments, or forms through the sandbox.

Retention and account deletion

Raw search-appearance records are scheduled for deletion after 30 days. Raw profile-view records are scheduled for deletion after 90 days. Sent or cancelled hiring-email delivery records are deleted after 30 days. Production request and error logs must be configured for no more than 30 days unless a specific security incident or legal hold requires longer preservation.

We keep account and portfolio data while the account is active. After deletion, shared workflow, message, booking, offer, review, report, and safety records are reviewed at least annually and are deleted or anonymized when no longer needed for a counterparty record, dispute, safety investigation, fraud prevention, or legal obligation. A documented legal hold may extend that event-based period. Published content can remain in third-party caches or copies outside our control.

Deleting your account removes or clears public profile and portfolio details, private drafts, saved items, analytics tied to your profile, preferences, and other removable data. Crealenty retains an anonymized profile tombstone and may retain non-public transaction, booking, offer, application, audition, message, review, report, moderation, and media evidence needed to preserve shared history, safety, or legal claims. Your authentication account is detached and deleted; retained records no longer use your public identity.

Your choices and rights

Use profile visibility, portfolio publishing, notification, block, report, workspace, and account settings to control common uses. Do not publish information you want to keep private.

Depending on applicable law, you may ask to access, correct, export, object to, restrict, or delete personal information, or withdraw consent. Contact Support with the account email and enough detail to verify and handle the request. You may also complain to your local privacy regulator.

We use access controls, scoped service roles, transport security, rate limits, and restricted media and script handling, but no online service is risk-free. Use a unique password, keep your account secure, and report suspected compromise promptly.

We will publish a new version when this notice changes materially. Append-only policy acceptance records are retained only as evidence of the notice and terms presented, for the life of the account and then with its anonymized tombstone while shared workflow or safety records remain. They are removed if that tombstone is finally erased and are not used for analytics.