1. Scope & Controller
2. Personal Information We Collect
We collect the following categories of personal information:
3. How We Use Personal Information
We use personal information for the following purposes:
- to create and administer your account and provide the Service;
- to authenticate you, prevent fraud, and secure the Service;
- to verify identity where required by law or platform policy;
- to facilitate the negotiation, formation, and settlement of Deals, and to generate Licensing Agreements;
- to process payments, hold funds in Escrow, and remit payouts;
- to communicate with you about your account, transactions, support requests, and policy changes;
- to enforce our Terms of Service and Acceptable Use Policy, and to comply with legal obligations;
- to conduct analytics, improve, and develop the Service;
- with your consent, to send marketing communications.
4. Legal Bases (GDPR)
Where the GDPR or UK GDPR applies, we rely on the following legal bases:
5. Sharing with Third Parties
We share personal information only as described below and only to the extent reasonably necessary:
- Stripe — payments, escrow, payouts, and identity verification.
- Resend — transactional email delivery.
- Google (Places / Address Validation) — address auto-completion and validation.
- Emergent — application hosting, database, and object storage.
6. International Transfers
7. Data Retention
- Account data — for the life of the account and up to 24 months after closure, unless a longer retention is required by law.
- Transaction records — 7 years from the end of the relevant financial year for tax and accounting compliance.
- Licensing Agreements — for the term of the licence plus 7 years.
- Identity verification records — for the period required by anti-money-laundering laws (typically 7 years).
- Support communications — 3 years from resolution.
- Marketing preferences — until withdrawal of consent plus 6 months.
8. Security
We implement technical and organisational measures designed to protect personal information, including encryption in transit (TLS 1.2+), encryption at rest for sensitive stores, access controls, secret rotation, audit logging, and regular security review of the Service. No system is perfectly secure, and we cannot guarantee absolute security.
9. Your Rights
Subject to applicable law, you have the following rights:
- Access — to obtain a copy of personal information we hold about you.
- Rectification — to have inaccurate personal information corrected.
- Erasure — to request deletion of personal information, subject to legal retention obligations.
- Restriction — to restrict processing in defined circumstances.
- Portability — to receive certain personal information in a structured, commonly used, machine-readable format and to have it transmitted to another controller.
- Objection — to object to processing based on legitimate interests, and to processing for direct marketing.
- Withdraw consent — where processing is based on consent, at any time, without affecting the lawfulness of prior processing.
- Complain — to lodge a complaint with your data-protection authority.
Requests may be exercised via the in-app support flow (Dashboard → Help & Support → Contact, category ‘Privacy’) or by emailing support@mylikeness.com.au. We will respond within the time limits required by applicable law (generally 30 days).
10. California Privacy Rights (CCPA/CPRA)
If you are a California resident, you have the additional rights to (i) know the categories and specific pieces of personal information we have collected about you, the sources, purposes, and third parties with whom it has been shared; (ii) delete personal information; (iii) correct inaccurate personal information; (iv) opt out of the sale or sharing of personal information (we do not sell or share); (v) limit the use of sensitive personal information; and (vi) not be discriminated against for exercising these rights. To exercise these rights, contact us via the in-app support flow or at support@mylikeness.com.au.
11. Australian Privacy Principles
If you are located in Australia, our handling of personal information is subject to the Australian Privacy Principles under the Privacy Act 1988 (Cth). If you believe we have breached the Australian Privacy Principles, please contact us via the in-app support flow (category ‘Privacy’) or at support@mylikeness.com.au. If you are not satisfied with our response, you may lodge a complaint with the Office of the Australian Information Commissioner (‘OAIC’) at oaic.gov.au.
13. Children's Privacy
The Service is not directed to, and is not intended for use by, children under the age of eighteen (18). We do not knowingly collect personal information from children. If you become aware that a child has provided personal information to us, please contact us via the in-app support flow (category ‘Trust & Safety’) or at support@mylikeness.com.au and we will delete it.
14. Changes to this Policy
We may update this Policy from time to time. Material changes will be notified by email to the address associated with your account and/or by prominent notice on the Service at least fourteen (14) days before the changes take effect.
15. Contact
Mylikeness Pty Ltd
All privacy enquiries and rights requests (access, rectification, erasure, portability, restriction, objection, withdrawal of consent, and complaints) should be submitted via the in-app support flow (Dashboard → Help & Support → Contact) using the ‘Privacy’ or ‘Trust & Safety’ category if you have an account, or by email to support@mylikeness.com.au. Please state clearly that your enquiry concerns privacy so it is routed to the appropriate team.