Privacy Policy

hdn.bio · Last updated [[YYYY-MM-DD]]

This policy explains what personal data hdn.bio collects, why, on what legal basis, and the rights you have under the EU General Data Protection Regulation (GDPR). It applies to our public link-in-bio pages and to our paid companion chat service.

1. Controller

[[OPERATOR LEGAL NAME]][[STREET + NO.]][[POSTAL CODE + CITY]][[COUNTRY]]

Privacy contact: [[CONTACT EMAIL]]. Full provider details are in our Imprint.

2. Your rights

Under the GDPR you have the right to:

  • access the personal data we hold about you (Art. 15);
  • rectify inaccurate data (Art. 16);
  • erasure (Art. 17);
  • restriction of processing (Art. 18);
  • data portability (Art. 20);
  • object to processing based on legitimate interest (Art. 21);
  • withdraw consent at any time, without affecting prior processing (Art. 7(3)).

To exercise any of these rights, contact [[CONTACT EMAIL]] free of charge. You also have the right to lodge a complaint with a data-protection supervisory authority, in particular the authority of your habitual residence or the competent authority for our establishment ([[COMPETENT SUPERVISORY AUTHORITY]]).

3. Data we process

  • Chat content & relationship memory. When you chat with our companion service we process your messages and derive a persistent profile (e.g. your name, preferences, recurring topics, conversation history) so the persona can remember you across sessions. This is a core feature of the service and may include data you choose to reveal about yourself.
  • Messaging identifiers. The chat runs over Telegram, so we receive the identifiers Telegram exposes (e.g. your Telegram user/chat ID and username).
  • Payment data. Membership and pay-per-view purchases are processed by Stripe. We receive transaction metadata (amount, currency, status, a purchase reference); we do not receive or store full card details.
  • Usage & technical data. When you open a bio page or follow a link we log technical data such as IP address, timestamp, user agent, referrer, and click/view events to provide and secure the service (Art. 6(1)(f) GDPR; security log data is deleted after a short period unless needed to investigate an incident).
  • Cookies / device data. See section 7.

4. Purposes & legal bases

  • Providing the chat and link-in-bio services — performance of a contract (Art. 6(1)(b) GDPR).
  • Processing payments — performance of a contract and compliance with legal (e.g. tax) obligations (Art. 6(1)(b), (c) GDPR).
  • Security, abuse prevention, and analytics — our legitimate interest in operating and protecting the service (Art. 6(1)(f) GDPR).
  • Age confirmation and any optional cookies — your consent (Art. 6(1)(a) GDPR; § 25(1) TDDDG), where required.
  • Where adult-content data reveals data of a special category, processing is based on your explicit consent (Art. 9(2)(a) GDPR).

5. Automated processing by AI providers

Our companion chat is operated by an AI persona, not a human. To generate replies, the content of your messages and the relevant relationship-memory context is sent to third-party large-language-model and embedding providers acting as our processors. They generate responses on our behalf; where the option exists, we instruct them not to use your data to train their own models. The service is for entertainment and companionship and does not make automated decisions that produce legal effects concerning you or similarly significantly affect you (Art. 22 GDPR).

6. Recipients & processors

We share data only with the providers needed to run the service. Some are located outside the EU/EEA; such transfers are safeguarded by an adequacy decision (e.g. the EU–US Data Privacy Framework) or the EU Standard Contractual Clauses (Art. 44 ff. GDPR).

ServicePurposeRegion
TelegramMessage transportEU / international
StripePayment processingEU / USA (DPF)
SupabaseApplication database & storageEU
Cloudways / VercelHosting of the worker and web appEU / USA (DPF)
Cloudflare (Turnstile)Bot / abuse protectionEU / USA (DPF)
LLM & embedding providers (e.g. OpenRouter, Voyage, Google)Reply generation & searchEU / USA (DPF / SCC)

7. Cookies & device data

We store and read information on your device only where strictly necessary to provide the service you requested, or otherwise with your consent (§ 25 TDDDG):

  • bio18 — stores your 18+ age confirmation so you are not asked again (strictly necessary for the adult-content gate).
  • cookieok — remembers that you dismissed our cookie notice.
  • Stripe / Turnstile cookies — set by those providers on checkout and protected pages for fraud prevention and security.

8. Retention

Because persistent memory is a core feature, chat history and the associated profile are retained for as long as the relationship is active; we do not auto-delete them. Payment and invoicing records are kept for the periods required by law. You can ask us to erase your data at any time (section 2); erasure is carried out as a single atomic operation across our systems. Any copy of the conversation stored in your own Telegram client is outside our control.

9. Data security

We use transport encryption (TLS) and appropriate technical and organisational measures to protect your data against manipulation, loss, and unauthorised access. Access to the underlying data is restricted to what is necessary to operate the service.

10. Children

The service is intended exclusively for adults. It is not directed to anyone under 18, and we do not knowingly process the data of minors.

11. Changes

We may update this policy as the service evolves. The current version always carries the effective date shown at the top of this page.

Terms·Privacy·Imprint

[[OPERATOR LEGAL NAME]] · hdn.bio