myProfile247
How it worksConfidenceUse casesDatingBusinessAgeRentingCredentialsSecurityRelease notes
Log inGet started
Legal

Privacy Policy

How myProfile247 collects, uses, protects and shares your personal information — and the rights you have over it.

Version 1.0·Effective 22 June 2026·Last updated 22 June 2026

On this page

  1. Who we are & scope
  2. The personal information we collect
  3. California categories of information
  4. How we collect it
  5. Why we use it & our legal bases
  6. How we protect it — our encryption model
  7. Cookies & similar technologies
  8. Blockchain anchoring
  9. When we disclose information & our subprocessors
  10. International data transfers
  11. How long we keep information
  12. Security
  13. Your privacy rights
  14. How to exercise your rights & complaints
  15. Children's privacy
  16. Automated decision-making & profiling
  17. Changes to this policy
  18. Contact us
In plain English

myProfile247 is an attribute wallet: you store facts about yourself and choose who to share them with. We are built to hold as little readable data as possible. Many attribute values are encrypted: values you encrypt on your own device (client-side, end-to-end) cannot be read by us at all, while others are encrypted at rest on our servers — see section 6 for the difference.

  • We collect your account details (email, names, optional handle), the attributes you add, technical/usage data, and identity-verification outcomes (only the result, never your documents).
  • We never store plaintext passwords (only salted hashes), and we hash IP addresses and session tokens.
  • We do not sell or share your personal information, and we use no third-party advertising or marketing trackers.
  • Only a salted, one-way hash of an aggregate log goes onto the public XRP Ledger — never your personal data, attribute values, names, emails, images or files.
  • You can access, correct, export and erase your data by contacting us. Self-service tools for deletion and export are not yet built; today these are handled on request.

1.Who we are & scope

myProfile247 (myprofile247.com) is a user-owned attribute wallet and self-sovereign identity service. It lets you store "attributes" — facts about yourself — each with a confidence score (0 to 100) and a trust tier (self, peer, official or authority), and to selectively disclose those attributes to other people and organisations. The service also supports peer attestation and verification, optional identity verification, and tamper-evident, on-chain receipts of actions.

myProfile247 is operated by eTech Consulting (Australia). eTech Consulting is the entity responsible for your personal information — the data controller under the EU and UK General Data Protection Regulation (GDPR), and the APP entity responsible under the Australian Privacy Act 1988 (Cth). In this policy "we", "us" and "our" mean eTech Consulting. The same operator also runs its own analytics and secrets infrastructure under the name "Asset of Things"; that infrastructure is operated by us and is not a separate third party.

Operator / data controller
eTech Consulting (Australia)
ABN / ACN
[ABN / ACN — TO BE COMPLETED]
Registered address
[REGISTERED BUSINESS ADDRESS — TO BE COMPLETED]
Privacy contact
privacy@myprofile247.com
Website
https://myprofile247.com
Data Protection Officer (DPO)
[DPO NAME / CONTACT — TO BE COMPLETED, OR "no DPO is appointed; we are not required to appoint one under Article 37 of the GDPR"]. Until a DPO is named, please direct privacy matters to the privacy contact above.
EU / UK Article 27 representative
[ARTICLE 27 REPRESENTATIVE NAME / CONTACT — TO BE COMPLETED, OR "no Article 27 representative is appointed because we assess that the conditions in Article 27(2) are not met"]. This value must be reviewed and completed before relying on this policy for EEA/UK users.

This policy applies to myProfile247 on the web and in our mobile apps, and to residents of Australia, the European Economic Area (EEA), the United Kingdom and California, as well as everyone else who uses the service. It explains in general terms what we collect and hold, how we collect and hold it, why we use it, and your rights. It is read together with our Cookie Policy and our Terms & Conditions.

This policy is published free of charge on our website and is kept up to date. We will provide it in another reasonable form on request. This policy is not a substitute for the collection notice we give you at or before the point of collection (for example, on a signup form), as required by Australian Privacy Principle (APP) 5 and Articles 13 and 14 of the GDPR.

2. The personal information we collect

The kinds of personal information we collect and hold depend on how you use myProfile247. Described in general terms, they are:

Account & identity data

When you sign up locally we collect:

  • Email address (required, and unique to your account);
  • First name and last name (required), and middle name (optional);
  • a handle / username (optional — if you leave it blank, we generate one from your name);
  • a password (optional). If you set one, we store it only as a salted hash — your plaintext password is never stored and cannot be retrieved by us.

Social-login data

If you choose to sign in with Facebook, Google or LinkedIn (using OAuth / OpenID Connect), we request only the provider's public profile and email scopes. From the provider we receive the subject identifier (a stable id for your account with that provider) and your email. We do not persist the provider's access tokens on our servers.

Profile data & encrypted attributes

Your profile record holds your:

  • account id, email, names and display name, and handle;
  • role (Person or Organisation), access role, a UI colour, a directory code (for example MP-XXXXX), and a created-at timestamp.

On top of this you can add attributes (each with a key, label, category and value-kind), assign them confidence scores and trust tiers, attach media assets (images and documents) to them, and group attributes into collections that you can mark public or private. Attribute values and media are encrypted — see section 6.

Some attributes you choose to store may amount to sensitive information under APP 3 or a special category of personal data under Article 9 of the GDPR (for example health, biometric, racial or ethnic, religious or sexual-orientation information), or to sensitive personal information (SPI) under the California Privacy Rights Act (for example account credentials, precise geolocation, or health data). You decide whether to add such attributes. Where you do, you consent to our storing and (when you direct us) disclosing them for the purpose of operating your wallet; for GDPR special-category data the condition we rely on is your explicit consent (Article 9(2)(a)). We do not require you to provide sensitive information to use the core service.

Identity-verification (IDV) outcomes

If you choose to verify your identity through a third-party IDV provider, we store only the verification outcome and a provider reference. We do not store your raw identity documents or selfies.

Sessions, tokens & technical data

  • Access and refresh tokens are stored as hashes, not in plaintext.
  • Session records include a hashed IP address (never plaintext), a device label, and the browser/device User-Agent string.
  • Mobile apps use short-lived (about three-minute) login tickets that are exchanged for session tokens.

Usage & analytics data (self-hosted OpenPanel)

We use our own self-hosted OpenPanel analytics. On the web, the client may capture page and screen views, outgoing link clicks, and configured attribute events; this is gated by an environment flag and a build-time client id. On the server, we capture one event per HTTP request containing the request method, both the route template and the raw request path (which can include identifiers contained in the URL), the status code and duration, the authenticated user id (if you are signed in), the client IP address (the real, unhashed IP via X-Forwarded-For, honouring our reverse proxy), and the User-Agent. There are no third-party advertising or marketing trackers (no Google Analytics, no Meta / Facebook Pixel) and no third-party error-tracking service is actively used.

Cookies & local storage

We set strictly-necessary authentication cookies and keep a non-sensitive UI mirror in your browser, and our mobile apps use the device's secure store. These are summarised in section 7 and detailed in our Cookie Policy.

3. California categories of information

This section is for California consumers and maps the personal information described in section 2 to the statutory categories in the California Consumer Privacy Act, as amended by the California Privacy Rights Act (together, the "CCPA"). For each category it states whether we collect it, the sources, the business or commercial purpose, and the categories of recipients to whom we disclose it for a business purpose. We do not "sell" or "share" (for cross-context behavioural advertising) any of these categories.

CCPA categoryCollected?SourcesBusiness / commercial purposeCategories of recipients
Identifiers (name, email, account id, handle, directory code, IP address)YesYou; OAuth providers (if you use social login)Account creation, authentication, operating your wallet, securityHosting/database (operator-run), OAuth providers (only if used)
Customer records (Cal. Civ. Code 1798.80(e)) — name, account credentialsYes (passwords only as salted hashes)YouAuthentication and account managementHosting/database (operator-run)
Protected classification characteristicsOnly if you choose to add them as attributes (optional)YouStoring and disclosing attributes you choose to addRecipients you direct (selective disclosure)
Commercial informationNo (no purchases; there are no paid features)Not applicableNot applicableNot applicable
Internet / electronic network activity (usage, request metrics, User-Agent)YesAutomatically, when you use the serviceReliability, diagnostics and security analyticsOperator-run analytics (OpenPanel)
Geolocation dataCoarse only, inferred from IP; no precise geolocation unless you add it as an attributeAutomatically (IP); you (if added as an attribute)Security and diagnostics; storing attributes you choose to addOperator-run analytics; recipients you direct
Sensory data (images/documents attached to attributes)Only if you attach media to an attribute (encrypted)YouOperating your wallet and selective disclosureRecipients you direct
Professional / employment informationOnly if you add it as an attribute (optional)YouStoring attributes you choose to addRecipients you direct
Education informationOnly if you add it as an attribute (optional)YouStoring attributes you choose to addRecipients you direct
Inferences (for example confidence scores)Yes (confidence scores computed from attestations and trust tiers)Derived from attestations and your attributesInformational trust signals shown to you and recipients you chooseYou and recipients you direct

Sensitive personal information (SPI). We collect SPI only in the following categories, and only as needed to provide and secure the service (not to infer characteristics about you):

  • Account log-in credentials — your password is stored only as a salted hash;
  • Precise geolocation, contents of communications, racial or ethnic origin, religious or philosophical beliefs, health, sex life or sexual orientation, and biometric or genetic data — only if you choose to store such information as an attribute or attached media. We do not require it for the core service.

Right-to-know look-back. When you make a verifiable request to know, we will disclose the personal information collected, used, disclosed and (if applicable) sold or shared over at least the preceding 12 months. For personal information collected on or after 1 January 2022, we will also respond to a request that covers a period beyond the prior 12 months, unless doing so proves impossible or would involve a disproportionate effort. We use SPI only for the permitted purposes in Cal. Civ. Code 1798.121, so the right to limit the use of SPI for additional purposes is not engaged by our practices.

4. How we collect it

  • Directly from you — when you sign up, set or change a password, build your profile, add attributes and media, create collections, request peer attestations, or contact us.
  • Automatically — through cookies, your browser's local storage, your device's secure store, session records, and our self-hosted server-side analytics, when you use the service.
  • From third parties you choose to involve — from OAuth providers (Facebook, Google, LinkedIn) when you use social login, and from IDV providers (such as Yoti, Persona, Veriff, or mobile driver's-licence / mDL verifiers) when you choose to verify your identity. We also receive peer attestations when other users attest to your attributes.

Where the GDPR's Article 14 applies because data did not come directly from you (for example the subject identifier from an OAuth provider, or a verification outcome from an IDV provider), the source is that provider; these are not publicly accessible sources.

If you do not provide certain information, we may be unable to provide the service. In particular, an email address is required to create an account; without it you cannot register. Names are required to create a profile. Most other information (handle, password, attributes, media, identity verification) is optional, though omitting it may limit features — for example, you cannot benefit from identity verification if you do not complete it.

5.Why we use it & our legal bases

We collect, hold, use and disclose personal information only for the purposes below. The primary purpose is to operate your attribute wallet and the related purposes are necessarily connected to it (relevant to APP 6). For users in the EEA and UK, the table maps each purpose to a lawful basis under Article 6 of the GDPR.

PurposeWhat this involvesGDPR lawful basis (Art. 6)
Create and manage your accountRegistration, authentication, sessions, social login, password verification.Performance of a contract (6(1)(b)); consent for social login (6(1)(a)).
Operate your walletStoring and encrypting your attributes, media and collections; computing confidence scores; enabling selective disclosure and grants.Performance of a contract (6(1)(b)).
Peer attestation & verificationRecording attestations from other users and trust tiers.Performance of a contract (6(1)(b)); consent of the attesting user (6(1)(a)).
Identity verificationRecording the outcome and provider reference of an optional IDV check you start.Consent (6(1)(a)); special-category condition explicit consent (Art. 9(2)(a)) where applicable.
Sensitive / special-category attributesStoring and disclosing attributes you choose to add that are sensitive.Consent (6(1)(a)) plus explicit consent as the Art. 9(2)(a) condition.
Security, fraud prevention & integrityHashed IPs/tokens, session records, the tamper-evident transparency log and its on-chain anchor.Legitimate interests (6(1)(f)): keeping the service and your data secure and tamper-evident.
Service analytics & reliabilitySelf-hosted OpenPanel page/route, status, duration and user-agent metrics to understand usage and diagnose problems.Consent (6(1)(a)) for EEA/UK visitors, because this storage/access is non-essential. As explained in section 7, consent is not yet collected because a consent banner is not yet implemented.
Communicating with you & handling requestsResponding to support and privacy requests and complaints.Performance of a contract (6(1)(b)); legal obligation (6(1)(c)); legitimate interests (6(1)(f)).
Complying with the lawMeeting legal, regulatory and record-keeping obligations.Legal obligation (6(1)(c)).

Where we rely on legitimate interests (Article 6(1)(f)), those interests are operating a secure, reliable, tamper-evident identity service and preventing fraud and abuse; we have balanced them against your rights and you can object (see section 13). We do not rely on legitimate interests for non-essential product analytics, where consent is the appropriate basis (see section 7). Where we rely on consent, you can withdraw it at any time without affecting processing already carried out. We will not use your personal information for a new, unrelated purpose without first telling you and, where required, obtaining your consent.

We do not use your personal information for direct marketing, and we do not currently send marketing messages. There is no third-party transactional email provider wired in and there are no paid features, so we use no payment processor.

6. How we protect it — our encryption model

Encryption is a core design feature of myProfile247. Attribute values and media are encrypted, in one of two ways depending on origin:

  • Client (end-to-end) encryption — encrypted on your device before it reaches us. Our servers store only opaque ciphertext that we cannot read. For these values we genuinely cannot see your data.
  • Server-side encryption at rest — using XChaCha20-Poly1305 authenticated encryption, with a per-value data-encryption key wrapped by a key-encryption key, whose key material is sealed by a deployment root key. Because our systems hold this key material, server-encrypted values can be decrypted by us in the course of operating the service; this is encryption against external compromise, not a promise that we can never read them.

Device keys. The server stores only your public keys (X25519 for key agreement and Ed25519 for signing). Your private keys remain on your device.

Zero-knowledge key backup. Your identity root key is sealed by a key derived from your passphrase (using Argon2id) and/or by social-recovery shards. The server can never open it.

Crypto-shredding. Marking a key as "shredded" destroys the wrapped key material so the associated data becomes permanently unrecoverable. This is how we support deletion and erasure of encrypted data. The effectiveness of crypto-shredding depends on robust key management and on current cryptographic assumptions remaining sound.

7.Cookies & similar technologies

On the web we use:

  • mp_access — a strictly-necessary authentication cookie (HttpOnly, Secure, lasting about 30 minutes);
  • mp_refresh — a strictly-necessary authentication cookie (HttpOnly, Secure, lasting about 30 days);
  • mp_session — a non-secret UI mirror held in your browser's localStorage (user id, email, names, handle, role, colour, directory code and API base URL) so the interface can render without an extra round-trip.

Our mobile apps store tokens in the operating system's secure store (Expo SecureStore) and non-sensitive metadata in AsyncStorage.

The authentication cookies above are strictly necessary and are exempt from prior consent under the ePrivacy rules (including the UK PECR). Our self-hosted OpenPanel analytics, although first-party, is generally not strictly necessary and would require prior consent for EEA and UK visitors. Honestly: a cookie-consent banner is not yet implemented, so analytics currently runs without a consent gate. We do not claim full ePrivacy / cookie-consent compliance, and we do not rely on legitimate interests as a substitute for the consent that the ePrivacy rules require. Adding a consent banner and gating analytics behind it is a committed follow-up. In the meantime, EEA/UK visitors can opt out using browser controls, "Do Not Track", or a Global Privacy Control (GPC) signal. Full details are in our Cookie Policy.

8. Blockchain anchoring

myProfile247 keeps an append-only transparency log: a Merkle tree (RFC 6962 style) over SHA-256 commitments of audit events, whose signed tree head is signed with Ed25519. Third parties can verify inclusion proofs, giving you tamper-evident receipts of actions.

We periodically anchor the state of this log to the public XRP Ledger (XRPL) as additional public notarisation. The only value written on-chain is a salted Merkle root — SHA-256(salt : rootHash) — together with the tree size.

What never goes on-chain: personal information, attribute values, images, document or content hashes, raw Merkle roots, salts, ciphertext, names, emails, or any per-record data.

What this means for erasure

The on-chain value is a salted, one-way hash of an aggregate tree head — not of any individual record. It is not reasonably re-identifiable, so we consider it not "personal data" under Article 4(1) of the GDPR or "personal information" under section 6 of the Privacy Act. The immutable ledger entry is therefore not itself subject to erasure. (We do not claim it is "anonymous" in an absolute sense; the salt is held by us server-side. We describe it as not reasonably identifiable.)

Your right to erasure is satisfied off-chain by crypto-shredding. On a valid erasure request (GDPR Article 17) or destruction request (APP 11.2), we destroy the off-chain plaintext and the keys that decrypt it, so any remaining ciphertext becomes permanently unrecoverable — effective erasure. The historical salted root legitimately remains for integrity and non-repudiation. This off-chain-storage-plus-crypto-shredding approach is the recognised way to reconcile an immutable ledger with the right to erasure; it is a method of erasure, not a refusal to erase.

Honest limitation: the on-chain anchor cannot be altered or deleted. We do not promise to delete anything written to the public chain. We retain the salted root on lawful bases — GDPR Article 17(3)(b) and (e) and our legitimate interest in tamper-evidence and fraud prevention, with equivalent reasoning under the APPs. Regulators (such as the EDPB and France's CNIL) accept off-chain storage with on-chain hashes plus crypto-shredding as a reasonable approach, but it has not been universally blessed as fully Article 17-compliant in every case.

9.When we disclose information & our subprocessors

We do not sell or share your personal information, and we use no third-party advertising or marketing trackers. We disclose information only as described below — to operate the service, when you direct us to (for example, by sharing an attribute with someone), or where the law requires. The subprocessors and recipients we rely on, and only these, are:

Recipient / subprocessorPurposeLocation
Self-hosted PostgreSQL databasePrimary storage of your account, profile and (encrypted) data.Our own server (Australia)
Docker + Traefik reverse proxyApplication deployment and TLS / HTTPS termination.Our own server (Australia)
CloudflareDNS resolution only (no proxying of personal data through Cloudflare).Global / United States
Self-hosted OpenPanel ("Asset of Things")First-party usage analytics on our own infrastructure.Operator infrastructure (Australia)
Public XRP Ledger networkAnchoring the salted Merkle root only. No personal information is written on-chain, so the ledger is not a recipient of personal information (see note below).Decentralised / global
OAuth providers (Facebook, Google, LinkedIn)Social login — only when you choose it.United States / global
IDV providers (e.g. Yoti, Persona, Veriff, mDL verifiers)Identity verification — only when you choose it.Varies by provider (e.g. UK, EU, US, Australia)
Infisical (operator's secrets infrastructure)Internal secrets management — holds no user personal data. Reached at a hosted vault endpoint operated for us.Hosted secrets endpoint; hosting location to be confirmed — treated as a possible overseas recipient in section 10

Note on the public XRP Ledger. Consistent with section 8, the only value anchored on-chain is a non-identifying, salted aggregate hash. No personal information, attribute values, names, emails, images, file hashes, salts or ciphertext are ever written to the ledger. We therefore do not treat the XRPL as a subprocessor or recipient of personal information in the GDPR or APP sense; it is included in this table only for completeness of our data flows.

We may also disclose personal information to professional advisers, or to courts, regulators and law-enforcement bodies, where reasonably necessary to comply with the law or to establish, exercise or defend legal claims. There is currently no third-party transactional email provider and no payment processor in use.

California (CCPA/CPRA): we do not "sell" your personal information and we do not "share" it for cross-context behavioural advertising, and we have not done so in the preceding 12 months. We disclose personal information to the subprocessors above for the business purposes shown (see also the per-category disclosure in section 3). Because we do not sell or share, a "Do Not Sell or Share My Personal Information" link and a "Limit the Use of My Sensitive Personal Information" link are not required; we nonetheless honour opt-out preference signals such as the Global Privacy Control for the analytics described in section 7.

10. International data transfers

Our core systems — the PostgreSQL database, application servers and OpenPanel analytics — are hosted on the operator's own infrastructure in Australia. Some recipients are nonetheless likely to be located overseas:

  • Cloudflare (DNS) operates globally, including in the United States;
  • OAuth providers (Facebook, Google, LinkedIn) are based in the United States — engaged only if you use social login;
  • IDV providers may be located in the United Kingdom, the EU, the United States or Australia depending on the provider you choose;
  • Infisical — our internal secrets manager is reached at a hosted vault endpoint whose hosting location we are confirming; we treat it as a possible overseas recipient out of caution, although it holds no user personal data (only application secrets);
  • the public XRP Ledger is decentralised and global — but, as explained in section 8, it never receives personal data.

For Australia (APP 8 and section 16C): where we disclose personal information to an overseas recipient, we remain accountable for that recipient's handling of it as if we had done the act ourselves, unless an exception applies (such as your consent under APP 8.2, or a substantially similar law). We take reasonable steps to ensure overseas recipients handle your information consistently with the APPs.

For the EEA and UK (GDPR Chapter V, Articles 44 to 49): where personal data is transferred to a third country without an adequacy decision (EU) or adequacy regulations (UK), we rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses, or the UK International Data Transfer Agreement (IDTA) or UK Addendum, supported by a transfer risk assessment and supplementary measures (notably encryption) where needed; or, where applicable, on an Article 49 derogation such as your explicit consent or transfer necessary for a contract. You can ask us for a copy of the relevant safeguards using the contact in section 18.

11. How long we keep information

We keep personal information only for as long as we need it for the purposes in section 5, or for as long as required by law. The periods or criteria for each category are:

  • Account, profile and attribute data — for as long as your account is active, and then until you ask us to delete it (see below). Determining criterion: the life of your account plus the time needed to action a deletion request.
  • Session records and tokens — only for the life of the session; access cookies last about 30 minutes and refresh cookies about 30 days, and tokens are held as hashes. Expired session records are not retained beyond what is needed for security review.
  • Server analytics events — retained for up to 14 months from the date of the event, after which they are deleted or irreversibly aggregated into non-identifying statistics. Determining criterion: the period needed to understand year-over-year usage and diagnose problems.
  • Identity-verification outcomes — kept as part of your profile while the account is active, and deleted with the account on a deletion request.
  • The salted root on the XRP Ledger — permanent and immutable, but it contains no personal data (section 8).

California per-category retention (CCPA/CPRA). We do not retain any category of personal information, or sensitive personal information, for longer than is reasonably necessary for the purpose for which it was collected. The retention period or determining criterion for each statutory category in section 3 is the same as the period set out above for the corresponding data: identifiers, customer records, sensory data and inferences are kept for the life of the account and then until deletion is actioned; internet/network activity (analytics) is kept for up to 14 months and then deleted or aggregated; and SPI (such as hashed credentials) is kept only while the account is active.

Honest position on deletion and export: there is currently no self-service production endpoint to delete your account or export your data (the only debug endpoints are disabled in production). Account deletion and data export are available on request via privacy@myprofile247.com. On a valid deletion request, crypto-shredding can render your encrypted data permanently unrecoverable. Self-service deletion and export tools are planned. We do not claim a self-service delete or export button exists today.

12. Security

We take reasonable steps to protect your personal information, including: encryption in transit (TLS / HTTPS), encryption at rest, end-to-end encryption for client-encrypted values we cannot read, salted-hashed passwords, hashed session tokens, hashed IP addresses, and a signed, tamper-evident transparency log (section 8). Private keys for end-to-end-encrypted data remain on your device.

Despite these measures, no method of transmission over the internet or method of electronic storage is 100% secure. We cannot guarantee absolute security, but we maintain a data-breach response process. Under Australia's Notifiable Data Breaches scheme, where we suspect an eligible data breach we assess it expeditiously — within 30 days at the latest, which is a maximum rather than a target. An eligible data breach is one likely to result in serious harm; if our assessment confirms an eligible breach, we will promptly notify the OAIC and the affected individuals and set out recommended remedial steps. We will likewise notify the relevant supervisory authority and affected individuals as required under the GDPR.

13. Your privacy rights

Your rights depend on where you live. We make all of these available free of charge, subject to verifying your identity.

Australia — Australian Privacy Principles

  • Access (APP 12) — you can request access to the personal information we hold about you; we will respond within a reasonable period (within 30 days for an organisation) and give access in the manner you request where reasonable. Access may only be refused on limited grounds, with written reasons.
  • Correction (APP 13) — you can ask us to correct information that is inaccurate, out of date, incomplete, irrelevant or misleading; we will take reasonable steps to correct it and, where you ask and it is reasonable, notify others of the correction.
  • Refusal notice (APP 12.9 / 13.4) — if we refuse access or correction, you are entitled to written reasons and information about how to complain.
  • Statement of disputed accuracy (APP 13.4) — if we refuse to correct information, you can ask us to attach a statement noting your view, and we will take reasonable steps to do so.
  • Anonymity and pseudonymity (APP 2) — you can deal with us without identifying yourself where practicable; note that some features (such as identity verification) require identification.
  • Direct marketing (APP 7) — we do not use your information for direct marketing; you can ask us to stop at any time.
  • No fee — we do not charge for making an access or correction request, and correction is free.

EEA & United Kingdom — GDPR / UK GDPR

  • Access (Art. 15) — confirmation of processing, a copy of your data, and supplementary information.
  • Rectification (Art. 16) — correction of inaccurate data and completion of incomplete data.
  • Erasure / "right to be forgotten" (Art. 17) — deletion where a ground applies; satisfied off-chain by crypto-shredding as described in section 8, subject to exemptions.
  • Restriction (Art. 18) — pausing or limiting processing in defined circumstances.
  • Portability (Art. 20) — receiving data you provided in a structured, commonly used, machine-readable format, where processing is based on consent or contract and is automated.
  • Objection (Art. 21) — objecting to processing based on legitimate interests; an absolute right to object to direct marketing (which we do not do).
  • Withdraw consent (Art. 7(3)) — where we rely on consent, you can withdraw it at any time, as easily as you gave it, without affecting prior lawful processing.
  • Lodge a complaint (Art. 77) — with the ICO (UK) or your competent EU supervisory authority (see section 14).

California — CCPA / CPRA

  • Right to know / access — the categories and specific pieces of personal information we collect, the sources, the business or commercial purposes, and the categories of third parties to whom it is disclosed (see section 3).
  • Right to delete — deletion of personal information we collected from you, subject to statutory exceptions.
  • Right to correct — correction of inaccurate personal information we maintain.
  • Right to opt out of sale / sharing — we do not sell or share your personal information, so there is nothing to opt out of; we still honour Global Privacy Control signals for the analytics in section 7.
  • Right to limit sensitive personal information — we use sensitive information only to provide the service and other permitted purposes, so the separate "limit" right is not engaged by additional uses.
  • Right to non-discrimination — we will not deny you service, charge you a different price, or give you a different quality of service for exercising your rights. We offer no financial incentives.
  • Right to data portability — to receive information from a know/access request in a portable, readily usable format where technically feasible.
  • Authorized agent — you may use an authorised agent to submit requests on your behalf; see section 14 for how we verify an agent's authority.

For California requests we will acknowledge within 10 business days and respond within 45 calendar days, extendable by a further 45 days with notice, after verifying your identity.

14.How to exercise your rights & complaints

To exercise any right above, you can contact us using either of the following methods. We will verify your identity before acting and will respond within the timeframes set out above. As noted in section 11, deletion and export are currently handled on request because self-service tools are not yet built.

  • Email — write to privacy@myprofile247.com with the subject "Privacy request"; and
  • Online request form — submit a request through the contact form on our website at https://myprofile247.com (this provides a second designated method for California consumers as required by the CCPA). If the form is unavailable, the email method above remains valid.

Authorised agents (California). An authorised agent may submit a request on your behalf. We will ask the agent to provide signed permission demonstrating that you authorised them to act for you, and we may also ask you to verify your own identity directly with us and to confirm that you gave the agent permission. We may deny a request from an agent who cannot provide proof of authorisation.

Complaints — Australia. If you believe we have breached the APPs, please complain to us first at privacy@myprofile247.com. We will investigate and respond, generally within 30 days. If you are not satisfied, or we have not responded within about 30 days, you can escalate to the Office of the Australian Information Commissioner (OAIC) at oaic.gov.au.

Complaints — EEA & UK. You also have the right to lodge a complaint with a supervisory authority: in the UK, the Information Commissioner's Office (ICO) at ico.org.uk; in the EEA, your local Data Protection Authority. We would appreciate the chance to address your concern first.

15. Children's privacy

myProfile247 is not directed to, and must not be used by, anyone under 16. We do not knowingly collect personal information from children, and if we discover that we have, we will delete it.

Honest disclosure: we do not currently enforce a technical age gate at signup, and we do not record a date of birth on the core profile. "Over 18" exists only as an optional, self-attested or verifiable attribute. We do not claim to technically prevent minors from registering; the position above is a policy stance and a contractual requirement. We will not knowingly sell or share the personal information of a consumer under 16, consistent with our practice of not selling or sharing personal information at all. Were we ever to sell or share personal information, we would not do so for a consumer we know to be under 16 without affirmative authorisation (opt-in): the consumer themselves for ages 13 to 15, and a parent or guardian for a child under 13, as required by the CCPA/CPRA.

16.Automated decision-making & profiling

Each attribute carries a confidence score computed from attestations and trust tiers. These scores are informational signals shown to you and to the people and organisations you choose to share with. They help you and others judge how well-supported an attribute is.

We do not use confidence scores, or any other processing, to make solely automated decisions that produce legal or similarly significant effects on you. There is therefore no automated decision-making of the kind addressed by Article 22 of the GDPR. Should we ever introduce such processing, we will tell you, explain the logic and consequences, and provide the safeguards required by law — including, where applicable, the automated-decision-making transparency disclosures coming into effect under the Australian Privacy Act amendments. Any decisions that significantly affect you (such as suspending an account) involve human judgement.

17. Changes to this policy

We keep this policy up to date and will revise it when our data practices, vendors, overseas recipients or purposes change, and review it periodically (and at least every 12 months for California consumers). The version and dates appear at the top of this page. Where we begin processing your personal information for a new, unrelated purpose, we will tell you and, where required, obtain your consent before doing so. The operator may update this policy from time to time; material changes will be highlighted.

18. Contact us

For any privacy question, request or complaint, contact our privacy team at privacy@myprofile247.com.

Operator / data controller
eTech Consulting (Australia)
ABN / ACN
[ABN / ACN — TO BE COMPLETED]
Registered address
[REGISTERED BUSINESS ADDRESS — TO BE COMPLETED]
Email
privacy@myprofile247.com

This policy is governed by the law of Victoria, Australia, and should be read with our Terms & Conditions and Cookie Policy.

This document is provided for general information and transparency. It is not legal advice. myProfile247 is operated by eTech Consulting (Australia). Questions? Contact privacy@myprofile247.com.

Terms & Conditions Cookie Policy
myProfile247

One verified you, shared on your terms. Self-sovereign identity with confidence scoring and on-chain receipts.

Launch the app
Product
How it worksConfidence modelSelective disclosureRequest flowSecurityRelease notes
Wedge pages
DatingBusinessAgeRentingCredentials
Try it
Live request demoSign upLog inProduct app
Legal
Privacy PolicyTerms & ConditionsCookie Policy
© 2026 myProfile247 · A product of eTech Consulting · build 6aa6dabSelf-sovereign identity — your data, encrypted and shared only on your terms.