Privacy Policy
Last updated: 16 July 2026 — This is a template
This document is a template and will be replaced with reviewed legal documents before public launch. It describes how Opentospeak is actually built and operated, but it has not been reviewed by a lawyer and is not a substitute for one.
This policy explains what Opentospeak collects, why, who we share it with, and what you can do about it.
The data controller is Prognox Ltd, a company registered in England and Wales under company number 15303071, whose registered office is 71-75 Shelton Street, Covent Garden, London, WC2H 9JQ, United Kingdom. Opentospeak is our trading name. Contact us at [email protected].
We are established in the United Kingdom, so we are regulated under the UK GDPR and the Data Protection Act 2018, and our supervisory authority is the Information Commissioner's Office (ICO). Where we serve people in the EEA, the EU GDPR applies to that processing as well.
1. What we collect
Account data — your name, email address, and password (stored only as a hash, never in readable form). If you enable two-factor authentication, we store the secret needed to verify your codes.
Profile data — whatever you choose to put on a speaker or organizer profile: headline, bio, topics, languages, location, fees, links, photo or logo, and video embed URLs. You decide whether a speaker profile is public or unlisted.
Marketplace activity — your event listings, applications and the pitches in them, invitations, matches, past engagements you record, and the reviews you write and receive.
Usage data — significant actions such as logging in, viewing a profile, and running a search, recorded with a hashed (not raw) IP address and your browser user-agent. We use this for analytics, support, and detecting abuse.
Billing data — if you subscribe to Pro, Stripe processes your payment and we store only a customer reference, the card type, and the last four digits so you can recognise your own card. Full card details never reach our servers.
Calendar free/busy — if you connect Google or Outlook, we read only whether you are busy, and store those blocks as dates. The permission we request cannot return event titles, attendees, or descriptions, and we do not store any.
2. What we do not do
We do not sell your personal data. We do not use it for third-party advertising, and we do not run advertising cookies. We do not show your email address or contact details to anyone before you have a match — accepting an application or an invitation is the only thing that reveals them.
3. Why we use it, and our legal basis
- To run the marketplace — your account, profiles, applications, invitations, matches, and reviews. Basis: performance of our contract with you.
- To display the public pages you choose to publish, and to include them in search engines and share cards. Basis: performance of our contract, and your choice of visibility.
- To send transactional email you have asked for or need — verification, applications, invitations, matches, reviews, billing. Basis: contract, and your preferences where the email is optional.
- To match you to opportunities and send alerts or a weekly digest. Basis: consent, through your notification preferences.
- To improve the product with analytics. Basis: consent, given through the cookie banner.
- To keep the platform safe — rate limits, abuse detection, moderation. Basis: our legitimate interest in a platform that is not abused.
- To meet legal and accounting obligations. Basis: legal obligation.
4. Processors we share it with
We use a small number of providers to run the service. Each processes data on our instructions only.
- Stripe — payments and subscriptions. Receives your email and payment details directly; we never hold your card.
- Resend — sends our transactional email. Receives your email address and the message contents.
- PostHog — product analytics: which features are used and where people get stuck. Only initialised if you accept analytics cookies.
- Google Analytics — acquisition reporting: how people find the site. Configured without Google Signals or ad personalization, and with IP anonymization on. Only initialised if you accept analytics cookies.
- Anthropic — powers the AI profile writer and match explanations. Receives the text you submit for drafting, and event or profile text for matching. It is not used to train models.
- Amazon Web Services — stores the images you upload, served through a CDN.
- Google and Microsoft — only if you connect a calendar, and only for read-only free/busy.
- MaxMind GeoLite2 — a database we run on our own servers to guess your city from your IP address so the homepage can show local events. No request leaves our infrastructure, and the result is never stored on your account.
Several of these providers are in the United States. Where personal data leaves the UK, the transfer relies on UK adequacy regulations where they apply, or otherwise on the UK International Data Transfer Agreement (or the UK Addendum to the EU standard contractual clauses), together with the provider's own safeguards.
We may also disclose data if the law requires it, or to establish or defend legal claims.
5. What is public
A public speaker profile is exactly that: indexed by search engines, shareable, and embeddable by you. It shows your name, headline, bio, topics, city and country, ratings, and verified engagements — never your email address or phone number. You can set your profile to unlisted at any time from your dashboard.
Organizer profiles and approved event listings are public. Reviews are public once both sides have submitted or the review window has closed.
Applications, invitations, pitches, availability, and your matching preferences are never public.
6. How long we keep it
- Account and profile data: until you delete your account.
- Activity log: 90 days, then aggregated and deleted.
- Email history: kept so we can show you what we sent and avoid sending it twice; deleted with your account.
- Calendar tokens and synced busy blocks: deleted immediately when you disconnect the calendar.
- Data exports: the file is deleted once its download link expires.
- Billing records: retained as long as tax and accounting law requires, even after deletion.
7. Deleting your account
You can delete your account from your privacy settings. Your profiles are hidden immediately, any subscription is cancelled at once, and 14 days later your personal data is permanently erased. The 14 days exist so a deletion you regret can be undone — contact us within them.
Two things survive, in anonymized form. Reviews you wrote are also a record of the other member's work, and matches are a record of an introduction you both took part in. We keep those, with your name and email replaced by "Deleted User", so that removing your account does not erase someone else's history. Everything identifying is gone: your name, email, password, profile text, photo, location, links, calendar tokens, activity log, and billing identifiers.
8. Your rights
Depending on where you live, you have some or all of these rights. You can exercise the first two yourself, right now, from your settings:
- Access and portability — request a full export of your data as a JSON file, from Settings → Privacy & data.
- Erasure — delete your account, from Settings → Privacy & data.
- Rectification — correct anything wrong, by editing your profile or account.
- Objection and restriction — object to processing based on legitimate interest, or ask us to restrict it.
- Withdraw consent — change your notification preferences, unsubscribe from any email in one click, or reject analytics cookies. Withdrawing consent does not affect what happened before.
Write to [email protected] to exercise any of these. We will respond within one month. If you are unhappy with our response you can complain to the Information Commissioner's Office (ico.org.uk), which regulates us — or, if you live in the EEA, to your own national data protection authority.
9. Security
The platform is HTTPS-only. Passwords are hashed, calendar tokens are encrypted at rest, and card details never touch our servers. Access to production data is limited to the people who need it, and admin actions are logged. No system is perfectly secure, but if a breach affects you we will tell you and the relevant authority as the law requires.
10. Children
Opentospeak is not intended for children, and we do not knowingly collect their data. If you believe a child has created an account, contact us and we will remove it.
11. Changes
If we change this policy materially, we will tell you by email or in the product before it takes effect. The "last updated" date at the top always reflects the current version.
See also: Cookie Policy · Terms of Service