Legal

Privacy Policy

Last updated: 19 May 2026

1. Introduction

Welcome to Filth ("we", "us", or "our"). We are committed to protecting your personal data and respecting your privacy in accordance with the General Data Protection Regulation (EU) 2016/679 ("GDPR"), the Spanish Organic Law 3/2018 on Personal Data Protection, and all other applicable data protection legislation.

This Privacy Policy explains how we collect, use, store, and protect your personal information when you use our website at filth.ai, register for events, submit casting applications, or create performer profiles.

By using our services, you acknowledge that you have read and understood this Privacy Policy.

2. Data Controller

The data controller responsible for your personal data is:

Filth

Barcelona, Spain

Email: privacy@filth.ai

3. Personal Data We Collect

We collect different categories of personal data depending on how you interact with us:

3.1 Casting Applicants

  • Full name, email address, phone number
  • Date of birth, gender, country of residence
  • Social media handles and follower counts (Instagram, TikTok, Twitter/X, OnlyFans)
  • Biographical information and photographs

3.2 Performers

  • Stage name, legal name, contact information
  • Date of birth, gender, country, city
  • Professional biography, experience, performance categories
  • Social media profiles, photographs, professional documents
  • Agency information (if applicable)

3.3 Registered Users

  • Name, email address, encrypted password
  • Event attendance records and preferences

3.4 Automatically Collected Data

  • IP address (anonymised), browser type, device information
  • Pages visited, referral sources, time on site
  • Cookies and tracking technologies (see our Cookie Policy)

4. Legal Basis for Processing

We process your personal data on the following legal bases under Article 6 of the GDPR:

PurposeLegal Basis
Casting applicationsConsent (Art. 6(1)(a))
Performer profiles & bookingsContractual necessity (Art. 6(1)(b))
Event managementContractual necessity (Art. 6(1)(b))
Analytics & site improvementConsent (Art. 6(1)(a))
Event communicationsLegitimate interest (Art. 6(1)(f))
Security & fraud preventionLegitimate interest (Art. 6(1)(f))
Legal/tax complianceLegal obligation (Art. 6(1)(c))

5. How We Use Your Data

  • Casting evaluation: Reviewing applications and assessing suitability for events.
  • Performer management: Managing profiles, facilitating bookings, and coordinating events.
  • Event operations: Managing guest lists, check-ins, and logistics.
  • Communication: Sending invitations, status updates, and notifications via email (Amazon SES).
  • Platform improvement: Analysing usage patterns to improve experience (with consent).
  • Security: Protecting against fraud and unauthorised access.
  • Financial processing: Managing payments and fulfilling tax obligations.

6. Data Sharing and Third Parties

We do not sell your personal data. We may share data with:

Third PartyPurposeLocation
Google AnalyticsWebsite analytics (with consent)USA (EU-US DPF)
Amazon SESEmail deliveryEU
Hosting providerWebsite hostingEU

All processors are bound by data processing agreements and must comply with GDPR.

7. International Data Transfers

Where we transfer data outside the EEA, we ensure safeguards including the EU-US Data Privacy Framework, Standard Contractual Clauses (SCCs), and adequacy decisions.

8. Data Retention

Data CategoryRetention Period
Approved casting applicationsMembership + 2 years
Denied casting applications6 months
Performer profilesActivity + 2 years
User accountsAccount life + 2 years
Event attendance5 years (legal)
Financial records6 years (Spanish tax law)
Analytics data26 months

9. Your Rights Under GDPR

  • Right of access — Request a copy of your personal data.
  • Right to rectification — Request correction of inaccurate data.
  • Right to erasure — Request deletion ("right to be forgotten").
  • Right to restrict processing — Limit how we use your data.
  • Right to data portability — Receive data in a machine-readable format.
  • Right to object — Object to processing based on legitimate interests.
  • Right to withdraw consent — Withdraw at any time.

See our GDPR Rights page for full details. Contact privacy@filth.ai to exercise any right. We respond within 30 days.

10. Data Security

We implement appropriate technical and organisational measures including:

  • Encryption in transit (TLS/SSL) and password hashing (bcrypt)
  • Role-based access controls and CSRF protection
  • Regular security reviews and restricted employee access

11. Children's Privacy

Our services are intended for individuals aged 18 and over. We do not knowingly collect data from minors. Contact privacy@filth.ai if you believe a minor has provided data.

12. Changes to This Policy

We may update this policy. Material changes will be communicated via updated dates, email notifications, and website notices.

13. Complaints

Please contact us first at privacy@filth.ai.

14. Contact Us

Email: privacy@filth.ai

Website: filth.ai