Privacy Policy
Last updated: 19 May 2026
1. Introduction
Welcome to Filth ("we", "us", or "our"). We are committed to protecting your personal data and respecting your privacy in accordance with the General Data Protection Regulation (EU) 2016/679 ("GDPR"), the Spanish Organic Law 3/2018 on Personal Data Protection, and all other applicable data protection legislation.
This Privacy Policy explains how we collect, use, store, and protect your personal information when you use our website at filth.ai, register for events, submit casting applications, or create performer profiles.
By using our services, you acknowledge that you have read and understood this Privacy Policy.
2. Data Controller
The data controller responsible for your personal data is:
3. Personal Data We Collect
We collect different categories of personal data depending on how you interact with us:
3.1 Casting Applicants
- Full name, email address, phone number
- Date of birth, gender, country of residence
- Social media handles and follower counts (Instagram, TikTok, Twitter/X, OnlyFans)
- Biographical information and photographs
3.2 Performers
- Stage name, legal name, contact information
- Date of birth, gender, country, city
- Professional biography, experience, performance categories
- Social media profiles, photographs, professional documents
- Agency information (if applicable)
3.3 Registered Users
- Name, email address, encrypted password
- Event attendance records and preferences
3.4 Automatically Collected Data
- IP address (anonymised), browser type, device information
- Pages visited, referral sources, time on site
- Cookies and tracking technologies (see our Cookie Policy)
4. Legal Basis for Processing
We process your personal data on the following legal bases under Article 6 of the GDPR:
| Purpose | Legal Basis |
|---|---|
| Casting applications | Consent (Art. 6(1)(a)) |
| Performer profiles & bookings | Contractual necessity (Art. 6(1)(b)) |
| Event management | Contractual necessity (Art. 6(1)(b)) |
| Analytics & site improvement | Consent (Art. 6(1)(a)) |
| Event communications | Legitimate interest (Art. 6(1)(f)) |
| Security & fraud prevention | Legitimate interest (Art. 6(1)(f)) |
| Legal/tax compliance | Legal obligation (Art. 6(1)(c)) |
5. How We Use Your Data
- Casting evaluation: Reviewing applications and assessing suitability for events.
- Performer management: Managing profiles, facilitating bookings, and coordinating events.
- Event operations: Managing guest lists, check-ins, and logistics.
- Communication: Sending invitations, status updates, and notifications via email (Amazon SES).
- Platform improvement: Analysing usage patterns to improve experience (with consent).
- Security: Protecting against fraud and unauthorised access.
- Financial processing: Managing payments and fulfilling tax obligations.
6. Data Sharing and Third Parties
We do not sell your personal data. We may share data with:
| Third Party | Purpose | Location |
|---|---|---|
| Google Analytics | Website analytics (with consent) | USA (EU-US DPF) |
| Amazon SES | Email delivery | EU |
| Hosting provider | Website hosting | EU |
All processors are bound by data processing agreements and must comply with GDPR.
7. International Data Transfers
Where we transfer data outside the EEA, we ensure safeguards including the EU-US Data Privacy Framework, Standard Contractual Clauses (SCCs), and adequacy decisions.
8. Data Retention
| Data Category | Retention Period |
|---|---|
| Approved casting applications | Membership + 2 years |
| Denied casting applications | 6 months |
| Performer profiles | Activity + 2 years |
| User accounts | Account life + 2 years |
| Event attendance | 5 years (legal) |
| Financial records | 6 years (Spanish tax law) |
| Analytics data | 26 months |
9. Your Rights Under GDPR
- Right of access — Request a copy of your personal data.
- Right to rectification — Request correction of inaccurate data.
- Right to erasure — Request deletion ("right to be forgotten").
- Right to restrict processing — Limit how we use your data.
- Right to data portability — Receive data in a machine-readable format.
- Right to object — Object to processing based on legitimate interests.
- Right to withdraw consent — Withdraw at any time.
See our GDPR Rights page for full details. Contact privacy@filth.ai to exercise any right. We respond within 30 days.
10. Data Security
We implement appropriate technical and organisational measures including:
- Encryption in transit (TLS/SSL) and password hashing (bcrypt)
- Role-based access controls and CSRF protection
- Regular security reviews and restricted employee access
11. Children's Privacy
Our services are intended for individuals aged 18 and over. We do not knowingly collect data from minors. Contact privacy@filth.ai if you believe a minor has provided data.
12. Changes to This Policy
We may update this policy. Material changes will be communicated via updated dates, email notifications, and website notices.
13. Complaints
Please contact us first at privacy@filth.ai.
14. Contact Us
Email: privacy@filth.ai
Website: filth.ai