1. Who we are
Spatial Regal, trading as SydGiG, is the organisation responsible for the SydGiG Platform. For EEA/UK GDPR purposes we are a controller of account, billing, safety, and platform-operation data. For some processing (for example, a Seller storing a client intake form about that Seller's own customer) the user is the controller and SydGiG is a processor. Details are in Section 12 and the Subprocessors & International Transfers page.
Privacy enquiries: privacy@sydgig.com. Data protection officer / privacy lead: dpo@sydgig.com. You may also use in-product support.
Effective 1 September 2026. Last updated 1 September 2026.
2. Scope
This Policy applies to personal data processed when anyone anywhere in the world visits or uses SydGiG websites, apps, APIs, messages, meetings, payments, SydGiG AI, support, or marketing. It covers Buyers, Sellers, visitors, support agents, and people whose data appears in user content (for example, a client named on an invoice).
It does not apply to third-party sites we link to, or to how another user uses data you share with them under your own contract. Those parties have their own responsibilities.
If a mandatory privacy law in your country is stricter than this Policy, we will follow that law for your data. The Global Privacy Rights page maps rights by region.
3. Personal data we collect
You provide
- Identity and contact: name, username, email, phone, country, address if you give it, government ID if we request verification.
- Profile and marketplace: headline, bio, photo, portfolio, credentials, skills, languages, rates, availability, gig listings, reviews you write.
- Workspace: briefs, quotes, invoices, time records, bookings, intake forms, files you upload.
- Communications: messages, attachments, meeting participation, support tickets, dispute materials.
- Payment: payout and billing details processed by payment partners (we do not store full card numbers). Tax IDs where required.
- Preferences: language, currency, cookie choices, marketing opt-in or opt-out.
Collected automatically
- Device and log data: IP address, browser, OS, language, referring URL, pages viewed, approximate location derived from IP, crash diagnostics.
- Cookies and similar technologies, as described in the Cookie Policy.
- Security signals: login times, suspicious-activity flags, rate-limit events.
From others
- The other party to an engagement (reviews, dispute evidence, payments that name you).
- Payment, identity, sanctions-screening, and fraud partners.
- Public sources and credential issuers if you ask us to display a verification.
- Your organisation, if it provisions an account for you.
Sensitive data. Please do not upload special-category or similarly sensitive data (health, biometrics, precise religion, union membership, sexual orientation, children's data, criminal records) unless it is strictly necessary for a lawful engagement and you have a legal basis. If you do, you are the controller of that content and must have a lawful basis to share it with us and with the other user. Identity-verification images, if used, are processed only for verification, fraud, and legal compliance.
4. Why we use personal data (purposes and legal bases)
Where GDPR, UK GDPR, or a similar "legal basis" regime applies, we rely on: contract (Art. 6(1)(b)); legitimate interests (Art. 6(1)(f)), balanced against your rights; consent (Art. 6(1)(a)) where we ask for it (certain cookies, some marketing, optional AI); legal obligation (Art. 6(1)(c)); and, rarely, vital interests. Elsewhere we use the closest equivalent (for example, "legitimate purposes", "performance of a contract", or consent under LGPD, POPIA, PIPL, DPDP, and others).
| Purpose | Examples | Typical legal basis |
|---|---|---|
| Create and secure accounts | Sign-up, login, MFA, session cookies | Contract; legitimate interests; legal obligation |
| Operate the marketplace | Profiles, search, gigs, reviews, messaging, meetings | Contract; legitimate interests |
| Workspace tools | Invoices, quotes, briefs, time, bookings | Contract |
| Payments and escrow | Fund, hold, release, refund, payout, FX, fraud checks | Contract; legal obligation; legitimate interests |
| Taxes and accounting | Withholding, forms, invoicing metadata | Legal obligation; contract |
| Safety, fraud, sanctions | AUP enforcement, AML/CFT, OFAC/EU/UN screening | Legal obligation; legitimate interests |
| Support and disputes | Tickets, evidence, appeals | Contract; legitimate interests; legal obligation |
| Improve the Platform | Aggregated analytics, debugging, quality | Legitimate interests; consent where required |
| Marketing | Product emails you opt into | Consent or soft opt-in where lawful; you can opt out |
| SydGiG AI | Optional prompts and outputs | Contract; consent where required; see AI Policy |
| Legal defence | Establish, exercise, or defend claims | Legitimate interests; legal obligation |
6. International transfers
SydGiG is a global service. Personal data may be processed in the country where you live, in the United States, in the European Economic Area, in the United Kingdom, on Cloudflare's global edge network, and in other countries where our processors operate. Those countries may have different data-protection standards.
Where a transfer law applies (GDPR Chapter V, UK IDTA, Swiss FADP, LGPD, PIPL export-security assessments, DPDP, POPIA, and others), we use one or more of: adequacy decisions; Standard Contractual Clauses / UK Addendum / Swiss addendum; data-processing agreements; encryption in transit; access controls; and, where required, supplementary measures or government-transfer assessments. See Subprocessors & International Transfers.
7. Retention
We keep personal data only as long as needed for the purposes above, including to meet legal, tax, accounting, AML, dispute, and safety periods. Typical periods:
- Account data: for the life of the account, then a short wind-down, then deletion or irreversible aggregation, unless a legal hold applies.
- Transaction, invoice, and tax records: typically 7–10 years depending on the strictest applicable tax or commercial-code rule.
- Messages and workspace files: until you delete them or close the account, subject to the other party's copy and legal holds.
- Security logs: typically 12–24 months.
- Cookie data: as in the Cookie Policy.
- Sanctions and fraud records: as required by AML/sanctions law.
When we delete data, residual copies may remain in backups for a limited period until those backups cycle.
8. Security
We use administrative, technical, and organisational measures appropriate to the risk, including TLS in transit, access control, session cookies, rate limiting, and infrastructure security provided by our cloud vendors. No method of transmission or storage is perfectly secure. See the Information Security page. Report vulnerabilities to security@sydgig.com.
9. Automated decision-making, ranking, and AI
Search ranking, fraud scoring, and spam detection may be partly automated. They may affect visibility of a listing or trigger a review of an account. They are not intended to produce legal effects without human review where GDPR Art. 22 or a similar rule applies. You may contest a solely automated decision that significantly affects you by contacting privacy@sydgig.com.
Optional SydGiG AI processes prompts and relevant workspace context to generate outputs. We do not use your private workspace content to train public foundation models unless we tell you and, where required, obtain consent. See the AI Features Policy.
10. Children
SydGiG is for adults. We do not knowingly collect personal data from children under 18, or under the higher age of majority in their country, or under 13/16 where COPPA, GDPR child-consent rules, or local equivalents set a lower digital-consent age for a different type of service. If you believe a child has created an account, contact privacy@sydgig.com. See Age Requirements & Children's Privacy.
11. Your rights (global summary)
Depending on your location, you may have some or all of the following rights. The Global Privacy Rights page lists the principal statutes by region and how to exercise them.
- Access / know: a copy of personal data we hold about you.
- Rectification / correction.
- Erasure / deletion / right to be forgotten, subject to legal keeps.
- Restriction or objection to certain processing, including legitimate-interests processing and direct marketing.
- Portability, in a structured, commonly used, machine-readable format, where technically feasible.
- Withdraw consent where processing is based on consent, without affecting prior lawful processing.
- Appeal a refusal (required in several US states and good practice worldwide).
- Lodge a complaint with a supervisory authority in your country.
- US state rights: delete, correct, know, opt out of sale/share/targeted advertising, limit use of sensitive personal information, and non-discrimination.
- Brazil LGPD: confirmation, access, correction, anonymisation, portability, deletion, information about sharing, revocation of consent.
- Similar catalogues under PIPEDA, POPIA, PIPL, APPI, PIPA, PDPA variants, DPDP, NDPR, Ghana DPA, Kenya DPA, UAE PDPL, KSA PDPL, KVKK, and others.
To exercise rights, email privacy@sydgig.com from your account email, or use in-product account tools when available. We will verify your identity. We may refuse requests that are unlawful, excessive, or would violate another person's rights. We will respond within the statutory period (for example, one month under GDPR, 45 days under CPRA, 15 days under LGPD for confirmation, and local equivalents).
12. Controller, processor, and user content
SydGiG is controller of Platform accounts, security, payments we operate, ranking, and our own marketing. When you store data about your own clients in workspace tools, you are the controller of that client data and must have a lawful basis (contract, consent, or otherwise) to process it. In that case SydGiG acts as a processor and will process that data on your instructions as implemented in the product, subject to our AUP, security, and legal obligations. If you need a signed data-processing agreement (GDPR Art. 28 or equivalent), email dpo@sydgig.com.
13. Regional notices (non-exhaustive)
EEA, UK, Switzerland
GDPR, UK GDPR, Swiss FADP, and ePrivacy/PECR apply. You may complain to your lead supervisory authority (for example, the ICO in the UK, or the authority of your EU member state). EU representative details, if required by Art. 27, will be published in the Legal Notice when designated.
United States
This Policy is also our CCPA/CPRA notice at collection. Categories collected: identifiers, commercial information, internet activity, geolocation (coarse), professional information, audio/visual if you use meetings, and inferences from profile data. Sources, purposes, and recipients are described above. We do not sell personal information for money. To opt out of any "sale" or "sharing" as defined by CPRA or similar state laws (VA, CO, CT, UT, TX, OR, MT, DE, IA, NE, NH, NJ, TN, MN, MD, and others as they enter force), email privacy@sydgig.com with the subject "Your privacy choices". Nevada and other state-specific opt-outs can use the same address. Financial incentive programmes, if any, will be described at the point of offer.
Canada
PIPEDA and provincial laws including Quebec Law 25. Cross-border processing is disclosed in Section 6. Quebec users may receive additional transparency on technologies that identify, locate, or profile.
Latin America
LGPD (Brazil), LFPDPPP (Mexico), Argentina 25.326, Colombia 1581, Chile 19.628, Peru 29733, Uruguay, Costa Rica, and others. ARCO and equivalent rights are honoured as mapped on the Global Privacy Rights page.
Africa
Including Ghana Data Protection Act 2012, Nigeria NDPR/NDPA, South Africa POPIA (information officer: dpo@sydgig.com), Kenya Data Protection Act 2019, Egypt, Morocco, Rwanda, and other national DPAs. Cross-border transfer conditions of those statutes are addressed via contracts and security measures.
Middle East
UAE PDPL, KSA PDPL, Qatar, Bahrain, Israel PPL, Türkiye KVKK, and similar. Local storage mandates, if they apply to a particular dataset, will be implemented or the feature limited.
Asia-Pacific
PIPL, CSL, and DSL (Mainland China); PDPO (Hong Kong); PDPA (Taiwan); APPI (Japan); PIPA (Korea); PDPA (Singapore, Malaysia, Thailand); PDP (Indonesia); DPA (Philippines); PDPD (Vietnam); DPDP Act (India); Privacy Act (Australia); Privacy Act (New Zealand). Export-security assessments, individual consent for certain exports, and local-representative requirements will be met or the processing limited.
Everywhere else
If your country has a personal-data statute not named here, we still apply this Policy's baseline (lawful purpose, minimisation, security, retention limits, and a request channel) and we honour that statute's additional rights when they apply to us.
15. Changes
We may update this Policy. Material changes will be notified as required by law. The "Last updated" date will change. Continued use after the effective date means you acknowledge the update, except where a statute requires consent.
16. Contact and complaints
Email privacy@sydgig.com or dpo@sydgig.com. You can also open a support ticket. You may complain to your national data-protection authority at any time. A non-exhaustive list of authorities is on the Global Privacy Rights page.
Serve legal notices by email to legal@sydgig.com. A registered office address for Spatial Regal will be published in the Legal Notice as soon as it is designated. Until then, email is the designated address for service.
