Fartissimo.net
Last updated: [DATE — insert on publication]
PLACEHOLDER NOTICE (remove before real launch): This Privacy Policy is drafted for the confirmed data controller, RRR FI LP, a Scottish Limited Partnership (company number SL034272, registered office 5 South Charlotte Street, Edinburgh, United Kingdom, EH2 4AN) — not an England & Wales private limited company. The UK GDPR and Data Protection Act 2018 (DPA 2018) apply UK-wide (including Scotland) regardless of the controller's corporate form or place of registration, so this does not change the substantive data-protection framework or the ICO as supervisory authority. It is not legal advice. Note: use of Google Analytics requires a working cookie-consent banner/mechanism to be live before Analytics is actually enabled in production (see Section 8) — that implementation is a developer task, not covered by this document.
Fartissimo ("Fartissimo", "we", "us", "our") operates the web platform at fartissimo.net (the "Service"), a contest platform for artistic sound video performances.
The data controller responsible for your personal data is RRR FI LP, a limited partnership registered in Scotland under the Limited Partnerships Act 1907, company number SL034272, with its registered office at 5 South Charlotte Street, Edinburgh, United Kingdom, EH2 4AN. Privacy contact: [email protected].
We process your personal data in accordance with the UK GDPR and the Data Protection Act 2018 (DPA 2018). The UK supervisory authority is the Information Commissioner's Office (ICO) — see Section 10 for your right to complain.
This Policy explains what personal data we collect, why, how we use and share it, how long we keep it, and the rights you have.
The Service is strictly for adults 18 years or older. We do not knowingly collect personal data from anyone under 18. If we learn we have done so, we will delete it.
We aim to minimize the personal data we collect and to avoid publicly displaying sensitive identifiers (for example, we do not display your email publicly).
We use your data to:
We rely on the following lawful bases under Article 6 of the UK GDPR:
| Purpose | Examples | Lawful basis (UK GDPR Art. 6) | |---|---|---| | Provide the Service | create/authenticate your account, host and display videos, run contests, count votes | Performance of a contract | | Moderate content & keep the Service safe | AI/human moderation, handling reports/appeals, preventing prohibited content | Legitimate interests; legal obligation | | Security & anti-fraud | hashed IP/user-agent, rate limits, detecting vote manipulation | Legitimate interests | | Communicate with you | verification emails, service notices, responses to requests | Performance of a contract; legitimate interests | | Analytics (if enabled) | understanding usage to improve the Service | Consent | | Comply with law | responding to lawful requests, enforcing Terms | Legal obligation; legitimate interests |
Where we rely on consent (e.g., analytics cookies), you may withdraw it at any time, without affecting the lawfulness of processing before withdrawal. Where we rely on legitimate interests, we have assessed that those interests (operating a safe, fraud-resistant contest platform) are not overridden by your interests, rights, and freedoms; you may object to such processing (see Section 10). We do not process special category data as a matter of course; any incidental special category data appearing in User Content is handled only to the extent necessary to operate and moderate the Service.
Data may be processed in countries outside the UK (for example, some of our sub-processors, such as our AI moderation provider or Cloudflare, may process data outside the UK). Where we transfer personal data outside the UK, we ensure an appropriate level of protection using one or more of the following safeguards required under the UK GDPR:
You may request a copy of the relevant safeguard by contacting us at [email protected].
Specifically: Google (Google OAuth and Google Analytics) and OpenAI (AI moderation) are US-based processors; transfers to them rely on the EU Standard Contractual Clauses (SCCs) together with the UK International Data Transfer Addendum, or an applicable UK adequacy mechanism where available. Cloudflare (R2 storage, CDN, Turnstile) processes data in accordance with its own published data-processing terms and equivalent UK-recognized safeguards. These mechanisms should be re-confirmed against each provider's current terms before real launch.
We do not sell your personal data. We share data only with:
We keep personal data only as long as necessary for the purposes above:
We use the following categories of cookies:
| Category | Examples | Purpose | Consent required? |
|---|---|---|---|
| Strictly necessary / session | Laravel session cookie, CSRF token | Keep you logged in, protect forms against cross-site request forgery | No — necessary for the Service to function |
| Functional / security | Cloudflare Turnstile cookie | Anti-bot / anti-fraud check (e.g., on login, upload, voting) | No — classified as necessary/functional |
| Analytics | Google Analytics cookies (e.g., _ga, _gid, and related Google Analytics cookies) | Understand usage/traffic to improve the Service | Yes — requires your consent under UK PECR/GDPR, given via our cookie banner |
Analytics cookies are only set after you consent via our cookie banner. You can change or withdraw consent at any time through the banner or your browser settings. If you do not consent, only the necessary/functional cookies above are used.
[PLACEHOLDER: confirm the exact current Google Analytics cookie names/durations against Google's official Analytics cookie documentation at the time Analytics is actually enabled — Google updates these from time to time.]
We use automated moderation to help decide whether uploaded videos can be published (accept / reject / send to manual review), based on a computed risk score and content labels. Under Article 22 of the UK GDPR you have rights in relation to decisions based solely on automated processing that produce legal or similarly significant effects. To respect this, borderline cases are routed to human review, and you may submit one appeal per rejected video for human reconsideration. This means you can obtain human intervention, express your point of view, and contest a moderation decision — you are not subject to a solely automated decision without a route to human review.
Depending on where you live, you may have the right to:
You can exercise many of these rights directly in your account settings (including account deletion and data export), or by contacting [email protected]. We may need to verify your identity before acting on a request. We will respond within one month of receiving your request, as required by the UK GDPR (this may be extended by up to two further months for complex or numerous requests, in which case we will let you know).
If you are unhappy with how we have handled your personal data, we would like the chance to resolve it — please contact us first. You also have the right to lodge a complaint with the UK supervisory authority, the Information Commissioner's Office (ICO):
If you are located in the EU/EEA, you may also have the right to complain to your local data protection authority.
We use reasonable technical and organizational measures to protect your data, including HTTPS/TLS, password hashing, hashed IP/user-agent storage, private storage for raw uploads, access controls and role-based permissions for staff, and audit logging. No system is perfectly secure, so we cannot guarantee absolute security.
The Service is not directed to and may not be used by anyone under 18. We do not knowingly collect data from minors.
We may update this Policy from time to time. We will update the "Last updated" date and, for material changes, provide additional notice where appropriate. Please review it periodically.
For privacy questions or to exercise your rights: [email protected] RRR FI LP, a limited partnership registered in Scotland, company number SL034272, registered office 5 South Charlotte Street, Edinburgh, United Kingdom, EH2 4AN (data controller).
We do not specifically target or monitor individuals located in the EU/EEA; the Service is offered on the same basis to users regardless of location. On this basis, an EU representative under Article 27 of the EU GDPR is not required. If this changes (e.g., specific EU/EEA-directed marketing or monitoring is introduced), this should be reassessed.
Supervisory authority: Information Commissioner's Office (ICO), ico.org.uk.