Privacy & Cookie Policy

Privacy & Cookie Policy

The English version shall prevail in the event of any inconsistency; translations are provided for convenience only. Capitalized terms have the meanings assigned to them in the Terms of Service.

  1. Controller

1.1 The controller of the personal data processed in connection with the Freelance Club marketplace interface (fwork.club, hereinafter the "Interface" or the "Platform") is the company (hereinafter the "Company"). "Freelance Club" is the trade name (brand) under which the Company operates the Platform.

1.2 The current privacy contact is: support@fwork.club (the Company's current operational contact serving as the legal contact and privacy contact).

1.2 Current contact for privacy matters: support@fwork.club (the Company's designated contact for operational, legal, and privacy matters).

2. Categories of Data Collected

2.1 Wallet and authentication data. The public wallet address you connect, SIWE authentication/session metadata, and, where an enabled on-chain feature is used, related public blockchain transaction data. The Company does not request or store private keys or seed phrases.

2.2 Account and profile data. Username, role (freelancer/employer/admin/reporter), display name, profile description, skills, portfolio items, and similar information you choose to provide.

2.3 Identity-verification data. Data submitted for Identity Verification, processed by the Company's identity-verification provider as described in Section 9. See that Section for what the Company itself receives and stores.

2.4 Marketplace and financial records. Project and service listings, proposals, orders, milestones, internal available and Escrow balance records, fees, refunds, withdrawal requests and destination wallet addresses, dispute evidence and lifecycle records, support cases, moderation records, notifications, and messages.

2.5 Device, security, log, and usage data. IP address, browser and device information, timestamps, session data, and similar technical information collected for security, fraud prevention, and Interface operation.

2.6 Cookies and similar technologies. See Section 7.

3. Purposes and Lawful Bases

3.1 The Company processes personal data to operate the Interface and its marketplace, accounting, Escrow, withdrawal, support, moderation, notification, security, and Product Dispute Resolution workflows; perform Identity Verification and risk review where configured or required; prevent abuse; comply with applicable law; and communicate with Users.

3.2 Depending on the applicable data-protection framework, these purposes are pursued on the basis of: performance of the agreement with the User, the Company's legitimate interests (security, fraud prevention, service improvement), compliance with a legal obligation (Identity Verification, sanctions screening, recordkeeping), and, where required, User consent.

4. Sumsub and Other Processors/Providers

4.1 The Company's current identity-verification provider is Sumsub. Identity-verification providers may change over time; where they do, this Policy will be updated to name the then-current provider. Identity-verification submissions are processed by the identity-verification provider on the Company's behalf, subject to that provider's own processing terms and security practices. See Section 9 for what data the Company receives back from this process.

4.2 The Company uses third-party hosting, database, monitoring, email/notification, decentralized-storage and, where an on-chain feature is enabled, blockchain-node/RPC providers. Provider access depends on the service used and its configuration.

5. International Transfers

5.1 Given the Company's providers and Users may be located in different jurisdictions, personal data may be transferred to and processed in countries other than the User's own. Where required by applicable law, such transfers are subject to appropriate safeguards.

6. Retention

6.1 The Company retains data as needed to operate accounts and active Orders and to meet security, accounting, dispute, audit, and legal requirements. The exact production retention schedule remains an operator and legal-review decision before this Policy becomes effective. Public blockchain or decentralized-storage records may persist independently — see Section 8.

7. Cookies, Analytics and Technical Data

7.1 The Platform uses necessary cookies, local storage, and similar technologies for login, session security, preference storage, language selection, abuse prevention, and proper Interface operation.

7.2 The Platform may use technical and product analytics to understand how the service works, including page usage, Interface stability, loading speed, errors, user experience quality, and general usage patterns.

7.3 Analytics is used in an aggregated and technical manner. It is not intended to collect seed phrases, private keys, passwords, secret codes, or other information that gives access to a wallet or account.

7.4 Certain technical data may include IP address, browser and device data, interface language, approximate event time, page address, referral source, and similar technical information. Such data is used for security, diagnostics, service improvement, and abuse prevention.

7.5 If a User interacts with blockchain features, some data may be public by the nature of blockchain networks. For example, a wallet address, transaction fact, confirmation time, and related public events may be visible on the relevant network independently of the Platform.

7.6 Users must not send seed phrases, private keys, passwords, recovery codes, or other secrets through forms, messages, support requests, or dispute evidence. The Platform does not request such information.

8. Blockchain Data Is Public

8.1 Where a transaction, Escrow event, or other data is recorded on a public blockchain in connection with the Platform:

  • that record may be public — visible to anyone able to read the relevant blockchain, not only to the Company or the User concerned;
  • that record may be permanent — blockchains are generally designed so that confirmed records are not removed;
  • that record cannot necessarily be altered or deleted, by the User, by the Company, or on the User's request; and
  • the Company cannot erase blockchain history. The Company's ability to fulfil a data-subject request (Section 13) is limited to data within its own systems and does not extend to data recorded on a public blockchain, which persists independently of the Interface.

8.2 Users should assume that any data written to a public blockchain (such as a wallet address and its associated transaction history) is permanently and publicly visible.

9. Identity-Verification Data — What the Company Receives

9.1 Identity-verification documents and checks submitted through the Company's identity-verification provider (currently Sumsub) are processed on that provider's systems. The Company does not claim to store the underlying identity documents unless its specific integration with that provider is confirmed to do so. Ordinarily, the Company receives and stores verification status, decision outcomes, and limited metadata (such as applicant identifiers and check timestamps) rather than the underlying document images, except where a specific, confirmed integration detail requires otherwise.

9.2 This Section will be updated once the Company's production identity-verification integration and data-retention configuration are finally confirmed, and whenever the identity-verification provider changes.

10. Automated Processing and AI Assistance

10.1 The Interface uses automated processing, including AI structured evaluation as part of Product Dispute Resolution and automated content/service moderation triage. AI outputs are one structured input to a deterministic Rule Engine or human review process; they are not, by themselves, a final determination of a User's legal rights.

10.2 Users may request information about the logic involved in automated processing that produces legal or similarly significant effects, to the extent required by applicable law.

11. Sanctions, Fraud, and Security Screening

11.1 The Company may process data for fraud, security, account and wallet risk review and applicable sanctions obligations. This Policy does not represent that a particular automated sanctions-screening integration is active unless the Interface expressly identifies it.

12. Minors

12.1 The Platform is not intended for individuals under eighteen (18) years of age. The Company does not knowingly collect personal data from minors. There is no parental-consent onboarding path or minor account type.

13. User Rights

13.1 Subject to applicable law, Users may have rights to access, correct, delete, restrict, or port their personal data, and to object to certain processing. Requests can be submitted to support@fwork.club. These rights do not extend to data that is permanently recorded on a public blockchain and outside the Company's control (Section 8).

14. Security

14.1 The Company implements technical and organizational measures designed to protect personal data. No system is completely secure, and the Company cannot guarantee absolute security of data transmitted to or stored by the Interface or its providers.

15. Contact and Complaints

15.1 Privacy questions, requests, and complaints may be directed to support@fwork.club. Users may also have the right to lodge a complaint with a competent data-protection authority under applicable law.

16. Changes to This Policy

16.1 The Company may update this Policy from time to time. Material changes will be reflected by an updated "Last updated" date and, where required by applicable law, communicated to Users through the Interface.