Privacy Policy
Last updated: —
Draft — not yet in force
This document is a structural placeholder. It has not been reviewed by counsel and creates no obligations for either party. Do not launch publicly until it has been completed and signed off.
1. Controller
To write: Legal entity operating LaraModels, registered address, and contact email. Must match the imprint. If a Data Protection Officer is appointed under Art. 37 GDPR, name them here.
2. What we collect
The platform holds different categories of data depending on whether you apply as a creator or as an agency.
To write: Enumerate per role. Creators: identity and age-verification documents, platform handles, content categories, communication history. Agencies: company details, references, revenue figures submitted per match. Both: account credentials, session data, support correspondence.
3. Why we process it, and on what legal basis
To write: Map every purpose to an Art. 6 GDPR basis. Contract performance for account and matching; legitimate interest for vetting and fraud prevention (document the balancing test); legal obligation for age-verification records; explicit consent for anything else.
4. Age verification
To write: Explain what identity documents are required, who reviews them, how long they are retained, and how they are stored. This is the most sensitive category on the platform and needs its own section.
5. Who we share data with
We use third-party processors to operate the platform. Each is bound by a data processing agreement.
To write: List the actual processors with their role and hosting region — email delivery, file storage, database hosting, error monitoring and analytics. Confirm a signed DPA exists for each before publishing.
6. International transfers
To write: Name any processor outside the EEA and the transfer mechanism relied on (adequacy decision or Standard Contractual Clauses).
7. How long we keep data
To write: State a retention period per category. Rejected applications, closed accounts, age-verification records and revenue records will each need a different answer.
8. Your rights
Under the GDPR you have the right to access your data, correct it, have it deleted, restrict or object to its processing, and receive it in a portable format. You may also lodge a complaint with a supervisory authority.
To write: Add the address to send requests to, the response window, and the competent supervisory authority for the operating entity.
9. Cookies
To write: List cookies actually set, split into strictly necessary and everything else. Anything beyond strictly necessary needs consent before it is set.
10. Changes to this policy
To write: How changes are announced and when they take effect.