Privacy Policy
Last updated: 29 June 2026
1. Controller
The controller responsible for processing your personal data is:
FOOH FlexCoWalling 12, 4300 St. Valentin, Austria
Email: hello@fooh.com
Firmenbuchnummer: FN 649844 d · UID: ATU81952601
Questions about data protection, or requests to exercise your rights, can be addressed to hello@fooh.com (attn. Moritz Lumetsberger). We process personal data in accordance with the General Data Protection Regulation (GDPR) and the Austrian Data Protection Act (Datenschutzgesetz, DSG).
2. What data we process
2.1 Data you provide
- Account: email address, password (stored only as a hash by our auth provider), and—if you sign in with Google—your Google display name and profile image.
- Profile / portfolio: display name and handle, talent type, country and city, biography, public contact email, availability, avatar, showreel, social links, key people you list, and your selected capabilities, industries and tools.
- Uploaded work: the videos, images, titles, descriptions, credits and other content you upload or submit, together with technical media metadata (dimensions, format, upload time).
- Engagement: likes, comments and collections you create.
- Jobs board: job/project postings you publish (company, description, logo, location, budget) and job applications you submit (your message and answers to screening questions).
- Awards: award entries, credits, votes and—where applicable—jury ballots.
- Newsletter: your email address if you subscribe.
- Contact & support: the content of messages you send us or to a creator through our forms.
- Payments: when you buy a paid service, our payment provider (Stripe) processes your payment data. We receive confirmation of payment plus limited details such as currency, amount and the billing email—not your full card number.
2.2 Data we collect automatically
- Server and security logs including IP address, browser and device type, and timestamps.
- View analytics for creators: when a profile or work item is viewed, we record an aggregated event with a one-way hashed visitor identifier (so the same visitor is counted once per day), the approximate country (from a network header), a device class, and the referring source. We do not build cross-site profiles and the hash cannot be reversed to identify you.
- Privacy-friendly, cookieless edge analytics (Cloudflare Web Analytics) measuring aggregate page views and performance.
- Google Analytics 4:we use Google Analytics to understand how the site is used — pages viewed, sessions, approximate location, device type and the referring source. It sets cookies (see “Cookies” below) and assigns a random client identifier; we do not use it to identify you personally.
2.3 Special categories
We do not intentionally collect special categories of personal data (e.g. health, ethnicity, political opinions, religious beliefs). Please do not submit such data through public profiles or uploads.
3. Purposes and legal bases
- Operating your account and providing the platform (library, profiles, uploads, engagement, jobs board, awards) — performance of a contract, Art. 6(1)(b) GDPR.
- Processing payments for paid services (job postings, awards entries) — Art. 6(1)(b) GDPR.
- Publicly displaying your profile and work and attributing credits — performance of our contract with you and our and your legitimate interest in attribution, Art. 6(1)(b) and (f) GDPR.
- Security, fraud and spam prevention (including bot detection via Cloudflare Turnstile) and keeping the service stable — legitimate interest, Art. 6(1)(f) GDPR.
- Aggregate analytics and improving the platform — legitimate interest, Art. 6(1)(f) GDPR.
- Sending the newsletter and any third-party embedded content that sets cookies — your consent, Art. 6(1)(a) GDPR (withdrawable at any time).
- Complying with legal obligations (e.g. accounting and tax retention) — Art. 6(1)(c) GDPR.
4. Public visibility
FOOH is a public, user-generated-content platform. Your profile, the work you upload, your public comments and any public collections are visible to anyone on the internet and may appear in search engines. Information you place on a public profile (such as your name, company, role or contact email) is published deliberately for attribution. You control most of this content and can edit or remove it from your account.
5. Recipients and processors
We use carefully selected service providers who process data on our behalf under data processing agreements:
- Google / Firebase — authentication and login.
- Google Analytics (Google Ireland Ltd / Google LLC)— website usage analytics. Data may be processed in the United States under Google’s EU–US Data Privacy Framework certification.
- Google Cloud (Cloud SQL) — hosting of our application database (EU region).
- Cloudflare — media storage and video streaming (R2 and Stream, served from media.fooh.com), CDN and security, bot protection (Turnstile) and cookieless website analytics.
- Stripe — payment processing.
- Mailchimp / Mandrill — newsletter and transactional email.
- Slack — internal operational notifications (e.g. a new job posting or award entry).
- Embedded players — when a profile or work page loads a YouTube, Vimeo or Instagram embed, your browser contacts those providers, who may receive your IP address and set their own cookies under their own privacy policies.
We do not sell your personal data.
6. International transfers
Some of the providers above are based in, or process data in, the United States. Where data is transferred outside the EU/EEA, we rely on an EU Commission adequacy decision (including the EU–US Data Privacy Framework, where the provider is certified) and/or the EU Standard Contractual Clauses together with additional safeguards. You can request more information or a copy of the relevant safeguards at hello@fooh.com.
7. Retention
- Account, profile and uploaded content: for as long as your account exists. When you delete your account or content, it is removed, subject to short technical backup cycles.
- Job and award data: for the duration of the relevant cycle plus the period needed for disputes.
- Payment and invoicing records: 7 years, to meet Austrian accounting and tax obligations.
- Newsletter: until you unsubscribe.
- Server logs and analytics events: kept only as long as needed for security and statistics, then deleted or aggregated.
8. Your rights
Under the GDPR you have the right to:
- access your personal data;
- rectify inaccurate data;
- erase your data (“right to be forgotten”);
- restrict processing;
- data portability (a structured, machine-readable copy);
- object to processing based on legitimate interest, including any direct-marketing processing;
- withdraw consent at any time, without affecting prior lawful processing.
To exercise any of these, contact hello@fooh.com. You can also delete or edit most of your data directly in your account.
9. Right to complain
If you believe our processing infringes data protection law, you can lodge a complaint with a supervisory authority. The competent authority in Austria is the:
Österreichische Datenschutzbehörde (Austrian Data Protection Authority)Barichgasse 40-42, 1030 Vienna, Austria
Email: dsb@dsb.gv.at · dsb.gv.at
10. Automated decision-making
We do not use automated decision-making or profiling that produces legal or similarly significant effects on you.
11. Cookies
We keep cookies to a minimum. We use a strictly necessary session cookie to keep you signed in, and our hosting/security provider may set strictly necessary cookies to protect the service. These do not require consent. Our edge analytics (Cloudflare) are cookieless.
We also use Google Analytics, which sets analytics cookies (such as _ga and _ga_*) to measure site usage with a random client identifier. You can prevent these through your browser’s cookie controls or Google’s opt-out browser add-on at tools.google.com/dlpage/gaoptout.
Non-essential cookies are only set by third-party content—embedded YouTube, Vimeo or Instagram players and, at checkout, our payment provider Stripe—when that content loads. These are governed by the third party’s own policy. You can manage or delete cookies through your browser settings; blocking all cookies may break parts of the site.
12. Data security
We apply appropriate technical and organisational measures—including encryption in transit, access controls and hashed credentials—to protect personal data. In the event of a data breach that is likely to result in a high risk to your rights, we will notify the supervisory authority within 72 hours where feasible and affected users without undue delay.
13. Changes
We may update this Privacy Policy from time to time. We will post the updated version here and revise the “Last updated” date; for significant changes we will provide a more prominent notice.