LEGAL FRAMEWORK/DATA GOVERNANCE

Privacy Policy

Effective 14 September 2026·Last updated 14 September 2026
SecondPass.net · Founded 14 September 2026 · Finland
Table of Contents (21 Sections)
Exercise Your Statutory GDPR Rights

Submit a formal access, deletion, rectification, or privacy inquiry using our dedicated public request form.

Privacy Request Form

This Privacy Policy explains how SecondPass.net (“Second Pass”, “we”, “us” or “our”) collects, uses, stores, discloses, and protects personal data when you visit our website, register for an account, participate in creative critique and discussions, showcase portfolio projects, submit guides, or otherwise interact with the Service.

SecondPass.net is currently an independently operated online platform based in Finland.

We are committed to transparent, lawful, and accountable data processing in full compliance with the General Data Protection Regulation (Regulation (EU) 2016/679 - “GDPR”) and the Finnish Data Protection Act (Tietosuojalaki 1050/2018).

This Privacy Policy is an informational transparency notice provided pursuant to Article 13 of the GDPR. It should be read in conjunction with our Terms of Service.

1. Introduction & Scope

Second Pass is a professional and educational creative community designed to facilitate peer feedback, technical problem-solving, iterative craftsmanship, and portfolio presentation.

This Privacy Policy applies to all personal data collected through SecondPass.net, including:

  • member registration, authentication, and profile management;
  • creative Workbenches, iterative Passes, and progress updates;
  • Contributions, critique, technical solutions, and peer replies;
  • Portfolio showcase projects and process documentation;
  • Library submissions, guides, and educational articles;
  • community recognition signals, helpful acknowledgements, and reputation records;
  • direct messaging between members;
  • moderation, safety reports, and community integrity enforcement; and
  • inquiries, feedback, and support communications.

By accessing or using Second Pass, you acknowledge the data collection and processing practices described in this document.

2. Data Controller

SecondPass.net is currently an independently operated online platform based in Finland. The platform does not currently operate as a registered company or legal entity with a Finnish Business ID (Y-tunnus).

Legally Responsible Data Controller:

Name: Shafa Sabeti Motlagh
Location: Oulu, Finland
Applicable Law: Laws of Finland & European Union GDPR
In-Platform Privacy & Data Rights: Account & Data Rights Settings (/settings/data)

Because Second Pass is an independent platform whose core activities do not involve large-scale regular and systematic monitoring of individuals or the processing of special categories of personal data, Second Pass has not designated a statutory Data Protection Officer under Article 37 of the GDPR.

Privacy inquiries, data subject requests, and questions concerning this Policy may be submitted directly through the public Privacy Request Form, through your account settings, or through the contact routes described in Section 20.

3. Personal Data We Collect

We adhere to the principle of data minimization (Article 5(1)(c) GDPR). We collect only the personal data strictly necessary to operate a secure, high-trust community. The categories of personal data we process comprise:

A. Authentication and Account Data

  • Email address: Used for account identity, authentication, password resets, and critical system notifications. Never displayed on your public profile.
  • Password hash: Authentication is provided through Supabase Auth. Passwords are stored in cryptographically hashed form rather than as readable plaintext. We never possess, view, or store plaintext passwords.
  • Unique user identifier: An internal, randomly generated UUID assigned to your account.
  • Legal notice audit timestamps: Terms acceptance timestamp (terms_accepted_at, version 1.0) and Privacy Policy transparency acknowledgement timestamp (privacy_notice_acknowledged_at, version 1.0).

B. Profile and Practitioner Identity

  • Username: Your unique public handle (@username) identifying you across the platform.
  • Display name: Optional name shown on your profile and contributions.
  • Avatar image: Optional profile picture uploaded by you.
  • Bio and Location: Optional short self-description and city or country of residence.
  • Primary discipline & role: Optional professional focus (e.g., 3D Modeling, Environment Art, Concept Art).
  • External portfolio links: Optional links to your personal website, ArtStation, Behance, LinkedIn, or YouTube profiles.

C. Creative Workbenches, Passes & Iteration Data

  • Workbench titles, descriptions, discipline tags, software tools used, and category classifications.
  • Pass update records, including version numbers, iteration notes (“what changed”), technical problem statements, attempted solutions, and next creative goals.
  • Uploaded creative media files (work-in-progress images, renders, turnaround sheets, reference screenshots).

D. Contributions, Peer Critique & Discussion Content

  • Constructive critique comments, technical solutions, and feedback posted to community Workbenches.
  • Discussion replies, technical advice, annotations, and optional image attachments demonstrating creative techniques.

E. Portfolio Projects & Showcase Data

  • Portfolio project titles, descriptions, project roles, completion year, and process challenge breakdowns.
  • Showcase gallery media (hero renders, turnaround shots, model wireframes).

F. Library Guides & Educational Techniques

  • Article titles, summaries, formatted markdown tutorial text, discipline tags, and software tool classifications.
  • Linked third-party instructional video URLs (e.g., YouTube, Vimeo).
  • Illustrative tutorial diagrams and step-by-step imagery.

G. Community Signals, Recognition & Reputation

  • Helpful marks awarded by authors of Workbenches to feedback that assisted their creative progress.
  • Community impressions and appreciations attached to Workbenches, passes, and portfolio pieces.
  • Reputation points (RP) ledger entries documenting points earned from peer recognition.
  • Computed practitioner tier indicators and community achievement badges.

H. Direct Messages & Communications

  • Private, one-on-one text messages sent between registered members.
  • Message timestamps, participant identifiers, and read indicators.

I. Moderation, Safety & Integrity Records

  • Reports filed regarding suspected violations of platform policies (category, explanation, target reference).
  • Immutable safety snapshots of reported content captured at the time of a report to enable objective investigation.
  • Moderation outcomes (formal notices, strikes, temporary suspensions, feature restrictions).
  • User blocking preferences and account safety status flags.

J. Administrative & Security Audit Logs

  • Security events, administrative role assignments, and elevated operations recorded in our append-only audit ledger (admin_audit_events).
  • Authentication session metadata managed by our infrastructure provider.

K. Username Cooling-Off Records

  • When an account is deleted, the lowercase username string is stored in a private reservation table (deleted_username_reservations) for exactly 90 days to prevent handle hijacking, identity confusion, or fraud.

L. Privacy & Data Rights Requests

  • Contact email address, optional full name, optional SecondPass username, and optional relevant content URL submitted via our public Privacy Request Form (/privacy/request).
  • Selected request category, descriptive explanation, and correspondence history.
  • Administrative request lifecycle records (processing status, internal triage notes, resolution timestamp, and handling staff identifier) stored in our private privacy_requests table.
  • Temporary rate-limiting telemetry (client IP and submission timestamps held in volatile server memory) utilized solely to prevent automated denial-of-service or form abuse.

M. Copyright & Intellectual-Property Complaints

  • Complainant full legal name or professional entity, contact email address, relationship to the rightsholder (creator/owner, authorised representative, exclusive licensee, or other), and organization/company name (if provided) submitted via our structured intake form (/copyright/report) or direct legal correspondence (legal@secondpass.net).
  • Specific identification and description of the protected work, exact reported SecondPass URL, detailed explanation of the alleged infringement, and optional supporting links, comparison images, or licensing documentation.
  • Good-faith confirmation statement and submission timestamp.
  • Optional authenticated user identifier (if submitted by an existing member while logged in).
  • Administrative complaint lifecycle records (processing status, internal staff triage notes including records of off-platform or email correspondence, handling staff identifiers, resolution timestamps, and outcome determinations) stored in our private copyright_reports table.
  • Affected-user account information, notifications dispatched, and counter-response communications exchanged in connection with the investigation.
  • Temporary rate-limiting telemetry (client IP address and email submission timestamps held in volatile server memory) utilized solely to prevent automated denial-of-service or form abuse.

N. Contact & Support Inquiries

  • Sender name, contact email address, selected inquiry category (General Question, Account & Technical Support, Business & Partnerships, Community & Moderation, Security Concern, or Other), subject line, descriptive message text, and optional relevant SecondPass URL submitted via our public Contact form (/contact) or direct support correspondence (support@secondpass.net).
  • Optional authenticated member account identifier (linked automatically if submitted while logged in).
  • Administrative inquiry lifecycle records (processing status, staff triage notes, internal priority, resolution timestamp, and handling staff identifier) stored in our private contact_requests table.
  • Abuse prevention and rate-limiting telemetry: to protect platform infrastructure against automated denial-of-service and form abuse, network requests are evaluated using keyed one-way HMAC-SHA-256 digests and window expiry timestamps stored in intake_rate_limits. No raw IP addresses are retained in the Contact intake or durable rate-limit database records; rate-limit identifiers are stored as keyed one-way digests.

4. Public Visibility & Image Metadata Protection

Second Pass is a public-facing community. By design, certain categories of information you submit are immediately accessible to anyone on the internet and may be indexed by public search engines:

  • your public username (@username), display name, avatar, bio, location, discipline, and linked external profile URLs;
  • Workbenches, Passes, technical challenge notes, and uploaded progress media;
  • Contributions, critique, solutions, and community discussions;
  • Portfolio showcase projects and creative process case studies;
  • approved Library guides, tutorials, and educational media; and
  • public recognition totals, reputation tiers, and community badges.

Privacy-by-Design: Automated Image Metadata Stripping

To safeguard member privacy and prevent accidental disclosure of sensitive geographical or device data, Second Pass implements automated client-side image sanitization across all public upload features (including profile avatars, Workbench images, Pass progress renders, Portfolio showcase media, Contribution attachments, and Library guides).

Before an image file is uploaded to our cloud storage, your browser re-encodes the image bitmap onto an HTML5 canvas. This process automatically and permanently strips all embedded EXIF metadata, GPS geographical coordinates, camera model information, lens specifications, and authoring device timestamps, while preserving your native visual dimensions and visual presentation.

5. How We Use Personal Data

We process your personal data for the following specific purposes:

  • Operating the Service: To provide, maintain, and optimize SecondPass.net, manage practitioner accounts, authenticate user sessions, and present member portfolios.
  • Facilitating Creative Critique & Collaboration: To enable members to post Workbenches, track iterative version history through Passes, contribute peer feedback, and share specialized technical knowledge.
  • Community Recognition & Reputation: To calculate helpful marks, track reputation points, award merit-based badges, and display community standing.
  • Direct Communication: To deliver direct messages between members and facilitate private peer discussions.
  • Assistive Skill Classification: To evaluate post titles and written descriptions using deterministic rule-based taxonomy matching to suggest canonical skill tags to improve content discoverability.
  • Platform Safety & Integrity: To investigate abuse reports, prevent spam and automated bot scraping, moderate prohibited content, detect impersonation, and enforce our Terms of Service.
  • Account Security & Step-Up Verification: To authenticate sensitive actions (such as email changes, password updates, data downloads, and account deletions) through 15-minute step-up reauthentication.
  • Data Portability & Erasure: To generate structured data export archives (data.json) and execute permanent account deletions upon request.
  • Handling Privacy & Data Rights Requests: To review, verify, process, and respond to data subject rights requests submitted under Chapter III of the GDPR (such as access, rectification, erasure, and restriction) and maintain auditable records of legal compliance.
  • Investigating & Resolving Intellectual-Property Complaints: To receive, verify, investigate, and resolve copyright and intellectual-property complaints submitted via our structured reporting form (/copyright/report) or legal contact desk (legal@secondpass.net), communicate with complainants and affected creators, execute proportionate corrective actions under our Copyright Policy, maintain audit records of dispute resolutions, and establish, exercise, or defend legal claims.
  • Handling Contact & Support Inquiries: To receive, review, and respond to general questions, technical support issues, account problems, business and partnership communications, community inquiries, and security vulnerability disclosures submitted via our public Contact form (/contact) or support desk (support@secondpass.net), maintain operational correspondence records, and defend against potential legal claims.
  • Legal Compliance: To comply with applicable Finnish and European legal obligations, respond to lawful authority requests, and maintain dispute evidence.

We do not sell, rent, or trade your personal data to third parties, and we do not use your personal data for behavioral advertising.

6. Legal Bases for Processing

Under Article 6 of the GDPR, every processing activity must rest upon a recognized lawful basis. The table below details the legal basis applied to each core processing activity on SecondPass.net:

Processing ActivityPersonal Data InvolvedGDPR Legal BasisRationale & Explanation
Account Registration & AuthenticationEmail, password hash, user UUID, legal notice timestampsArt. 6(1)(b) ContractNecessary to enter into and perform the user contract (Terms of Service) to provide an authenticated account.
Public Profile & Portfolio HostingUsername, display name, avatar, bio, external links, showcase mediaArt. 6(1)(b) ContractNecessary to fulfill the core service of presenting your practitioner identity and creative work to the community.
Workbenches, Passes & ContributionsIteration updates, problem/goal notes, critique text, uploaded mediaArt. 6(1)(b) ContractNecessary to deliver the collaborative critique and feedback features requested by members.
Direct MessagingMessage text, recipient/sender IDs, read receiptsArt. 6(1)(b) ContractNecessary to transmit private communications between consenting platform members.
Reputation & Recognition SystemsHelpful marks, appreciation counts, RP ledger, badgesArt. 6(1)(b) Contract & Art. 6(1)(f) Legitimate InterestsNecessary to provide the community recognition framework and incentivize constructive, high-quality feedback.
Assistive Skill ClassificationSubmitted post/guide titles and descriptions (text only)Art. 6(1)(f) Legitimate InterestsOur legitimate interest in offering deterministic taxonomy assistance to help creators organize and discover relevant work.
Platform Safety, Anti-Abuse & ModerationSafety reports, reported content snapshots, sanctions, blocksArt. 6(1)(f) Legitimate Interests & Art. 6(1)(c) Legal ObligationOur legitimate interest in maintaining a secure, harassment-free platform, and complying with EU digital safety laws.
Security Audit Logging & Access ControlsSecurity audit events, administrative actions, reauth logsArt. 6(1)(f) Legitimate Interests & Art. 6(1)(c) Legal ObligationEnsuring the continuous integrity, confidentiality, and availability of our systems under Article 32 GDPR.
Username Reservation Hold (90 Days)Deleted account username stringArt. 6(1)(f) Legitimate InterestsPreventing username squatting, bad-faith handle recycling, and impersonation of recently departed creators.
Privacy & Data Rights Requests (/privacy/request)Contact email, optional full name/username/URL, request category, message explanation, resolution status, and internal staff triage notesArt. 6(1)(c) Legal Obligation & Art. 6(1)(f) Legitimate InterestsComplying with statutory legal obligations under Chapter III of the GDPR (responding to data subject rights requests) and our legitimate interests in verifying requester identity, preventing fraudulent requests, and maintaining defensible records of request fulfillment.
Copyright & Intellectual-Property Complaints (/copyright/report & legal@secondpass.net)Complainant name, contact email, relationship, protected work description, reported URL(s), infringement explanation, supporting links, affected-user information, internal staff notes, and resolution decisionsArt. 6(1)(c) Legal Obligation & Art. 6(1)(f) Legitimate Interests
Legal obligation — GDPR Article 6(1)(c):Where processing is necessary to comply with legal obligations applicable to SecondPass, including applicable Digital Services Act notice-and-action, notification, record-handling, authority-order, or other statutory obligations.
Legitimate interests — GDPR Article 6(1)(f):For receiving, assessing and administering intellectual-property complaints beyond specific statutory requirements; protecting users’ and rightsholders’ creative work; preventing abuse of reporting mechanisms; preserving community integrity; maintaining appropriate dispute records; and establishing, exercising or defending legal claims, where those interests are not overridden by the rights and freedoms of affected individuals.
Contact & Support Inquiries (/contact & support@secondpass.net)Sender name, contact email, inquiry category, subject, message, optional relevant URL, optional user ID, internal triage notes, and rate-limiting key hashesArt. 6(1)(b) Contract & Art. 6(1)(f) Legitimate Interests
Contract / steps at user’s request — GDPR Article 6(1)(b):Where processing is necessary to provide account or service support requested by a user in connection with their use of SecondPass, or to take relevant pre-contractual steps requested by the individual where applicable.
Legitimate interests — GDPR Article 6(1)(f):For receiving, reviewing and responding to general questions, business inquiries, partnership requests, community questions, and security concerns; maintaining operational communication records; investigating security vulnerabilities; preventing abuse of contact channels; and establishing, exercising or defending legal claims.

7. Recognition, Recommendations & Automated Processing

Second Pass incorporates community recognition features designed to celebrate helpful feedback, craftsmanship, and educational contributions:

  • Helpful Marks: Authors of Workbenches can mark specific peer contributions as helpful, acknowledging actionable advice that aided their iteration.
  • Reputation Points (RP) & Tiers: Points are awarded deterministically for peer-validated help and approved educational guides. Point totals map to community practitioner tiers.
  • Content Discovery: Public feeds and showcases use algorithmic ordering based on objective criteria such as chronological submission time, category filters, and community recognition.
No Automated Decision-Making Producing Legal Effects:

Second Pass does not engage in automated decision-making or profiling within the meaning of Article 22 of the GDPR that produces legal effects concerning you or similarly significantly affects you. Moderation decisions involving content removal, formal strikes, account suspensions, or permanent bans always involve human evaluation and are subject to human review and appeal under our Terms of Service.

8. Taxonomy Classification & Creative Rights

We maintain an uncompromising commitment to creative ownership and transparency regarding artificial intelligence and automated systems:

A. Production Launch: Deterministic Rule-Based Classification Active

For the production launch, Second Pass uses deterministic, rule-based taxonomy classification executing locally on our application servers. When you draft or update a Workbench, Pass, Technique, or Portfolio project, our server matches title and text keywords against our canonical 3D/game development skill ontology locally.

External artificial intelligence foundation models (including the Google Gemini API) are disabled and dormant by platform policy for launch. Zero user text, creative notes, or feedback are transmitted to external AI providers.

Strict Guarantee: No Generative Model Training on Creative Work:

Second Pass does not use, sell, or license user-uploaded creative media—including 2D artwork, 3D models, digital sculpts, turnaround renders, animations, videos, or portfolio case studies—to train commercial generative artificial intelligence models or foundation models. Your creative intellectual property remains strictly yours.

B. Future AI Feature Governance

If external artificial intelligence classification is enabled in future updates, it will operate strictly under an explicit secondary administrative opt-in, remain restricted to text taxonomy classification only, comply with under-18 safety requirements, and be governed by enterprise zero-data-retention commitments.

9. Service Providers & Processors

To deliver the Service, we partner with specialized cloud infrastructure providers acting as data processors under Article 28 of the GDPR:

Supabase, Inc. (Delaware, USA)Database, Auth & Storage

Provides our managed PostgreSQL database, authentication infrastructure (Supabase Auth), transactional notification emails (signup confirmation and password resets), and secure object storage (community-media). Database and media storage are hosted in the European Union (AWS region eu-west-1, Ireland). Processing is governed by Supabase’s Data Processing Addendum incorporating European Commission Standard Contractual Clauses (SCCs).

Transactional Email & Communications InfrastructureSMTP Mail Delivery (Polar55)

Delivers transactional emails, authentication notices, and statutory notices under EU DSA Article 16 via authenticated TLS transport (cp03.polar55.com). Recipient email addresses and transmission logs are processed strictly to ensure verifiable delivery and legal compliance.

Application Hosting & Edge Delivery ProviderCDN & Compute (Vercel, Inc., USA)

Delivers web application pages, static bundles, and edge API execution under standard data protection terms and security commitments.

Google Gemini / External LLM APIsINACTIVE / DORMANT AT LAUNCH

External artificial intelligence classification APIs are disabled at launch. No personal data, titles, descriptions, or creative work are transmitted to Google or external AI providers.

No Advertising or Analytics Processors: Second Pass does not integrate Google Analytics, Meta Pixel, PostHog, Hotjar, or advertising broker networks. We do not monetize member personal data.

10. International Data Transfers

Second Pass is operated from Finland. Our primary database instances and media storage repositories are located within the European Economic Area (AWS eu-west-1, Ireland, via Supabase).

However, our technology processors (including Supabase, Inc. and our hosting provider) are entities organized under United States law or maintain international operations. In the course of global edge routing, network telemetry, and system maintenance, personal data or network metadata may be processed by or accessible to these US-based entities.

Where personal data is transferred to or accessed from countries outside the European Economic Area (EEA), such transfers are governed by appropriate safeguards under Chapter V of the GDPR:

  • European Commission Standard Contractual Clauses (SCCs) executed with our service processors;
  • the EU-U.S. Data Privacy Framework (DPF) adequacy decision for participating certified entities, where applicable; and
  • supplementary technical safeguards, including cryptographic hashing of credentials, client-side EXIF sanitization, TLS 1.2/1.3 transmission encryption, and strict least-privilege administrative access controls.

11. Data Retention & Criteria

We retain personal data only for as long as necessary to satisfy the purposes for which it was collected or to comply with statutory legal requirements:

  • Active Accounts: Profile information, creative Workbenches, Passes, Contributions, Portfolio projects, Library guides, and direct messages remain stored while your account remains open.
  • Authentication Credentials upon Deletion: Your email address, password hash, and active authentication session records are permanently deleted from authentication tables immediately upon account erasure.
  • Portfolio Projects upon Deletion: Portfolio showcase projects and media are permanently deleted immediately upon account erasure.
  • Deleted Username Cooling-Off Reservation (90 Days): When an account is deleted, the lowercase username string is stored in a private reservation table (deleted_username_reservations) for exactly 90 days. This temporary reservation prevents bad actors from immediately claiming a departed creator’s handle to impersonate them. The reservation automatically expires after 90 days.
  • Safety Investigation Records: Where an account deletion occurs while involved in an active safety investigation, moderation records are marked for safety review for up to 90 days to prevent bad actors from evading platform abuse sanctions.
  • Append-Only Audit Logs: Security and administrative audit records in admin_audit_events are retained based on criteria of maintaining platform security forensics, preventing fraud, and demonstrating regulatory compliance.
  • Privacy & Data Rights Requests: Requests and correspondence submitted via /privacy/request are retained in our private privacy_requests table for the period necessary to investigate, fulfill, and document compliance with the request, and thereafter as necessary for the establishment, exercise, or defense of legal claims or statutory limitation periods under Finnish law. Identity verification correspondence is retained only as long as required to substantiate identity for the request.
  • Copyright & Intellectual-Property Reports: Copyright and intellectual-property complaint records are retained for as long as reasonably necessary to investigate and resolve the report, comply with applicable legal obligations, prevent repeated abuse, maintain appropriate dispute and enforcement records, and establish, exercise or defend legal claims. Relevant records may be retained for longer where an applicable legal limitation period, pending dispute, authority request or other legal requirement makes this necessary. Records are deleted or anonymised when they are no longer reasonably required for these purposes. (In the current platform implementation, complaint records in copyright_reports are retained under this governance policy, and automated deletion schedules remain subject to pre-launch operational review).
  • Contact & General Support Inquiries: Contact and support correspondence is retained for as long as reasonably necessary to respond to the inquiry, provide support, maintain appropriate operational records, prevent abuse, resolve disputes, and establish, exercise or defend legal claims. Records are deleted or anonymised when they are no longer reasonably required for these purposes, subject to applicable legal obligations.

12. Account Deletion & Anonymization

You have the absolute right to delete your account at any time via Account & Data Rights Settings.

Because Second Pass is a collaborative community where creators build upon one another’s critique, technical solutions, and feedback, our relational account deletion procedure operates as follows:

1. Identity Anonymization & Credential Purge

  • Your profile record is neutralized: your display name, biography, geographical location, primary discipline, and all external social links are permanently overwritten and erased.
  • Your avatar image is permanently purged from cloud storage.
  • Your public username is permanently replaced with a randomized anonymous placeholder (e.g., former_member_a1b2c3d4).
  • Your authentication record in Supabase Auth is permanently deleted, terminating all active sessions.
  • Private data—including bookmarks, saved workbenches, followed creators, blocked users, and inbox notifications—is permanently deleted.

2. Portfolio Showcase Deletion

All Portfolio showcase projects, process breakdowns, and associated media files are permanently deleted from database tables and storage buckets.

3. Collaborative Content Choice: Removal vs. Anonymized Preservation

When requesting account deletion, you choose how your collaborative community content (Workbenches, Passes, Contributions, and Library Guides) is handled:

  • Removal: Your Workbenches, Passes, and Contributions are removed from public display. Where other creators have already built upon a thread, structural tombstone placeholders maintain conversational continuity.
  • Anonymized Preservation: When an Account is deleted, certain Contributions may remain as part of an existing public discussion after identifying account information has been removed. Where the remaining material is no longer reasonably identifiable as relating to the former user, it is no longer treated as personal data. Attribution (author_id) is permanently removed and set to null in database records, all personal account metadata is wiped, and entries are displayed under the neutral placeholder “Former member”.

4. Direct Messages

In existing conversation threads, your sender identifier is unlinked, displaying your historical messages under the anonymous placeholder “Former member”.

13. Security & Access Safeguards

We implement robust technical and organizational security measures under Article 32 of the GDPR to protect personal data:

  • Row-Level Security (RLS): PostgreSQL Row-Level Security policies are enforced across database tables, ensuring members can only query or modify their authorized records.
  • Role-Based Access Control (RBAC): Administrative and moderation tools require verified role assignments (moderator, admin, owner). Regular users cannot access internal safety or audit tables.
  • Step-Up Reauthentication: Sensitive account operations—including changing your email, updating your password, initiating a data export, or executing account deletion—require explicit reauthentication by entering your current password. Successful reauthentication issues a time-limited token with a 15-minute expiration window.
  • Transport Layer Security (TLS): All web traffic and API transmissions are encrypted in transit using modern TLS 1.2 and TLS 1.3 cryptographic protocols with strict HSTS enforcement.
  • Cryptographic Password Hashing: User passwords are never stored in plaintext and are salted and hashed using modern cryptographic standards managed by Supabase Auth.
  • Direct Message Privacy Controls: Direct messages are protected by database Row-Level Security so that only conversation participants can query them via client APIs. Second Pass staff members cannot browse private messages in ordinary workflows; staff only review messages when a participant files a safety report selecting that message, which creates an immutable safety snapshot strictly for investigation. System administrators with direct service-role database access technically have low-level access for security maintenance, disaster recovery, or legal compliance. Direct messages are not end-to-end encrypted.
  • Privacy Request Access Protection: Formal privacy and data-rights requests submitted via /privacy/request are stored in a dedicated, private table shielded by PostgreSQL Row-Level Security. Anonymous and regular user clients have zero read or write access. Only authorized platform operators and designated staff with verified access rights can review, triage, or update request records.
  • Copyright Report Access Protection: Intellectual-property complaints and associated staff triage notes submitted via /copyright/report are stored in a dedicated, private table shielded by PostgreSQL Row-Level Security. Anonymous and regular user clients have zero read or write access. Only authorized platform operators and designated staff with verified access rights can review, triage, or update complaint records and internal notes.
  • Contact Request Access Protection: General inquiries, support messages, and security vulnerability reports submitted via /contact are stored in a dedicated, private table shielded by PostgreSQL Row-Level Security. Anonymous and regular user clients have zero read or write access. Only authorized platform operators, administrators, and designated operations/support staff with verified capabilities (operations.read, operations.manage, or user.account.support) can access or triage contact records and internal staff notes. No raw IP addresses are retained in the Contact intake or durable rate-limit database records; rate-limit identifiers are stored as keyed one-way digests.

14. Your Rights under the GDPR

As an individual in the European Union or accessing Second Pass, you possess comprehensive statutory rights under Chapter III of the GDPR. You can exercise these rights at any time using our public Privacy Request Form (/privacy/request) or directly through your self-service account controls:

Statutory Response Timeline (Article 12(3) GDPR):

We will respond to eligible data-rights requests without undue delay and, in any event, within one month of receiving the request. Where permitted by law, that period may be extended by up to two additional months where necessary because of the complexity or number of requests. If an extension is required, we will inform the requester within the initial one-month period.

Where reasonably necessary to protect accounts against unauthorized access or disclosure, we may request additional information to confirm the identity of the person making the request (for example, by requiring confirmation from the registered account email). SecondPass does not collect or require government identity cards or passport copies for standard data rights inquiries.

A. Right of Access (Article 15 GDPR)

You have the right to obtain confirmation as to whether your personal data is being processed, and to access that data along with information regarding processing purposes, categories of data, and recipients.

B. Right to Rectification (Article 16 GDPR)

You have the right to rectify inaccurate personal data or complete incomplete information. You can directly update your profile, display name, bio, location, discipline, and external links at any time in Profile Settings.

C. Right to Erasure / “Right to be Forgotten” (Article 17 GDPR)

You have the right to request the permanent erasure of your personal data. You can exercise this directly through our automated deletion tool at Account & Data Rights, which permanently purges your credentials and profile.

D. Right to Data Portability (Article 20 GDPR)

You have the right to receive your personal data in a structured, commonly used, and machine-readable format. Second Pass provides a self-service “Download My Data” export feature at Account & Data Rights. The generated ZIP archive contains:

  • data.json: Complete structured record of your profile, workbenches, passes, contributions, portfolio projects, saved items, follows, and reputation ledger; and
  • a dedicated media folder containing original-resolution copies of your uploaded creative assets.

E. Right to Restriction of Processing (Article 18 GDPR)

You have the right to request the restriction of processing where you contest data accuracy, where processing is unlawful, or while an objection is evaluated.

F. Right to Object (Article 21 GDPR)

You have the right to object to processing based on our legitimate interests (Article 6(1)(f) GDPR) on grounds relating to your particular situation.

G. Right to Withdraw Consent (Article 7(3) GDPR)

Where a specific processing activity is based on your consent, you have the right to withdraw that consent at any time without affecting the lawfulness of processing prior to withdrawal. This applies only where a specific processing activity is based on your consent. Note that core SecondPass processing activities (such as operating your account, hosting your portfolio showcase, and delivering collaborative community discussions) are performed pursuant to contract performance under our Terms of Service or legitimate interests rather than voluntary consent.

15. Finnish Supervisory Authority & Complaints

If you believe our processing of your personal data infringes the GDPR or Finnish data protection law, you have the statutory right under Article 77 of the GDPR to lodge a complaint with a data protection supervisory authority.

Because Second Pass is operated from Finland, our competent supervisory authority is the Office of the Data Protection Ombudsman (Tietosuojavaltuutetun toimisto):

Tietosuojavaltuutetun toimisto (Office of the Data Protection Ombudsman)
Visiting Address: Lintulahdenkuja 4, 00530 Helsinki, Finland
Postal Address: PL 800, 00531 Helsinki, Finland
Email: tietosuoja@om.fi
Telephone: +358 (0)29 566 6700
Website: tietosuoja.fi

You may also lodge a complaint with the supervisory authority in your EU Member State of habitual residence or place of work. We encourage you to reach out to us first so we can promptly address your concerns.

16. Minimum Age & Children

SecondPass requires users to be at least 16 years old to create an Account.

This requirement is a platform eligibility rule established by Second Pass, and does not represent the Finnish statutory age of consent for information society services (which is 13 under Section 5 of the Finnish Data Protection Act, Tietosuojalaki 1050/2018).

We do not knowingly collect, solicit, or maintain personal data from individuals under the age of 16. If we become aware that an account has been registered by a person under 16, we will promptly close the account, terminate authentication, and erase their personal data from our systems.

Parents or legal guardians who discover that their minor child has registered an account may contact us through the methods listed in Section 20 to request immediate deletion.

17. Cookies & Storage Technologies

Second Pass maintains a strict commitment to privacy and data minimization:

A. Strictly Necessary Authentication Cookies

The only cookies utilized by Second Pass are strictly necessary authentication/session cookies managed by our authentication provider (sb-*-auth-token). These cookies are used to maintain signed-in sessions and support authentication.

  • Cookie Name: sb-*-auth-token (and chunked session keys)
  • Purpose: Maintaining signed-in session authentication between server and client
  • Path: /
  • SameSite: Lax
  • HttpOnly: false (configured to allow client-side session synchronization by the authentication SDK)
  • Secure: Transmitted securely over HTTPS in production

B. No Third-Party Trackers or Advertising Cookies

Second Pass does not use:

  • third-party advertising or retargeting cookies;
  • commercial analytics suites (e.g., Google Analytics, Meta Pixel, PostHog);
  • behavioral heatmaps or session-recording tools; or
  • browser fingerprinting technologies.

C. Client-Side Browser Storage

Second Pass does not use localStorage or sessionStorage to store personal profiles or tracking identifiers.

Exemption from Cookie Consent Banners:

Under Article 5(3) of the EU ePrivacy Directive (Directive 2002/58/EC as amended) and Section 205 of the Finnish Act on Electronic Communications Services (Laki sähköisen viestinnän palveluista 917/2014), cookies strictly necessary to provide an information society service explicitly requested by the subscriber or user do not require prior consent. Because Second Pass uses solely strictly necessary session cookies, no cookie consent banner is required.

18. External Links & Video Embeds

The Service may contain links to external third-party websites (such as external portfolio platforms, personal websites, social networks, and software vendor sites) or allow embedded video media in educational guides:

  • External Hyperlinks: Clicking on an external hyperlink directs your browser to a third-party website governed by that third party’s own privacy policy and terms. We are not responsible for the privacy practices or content of external sites.
  • Embedded Video Media: Educational guides in our Library may link to or embed instructional video streams from third-party hosting platforms (e.g., YouTube, Vimeo). When you play an embedded video, that third-party provider may receive your IP address and set cookies in accordance with their respective privacy policies.

19. Changes & Updates

We may revise this Privacy Policy periodically to reflect enhancements to our platform features, operational practices, security measures, or changes in legal and regulatory requirements.

When we make changes, we will update the “Last updated” date at the top of this page. For material changes that significantly alter your privacy rights or how we handle your personal data, we will provide prominent notice through the platform (such as an in-app announcement banner or direct email notification to your registered address) prior to the changes taking effect.

We encourage you to review this Privacy Policy periodically to stay informed about our data protection standards.

20. Contact & Inquiries

SecondPass.net is operated by its founder and individual operator in Oulu, Finland. If you have questions, feedback, or concerns regarding this Privacy Policy or our data governance practices, or wish to exercise your statutory rights, please reach out to us:

Public Data Rights & Privacy Contact Channel:

For all formal GDPR requests, data inquiries, or notices regarding personal data, please use our public submission form or direct email:

Web Request Form: https://secondpass.net/privacy/request (Accessible to all visitors & account holders)
Email Contact: privacy@secondpass.net
Data Controller: Shafa Sabeti Motlagh, Oulu, Finland
Response Timeline: Without undue delay and, in any event, within 1 month (Art. 12(3) GDPR)

Self-Service Account & Privacy Controls (Registered Members):

21. Plain-Language Summary

This summary provides an accessible overview of our data commitments. It does not replace the legally binding terms set out above.

Your Creative Work is YoursWe do not use or sell your artwork, 3D models, or renders to train generative AI models. Classification at launch is entirely deterministic and rule-based, running locally with zero external AI calls.
Automated Image PrivacyAll images uploaded to Second Pass have their EXIF metadata and GPS location automatically stripped before storage.
No Tracking CookiesWe do not run Google Analytics, advertising pixels, or third-party trackers. We only use strictly necessary cookies to keep you signed in securely.
Full Data PortabilityYou can download a complete ZIP file of all your data (data.json) and original media at any time with one click.
Transparent DeletionYou can permanently delete your account at any time. Your profile and portfolio are purged immediately, and you choose whether your helpful comments remain anonymously or are removed.