Privacy Policy
Last updated: 5 September 2026
1. Controller and contact
- Turn To Be Done is operated by Jaroslav Tuzinsky, The Pulse Boulevard Apartments – C3, 1103, Madinat Al Mataar, Dubai, United Arab Emirates. Send privacy questions and rights requests to support@tbdone.com. This contact is available without signing in or paying for membership.
- Representative in the European Union under Article 27 GDPR: Marina Tuzhinskaya, Vysoká 10, 934 01 Levice, Slovak Republic. Email: tbdone@gmail.com. Individuals and supervisory authorities may contact the representative on matters concerning personal data protection in addition to or instead of the controller.
2. Data and its sources
- We receive the information you provide when registering and using the service: name, email, profile, contact and business details, addresses, requests, offers, messages, photos and videos. Provider verification also involves submitted business evidence and the verification outcome.
- Other data arises from using the service: account identifiers, job status, reviews and content from the other party, sign-in and security records, technical information and notification tokens. Apple or Google sign-in provides the information made available by that provider for authentication.
3. Why we process data
- We process account information, requests, offers and communications to provide the agreed service features, generally to perform a contract or take steps before entering one. Without information necessary for a particular feature, we cannot provide that feature.
- Security, abuse prevention and protection of rights are assessed on the basis of legitimate interests of the operator and users; you can object to such processing. Legal obligations are handled under the applicable law. Where processing relies on consent, you can withdraw it without affecting the lawfulness of earlier processing. Accepting the Terms is not blanket consent to all processing.
4. Sharing and verification evidence
- Provider profiles, portfolios, inspiration posts and reviews are intended for other users according to the relevant feature. Requests are shown to prospective providers. Do not include information you do not want to disclose to that audience.
- Messages and private job photos are intended for the job participants. An authorised administrator may access information needed for support, security or verification. Verification evidence is not a public portfolio. Do not send passports or national identity cards; redact unrelated private details from business evidence.
- The updated provider verification process uses human review. Verification evidence is not sent to an external AI service in that process. Contact support@tbdone.com with questions or objections about a verification outcome.
5. Service providers and international processing
- We use Google Firebase and Google Cloud for authentication, the database, file storage, server functions and notifications. The website is intended for hosting on Cloudflare. Notification delivery to Apple devices also relies on Apple services. The email provider processes correspondence sent to support.
- Optional location, maps, geocoding and dictation may involve providers of the feature or operating system. You can change device permissions in its settings. Declining an optional permission may limit that feature.
- The operator is based in the United Arab Emirates. Processing and access may involve countries outside the EEA. You can request information about specific recipients and the applicable transfer safeguards at support@tbdone.com.
6. Retention and deletion
- Account information and content needed to provide the service are retained while the account is in use. Account deletion removes associated information as described on the Delete account page.
- Verification evidence becomes eligible for automatic cleanup 30 days after a final decision; pending reviews are not deleted under this rule. Unused incomplete uploads become eligible after 7 days. Cleanup runs daily in batches. Routine cloud operational logs are configured for 30-day retention.
- File storage has a 7-day recovery period after deletion. Separate provider retention applies to internal and backup systems; for Firebase Authentication, Google states removal from live and backup systems within 180 days after account deletion is initiated.
- Resolved privacy requests and administrator audit records become eligible for cleanup 365 days after resolution or creation respectively. This operational period supports review of request handling and security. Completed account-deletion locks become eligible after 30 days if the account no longer exists. Open requests, incomplete deletions and records under a justified preservation hold are excluded.
- Some shared job records and the other party’s content may remain. A record containing an identifier instead of a name can still be personal data. The reason and necessity for further retention must be assessed for the particular record; a record remaining in the system does not itself justify indefinite retention.
- Security records, completed requests and backups are assessed according to the need to demonstrate request handling, investigate an incident, protect rights or meet a specific legal obligation. Account deletion does not promise immediate removal from every backup or copy obtained by another user. Contact support@tbdone.com for details or assessment of further erasure.
7. Your rights and requests
- Subject to the GDPR conditions, you may request access and a copy, correction, erasure, restriction and portability, and object to processing based on legitimate interests. Not every right applies to every type of processing.
- Email support@tbdone.com. App versions with Privacy and my data also let you submit a request from settings. Include your account email and what you are requesting; do not send your password. Where there are reasonable doubts, we may request information needed to verify your identity.
- We will respond without undue delay, normally within one month. Where the legal conditions allow an extension for a complex request, we will explain the reasons and extension within one month, up to two additional months. We will explain a refusal. Requests are normally free of charge.
- You can complain to the Office for Personal Data Protection of the Slovak Republic or another competent supervisory authority, particularly where you habitually live, work or consider an infringement to have occurred.
8. Website, device and changes
- The website and app need technical information to deliver content, authenticate users and provide security. From 10 September 2026, the public website uses Google Analytics 4 only with visitor consent, measuring page visits, app store clicks and web app opens. From 12 September 2026, fresh consent also covers web registration steps: form views and starts, attempts, general error categories, cancellations and success. Only account type, registration method and result category are sent, without field contents or account identifiers. Analytics cookies (_ga and _ga_*) and the consent choice are configured to expire after 180 days. Consent can be changed at any time through Privacy settings; rejection does not restrict the service. We do not intentionally send names, emails, form contents, messages or work records. Advertising personalisation is disabled. Google processes this data, potentially outside your country. More: https://policies.google.com/technologies/partner-sites.
- The service is not intended for people under 16. We will provide appropriate notice of material changes to processing. The date of this version appears above.