Rory Privacy & Data Retention Policy (UK & GDPR Edition)

Last Updated: September 7, 2026
Effective Date: September 7, 2026
Controller: Rory LLC ("Rory", "we", "us", or "our")
Contact: [email protected] / [email protected]
Canonical URL: https://legal.joinrory.com/en-gb/privacy

This Privacy Policy applies to data subjects in the United Kingdom (under the UK GDPR and Data Protection Act 2018) and the European Economic Area (under the EU General Data Protection Regulation 2016/679).


1. Data Controller Identification

Rory LLC is the Data Controller responsible for your personal data processed through joinrory.com, app.joinrory.com, rory.page, and rorypay.com.


2. Personal Data We Collect & Lawful Bases

We collect and process personal data strictly in accordance with Article 6 of the GDPR:

  • Contractual Necessity (Art. 6(1)(b)): Processing usernames, email addresses, password hashes, coin purchases, ledger transactions, and creator USD payouts.
  • Legal Obligation (Art. 6(1)(c)): Retaining financial records, tax data, and identity verification outcomes under anti-money laundering (AML) and financial reporting regulations.
  • Legitimate Interests (Art. 6(1)(f)): Protecting platform security, investigating fraud, maintaining system stability, and enforcing our terms.
  • Consent (Art. 6(1)(a)): Non-essential cookies and analytics signals on joinrory.com.

3. Statutory Data Retention Schedule

Under Article 5(1)(e) (Storage Limitation), personal data is retained only for as long as necessary to satisfy the purposes for which it was collected or to comply with mandatory statutory requirements:

  1. Financial Ledger & Transaction Records: Retained for 7 years following the transaction date to comply with corporate tax laws, accounting standards, and statutory audit obligations.
  2. KYC & Anti-Money Laundering Verification: Retained for 5 years following the termination of the creator relationship in compliance with statutory AML directives.
  3. Account & Profile Records: Retained for the duration of the active account relationship plus 30 days following verified account closure.
  4. Direct Messages & Media: Retained for up to 3 years or until deleted by account holders.
  5. Session Cookies & Audit Logs: Stored for 7 to 90 days for operational security.

4. International Data Transfers

When transferring personal data outside the UK or EEA (such as to our servers in the United States), Rory ensures appropriate safeguards pursuant to Article 46 of the GDPR, including Standard Contractual Clauses (SCCs) approved by the European Commission and the UK Information Commissioner's Office (ICO).


5. Your Rights Under GDPR & UK DPA

You possess the following statutory rights:

  • Right of Access (Art. 15): Obtain confirmation and a copy of your personal data.
  • Right to Rectification (Art. 16): Correct inaccurate or incomplete data.
  • Right to Erasure (Art. 17): Request deletion of data, subject to legal and statutory retention mandates (such as our 7-year financial recordkeeping obligation).
  • Right to Restriction (Art. 18) & Portability (Art. 20): Request limits on processing or export of your data in a structured, machine-readable format.
  • Right to Object (Art. 21): Object to processing based on legitimate interests.
  • Right to Lodge a Complaint: You have the right to lodge a complaint with your supervisory authority (in the UK, the Information Commissioner's Office at ico.org.uk).

To exercise any right, contact [email protected].

Version History

  • Version 1 (Current)September 8, 2026