Legal

Privacy Policy

What we collect, why we collect it, who sees it, how long we keep it and what you can require us to do about it.

Last updated: 5 August 2026

1. Who is responsible

Nemodits Digital Ltd, registered in the United Kingdom under company number 14827305 at Suite 12, 84 Great Eastern Street, London EC2A 3JL, United Kingdom, is the data controller for the personal data described here. Write to privacy@nemodits.net for anything in this policy.

2. What we collect

CategoryExamplesWhere it comes from
Application data Name, email address, age, country, devices, availability, study interests, your written answer, and the consents you gave You, when applying to join
Account data Name, email address, hashed password, account status You, at registration
Profile data Age range, country, languages, devices, interests You, when completing your profile
Participation data Studies offered and accepted, answers, timestamps, review outcomes Generated as you take part
Payout data Chosen method, payout account identifier, payment history You, and our payment providers
Verification data Identity check result and, where required, an identity document You, via our verification provider
Technical data IP address, browser and device type, pages viewed, error logs Collected automatically when you use the site
Support data Emails you send us and our replies You

We do not ask for special category data (health, beliefs, biometrics and similar). If a specific study needs anything of that kind, it is explained before you start and taking part is optional and based on your separate, explicit consent.

3. Why we use it, and our legal basis

PurposeLegal basis
Reviewing your application to joinSteps taken at your request before entering a contract
News emails, if you opted in when applyingConsent — withdraw any time via the link in any email or by writing to us
Creating and running your accountPerformance of our contract with you
Matching you to studiesPerformance of our contract with you
Reviewing submissions and paying pointsPerformance of our contract with you
Preventing duplicate accounts and fraudLegitimate interests — protecting members, clients and the platform
Identity verification before payoutLegal obligation, and our legitimate interest in preventing fraud
Keeping payment and accounting recordsLegal obligation
Responding to support requestsPerformance of our contract, and legitimate interests
Analytics about how the site is usedConsent, given through the cookie banner
Measuring our advertisingConsent, given through the cookie banner

Where we rely on consent you can withdraw it at any time — for cookies, through the Cookie settings link in the footer. Withdrawing consent does not affect processing that already happened.

4. Who we share it with

  • Clients who commission studies. They receive findings — your answers and observations — under contract. Unless a study states otherwise and you agree to it separately, they do not receive your name or contact details.
  • Payment providers, to send you money. They receive only what is needed to make the payment.
  • Our identity verification provider, where a check is required.
  • Infrastructure and email providers that host the service on our behalf, under written processing agreements.
  • Professional advisers, auditors and authorities, where we are legally required to disclose.

We do not sell personal data, and we do not share it with data brokers.

5. International transfers

Some of our providers operate outside the United Kingdom and the European Economic Area. Where data is transferred, we rely on an adequacy decision where one exists, and otherwise on the UK International Data Transfer Agreement or the EU Standard Contractual Clauses, together with an assessment of the safeguards in place. You can ask us for details of the mechanism used for a specific transfer.

6. How long we keep it

DataRetention
Rejected applicationsDeleted 6 months after the decision
Approved applicationsUntil your account is created, or until you ask us to remove it
Account and profile dataWhile your account is open, then 12 months
Participation data24 months after the study closes, then pseudonymised
Payment and accounting records6 years, as required by tax law
Identity verification records12 months after the check, unless a dispute is open
Support correspondence24 months after the request is closed
Technical and error logs90 days
Fraud records for closed accounts5 years, to stop the account being reopened

7. Your rights

Under UK and EU data protection law you can ask us to:

  • give you access to the personal data we hold about you;
  • correct anything inaccurate or incomplete;
  • delete your data, where we have no overriding obligation to keep it;
  • restrict how we use it while a question about it is resolved;
  • port it — receive it in a machine-readable format, or have it sent elsewhere;
  • object to processing we base on legitimate interests;
  • withdraw consent where consent is our basis.

Email privacy@nemodits.net from the address on your account. We respond within one month and will tell you if we need longer. We do not charge for this, and exercising these rights never affects how many studies you are offered.

8. Security

Traffic is encrypted in transit. Passwords are stored hashed, never in readable form. Access to member data inside the company is limited to staff who need it and is logged. No system is perfectly secure, so if a breach affects your rights we will notify you and the relevant supervisory authority as the law requires.

9. Children

The service is for people aged 18 and over. We do not knowingly collect data from anyone younger. If you believe a minor has registered, tell us and we will close the account and delete the data.

10. Changes

We will post any updated version here with a new date, and where a change materially affects you we will tell you by email before it takes effect.

11. Contact and complaints

privacy@nemodits.net — Nemodits Digital Ltd, Suite 12, 84 Great Eastern Street, London EC2A 3JL, United Kingdom.

If you are not satisfied with our answer you can complain to your data protection supervisory authority. In the United Kingdom that is the Information Commissioner's Office; in the EU it is the authority for the country where you live.