Privacy
Last updated: 20 September 2026
1. Controller, scope, and contact
Joel R. Klemmer, United States, operates joelklemmer.com and is responsible for decisions about the personal information described in this policy. Where an applicable privacy law uses the term controller, business, organization, data fiduciary, personal-information handler, or a comparable term, Joel R. Klemmer acts in that capacity for the site’s own processing.
This policy applies to the website, its contact form, the AI Guide, optional display preferences, public and professional records, and downloadable resources controlled by joelklemmer.com. It does not govern a publisher, retailer, media outlet, social platform, government source, or other external service reached through a link. That service applies its own privacy terms when you choose to visit it.
Privacy questions, requests, and complaints may be submitted through the contact form or by email to contact@joelklemmer.com. Identify the relevant page, interaction, email address, and action requested so the request can be located and assessed without collecting unnecessary information.
2. Processing principles
The site is designed to collect and retain only information reasonably connected with a stated function. Personal information is used for the purpose described at collection or for a compatible, lawful purpose; kept accurate where accuracy matters; protected in proportion to the information and risk; and deleted, anonymized, or reviewed when it is no longer needed, subject to lawful retention.
The site does not include visitor accounts, payment processing, analytics, advertising, marketing pixels, session replay, cross-site behavioral tracking, or behavioral advertising profiles. It does not sell personal information or exchange it for money or another valuable benefit, share it for cross-context behavioral advertising, or offer a financial incentive for personal information.
3. Information processed and where it comes from
Pages, files, and security
When a browser requests a page, image, script, document, or other file, Vercel and related network and security systems may process technical request information needed to deliver and protect the service. Depending on what the browser and network supply, this may include:
- network address and approximate network-derived location;
- requested address, request method, response status, date, and time;
- browser, operating-system, device, and user-agent information;
- referrer information;
- language, encoding, and similar protocol information; and
- security, error, performance, and diagnostic signals.
The sources are your browser or device, network intermediaries, and the hosting and security provider. The site uses this information to deliver requested material, maintain reliability, prevent abuse, diagnose errors, and protect the service and its users.
Display preferences and device signals
The application reads one local-storage item named jk.preferences. It writes that item only if you turn on Remember display settings. It contains your theme, motion, and graphics choices and the fact that you asked the browser to remember them. Without that choice, display settings remain in memory for the current page session.
Before you choose a setting, the browser may report color-scheme, reduced-motion, data-saving, connection, or device-memory signals so the page can select an initial presentation. The application does not write those raw signals into jk.preferences. The selected locale is represented in the website address. The Cookie and Browser Storage Policy provides the full storage inventory and controls.
Contact form and email
When you use the contact form, the site processes the name, email address, subject, and message you submit. It also processes limited request and security information to validate, rate-limit, deduplicate, deliver, and respond to the inquiry.
The application converts the relevant network address and a submission signature into keyed cryptographic hashes before sending abuse-prevention and duplicate-submission records to Upstash. Upstash receives counters, expiry values, hashes, and a limited delivery identifier for those controls, not the raw contact message or raw network address. Resend receives the submitted name, email address, subject, and message to deliver the email. Microsoft hosts the receiving mailbox.
Do not submit confidential information, legally protected secrets, sensitive personal information, or another person’s information unless it is necessary and you are authorized to provide it.
AI Guide
When you submit a question to the AI Guide, the application processes the question, selected curated public-source records from this site, the requested locale, technical request data, and rate-limit data to generate and secure a response. It does not retrieve from or send private Obsidian notes, Neo4j memory, private correspondence, or an unpublished personal knowledge base.
OpenAI is the primary model provider. The primary request uses the Responses API with store: false. If the primary service is unavailable, over the configured daily budget, times out, rejects the request for quota or cost reasons, or returns an invalid response, the application may send the same question and selected public sources through OpenRouter’s free-model route. The fallback request disables provider fallbacks beyond that selected route, requires supported parameters, sets provider data collection to deny, and caps provider price at zero.
These controls reduce collection and cost but do not promise zero retention. Under OpenAI’s default API controls, API inputs and outputs are not used to train models by default, but abuse-monitoring data may be retained for up to 30 days unless the account has an applicable enhanced retention control. Setting store: false prevents Responses API application-state storage; it does not by itself establish Zero Data Retention. The OpenRouter fallback does not require a Zero Data Retention endpoint, and OpenRouter and the selected downstream provider apply their current terms and controls.
The application does not add your network address, contact-form email address, or a private account profile to the model-provider payload. A provider receives the server-side request metadata ordinarily needed to operate its API, and it receives personal information if you include that information in the question itself. The application does not write the AI question or answer to Upstash. It stores only keyed rate-limit counters. Operational logs are designed to contain a random request identifier, status, outcome, provider route, and fallback reason, not the question or answer. Do not submit confidential information or personal information that is unnecessary for the question. AI output is automated, may be inaccurate, and is not Joel R. Klemmer speaking.
Public and professional records
The site processes limited professional, bibliographic, media, recognition, and public-record information from cited public sources. Sources may include publishers, retailers, media outlets, platforms, issuing organizations, government records, and material made public by the relevant person or organization.
The site may publish a name, role, organization, work, date, quotation, source link, or other context reasonably supported by the cited record. A public source does not make every later use unrestricted. A request to correct, contextualize, restrict, or remove a record is assessed under applicable privacy law together with accuracy, record integrity, rights of expression and reporting, and the public interest in supported information.
Privacy requests and legal records
When you exercise a privacy right or make a complaint, the site processes the request, related correspondence, information reasonably needed to verify authority, the response, and a limited administrative record. Information may also be processed where reasonably necessary to comply with law, respond to lawful process, investigate security or abuse, or establish, exercise, or defend legal rights.
4. Purposes and lawful grounds
The site processes personal information for the following purposes:
- to deliver requested pages, files, and accessibility alternatives;
- to remember display settings when you request persistence;
- to receive, secure, deliver, review, and respond to communications;
- to answer an AI Guide question using identified public sources;
- to prevent abuse, repeated submissions, unauthorized access, and excessive automated use;
- to maintain availability, diagnose errors, and protect service integrity;
- to publish, support, correct, and contextualize professional and public records;
- to comply with binding legal obligations and lawful process; and
- to establish, exercise, or defend legal rights and claims.
Where the applicable law recognizes the relevant ground, processing may rely on:
- your consent for optional persistent display preferences and another activity for which consent is specifically requested;
- steps you request, such as delivering a response or receiving an inquiry, where the law recognizes that ground;
- legitimate interests in operating and securing a proportionate informational website, responding to communications, providing a requested AI answer, maintaining accurate supported records, presenting professional and public information, and protecting legal rights, but only where that ground is legally recognized and not overridden by your rights;
- compliance with a legal obligation; or
- another basis permitted by the applicable law for the specific activity.
Legitimate interests is not asserted as a universal basis. Where a jurisdiction requires consent or another basis for a particular activity, that rule controls. Establishing, exercising, or defending a legal claim is a purpose and may also be a condition for limited sensitive-data processing where a law expressly provides it; it is not presented as a standalone universal lawful basis.
You may withdraw consent without affecting processing already carried out lawfully. Where the applicable law permits an objection to interests-based processing, the operator will assess the reason for the objection, the site’s purpose, and the effects on your rights.
5. Sensitive information and automated decisions
The site does not intentionally solicit legally defined sensitive or special-category information. The contact form and AI Guide should not be used to submit health information, government identifiers, precise financial information, passwords, private employment records, biometric data, racial or ethnic origin, religion, political opinion, sexual life or orientation, or other sensitive information unless it is strictly necessary and lawful.
If unnecessary sensitive information is submitted, it may be deleted or restricted. If limited processing is necessary, it must have a lawful purpose, a valid legal basis, and any additional condition required by applicable law.
The site does not use personal information to make a solely automated decision that produces legal or similarly significant effects about a visitor. The AI Guide generates informational text; it does not decide eligibility, employment, credit, housing, insurance, education, health care, government benefits, or another consequential service.
6. Recipients and processors
Personal information may be disclosed only as reasonably necessary to the following categories:
- Vercel, for hosting, content delivery, request handling, security, diagnostics, and deployment infrastructure.
- Upstash, for keyed contact and AI rate-limit hashes, counters, expiry values, and limited contact-delivery identifiers.
- Resend, for contact-message delivery.
- Microsoft, for the contact@joelklemmer.com receiving mailbox and related mailbox functions.
- OpenAI, as the primary AI model provider when you use the AI Guide.
- OpenRouter and a downstream model provider, only when the AI fallback route is used.
- Professional advisers and technical service providers under appropriate duties, where their involvement is necessary.
- Courts, regulators, law-enforcement bodies, emergency recipients, or other parties where disclosure is required by binding law or lawful process, or reasonably necessary to protect rights, safety, or service integrity.
The site may publish supported professional and public-record information to visitors. External links identify their destination and do not authorize an external service to receive contact or AI submissions through this site.
7. No sale, targeted advertising, or direct marketing
The site does not:
- sell personal information;
- share personal information for cross-context behavioral advertising;
- use personal information for targeted advertising;
- create a behavioral advertising profile;
- disclose personal information in exchange for money or another valuable benefit;
- run a direct-marketing email list; or
- offer a financial incentive for personal information.
A Global Privacy Control or similar opt-out signal therefore does not change current behavior. The required signal handling and opt-out controls will be implemented before any practice that makes such a signal operative is enabled.
8. International processing and safeguards
The controller is in the United States. Providers and their subprocessors may process information in the United States and other countries where they operate. Privacy protection and government-access rules may differ from those in your country.
The current Vercel Pro agreement incorporates Vercel’s Data Processing Addendum, including applicable Standard Contractual Clauses and United Kingdom transfer terms. Resend’s and Upstash’s service agreements incorporate their Data Processing Addenda. OpenAI, OpenRouter, Microsoft, and their relevant subprocessors apply their current service terms, data-processing terms, locations, and transfer mechanisms to the processing they perform.
Where applicable law requires a transfer mechanism, the transfer will be based on a mechanism valid for the actual relationship and route, such as an adequacy decision, approved or standard contractual clauses, a United Kingdom addendum, consent where lawfully available, or another recognized safeguard or exception. Naming a possible mechanism does not claim that every mechanism applies to every transfer.
You may request information about the safeguard relevant to your information. Commercially confidential terms, third-party rights, and security details may be redacted where the law permits.
9. Retention
The operator uses the following schedule and reviews it manually each month:
jk.preferencesremains in your browser until you disable Remember display settings, clear site data, or the browser removes it.- A contact-form client rate-limit record expires after 10 minutes.
- The contact-form global delivery counter expires after one hour.
- A pending duplicate-submission claim expires after 20 seconds.
- A completed contact-submission identifier, consisting of a keyed submission digest and limited provider identifier, expires after 24 hours.
- An AI Guide client rate-limit counter expires after one hour.
- The AI Guide global request counter and primary-provider daily budget counter expire after 24 hours.
- The application does not store AI questions or answers in Upstash.
- OpenAI API requests use
store: false; under default API controls, abuse-monitoring data may be retained for up to 30 days unless an applicable account-level control provides a shorter period. - OpenRouter and its selected fallback provider retain data under their applicable settings and terms. The request restricts data collection but does not require Zero Data Retention.
- Resend retains contact-message delivery data under the current Transactional Free plan for 30 days.
- Spam and irrelevant mailbox messages are deleted within 30 days after classification.
- Routine inquiries and related operator-controlled mailbox copies are deleted within 12 months after the inquiry is closed.
- A minimal administrative record needed to document and complete a privacy request is retained for 24 months after closure.
- Hosting, security, and diagnostic information is retained only while needed for delivery, security, diagnosis, incident response, legal obligations, or claims under the active provider account and configuration.
- Public and professional records remain while supported, relevant to the publishing purpose, and not required to be corrected, restricted, or removed.
A legal hold, active dispute, security incident, binding legal duty, or applicable limitation period may require longer retention. Provider backup, recovery, and deletion cycles may preserve protected copies for a limited additional period. Deletion from one system does not automatically delete a copy held independently by a person who received an email or by an external source linked from the site.
10. Security and incident response
The site uses measures proportionate to the information and risk. Current controls include encrypted transport, server-side credentials, keyed hashing, rate limiting, bounded inputs, fixed delivery destinations, origin controls, provider budget limits, least-privilege service access, restricted operational logging, and fail-closed handling for unavailable security dependencies.
No internet service can promise absolute security. A suspected incident will be assessed for the information involved, likely consequences, containment, recovery, and applicable notice duties. A regulator and affected people will be notified within the time and risk threshold required by the law that applies; this policy does not promise notice for every technical event.
11. Your global request options
The site accepts privacy requests from anyone, even where a particular law’s organizational or volume threshold may not apply. Subject to reasonable verification, the information held, technical feasibility, lawful exceptions, and the specific law, you may ask to:
- confirm whether personal information about you is processed;
- access or obtain a copy of it;
- learn its source, purposes, recipients, and relevant retention criteria;
- correct incomplete or inaccurate information;
- delete or anonymize information that is no longer lawfully needed;
- restrict, block, or object to processing;
- receive eligible information in a portable form;
- withdraw consent;
- opt out of sale, sharing for cross-context behavioral advertising, targeted advertising, or qualifying profiling;
- limit a legally regulated use of sensitive information;
- use an authorized agent;
- appeal a denied request where a right of appeal applies; and
- complain to a competent privacy or data-protection authority.
The site does not currently conduct the sale, sharing, targeted-advertising, sensitive-information, or consequential-profiling activities described in those opt-out rights.
How to submit a request
Use the contact form or email contact@joelklemmer.com. State that the message is a privacy request or privacy appeal and include:
- the page, interaction, or record involved;
- the email address or other information needed to locate the interaction;
- the right or action requested; and
- if an authorized agent acts for you, enough information to verify the authorization and, where required, your identity.
Do not send a passport, national identifier, or other high-risk identity document unless specifically requested and reasonably necessary. Verification will be proportionate to the request and the risk of disclosing or deleting the wrong person’s information. Information collected for verification will be used only to assess and document the request, security, and legal compliance.
Requests are ordinarily free. A fee may be charged or a request refused only where applicable law permits it, such as for a manifestly unfounded, excessive, or repetitive request, and the reason will be explained. A request may be limited where required to protect another person’s privacy, preserve security, comply with law, maintain privileged material, establish or defend rights, or protect lawful expression, reporting, archiving, or public-record integrity.
The operator will respond within the period required by applicable law. If a lawful extension, pause, or clarification is needed, the reason and available appeal or complaint route will be communicated within the time required by that law. You will not be unlawfully discriminated against for exercising a privacy right.
12. Accuracy, corrections, and public records
If you believe a professional or public record is inaccurate, incomplete, outdated, misattributed, or presented without necessary context, identify the page and provide the correction and supporting source. The request will be assessed against the cited record, the publishing purpose, applicable privacy and defamation law, rights of expression and reporting, and the integrity of the historical record.
Correction, contextualization, source replacement, restriction, de-indexing, or removal may be appropriate depending on the facts. A deletion request does not automatically override lawful reporting, expression, archiving, or legal-retention interests, and a public source does not automatically defeat a valid privacy right.
13. Children
This is a general-audience professional, publishing, and informational site. It is not directed to children and does not knowingly solicit information from them. There are no visitor accounts, behavioral advertising profiles, or purchases on the site.
A parent, guardian, or eligible young person may ask the operator to assess information submitted by a child. The operator will verify the request as reasonably necessary and apply the child-protection, consent, deletion, and best-interest rules required by the applicable law. The AI Guide and contact form should not be used to submit a child’s unnecessary personal information.
14. Regional supplements
The global request options above are offered as an operational baseline. The supplements below apply only when the named law’s territorial, material, and coverage conditions are met. They do not reduce a stronger mandatory right.
European Union and European Economic Area
If the GDPR applies, you may request access, rectification, erasure, restriction, and portability where their statutory conditions are met; object to processing based on legitimate interests; object at any time to direct marketing; withdraw consent; and complain to the supervisory authority for your habitual residence, place of work, or the alleged infringement.
The operator normally responds without undue delay and within one month. Where the GDPR permits an extension, up to two additional months may be used and the extension will be explained within the first month. Requests are ordinarily free; a fee or refusal applies only where the GDPR permits it. The site does not use solely automated processing to make a decision covered by GDPR Article 22.
The controller is Joel R. Klemmer, United States. No Data Protection Officer is identified because that role has not been established as required for the current processing. Whether an EU representative is required depends on Article 3(2), Article 27, and the actual offering, monitoring, regularity, scale, and risk. The contact route above remains available regardless.
United Kingdom
If United Kingdom data-protection law applies, you may exercise the corresponding UK GDPR rights and complain to the Information Commissioner. Requests are normally answered within one month, subject to a legally permitted extension, pause, clarification, identity step, or fee.
You may also make a data-protection complaint through the contact form or contact@joelklemmer.com. A complaint covered by the current statutory procedure will be acknowledged within 30 days, investigated without undue delay, and followed by an outcome and information about the ICO complaint route. The site does not make solely automated significant decisions about visitors; if that changes, the required information, human intervention, representation, and contest safeguards will be added before use.
Switzerland
If the Swiss Federal Act on Data Protection applies, you may request information about processing, correction, and other relief available under Swiss law, ask that unlawful processing be prohibited or stopped where the statutory conditions are met, and request portability for qualifying automated processing based on consent or a directly connected contract. Access requests are generally answered within 30 days, and a permitted extension will be communicated within that period.
The site does not use solely automated processing for a high-impact individual decision. The statutory conditions for a Swiss representative are cumulative and fact-dependent; publication of this policy does not assert that those conditions are met.
United States
United States privacy obligations vary by state, activity, and coverage threshold. Comprehensive consumer-privacy laws effective by or during 2026 include California, Colorado, Connecticut, Delaware, Florida, Indiana, Iowa, Kentucky, Maryland, Minnesota, Montana, Nebraska, New Hampshire, New Jersey, Oregon, Rhode Island, Tennessee, Texas, Utah, and Virginia. Alabama, Louisiana, Oklahoma, and Vermont enacted comprehensive laws in 2026 that take effect in 2027 or 2028. Other states and territories may impose website-notice, breach, biometric, health, children’s, data-broker, communications, or consumer-protection duties.
Where an applicable state law provides them, rights may include confirmation, access, correction, deletion, portability, disclosure of categories and recipients, opt-out of sale or targeted advertising, opt-out of qualifying profiling, limitation of sensitive-information use, non-discrimination, use of an authorized agent, and appeal. California residents may also request the categories and specific pieces of personal information covered by the CCPA and information about sources, purposes, and disclosures where that law applies.
The current site does not sell or share personal information for behavioral advertising, target advertising, or make qualifying consequential profiles. It will honor a legally recognized opt-out signal before enabling any practice to which the signal applies. State-law coverage thresholds are not claimed to be met merely because this notice is available.
Canada
If PIPEDA applies, you may ask whether the operator holds personal information about you, request access to information about its use and disclosure, request correction, withdraw consent subject to legal or contractual restrictions and reasonable notice, or challenge compliance through the privacy contact above. Written access requests are generally answered within 30 days, subject to the limited extension allowed by law, at minimal or no cost.
PIPEDA does not create an unconditional general erasure right. Alberta, British Columbia, and Quebec have substantially similar private-sector laws for some intraprovincial processing, and provincial health or sector-specific laws may also apply. Cross-border service providers remain subject to contractual or comparable safeguards where required, and foreign authorities may obtain lawful access under their law.
Brazil
If the LGPD applies, you may request confirmation, access, correction, anonymization, blocking or deletion of unnecessary, excessive, or unlawfully processed data; portability where regulated; information about sharing; deletion of consent-based data subject to lawful retention; and withdrawal of consent. You may object to non-consent processing that violates the LGPD and request review of qualifying automated decisions.
Requests are free. Confirmation or access may be provided immediately in simplified form or through a complete statement within 15 days. That 15-day period is not represented as the response time for every LGPD right. You may petition the ANPD after first trying to resolve the issue through the controller’s available channel. Where appointment of an encarregado is required, the applicable identity and contact information must be published; the current contact route is provided without asserting that a particular appointment exemption applies.
Mexico, Argentina, and other Latin American jurisdictions
Where Mexico’s private-sector law applies, you may exercise applicable access, rectification, cancellation, and opposition rights and revoke consent subject to lawful limits. A complete Mexican privacy notice may require a controller domicile; the operator’s stable postal address has not been established, so the email and contact-form route is the current operational channel.
Where Argentina’s law applies, rights may include access, rectification, updating, suppression, and a complaint to the competent authority. Where Uruguay’s Law 18.331 applies, rights include information, access, updating, rectification, inclusion, suppression, and protections concerning solely automated evaluations; the statutory five-business-day period applies to the requests identified by that law. Other Latin American and Caribbean laws have distinct consent, registration, transfer, security, and response requirements. The global baseline applies while a country-specific mandatory rule, where triggered, controls.
Australia and New Zealand
If Australia’s Privacy Act and Australian Privacy Principles apply, you may request access and correction and make a privacy complaint. Coverage depends on whether the operator is an APP entity, including turnover and activity tests; publication of this policy does not assume those tests are met. Where practicable and lawful, you may interact anonymously or by pseudonym, although a reply requires a usable destination.
If New Zealand’s Privacy Act applies, you may request access or correction and complain to the Office of the Privacy Commissioner. Overseas-disclosure requirements apply according to the relationship and safeguards for the actual recipient.
Japan, Singapore, and South Korea
If Japan’s APPI applies, you may seek disclosure, correction, suspension of use, or deletion where the statute provides it, and applicable cross-border disclosure and consent rules control. If Singapore’s PDPA applies, you may request access and correction, withdraw consent subject to lawful limits and consequences, and contact the operator about the designated accountability route. If South Korea’s PIPA applies, rights and foreign-business, cross-border, notice, representative, and breach duties depend on the statute’s actual territorial and impact tests.
The site offers Japanese and Korean localization, but localization alone is not represented as a final legal conclusion about every extraterritorial trigger. Provider transfers and any required point-of-collection notice must be reconciled before a targeted service change.
China
China’s PIPL may apply to processing outside China when it is for providing products or services to people in China, analyzing or evaluating their behavior, or another statutory case. The site does not behaviorally analyze visitors. If PIPL applies, consent, separate consent, cross-border, representative, localization, security-assessment, and individual-right requirements will be applied according to the actual processing and thresholds. A Chinese translation or global accessibility alone is not treated as proof that every PIPL extraterritorial condition is met.
India
India’s Digital Personal Data Protection Act and Rules have phased commencement. On this policy’s date, the core processing, notice, consent, and data-principal-right provisions scheduled for the later commencement are not described as already operative statutory rights. The global request options remain available voluntarily. The policy and controls must be refreshed as each applicable provision commences, including the later phases scheduled for 13 November 2026 and 13 May 2027 under the official commencement instruments.
Africa and the Middle East
If South Africa’s POPIA applies, applicable access, correction, objection, deletion, security, cross-border, and regulator rights control; POPIA’s territorial test is not satisfied merely because a site is visible from South Africa. Kenya’s Data Protection Act may impose rights and foreign-controller registration duties, subject to the actual territorial and exemption facts. Nigeria’s Data Protection Act may impose lawful-basis, rights, transfer, security, and registration duties under its application tests.
Saudi Arabia’s PDPL has a broad residence-based territorial rule and may require a foreign-controller registration or representative process. The applicability of that process to the current low-volume informational site has not been established. The UAE federal PDPL and separate free-zone laws have their own territorial, transfer, and rights rules; the applicable regime depends on the actual processing connection.
Other African and Middle Eastern laws are not reduced to these examples. The global request route remains available, and any mandatory local duty applies when its jurisdictional facts are met.
Other jurisdictions
The site is globally accessible and offers the same baseline request route regardless of location. Accessibility from a country does not always establish that its law applies; some laws require establishment, targeting, commercial activity, monitoring, volume, revenue, risk, or another connection. Where an applicable law grants a stronger right or imposes a stricter duty, that rule controls. A jurisdiction-specific registration, representative, local-storage, assessment, or regulator-notification duty cannot be satisfied by policy text alone and must be completed when its trigger is established.
15. Named jurisdiction supplement
This directory provides jurisdiction-specific notice alongside the global request route in this policy. It names the 50 United States states, the District of Columbia, the five United States territories, and 195 countries. A listed law applies only if its territorial, material, activity, and any threshold conditions are met. Nothing here limits a stronger mandatory right or states that the operator has met a registration, representative, assessment, consent, transfer, or regulator-notification condition.
United States states, District of Columbia, and territories
- Alabama. The enacted comprehensive privacy law is effective 1 May 2027. It applies only if its coverage conditions are met.
- Alaska. The global request route is available. Applicable state and sector-specific protections control.
- Arizona. The global request route is available. Applicable state and sector-specific protections control.
- Arkansas. The global request route is available. Applicable state and sector-specific protections control.
- California. If the applicable comprehensive privacy law covers our processing, use the United States baseline rights in this policy. Coverage thresholds, exemptions, and the actual processing remain controlling.
- Colorado. If the applicable comprehensive privacy law covers our processing, use the United States baseline rights in this policy. Coverage thresholds, exemptions, and the actual processing remain controlling.
- Connecticut. If the applicable comprehensive privacy law covers our processing, use the United States baseline rights in this policy. Coverage thresholds, exemptions, and the actual processing remain controlling.
- Delaware. If the applicable comprehensive privacy law covers our processing, use the United States baseline rights in this policy. Coverage thresholds, exemptions, and the actual processing remain controlling.
- Florida. If the applicable comprehensive privacy law covers our processing, use the United States baseline rights in this policy. Coverage thresholds, exemptions, and the actual processing remain controlling.
- Georgia. The global request route is available. Applicable state and sector-specific protections control.
- Hawaii. The global request route is available. Applicable state and sector-specific protections control.
- Idaho. The global request route is available. Applicable state and sector-specific protections control.
- Illinois. The global request route is available. Applicable state and sector-specific protections control.
- Indiana. If the applicable comprehensive privacy law covers our processing, use the United States baseline rights in this policy. Coverage thresholds, exemptions, and the actual processing remain controlling.
- Iowa. If the applicable comprehensive privacy law covers our processing, use the United States baseline rights in this policy. Coverage thresholds, exemptions, and the actual processing remain controlling.
- Kansas. The global request route is available. Applicable state and sector-specific protections control.
- Kentucky. If the applicable comprehensive privacy law covers our processing, use the United States baseline rights in this policy. Coverage thresholds, exemptions, and the actual processing remain controlling.
- Louisiana. The enacted comprehensive privacy law is effective 1 January 2027. It applies only if its coverage conditions are met.
- Maine. The global request route is available. Applicable state and sector-specific protections control.
- Maryland. If the applicable comprehensive privacy law covers our processing, use the United States baseline rights in this policy. Coverage thresholds, exemptions, and the actual processing remain controlling.
- Massachusetts. The global request route is available. Applicable state and sector-specific protections control.
- Michigan. The global request route is available. Applicable state and sector-specific protections control.
- Minnesota. If the applicable comprehensive privacy law covers our processing, use the United States baseline rights in this policy. Coverage thresholds, exemptions, and the actual processing remain controlling.
- Mississippi. The global request route is available. Applicable state and sector-specific protections control.
- Missouri. The global request route is available. Applicable state and sector-specific protections control.
- Montana. If the applicable comprehensive privacy law covers our processing, use the United States baseline rights in this policy. Coverage thresholds, exemptions, and the actual processing remain controlling.
- Nebraska. If the applicable comprehensive privacy law covers our processing, use the United States baseline rights in this policy. Coverage thresholds, exemptions, and the actual processing remain controlling.
- Nevada. The global request route is available. Applicable state and sector-specific protections control.
- New Hampshire. If the applicable comprehensive privacy law covers our processing, use the United States baseline rights in this policy. Coverage thresholds, exemptions, and the actual processing remain controlling.
- New Jersey. If the applicable comprehensive privacy law covers our processing, use the United States baseline rights in this policy. Coverage thresholds, exemptions, and the actual processing remain controlling.
- New Mexico. The global request route is available. Applicable state and sector-specific protections control.
- New York. The global request route is available. Applicable state and sector-specific protections control.
- North Carolina. The global request route is available. Applicable state and sector-specific protections control.
- North Dakota. The global request route is available. Applicable state and sector-specific protections control.
- Ohio. The global request route is available. Applicable state and sector-specific protections control.
- Oklahoma. The enacted comprehensive privacy law is effective 1 January 2027. It applies only if its coverage conditions are met.
- Oregon. If the applicable comprehensive privacy law covers our processing, use the United States baseline rights in this policy. Coverage thresholds, exemptions, and the actual processing remain controlling.
- Pennsylvania. The global request route is available. Applicable state and sector-specific protections control.
- Rhode Island. If the applicable comprehensive privacy law covers our processing, use the United States baseline rights in this policy. Coverage thresholds, exemptions, and the actual processing remain controlling.
- South Carolina. The global request route is available. Applicable state and sector-specific protections control.
- South Dakota. The global request route is available. Applicable state and sector-specific protections control.
- Tennessee. If the applicable comprehensive privacy law covers our processing, use the United States baseline rights in this policy. Coverage thresholds, exemptions, and the actual processing remain controlling.
- Texas. If the applicable comprehensive privacy law covers our processing, use the United States baseline rights in this policy. Coverage thresholds, exemptions, and the actual processing remain controlling.
- Utah. If the applicable comprehensive privacy law covers our processing, use the United States baseline rights in this policy. Coverage thresholds, exemptions, and the actual processing remain controlling.
- Vermont. The enacted comprehensive privacy law is effective 1 January 2028. It applies only if its coverage conditions are met.
- Virginia. If the applicable comprehensive privacy law covers our processing, use the United States baseline rights in this policy. Coverage thresholds, exemptions, and the actual processing remain controlling.
- Washington. If Washington's My Health My Data Act covers consumer-health data in our processing, its mandatory rights and notices control. The global request route remains available.
- West Virginia. The global request route is available. Applicable state and sector-specific protections control.
- Wisconsin. The global request route is available. Applicable state and sector-specific protections control.
- Wyoming. The global request route is available. Applicable state and sector-specific protections control.
- District of Columbia. The global request route is available. Applicable state and sector-specific protections control.
- American Samoa. The global request route is available. Applicable territorial protections control.
- Guam. The global request route is available. Applicable territorial protections control.
- Northern Mariana Islands. The global request route is available. Applicable territorial protections control.
- Puerto Rico. The global request route is available. Applicable territorial protections control.
- U.S. Virgin Islands. The global request route is available. Applicable territorial protections control.
Countries
Africa
- Algeria. If Law No. 18-07, as amended and supplemented by Law No. 25-11 of 24 July 2025, applies to our processing, statutory rights and any regulator complaint route control. The global request route remains available.
- Angola. If Law 22/11 applies to our processing, statutory rights and any regulator complaint route control. The global request route remains available.
- Benin. If Law No. 2017-20, as amended by Law No. 2020-35 of 6 January 2021, applies to our processing, statutory rights and any regulator complaint route control. The global request route remains available.
- Botswana. If the Data Protection Act 2024 applies to our processing, its mandatory rights and applicable complaint process control. The global request route remains available.
- Burkina Faso. If Law 001-2021/AN applies to our processing, statutory rights and any regulator complaint route control. The global request route remains available.
- Burundi. If Law No. 1/03 of 10 March 2026 on the Protection of Personal Data applies to our processing, statutory rights and any regulator complaint route control. The global request route remains available.
- Cabo Verde. If Law No. 133/V/2001, as amended by Law No. 41/VIII/2013 and Law No. 121/IX/2021, applies to our processing, statutory rights and any regulator complaint route control. The global request route remains available.
- Cameroon. If Law 2024/017 applies to our processing, statutory rights and any regulator complaint route control. The global request route remains available.
- Central African Republic. If Law No. 24.001 applies to our processing, statutory rights and any regulator complaint route control. The global request route remains available.
- Chad. If Law 007/PR/2015 applies to our processing, statutory rights and any regulator complaint route control. The global request route remains available.
- Comoros. If applicable national privacy, data-protection, or sectoral law covers our processing, statutory rights and complaint procedures control. The global request route remains available.
- Democratic Republic of the Congo. If Ordinance-Law No. 23/010 of 13 March 2023 (Digital Code) applies to our processing, statutory rights and any regulator complaint route control. The global request route remains available.
- Republic of the Congo. If Law 29-2019 applies to our processing, statutory rights and any regulator complaint route control. The global request route remains available.
- Côte d’Ivoire. If Law 2013-450 applies to our processing, statutory rights and any regulator complaint route control. The global request route remains available.
- Djibouti. The global request route is available. Any mandatory local privacy or browser-storage protection controls when applicable.
- Egypt. If Law 151/2020 applies to our processing, statutory rights and any regulator complaint route control. The global request route remains available.
- Equatorial Guinea. The global request route is available. Any mandatory local privacy, data-protection, or browser-storage right controls when applicable.
- Eritrea. The global request route is available. Any mandatory local privacy, data-protection, or browser-storage right controls when applicable.
- Eswatini. If the Data Protection Act 5 of 2022 applies to our processing, its mandatory rights and applicable complaint process control. The global request route remains available.
- Ethiopia. If Proclamation 1321/2024 applies to our processing, statutory rights and any regulator complaint route control. The global request route remains available.
- Gabon. If Law No. 001/2011, as amended, including by Law No. 025/2023, applies to our processing, statutory rights and any regulator complaint route control. The global request route remains available.
- Gambia. If applicable national privacy, data-protection, or sectoral law covers our processing, statutory rights and complaint procedures control. The global request route remains available.
- Ghana. If the Data Protection Act 2012 (Act 843) applies to our processing, its access, correction, erasure, objection, and complaint provisions control. The global request route remains available.
- Guinea. If applicable national privacy, data-protection, or sectoral law covers our processing, statutory rights and complaint procedures control. The global request route remains available.
- Guinea-Bissau. If applicable national privacy, data-protection, or sectoral law covers our processing, statutory rights and complaint procedures control. The global request route remains available.
- Kenya. If applicable national privacy, data-protection, or sectoral law covers our processing, statutory rights and complaint procedures control. The global request route remains available.
- Lesotho. If the Data Protection Act, 2011 (Act 5 of 2012) applies to our processing, its mandatory rights and applicable complaint process control. The global request route remains available.
- Liberia. If applicable national privacy, data-protection, or sectoral law covers our processing, statutory rights and complaint procedures control. The global request route remains available.
- Libya. If applicable national privacy, data-protection, or sectoral law covers our processing, statutory rights and complaint procedures control. The global request route remains available.
- Madagascar. If Law 2014-038 applies to our processing, statutory rights and any regulator complaint route control. The global request route remains available.
- Malawi. If the Data Protection Act 2024 applies to our processing, its mandatory rights and applicable complaint process control. The global request route remains available.
- Mali. If Law No. 2013-015, as amended by Law No. 2017-070 of 18 December 2017, applies to our processing, statutory rights and any regulator complaint route control. The global request route remains available.
- Mauritania. If Law 2017-020 applies to our processing, statutory rights and any regulator complaint route control. The global request route remains available.
- Mauritius. If the Data Protection Act 2017 applies to our processing, its mandatory rights and applicable complaint process control. The global request route remains available.
- Morocco. If Law 09-08 applies to our processing, statutory rights and any regulator complaint route control. The global request route remains available.
- Mozambique. If the Electronic Transactions Law (Law No. 3/2017 of 9 January) applies to our processing, its mandatory data-processing requirements and any applicable complaint procedure control. The global request route remains available.
- Namibia. The global request route is available. Any mandatory local privacy or browser-storage protection controls when applicable.
- Niger. If Law No. 2022-59, as amended, applies to our processing, statutory rights and any regulator complaint route control. The global request route remains available.
- Nigeria. If applicable national privacy, data-protection, or sectoral law covers our processing, statutory rights and complaint procedures control. The global request route remains available.
- Rwanda. If applicable national privacy, data-protection, or sectoral law covers our processing, statutory rights and complaint procedures control. The global request route remains available.
- São Tomé and Príncipe. If Law No. 3/2016 applies to our processing, statutory rights and any regulator complaint route control. The global request route remains available.
- Senegal. If Law 2008-12 applies to our processing, statutory rights and any regulator complaint route control. The global request route remains available.
- Seychelles. If the Data Protection Act 2023 applies to our processing, its mandatory rights and applicable complaint process control. The global request route remains available.
- Sierra Leone. The global request route is available. Any mandatory local privacy or browser-storage protection controls when applicable.
- Somalia. If the Data Protection Act 005/2023 applies to our processing, its access, correction, deletion, and complaint provisions control. The global request route remains available.
- South Africa. If POPIA applies to our processing, statutory rights and any regulator complaint route control. The global request route remains available.
- South Sudan. If applicable national privacy, data-protection, or sectoral law covers our processing, statutory rights and complaint procedures control. The global request route remains available.
- Sudan. If applicable national privacy, data-protection, or sectoral law covers our processing, statutory rights and complaint procedures control. The global request route remains available.
- Tanzania. If the Personal Data Protection Act 2022 (Act 11) applies to our processing, its access, correction, deletion, restriction, and complaint provisions control. The global request route remains available.
- Togo. If Law 2019-014 applies to our processing, statutory rights and any regulator complaint route control. The global request route remains available.
- Tunisia. If Law 2004-63 applies to our processing, statutory rights and any regulator complaint route control. The global request route remains available.
- Uganda. If the Data Protection and Privacy Act 2019 applies to our processing, its access, rectification, blocking, erasure, and complaint provisions control. The global request route remains available.
- Zambia. If the Data Protection Act 3 of 2021 applies to our processing, its mandatory rights and applicable complaint process control. The global request route remains available.
- Zimbabwe. If the Cyber and Data Protection Act 5 of 2021 applies to our processing, its mandatory rights and applicable complaint process control. The global request route remains available.
Americas
- Antigua and Barbuda. If the Data Protection Act 2013 applies to our processing, its mandatory rights and applicable complaint process control. The global request route remains available.
- Argentina. If Personal Data Protection Law No. 25.326 applies to our processing, statutory rights and any regulator complaint route control. The global request route remains available.
- Bahamas. If the Data Protection (Privacy of Personal Information) Act 2003 applies to our processing, its mandatory rights and applicable complaint process control. The global request route remains available.
- Barbados. If the Data Protection Act 2019-29 applies to our processing, its mandatory rights and applicable complaint process control. The global request route remains available.
- Belize. If the Data Protection Act 2021 (Act 45) applies to our processing, its mandatory rights and applicable complaint process control. The global request route remains available.
- Bolivia. If applicable national privacy, data-protection, or sectoral law covers our processing, statutory rights and complaint procedures control. The global request route remains available.
- Brazil. If LGPD applies to our processing, statutory rights and any regulator complaint route control. The global request route remains available.
- Canada. If PIPEDA applies to our processing, statutory rights and any regulator complaint route control. The global request route remains available.
- Chile. If Chile's Law 19,628 applies, use the Latin America baseline above. Law 21,719 takes effect 1 December 2026.
- Colombia. If Law 1581 applies to our processing, statutory rights and any regulator complaint route control. The global request route remains available.
- Costa Rica. If Law 8968 applies to our processing, statutory rights and any regulator complaint route control. The global request route remains available.
- Cuba. The global request route is available. Any mandatory local privacy, data-protection, or browser-storage right controls when applicable.
- Dominica. If applicable national privacy, data-protection, or sectoral law covers our processing, statutory rights and complaint procedures control. The global request route remains available.
- Dominican Republic. If Law 172-13 applies to our processing, statutory rights and any regulator complaint route control. The global request route remains available.
- Ecuador. If applicable national privacy, data-protection, or sectoral law covers our processing, statutory rights and complaint procedures control. The global request route remains available.
- El Salvador. If applicable national privacy, data-protection, or sectoral law covers our processing, statutory rights and complaint procedures control. The global request route remains available.
- Grenada. If the Data Protection Act No. 1 of 2023 applies to our processing, its mandatory rights and applicable complaint process control. The global request route remains available.
- Guatemala. If applicable national privacy, data-protection, or sectoral law covers our processing, statutory rights and complaint procedures control. The global request route remains available.
- Guyana. If the Data Protection Act 18 of 2023 applies to our processing, including its foreign-controller conditions, its mandatory rights and applicable complaint process control. The global request route remains available.
- Haiti. If applicable national privacy, data-protection, or sectoral law covers our processing, statutory rights and complaint procedures control. The global request route remains available.
- Honduras. If applicable national privacy, data-protection, or sectoral law covers our processing, statutory rights and complaint procedures control. The global request route remains available.
- Jamaica. If the Data Protection Act 2020 applies to our processing, its access, correction, objection, and complaint provisions control. The global request route remains available.
- Mexico. If applicable national privacy, data-protection, or sectoral law covers our processing, statutory rights and complaint procedures control. The global request route remains available.
- Nicaragua. If Law 787 applies to our processing, statutory rights and any regulator complaint route control. The global request route remains available.
- Panama. If Law 81 applies to our processing, statutory rights and any regulator complaint route control. The global request route remains available.
- Paraguay. Law 7593/2025 takes effect 27 November 2027. The global request route remains available, and any current mandatory local protection controls when applicable.
- Peru. If Personal Data Protection Law No. 29733 applies to our processing, statutory rights and any regulator complaint route control. The global request route remains available.
- Saint Kitts and Nevis. If the Data Protection Act 5 of 2018 applies to our processing, its mandatory rights and applicable complaint process control. The global request route remains available.
- Saint Lucia. If the Data Protection Act, No. 11 of 2011, as amended by the Data Protection (Amendment) Act, No. 2 of 2015, applies to our processing, its mandatory rights and applicable complaint process control. The global request route remains available.
- Saint Vincent and the Grenadines. If applicable national privacy, data-protection, or sectoral law covers our processing, statutory rights and complaint procedures control. The global request route remains available.
- Suriname. If applicable national privacy, data-protection, or sectoral law covers our processing, statutory rights and complaint procedures control. The global request route remains available.
- Trinidad and Tobago. The Data Protection Act, Chapter 22:04 is only partially proclaimed. If an operative provision applies to our processing, its mandatory rights and applicable complaint process control. The global request route remains available.
- United States. If applicable national privacy, data-protection, or sectoral law covers our processing, statutory rights and complaint procedures control. The global request route remains available.
- Uruguay. If Law 18.331 applies to our processing, statutory rights and any regulator complaint route control. The global request route remains available.
- Venezuela. If applicable national privacy, data-protection, or sectoral law covers our processing, statutory rights and complaint procedures control. The global request route remains available.
Asia and the Middle East
- Afghanistan. If applicable national privacy, data-protection, or sectoral law covers our processing, statutory rights and complaint procedures control. The global request route remains available.
- Armenia. If applicable national privacy, data-protection, or sectoral law covers our processing, statutory rights and complaint procedures control. The global request route remains available.
- Azerbaijan. If applicable national privacy, data-protection, or sectoral law covers our processing, statutory rights and complaint procedures control. The global request route remains available.
- Bahrain. If Law 30/2018 applies to our processing, statutory rights and any regulator complaint route control. The global request route remains available.
- Bangladesh. If the Personal Data Protection Act 2026 (Act No. 63 of 2026) applies to our processing, its mandatory rights and applicable complaint process control. The global request route remains available.
- Bhutan. If applicable national privacy, data-protection, or sectoral law covers our processing, statutory rights and complaint procedures control. The global request route remains available.
- Brunei. If applicable national privacy, data-protection, or sectoral law covers our processing, statutory rights and complaint procedures control. The global request route remains available.
- Cambodia. If applicable national privacy, data-protection, or sectoral law covers our processing, statutory rights and complaint procedures control. The global request route remains available.
- China. If PIPL applies to our processing, statutory rights and any regulator complaint route control. The global request route remains available.
- Cyprus. If the GDPR and Cyprus's applicable national rules cover our processing, use the EU/EEA baseline above and the complaint route to the Commissioner for Personal Data Protection.
- Georgia. If applicable national privacy, data-protection, or sectoral law covers our processing, statutory rights and complaint procedures control. The global request route remains available.
- India. India's later DPDP commencement phase and Rules phase are scheduled for 13 November 2026 and 13 May 2027. Until the relevant provision applies, the global request route remains available.
- Indonesia. If Law 27/2022 applies to our processing, statutory rights and any regulator complaint route control. The global request route remains available.
- Iran. The global request route is available. Any mandatory local privacy, data-protection, or browser-storage right controls when applicable.
- Iraq. If applicable national privacy, data-protection, or sectoral law covers our processing, statutory rights and complaint procedures control. The global request route remains available.
- Israel. If Law 5741-1981 applies to our processing, statutory rights and any regulator complaint route control. The global request route remains available.
- Japan. If APPI applies to our processing, statutory rights and any regulator complaint route control. The global request route remains available.
- Jordan. If Law 24/2023 applies to our processing, statutory rights and any regulator complaint route control. The global request route remains available.
- Kazakhstan. If Law 94-V applies to our processing, statutory rights and any regulator complaint route control. The global request route remains available.
- Kuwait. If applicable national privacy, data-protection, or sectoral law covers our processing, statutory rights and complaint procedures control. The global request route remains available.
- Kyrgyzstan. If the Digital Code of the Kyrgyz Republic No. 178 of 31 July 2025 applies to our processing, statutory rights and any regulator complaint route control. The global request route remains available.
- Laos. If applicable national privacy, data-protection, or sectoral law covers our processing, statutory rights and complaint procedures control. The global request route remains available.
- Lebanon. If Law 81/2018 applies to our processing, statutory rights and any regulator complaint route control. The global request route remains available.
- Malaysia. If the Personal Data Protection Act 2010 (Act 709) applies to our processing, its access, correction, and complaint provisions control. The global request route remains available.
- Maldives. If applicable national privacy, data-protection, or sectoral law covers our processing, statutory rights and complaint procedures control. The global request route remains available.
- Mongolia. If applicable national privacy, data-protection, or sectoral law covers our processing, statutory rights and complaint procedures control. The global request route remains available.
- Myanmar. If applicable national privacy, data-protection, or sectoral law covers our processing, statutory rights and complaint procedures control. The global request route remains available.
- Nepal. If the Privacy Act 2075 applies to our processing, its mandatory rights and applicable complaint process control. The global request route remains available.
- North Korea. The global request route is available. Any mandatory local privacy, data-protection, or browser-storage right controls when applicable.
- Oman. If Royal Decree 6/2022 applies to our processing, statutory rights and any regulator complaint route control. The global request route remains available.
- Pakistan. If applicable national privacy, data-protection, or sectoral law covers our processing, statutory rights and complaint procedures control. The global request route remains available.
- State of Palestine. If applicable national privacy, data-protection, or sectoral law covers our processing, statutory rights and complaint procedures control. The global request route remains available.
- Philippines. If Republic Act No. 10173 applies to our processing, its mandatory rights and National Privacy Commission complaint process control. The global request route remains available.
- Qatar. If Law 13/2016 applies to our processing, statutory rights and any regulator complaint route control. The global request route remains available.
- Saudi Arabia. If PDPL applies to our processing, statutory rights and any regulator complaint route control. The global request route remains available.
- Singapore. If PDPA applies to our processing, statutory rights and any regulator complaint route control. The global request route remains available.
- South Korea. If applicable national privacy, data-protection, or sectoral law covers our processing, statutory rights and complaint procedures control. The global request route remains available.
- Sri Lanka. The Personal Data Protection Act No. 9 of 2022, as amended by Act No. 22 of 2025, has staged commencement. Sections 2 and 3 and Parts I and III take effect on 1 January 2027 under Extraordinary Gazette No. 2498/16. The global request route remains available, and any provision in force controls when applicable.
- Syria. If applicable national privacy, data-protection, or sectoral law covers our processing, statutory rights and complaint procedures control. The global request route remains available.
- Tajikistan. If Law No. 1537 applies to our processing, statutory rights and any regulator complaint route control. The global request route remains available.
- Thailand. If PDPA applies to our processing, statutory rights and any regulator complaint route control. The global request route remains available.
- Timor-Leste. The global request route is available. Any mandatory local privacy or browser-storage protection controls when applicable.
- Türkiye. If Law 6698 applies to our processing, statutory rights and any regulator complaint route control. The global request route remains available.
- Turkmenistan. If applicable national privacy, data-protection, or sectoral law covers our processing, statutory rights and complaint procedures control. The global request route remains available.
- United Arab Emirates. If PDPL applies to our processing, statutory rights and any regulator complaint route control. The global request route remains available.
- Uzbekistan. If applicable national privacy, data-protection, or sectoral law covers our processing, statutory rights and complaint procedures control. The global request route remains available.
- Vietnam. If Law 91/2025/QH15 applies to our processing, statutory rights and any regulator complaint route control. The global request route remains available.
- Yemen. If applicable national privacy, data-protection, or sectoral law covers our processing, statutory rights and complaint procedures control. The global request route remains available.
Europe
- Albania. If Law 124/2024 applies to our processing, statutory rights and any regulator complaint route control. The global request route remains available.
- Andorra. If Law 29/2021 applies to our processing, statutory rights and any regulator complaint route control. The global request route remains available.
- Austria. If the GDPR and Austria's applicable national rules cover our processing, use the EU/EEA baseline above and the complaint route to the Austrian Data Protection Authority.
- Belarus. If Law No. 99-Z applies to our processing, statutory rights and any regulator complaint route control. The global request route remains available.
- Belgium. If the GDPR and Belgium's applicable national rules cover our processing, use the EU/EEA baseline above and the complaint route to the Belgian Data Protection Authority.
- Bosnia and Herzegovina. If applicable national privacy, data-protection, or sectoral law covers our processing, statutory rights and complaint procedures control. The global request route remains available.
- Bulgaria. If the GDPR and Bulgaria's applicable national rules cover our processing, use the EU/EEA baseline above and the complaint route to the Commission for Personal Data Protection.
- Croatia. If the GDPR and Croatia's applicable national rules cover our processing, use the EU/EEA baseline above and the complaint route to the Croatian Personal Data Protection Agency.
- Czechia. If the GDPR and Czechia's applicable national rules cover our processing, use the EU/EEA baseline above and the complaint route to the Office for Personal Data Protection.
- Denmark. If the GDPR and Denmark's applicable national rules cover our processing, use the EU/EEA baseline above and the complaint route to the Danish Data Protection Agency.
- Estonia. If the GDPR and Estonia's applicable national rules cover our processing, use the EU/EEA baseline above and the complaint route to the Data Protection Inspectorate.
- Finland. If the GDPR and Finland's applicable national rules cover our processing, use the EU/EEA baseline above and the complaint route to the Office of the Data Protection Ombudsman.
- France. If the GDPR and France's applicable national rules cover our processing, use the EU/EEA baseline above and the complaint route to the CNIL.
- Germany. If the GDPR and Germany's applicable national rules cover our processing, use the EU/EEA baseline above and the complaint route to the competent German supervisory authority.
- Greece. If the GDPR and Greece's applicable national rules cover our processing, use the EU/EEA baseline above and the complaint route to the Hellenic Data Protection Authority.
- Holy See. If applicable national privacy, data-protection, or sectoral law covers our processing, statutory rights and complaint procedures control. The global request route remains available.
- Hungary. If the GDPR and Hungary's applicable national rules cover our processing, use the EU/EEA baseline above and the complaint route to the National Authority for Data Protection and Freedom of Information.
- Iceland. If the GDPR and Iceland's applicable national rules cover our processing, use the EU/EEA baseline above and the complaint route to the Data Protection Authority.
- Ireland. If the GDPR and Ireland's applicable national rules cover our processing, use the EU/EEA baseline above and the complaint route to the Data Protection Commission.
- Italy. If the GDPR and Italy's applicable national rules cover our processing, use the EU/EEA baseline above and the complaint route to the Garante per la protezione dei dati personali.
- Latvia. If the GDPR and Latvia's applicable national rules cover our processing, use the EU/EEA baseline above and the complaint route to the Data State Inspectorate.
- Liechtenstein. If the GDPR and Liechtenstein's applicable national rules cover our processing, use the EU/EEA baseline above and the complaint route to the Data Protection Authority.
- Lithuania. If the GDPR and Lithuania's applicable national rules cover our processing, use the EU/EEA baseline above and the complaint route to the State Data Protection Inspectorate.
- Luxembourg. If the GDPR and Luxembourg's applicable national rules cover our processing, use the EU/EEA baseline above and the complaint route to the National Commission for Data Protection.
- Malta. If the GDPR and Malta's applicable national rules cover our processing, use the EU/EEA baseline above and the complaint route to the Information and Data Protection Commissioner.
- Moldova. If Law No. 195/2024 on Personal Data Protection applies to our processing, statutory rights and any regulator complaint route control. The global request route remains available.
- Monaco. If Law No. 1.565 of 3 December 2024 relating to the protection of personal data applies to our processing, statutory rights and any regulator complaint route control. The global request route remains available.
- Montenegro. If applicable national privacy, data-protection, or sectoral law covers our processing, statutory rights and complaint procedures control. The global request route remains available.
- Netherlands. If the GDPR and the Netherlands' applicable national rules cover our processing, use the EU/EEA baseline above and the complaint route to the Dutch Data Protection Authority.
- North Macedonia. If Law 42/2020 applies to our processing, statutory rights and any regulator complaint route control. The global request route remains available.
- Norway. If the GDPR and Norway's applicable national rules cover our processing, use the EU/EEA baseline above and the complaint route to the Norwegian Data Protection Authority.
- Poland. If the GDPR and Poland's applicable national rules cover our processing, use the EU/EEA baseline above and the complaint route to the Personal Data Protection Office.
- Portugal. If the GDPR and Portugal's applicable national rules cover our processing, use the EU/EEA baseline above and the complaint route to the National Data Protection Commission.
- Romania. If the GDPR and Romania's applicable national rules cover our processing, use the EU/EEA baseline above and the complaint route to the National Supervisory Authority.
- Russia. If Law 152-FZ applies to our processing, statutory rights and any regulator complaint route control. The global request route remains available.
- San Marino. If Law 171/2018 applies to our processing, statutory rights and any regulator complaint route control. The global request route remains available.
- Serbia. If applicable national privacy, data-protection, or sectoral law covers our processing, statutory rights and complaint procedures control. The global request route remains available.
- Slovakia. If the GDPR and Slovakia's applicable national rules cover our processing, use the EU/EEA baseline above and the complaint route to the Personal Data Protection Office.
- Slovenia. If the GDPR and Slovenia's applicable national rules cover our processing, use the EU/EEA baseline above and the complaint route to the Information Commissioner.
- Spain. If the GDPR and Spain's applicable national rules cover our processing, use the EU/EEA baseline above and the complaint route to the Spanish Data Protection Agency.
- Sweden. If the GDPR and Sweden's applicable national rules cover our processing, use the EU/EEA baseline above and the complaint route to the Swedish Authority for Privacy Protection.
- Switzerland. If the Swiss Federal Act on Data Protection applies, use the Switzerland baseline above and the Federal Data Protection and Information Commissioner route.
- Ukraine. If Law 2297-VI applies to our processing, statutory rights and any regulator complaint route control. The global request route remains available.
- United Kingdom. If United Kingdom data-protection law applies, use the United Kingdom baseline above and the Information Commissioner complaint route.
Oceania
- Australia. If Privacy Act applies to our processing, statutory rights and any regulator complaint route control. The global request route remains available.
- Fiji. The global request route is available. Any mandatory local privacy or browser-storage protection controls when applicable.
- Kiribati. If the Data Protection Act 2025 applies to our processing, its confirmation, access, correction, deletion, and consent-withdrawal rights control. The global request route remains available.
- Marshall Islands. If the Personal Data Protection Act 2025 applies to our processing, its mandatory provisions control. The global request route remains available.
- Micronesia. The global request route is available. Any mandatory local privacy or browser-storage protection controls when applicable.
- Nauru. If applicable national privacy, data-protection, or sectoral law covers our processing, statutory rights and complaint procedures control. The global request route remains available.
- New Zealand. If Privacy Act applies to our processing, statutory rights and any regulator complaint route control. The global request route remains available.
- Palau. If applicable national privacy, data-protection, or sectoral law covers our processing, statutory rights and complaint procedures control. The global request route remains available.
- Papua New Guinea. The global request route is available. Any mandatory local privacy or browser-storage protection controls when applicable.
- Samoa. The global request route is available. Sectoral telecommunications customer-information duties may apply to telecommunications service providers; any mandatory local protection controls when applicable.
- Solomon Islands. If applicable national privacy, data-protection, or sectoral law covers our processing, statutory rights and complaint procedures control. The global request route remains available.
- Tonga. If applicable national privacy, data-protection, or sectoral law covers our processing, statutory rights and complaint procedures control. The global request route remains available.
- Tuvalu. The global request route is available. Any mandatory local privacy or browser-storage protection controls when applicable.
- Vanuatu. If the Data Protection and Privacy Act 13 of 2024 applies to our processing, its mandatory rights and applicable complaint process control. The global request route remains available.
16. Changes to this policy
This policy will be reviewed when the site changes a material collection, purpose, provider, transfer route, retention practice, browser-storage technology, advertising practice, or AI feature. A material revision will carry a new date. Where law requires notice or consent before a change, the change will not take effect until that requirement is met.
Historical versions and the factual basis for a material change should be retained as governance records. This policy does not retroactively remove a right or legal protection.