Legal
Privacy Policy
A marketplace works by showing people to each other. Sections 3 and 4 are where that line falls — what you publish, what stays private, and when contact details unlock.
1. Summary
| What | Short answer |
|---|---|
| Who runs this | Metamex LLC, a Florida limited liability company, operating as PoloRFP |
| What it is | A marketplace where polo players publish requests — for an experience, to buy a pony, or to hire staff — and polo professionals respond to them |
| Who can use it | Adults aged 18 or over, anywhere in the world |
| Do we sell your data | We never sell it for money. If you accept optional cookies, the advertising tags in section 5.2 count as "sharing" under California law. Declining stops it, and so does withdrawing later |
| Do we track you | Only if you say yes. Two necessary cookies aside, nothing loads until you accept — not a request, not a script, not a cookie. Declining changes nothing about how the Service works |
| Do we train AI on your data | No. Your CV, requests, messages and photographs are not used to train AI models, and we do not license them to anyone who does |
| Who else sees it | Other users, under the rules in section 4. Some of what you publish is visible to the public internet — section 3 is the part to read |
| Where it is processed | Primarily in the United States, including the database holding your profile and messages. See section 9 |
| How to reach us | hello@polorfp.com |
2. Who we are and who this covers
Metamex LLC, a limited liability company formed in the State of Florida, United States ("we", "us"), operates PoloRFP at polorfp.com (the "Service"). For the purposes of the EU and UK General Data Protection Regulation we are the data controller for the personal data described here.
We operate through a stable establishment in Poland, in the context of whose activities this processing is carried out. On that basis Article 3(1) of the GDPR applies to us directly, and we are not required to designate a representative under Article 27. Our supervisory authority is the Polish Urząd Ochrony Danych Osobowych (UODO).
Our Terms of Service govern your use of the Service. This notice explains what we do with personal data; the Terms explain everything else.
This notice applies to everyone who uses the Service, wherever they are:
- a player who holds an account and publishes requests;
- a professional who holds an account and maintains a Polo CV;
- a visitor who is not signed in and reads a public page;
- a third party whose details appear in something another user wrote — a named referee on a CV, or a previous employer. Section 6 is for you.
All privacy matters, rights requests and security reports: hello@polorfp.com
3. Read this first
Parts of this Service are public. Publishing on it is a deliberate act with consequences we cannot undo for you.
If you are a professional and you set your Polo CV to PUBLIC, it is published on the open internet at a stable, human-readable address, and search engines are permitted to index it. That page carries your name, photograph, headline, biography, role, handicaps, employment history, tournament history, education, certifications, languages, skills, licences, the countries you may work in, your availability, and the recommendations you have approved. Anyone in the world can read it, copy it, archive it, or feed it into a search engine or an AI system, and we have no ability to retrieve it once they have. Your CV starts as PRIVATE. You choose whether to change that.
Contact details are the exception, and they are protected by a single rule that runs through every page, export and PDF on the Service: a professional's contact email, phone number and rate expectation, and a player's email address, are never shown on a public page. They become visible to the other party only inside a conversation, and only once the player has sent a reply. Before that reply, neither side sees the other's contact details.
Request titles and summaries are also public. The rest of a request — dates, country, budget, requirements, accommodation, and the author's name — is visible only to signed-in members, and the request board itself cannot be browsed by anyone who is not signed in.
4. Who can see what
This section determines your actual exposure. It describes the rules the software enforces on the server, not merely what the interface shows.
4.1 Player profiles are private
A player profile is never public. It opens to exactly two viewers: the player who owns it, and a professional already in a conversation with that player. Everyone else — including other players, and professionals who have not written — receives a "not found" response, so the existence of a profile cannot be confirmed by guessing at addresses. Player profiles are excluded from search-engine indexing unconditionally.
A player's name travels with their requests and is readable by signed-in members. Their profile does not.
4.2 Polo CV visibility is yours to set
| Setting | Who can read it |
|---|---|
| PRIVATE (the default) | You, and players you have messaged or applied to |
| UNLISTED | Anyone with the link. Search engines are instructed not to index it |
| PUBLIC | Anyone. Search engines are permitted to index it |
UNLISTED is link-security, not access control: a link can be forwarded, and we cannot control what happens after it is. Treat UNLISTED as semi-public.
The PDF export of your CV follows the same rule as the page, and is authenticated rather than merely hard to guess. It never contains contact details or rate expectations unless you are the person downloading your own CV.
4.3 Requests
| Part of a request | Who can read it |
|---|---|
| Title and summary | Anyone, including search engines |
| Everything else — dates, location, budget, requirements, accommodation, author's name | Signed-in members only |
| The board of all open requests | Signed-in members only |
| The number of responses a request has received | The request's author only |
Write your summary on the assumption that it will be read by people outside the polo world.
4.4 Messages
Conversations are always anchored to a specific request. There is no open-ended inbox: a professional may open a conversation about a request, and nobody may cold-message anybody. Only the two participants may read a thread, and this is checked on every read, not only when the inbox is listed.
Messages are not end-to-end encrypted. We can technically access message content, and we do so only for the purposes in section 7 — chiefly investigating abuse and responding to lawful requests.
4.5 Recommendations
A recommendation is written by a player about a professional. It is submitted as pending; only the professional it concerns can approve it, and only approved recommendations appear on a CV or in its PDF. If you write one, understand that approving it publishes your words alongside your name on a page that may be public.
4.6 What we do not verify
We do not verify anything users tell us. Handicaps, certifications, employment history, qualifications, right to work, identity and references are all self-reported, and the Service marks them as such. We are not an employment agency, an introduction agency, a background-check provider or an escrow service, and no listing, CV or recommendation on the Service is an endorsement by us. Decisions you make about whom to hire, whom to work for, or from whom to buy a horse are yours alone.
5. What we collect
5.1 Information you give us
Account. Our authentication provider (WorkOS) handles sign-in itself; we receive and store your email address, a display name, an identifier for you at that provider, and whether your account is a player or a professional account. The account type is fixed at sign-up. We also record when your account was created and, at most once an hour, that you signed in. We never see, receive or store your password.
Player profile. First name, surname, profile photograph, a short biography, your connection to polo, your current and highest handicap and the association that issued it, your home country and the country you are based in, your home clubs and the clubs you have played at, and optionally your workplace, college and hobbies.
Polo CV. A larger record, because it is a job application: name and surname, headline, biography, professional role, years in polo, playing positions, city and country you are based in, country you are from, profile photograph, up to twelve gallery photographs, a link to playing footage, your contact email and phone number, your skills, whether you travel with horses, your string size and horses managed, driving and lorry licences, whether you have your own transport, free-text visa notes, the countries whose passports you hold and where you are eligible to work, your availability dates, whether you will relocate, the contract types and hours you seek, your rate expectation and currency, your indoor and outdoor handicaps with year and issuing association, your employment history, tournament history, languages, education, certifications, and named references with their organisations.
Two categories deserve particular care:
- Immigration and right-to-work information — passport countries, work-eligibility countries and visa notes. This can reveal your nationality and immigration status. Give only what an employer genuinely needs. Do not put passport numbers, visa numbers or identity-document images anywhere on the Service; no field asks for them and there is no reason to volunteer them.
- Named third parties — referees, previous employers, and the organisations you name. You are responsible for having a proper basis to share their details with us, and for telling them you have.
Requests. Depending on type: dates, countries, cities, club preferences, budgets and currencies, group sizes, chukkers, ponies, accommodation notes, and your own account of what you want. Job ads additionally carry position details, job descriptions, qualifications, salary ranges, schedules, living arrangements, language requirements and right-to-work requirements. Pony requests carry the horse's details and up to eight photographs.
Messages, applications and recommendations. The text you write, when you wrote it, and when the other party read it. Message bodies are stored and displayed as plain text — never as HTML or markdown — and are capped at 5,000 characters.
Photographs. JPEG, PNG or WebP, up to 8 MB each, capped per record. Images are stored under an internal key rather than a public address, and are served through a route that checks whether you may see the owning record. Possession of a key is not permission to read it. Note that photographs can carry embedded metadata, including where they were taken — strip it before uploading if that matters to you.
5.2 Cookies, and the measurement tags
Three cookies are ours and load for everyone. Everything else is optional, off until you say otherwise, and listed here by name.
| Cookie | Set by | Purpose | Duration | Consent needed |
|---|---|---|---|---|
| Session | WorkOS AuthKit | Keeps you signed in. The Service cannot work without it | Session | No — strictly necessary |
| Theme | PoloRFP | Remembers whether you chose the light or dark appearance | 1 year | No — set at your request |
| Consent | PoloRFP | Remembers your answer to the cookie bar, so we stop asking | 6 months | No — required to honour your choice |
_ga, _ga_* | Google Analytics | Counts visits and measures which pages are used | Up to 2 years | Yes |
_fbp | Meta | Measures whether a visit followed one of our advertisements | 3 months | Yes |
_ttp | TikTok | The same, for advertisements on TikTok | Up to 13 months | Yes |
How the optional tags get here. We use Google Tag Manager, a container that lets us add or remove measurement tags without changing the site's code. The tags configured in it are Google Analytics 4, the Meta pixel and the TikTok pixel. Each appears in section 8.2 as a recipient, and that list is kept accurate: if we add a tag, this notice changes first, under section 19.
Nothing in that container loads until you accept, and this is stricter than it sounds. Until you press Accept, the Tag Manager script is not in the page — not loaded and held back, but absent. No request is made to Google, Meta or TikTok, and none of their cookies exists. Pressing Decline, or ignoring the bar entirely, leaves it that way. The check runs on our server before the page is built, which is why it cannot be defeated by a tag misfiring in your browser.
One rule, everywhere. We do not ask Europeans and quietly measure everyone else. The same consent gate applies to every visitor, wherever you are.
Changing your mind. The Cookies link in the footer reopens the bar at any time. Withdrawing takes effect at once: it deletes the analytics and advertising cookies we are able to reach and reloads the page, so anything already running is gone rather than merely told to stop. Refusing is exactly as easy as accepting — the two buttons are the same size, in the same style, side by side, and neither is the louder one.
What we commit to, beyond asking. Each of these is a commitment we have configured, not a description of anybody's defaults:
- We do not send identifiers. No account identifier, email address or name is passed to any tag, and no Google Analytics User-ID is configured.
- Public CV pages are excluded from measurement. A Polo CV lives at an address containing the professional's name, so sending those addresses to an analytics or advertising company would hand it a record of which named people are being looked at — including people who never agreed to anything. Those pages are excluded from every tag.
- Google Signals and advertising features are switched off in Google Analytics, and analytics data is not used to build advertising audiences.
- Analytics data retention is set to the shortest period Google offers, currently 2 months, against a default of 14.
What is not here at all. There is no session recorder, no heatmap, no chat widget, no third-party font host, and no advertising anywhere on PoloRFP. We do not show you ads; the Meta and TikTok tags exist only to tell us whether our own advertising brought you here.
5.3 Server records
Our hosting provider generates technical logs in the ordinary course of serving the site, typically including IP addresses, timestamps, requested addresses, and browser and device information. We use these to keep the Service running, to investigate faults and to detect abuse. We do not use them to build a profile of you.
We also count how many conversations a professional has started in the preceding 24 hours, and refuse more than ten. This keeps the request board from being spammed.
5.4 What we do not collect
We do not ask for and have no field for: payment card or bank details (there are no payments on the Service), government identity numbers, passport or visa numbers, precise geolocation, biometric data, health data, or data about your racial or ethnic origin, political opinions, religious beliefs, trade union membership, sex life or sexual orientation.
Please do not volunteer any of the above in a free-text field. If you do, you are supplying it on your own initiative; we do not want it, we will remove it if we notice it, and you may ask us to remove it at any time.
6. People who are not users
Users can name other people — most often a referee or previous employer on a Polo CV, or a club in a request. We receive that information from the user who wrote it, not from you.
If your details appear on the Service and you did not put them there, write to hello@polorfp.com and we will locate the record and remove your details, ordinarily within 30 days. You do not need an account. Section 12 sets out your other rights, all of which apply to you as much as to a registered user.
7. Why, and on what legal basis
| Purpose | Lawful basis (GDPR Art. 6) |
|---|---|
| Providing the Service | Contract — Art. 6(1)(b) |
| Publishing what you choose to publish | Contract, and your choice of visibility setting |
| Notifying you about your conversations | Contract — service messages, not marketing |
| Keeping the Service safe | Legitimate interests — Art. 6(1)(f) |
| Fixing faults | Legitimate interests |
| Measurement and advertising attribution | Consent — Art. 6(1)(a). Withdrawable at any time from the footer, with no effect on the Service |
| Meeting legal obligations | Legal obligation — Art. 6(1)(c) |
| Defending legal claims | Legitimate interests, and Art. 9(2)(f) where relevant |
Where we rely on legitimate interests we have considered whether our interest is overridden by your rights and concluded it is not, because the processing is limited to what running the marketplace requires and is what a user would reasonably expect. You may object at any time.
We do not carry out automated decision-making that produces legal or similarly significant effects, and we build no profile of you. The Service filters CVs against job requirements, but this only decides what a human is shown; the human decides everything that matters. It never accepts, rejects, ranks or scores a person.
We should be straightforward about the limit of that promise: it covers what *we* do. If you accept the optional advertising tags in section 5.2, Meta and TikTok may add what they learn to profiles they hold about you, under their own notices and outside our control. That is a reason to decline, and declining costs you nothing here.
8. Who we share with
We do not sell personal data. We do not disclose it for advertising except through the tags in section 5.2, which run only with your consent. Otherwise we disclose it only as follows.
8.1 To other users
As set out in section 4, and only as set out there.
8.2 To service providers who run the Service for us
Each is bound by a data processing agreement to process data only on our instructions, to keep it confidential, and to protect it.
| Provider | What they do | Where |
|---|---|---|
| Vercel Inc. | Hosting, application execution, photograph storage, server logs | United States, with edge locations worldwide |
| WorkOS, Inc. | Authentication. Holds your credentials; we never see them | United States |
| Neon Inc. | The database holding everything described in section 5.1 | United States — AWS us-east-1 (Washington, D.C.) |
| Resend (Plus Five Five, Inc.) | Sends the notification emails described in section 7 | United States |
The measurement companies are not on the same footing. The three below receive data only if you accept optional cookies, and for what their tags collect they act as controllers in their own right rather than purely on our instructions — with Meta and TikTok, jointly with us. Their own notices, linked below, govern what they then do, and that is a further reason the choice in section 5.2 is yours to make.
| Recipient | What they receive | Where |
|---|---|---|
| Google Ireland Limited | Tag Manager, and Google Analytics 4 configured as section 5.2 describes | Ireland, with processing in the United States |
| Meta Platforms Ireland Limited | Whether a visit followed one of our advertisements | Ireland, with processing in the United States |
| TikTok Information Technologies UK Limited | The same, for advertisements on TikTok | United Kingdom and Ireland, with processing in the United States, Singapore and Malaysia |
Both lists are current as at the effective date above. If we engage a new provider or add a tag we will update them; material changes are handled under section 19.
8.3 For legal reasons
We may disclose personal data where we believe in good faith that it is necessary to comply with a law, regulation, legal process or enforceable governmental request; to enforce our Terms of Service; to detect, prevent or address fraud, security or technical problems; or to protect the rights, property or safety of our users, ourselves or the public. Where we are legally permitted to tell you about such a request, we will make reasonable efforts to do so.
8.4 In a business transfer
If we are involved in a merger, acquisition, financing, reorganisation or sale of assets, personal data may be transferred as part of that transaction. We will give notice before your data becomes subject to a materially different privacy notice, and you will be able to delete your account first.
8.5 Links to other sites
Professionals may link to playing footage on YouTube, Vimeo or elsewhere. These are ordinary outbound links — the video is not embedded, and no third-party video content loads on our pages — but once you follow one you are on someone else's site, governed by their privacy notice, not ours.
9. International transfers
The Service is available worldwide and our providers operate internationally. Your personal data will be transferred to, stored in, and processed in countries other than your own, including the United States, whose data protection laws may differ from those of your country and may permit access by public authorities in ways your own law does not. The database holding your profile, CV, requests and messages is located in the United States.
By its nature this Service also transfers data internationally *between users*: a professional in Argentina applying to a job ad in England is sending their CV to England. That is the purpose of the Service.
Where we transfer personal data out of the EEA, the UK or Switzerland, we rely on:
- an adequacy decision where one covers the recipient — including the EU–US Data Privacy Framework and its UK and Swiss extensions, to the extent of a provider's certification; and
- the European Commission's Standard Contractual Clauses, with the UK International Data Transfer Addendum where the UK GDPR applies, incorporated into our agreements with the providers in section 8.2, together with supplementary measures where a transfer risk assessment identifies a need for them.
If you accept optional cookies, the measurement companies in section 8.2 receive data under their own transfer arrangements rather than ours, and TikTok's in particular extend beyond Europe and the United States to Singapore and Malaysia. Declining, or withdrawing from the footer, means no such transfer happens at all.
You may request a copy of the safeguards in place by writing to hello@polorfp.com. We may redact commercial terms.
10. How long we keep things
| Data | Retention |
|---|---|
| Account, profile and Polo CV | While your account is open. Deleted or anonymised within 30 days of you closing it, subject to the exceptions below |
| Requests | Requests expire 90 days after opening unless renewed. Expired requests remain visible to their author and are deleted with the account |
| Conversations and messages | Deleted with your account. A copy remains in the other participant's thread until they too delete their account, because a conversation is a shared record |
| Recommendations you wrote | Retained on the recipient's CV. If you close your account we sever your name from it rather than delete their page. Ask us and we will remove it entirely |
| Photographs | Deleted from storage when you delete the record they belong to, or when your account is closed |
| Server logs | As retained by our hosting provider, typically 30 days |
| Analytics and advertising data | Only if you consented. 2 months at Google, being the shortest retention Google Analytics offers; Meta and TikTok retain attribution data under their own notices, linked in section 8.2 |
| Records needed for a claim or abuse investigation | As long as necessary for that purpose, and no longer |
| Records the law requires us to keep | For the period the law requires |
How to delete your account. There is currently no self-service delete button. Email hello@polorfp.com from the address on your account and we will action it, ordinarily within 30 days.
Content you made public may persist outside our control — in search-engine caches, web archives, or in copies other people made. We will delete it from the Service; we cannot delete it from the internet, and we do not promise to.
11. Security
We protect the Service with measures appropriate to its risk, including:
- credentials handled entirely by a specialist authentication provider, never by us;
- session tokens verified against the provider's published keys on every request;
- authorization decided on the server for every read, including every individual message — never in the browser, and never by hiding a link;
- private files stored under internal keys and served only through a route that checks whether the requester may see the owning record;
- encryption in transit throughout, and encryption at rest by our database and storage providers;
- message text sanitised on write and escaped on render;
- rate limits on the actions most open to abuse.
No service can be completely secure. We do not guarantee, and cannot guarantee, that the Service will be free of unauthorised access, and you transmit information to us at your own risk. This is a statement of fact, not an attempt to exclude liability we are not permitted to exclude.
You are responsible for the security of the account you sign in with. If you believe your account has been compromised, or you find a security flaw, write to hello@polorfp.com immediately.
Breach notification. Where the law requires it we will notify the relevant authority and affected individuals of a personal data breach: within 72 hours of becoming aware, under the GDPR; and as required by the Florida Information Protection Act (Fla. Stat. section 501.171), which obliges us to notify affected individuals within 30 days and, where more than 500 Florida residents are affected, the Florida Department of Legal Affairs.
12. Your rights
12.1 Rights available to everyone, wherever you are
As a matter of our own policy we extend these to every user regardless of location:
- Access — ask what personal data we hold about you and get a copy.
- Correction — have inaccurate data corrected. Most fields you can edit yourself.
- Deletion — ask us to delete your account and data.
- Objection and restriction — object to processing based on legitimate interests, or ask us to pause while a dispute is resolved.
- Portability — receive the data you gave us in a structured, machine-readable format. Professionals can already export a Polo CV as a PDF.
- Withdraw consent — where we rely on consent, at any time. This does not affect processing already carried out.
- Complain — to us first, and to your data protection authority if we do not resolve it.
How to exercise them: email hello@polorfp.com from the address on your account, or from any address if you are not a user. We will respond within 30 days, and will tell you if we need longer (the GDPR permits an extension of two further months for complex requests). We do not charge unless a request is manifestly unfounded or excessive. We may need to verify your identity, in proportion to the sensitivity of what you are asking for. We will not discriminate against you for exercising a privacy right.
12.2 EEA, UK and Switzerland
You have the rights in Articles 15–22 of the GDPR and UK GDPR, which are those listed above.
We are subject to the GDPR under Article 3(1) through our establishment in Poland, and our supervisory authority is the Urząd Ochrony Danych Osobowych (UODO), ul. Stawki 2, 00-193 Warsaw, Poland — uodo.gov.pl. Because we have an EU establishment, the one-stop-shop mechanism applies and UODO is our lead authority.
You may complain to UODO, or to the authority where you live or work, or where you believe an infringement occurred. In the UK that is the Information Commissioner's Office; in Switzerland, the FDPIC. We would appreciate the chance to address your concern first.
12.3 California
Under the CCPA as amended by the CPRA:
- We have never sold personal information for money, and we do not intend to. But if you accept optional cookies, the Meta and TikTok tags described in section 5.2 amount to sharing for cross-context behavioural advertising as the CCPA defines that term, and we would rather say so than rely on a narrow reading of it.
- The "Cookies" link in the footer is our "Do Not Sell or Share My Personal Information" control. It is on every page. Because those tags load only if you opt in, and the same link withdraws consent at any time, a Californian gets more than the statute requires: the default is already off, so there is nothing to opt out of unless you first chose it.
- We do not use or disclose sensitive personal information beyond the purposes permitted by section 7027(m) of the CCPA regulations, so no "Limit the Use of My Sensitive Personal Information" link is required.
- The categories we collect, the purposes, the sources and the recipients are in sections 5, 7 and 8; retention is in section 10. Read against the CCPA's categories, we collect identifiers, personal records (Cal. Civ. Code section 1798.80), professional and employment information, education information, and internet activity — which is limited to server logs unless you accept optional cookies, in which case it also covers which pages you viewed. We draw no inferences about you.
- You may use an authorised agent; we will require written proof of authorisation and will verify you directly.
12.4 Other US states
If you live in Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana or another state with a comprehensive privacy law, you have broadly the rights in section 12.1, including the right to appeal a refusal. To appeal, reply to our decision with the word "appeal"; we will respond within the period your state's law allows and, if we still refuse, tell you how to contact your Attorney General. We do not sell personal data, and we do not profile you in furtherance of decisions producing legal or similarly significant effects. If you accept optional cookies, the tags in section 5.2 may count as targeted advertising under your state's law; the "Cookies" link in the footer is the opt-out, and the default is already off.
12.5 Brazil, Canada, Australia, Argentina and elsewhere
- Brazil (LGPD): the rights in Article 18, exercisable through section 12.1; you may complain to the ANPD.
- Canada (PIPEDA): access and correction, and complaint to the Office of the Privacy Commissioner.
- Australia (Privacy Act): access and correction, and complaint to the OAIC. We will tell you if we cannot give access and why.
- Argentina (Law 25.326): access, rectification and suppression, and complaint to the Agencia de Acceso a la Información Pública.
- Elsewhere: the rights in section 12.1 are available to you as a matter of our policy, in addition to any your local law gives you.
13. Children
The Service is for adults. You must be at least 18 to hold an account, and by creating one you confirm that you are.
We do not knowingly collect personal data from anyone under 18. If we learn that we have, we will delete the account and its data promptly. If you believe a child has given us personal data, write to hello@polorfp.com. Because we have no users under 18, we do not knowingly sell or share the personal information of consumers under 16 within the meaning of the CCPA.
14. AI and machine learning
We do not use AI to make decisions about you, and we do not use your content to train AI models. Specifically:
- Your Polo CV, requests, messages, recommendations and photographs are not used to train, fine-tune or evaluate any machine-learning model, by us or by anyone we share data with.
- We do not send your content to a third-party AI provider.
- Nothing on the Service scores, ranks or judges a person automatically. Filtering CVs against a job ad's requirements decides only what a human is shown.
If this ever changes we will update this notice under section 19 and, where consent is required, ask for it before the change takes effect.
15. Aggregated and anonymised data
We may create aggregated or de-identified data that cannot reasonably be used to identify you — for example, the number of open job ads in a country, or how many professionals list a given skill. This is no longer personal data and we may use and publish it for any purpose. We will not attempt to re-identify de-identified data, and we will require anyone we give it to under contract not to.
16. Your responsibilities, and indemnification
You are responsible for the content you put on the Service and for the consequences of publishing it. In particular you agree that:
- you have the right to submit everything you submit, including any third party's details;
- what you publish is accurate, and you will not misrepresent your handicap, qualifications, employment history or right to work;
- you will not use another user's contact details, once disclosed to you under section 3, for any purpose other than the conversation that disclosed them — no marketing, no resale, no addition to a mailing list;
- you will not scrape, harvest, bulk-download or systematically copy profiles, CVs or requests from the Service; and
- if you are advertising a position, you are responsible for compliance with the employment, pay-transparency, immigration and anti-discrimination laws of every jurisdiction your advertisement reaches.
You agree to indemnify and hold harmless Metamex LLC and its members, officers and agents from any claim, loss, liability or expense (including reasonable legal fees) arising out of content you submit, your breach of this notice or the Terms of Service, your misuse of another user's personal data, or your violation of any law or the rights of a third party.
17. Limitation of liability
To the fullest extent permitted by applicable law:
- The Service and everything on it is provided "as is", without warranty of any kind. We do not warrant that the Service will be uninterrupted, secure or error-free, nor that any information a user publishes on it is accurate, current or lawful.
- We are not liable for the acts or omissions of other users, including what they do with personal data disclosed to them through the Service, whether they honour an agreement reached through it, or whether they are who they say they are.
- We are not liable for indirect, incidental, special, consequential, exemplary or punitive damages, or for lost profits, revenue, data, goodwill or business opportunity, however caused and on any theory of liability.
- Our total cumulative liability for all claims arising from or related to this notice or the Service shall not exceed one hundred U.S. dollars ($100).
Nothing in this section limits liability that cannot be limited by law. That includes liability for death or personal injury caused by negligence, for fraud or fraudulent misrepresentation, and — importantly — your rights and our obligations under the GDPR, the UK GDPR, the CCPA and comparable data protection laws, including your right to compensation under Article 82 GDPR, none of which this section affects. If you are a consumer, nothing here removes any mandatory protection your local law gives you.
18. Governing law and disputes
This notice is governed by the laws of the State of Florida, without regard to conflict of law principles, except where superseded by applicable data protection law. Any dispute arising out of or relating to it will be resolved by binding arbitration in Florida, or in the state or federal courts located in Florida where an exception to arbitration applies.
This section does not apply where it cannot. If you are a consumer resident in the EEA, the UK or another jurisdiction whose law gives you a non-waivable right to bring proceedings in your local courts, or to the protection of your local mandatory consumer law, that right is unaffected and prevails over this section. Nothing here prevents you from complaining to a supervisory authority under section 12.
19. Changes to this notice
We may update this notice as the Service changes or the law does. The version and date at the top always reflect the current text.
For material changes — a new category of data, a new purpose, a new class of recipient, or anything that meaningfully affects your rights — we will give notice by email and/or a prominent notice in the Service at least 14 days before the change takes effect, so that you can object, exercise your rights, or close your account first. Continuing to use the Service after that date means the updated notice applies. Where a change requires your consent, we will ask for it rather than assume it.
Earlier versions of this notice are available on request from hello@polorfp.com.
20. Contacting us
| Who | How to reach them |
|---|---|
| Privacy, rights requests, security | hello@polorfp.com |
| Controller | Metamex LLC, State of Florida, United States |
| Supervisory authority | Urząd Ochrony Danych Osobowych (UODO), ul. Stawki 2, 00-193 Warsaw, Poland |
If you are not satisfied with our response you may complain to a supervisory authority — see section 12.2.