Creator Data Annex

    www.twelve-app.com · Effective date: 5 August 2026 · Last updated: 5 August 2026

    Operator: Mentortain S.R.L. (Romania) · Application / brand: Twelve

    Registered office: Sat Bucov, Comuna Bucov, Strada Dacia nr. 78, Județul Prahova, Romania

    Trade Register: J29/396/2024 · CUI: 49569212

    Contact: help@twelve-app.com

    1. Purpose and scope

    This Creator Data Annex governs how Creators handle personal data of Users that they receive through Twelve in order to perform a Service — Order requirements, Order-thread messages, inputs to a Deliverable, and any information a User volunteers, including health-related information. It forms part of the Terms of Service and is binding on every Creator from the moment they list anything for sale; breaching it is a material breach of the Terms (Section 21.3), triggering the enforcement ladder and the Creator indemnity (Section 22.6).

    2. Roles

    For the data you receive to perform a Service, you (the Creator) act as an independent controller: you decide how to perform your service and what you need for it, and you carry your own responsibilities under the GDPR and any other data-protection law applicable to you or to the Users you serve. Twelve is a separate, independent controller for operating the platform (hosting, moderation, payments, safety), as described in the Privacy Policy. You and Twelve are not joint controllers, and you do not process data on Twelve’s behalf.

    3. The golden rule

    Use it only to perform the Order. Nothing else. You may process User data solely to deliver the specific Service purchased. You must not use it for marketing, prospecting, profiling, audience building, research, training AI systems, or any purpose of your own; you must not sell it, share it, or use it to contact the User outside Twelve (which is also circumvention under Section 13(c) of the Terms).

    4. Minimisation — especially for health data

    Request only the information genuinely needed to perform the Service, and prefer structured Order requirements over open-ended questioning.

    Never request medical records, diagnoses, laboratory results or clinical documentation. If a User needs clinically supervised work, the correct answer is to refer them to a healthcare professional, not to collect clinical data.

    Do not collect data about third parties (family members, partners) through a User.

    Treat everything a User shares about their body, eating, training, medication or mental state as sensitive, whether or not it is formally special-category data.

    5. Security and confidentiality

    Keep User data inside the platform wherever possible — deliver through the Order thread and platform delivery tools rather than exporting.

    If you must hold a working copy (for example, to prepare a plan), store it on a device protected by a passcode and full-disk encryption, in an account only you control; do not store it in shared folders, shared accounts or unmanaged spreadsheets.

    Do not disclose User data to anyone. Assistants or subcontractors may only be involved with the User’s prior consent and under a written confidentiality obligation, and you remain fully responsible for them.

    Screenshots of Orders, requirements or conversations must never be published, including in anonymised “client story” form, without the User’s explicit consent.

    6. Retention and deletion

    Delete every copy of User data you hold outside the platform within 90 days after the Order is completed or cancelled, unless a law that applies to you requires longer retention (in which case you keep it only for that purpose and period, and tell the User on request). The Order thread itself remains on the platform under Twelve’s retention rules in the Privacy Policy.

    7. Users’ rights and requests

    If a User asks you for access to, correction of, or deletion of data they gave you — or sends you any other data-protection request — respond honestly and promptly within the timelines of applicable law, and forward a copy of the request to help@twelve-app.com so Twelve can handle its own side. Never charge for it, and never retaliate through the Order, reviews or disputes.

    8. Breach notification

    If User data in your hands is lost, stolen, wrongly disclosed or otherwise compromised, notify Twelve at help@twelve-app.com without undue delay and in any event within 48 hours of becoming aware, with enough detail to assess the risk. This does not replace your own legal duties to notify supervisory authorities or affected individuals where those duties apply to you as controller — those remain yours.

    9. Creators outside the EEA

    If you are established outside the European Economic Area and serve Users in it, you are responsible for your own compliance with the GDPR’s rules on international application and transfers with respect to the data you receive. Keeping the data inside the platform (Section 5) is the simplest way to avoid creating transfers of your own.

    10. Duration

    Your obligations under this Annex apply for as long as you hold any User data, and survive Order completion, delisting, and termination of your account.