Version: concept v0.1 / Date: 14 September 2026
Controller: [COMPANY NAME + LEGAL FORM], [CHAMBER OF COMMERCE NUMBER], [ADDRESS], [PRIVACY EMAIL]
1. Who this policy covers
This policy applies to visitors, fans, account holders, PPV buyers, members, fighters, ambassadors, applicants, newsletter subscribers and people who contact GRPL.
2. Data we process
Depending on your use of GRPL, we process account data, payment references, orders, entitlements, membership status, video access data, followed fighters, email preferences, contact messages, fighter profile data, application data and technical logs.
3. Payments and access
Stripe processes payments. GRPL stores payment status, order references and local access rights. Full payment card details are not stored by GRPL.
4. Viewing data and revenue allocation
For memberships and fighter revenue, GRPL can track which member watched which match, when, and whether a view meets the configured minimum watch rule. This supports access control, abuse prevention and revenue allocation.
5. Fighter profiles
Fighter profiles can contain name, country, age or birthdate, height, weight, sports, photos, bio, social links, visibility settings, linked account details and related matches. Missing fields are not shown publicly.
6. Email and newsletters
GRPL sends transactional emails for account, payment and access purposes. Marketing emails are sent only where consent is available and can be unsubscribed from.
7. Legal bases
GRPL processes data based on contract performance, consent, legitimate interests, legal obligations and, where relevant, explicit application or publication consent.
8. Processors and providers
GRPL can use Hostinger, Stripe, Bunny.net, YouTube/Google, SMTP/Brevo, Google Analytics and other technical providers. These providers can have their own privacy terms.
9. Retention
Data is retained only as long as needed for the platform, account access, payments, tax administration, support, security, revenue administration and legal obligations.
10. Your rights
You can request access, correction, deletion, restriction, portability, objection or withdrawal of consent by contacting [PRIVACY EMAIL]. You may also complain to the Dutch Data Protection Authority.
11. Security
GRPL uses measures such as HTTPS, hashed passwords, restricted admin access, payment-provider separation, temporary playback access and abuse prevention.
12. Updates
This Privacy Policy may be updated when GRPL changes or legal requirements change.