didact-one Privacy Policy
Last updated: [DATE TO BE SET ON PUBLICATION] Draft prepared: 2026-09-15 — see "Attorney review required" note at the bottom.
This Privacy Policy explains how JANT LLC ("didact-one," "we," "us") collects, uses, and shares information when you use the didact-one website and mobile applications (the "Platform").
1. Information We Collect
You provide directly
- Account information: full name, email address, password (stored as a one-way cryptographic hash — we never store or can retrieve your actual password), and optionally a phone number.
- Organization information: organization name, and if you provide it, a D-U-N-S® Number or other business-identity documentation.
- Talent profile information: headline, bio, hourly rate, and skills, if you create a Talent Profile.
- Content you create: project postings, proposals, messages between contract parties, and ratings/reviews.
Collected automatically or from third parties
- Sanctions screening results: when an Organization is created, we submit the organization's name to the U.S. government's public Consolidated Screening List (via
api.trade.gov) and store the result (clear/flagged) and any matched entries. This is a compliance requirement, not a marketing or profiling use of your data — see Section 6. - Usage data: standard technical logs (IP address, device/browser type, pages or screens visited, timestamps) generated by using the Platform.
We do not currently collect precise location data, biometric data, or payment card numbers directly — payment processing, when live, is handled by third-party payment providers under their own privacy terms (see Section 4).
2. How We Use Information
We use the information above to:
- Create and maintain your account;
- Operate the marketplace (matching clients and talent, facilitating proposals, contracts, messages, and ratings);
- Screen Organizations against sanctions/denied-party lists before they can transact, as legally required;
- Communicate with you about your account or transactions;
- Detect and prevent fraud, abuse, and violations of our Terms of Service;
- Comply with legal obligations.
We do not sell your personal information.
3. Legal Bases (for users in jurisdictions that require this)
Where applicable law requires a legal basis for processing (for example, the EU/UK GDPR), we process your information based on: performance of a contract with you (operating the marketplace), compliance with a legal obligation (sanctions screening, tax/financial recordkeeping), and our legitimate interests (fraud prevention, platform security), balanced against your rights.
4. Who We Share Information With
- Other users, as part of how the Platform works: a Talent Profile's headline, name, skills, hourly rate, and ratings are visible to anyone browsing talent. A Project posting is visible to anyone browsing projects. Messages within a contract are visible only to that contract's client organization members and the talent.
- Service providers who help us run the Platform: hosting and infrastructure providers, and — once integrated — payment processors, identity/business-verification vendors, and email/SMS delivery providers. These providers only receive the information needed to perform their function and are contractually restricted from using it for other purposes.
- Government/regulatory bodies: sanctions-screening queries are sent to the U.S. Consolidated Screening List as described in Section 6; we may also disclose information where required by law, subpoena, or court order.
- In a business transfer: if JANT LLC is involved in a merger, acquisition, or sale of assets, user information may be transferred as part of that transaction, subject to this Policy (or a successor policy you're notified of).
5. International Data Transfers
didact-one is designed for clients and talent across developing markets globally (currently Africa, Latin America, the Caribbean, and Asia) as well as talent located anywhere in the world. Because of this, your information may be transferred to, stored, and processed in the United States or other countries whose data protection laws may differ from those in your own country. Where required by applicable law, we take steps intended to provide an adequate level of protection for such transfers. [PLACEHOLDER: a specific data-residency commitment is only made reactively, per client request, per docs/DEVELOPMENT_PLAN.md §5 — do not add a blanket data-residency promise here without confirming it matches that policy.]
6. Sanctions Screening Data, Specifically
When you create an Organization, its name is screened against the U.S. Departments of Commerce, State, and Treasury's Consolidated Screening List, a free, public U.S. government database used to identify parties subject to certain export controls and sanctions. We store the result of this screening (and, if flagged, the details of the matched entry) as part of our legal compliance obligations. This is not used for any advertising, profiling, or unrelated purpose.
7. Data Retention
We retain account and transaction information for as long as your account is active and as needed to comply with our legal, tax, and recordkeeping obligations after account closure. Sanctions-screening records are retained as part of our compliance recordkeeping.
8. Your Rights
Depending on where you live, you may have rights to access, correct, delete, or export your personal information, or to object to or restrict certain processing. To exercise any of these rights, contact us at support@didact-one.com. We will respond consistent with applicable law. Some information (for example, sanctions-screening and financial records) may need to be retained even after a deletion request, where required by law.
9. Children's Privacy
The Platform is not directed to, and we do not knowingly collect information from, anyone under 18. If we learn we have collected information from someone under 18, we will delete it.
10. Security
We use reasonable technical and organizational measures to protect your information (for example, passwords are hashed, never stored in plain text). No system is completely secure, and we cannot guarantee absolute security.
11. Changes to This Policy
We may update this Privacy Policy from time to time. If we make a material change, we will provide notice (such as an in-app notice or email) before the change takes effect.
12. Contact
Questions about this Privacy Policy, or requests regarding your personal information, can be sent to support@didact-one.com.
Attorney review required — do not publish or rely on this document as-is
This draft reflects didact-one's actual, currently-built data practices (what's genuinely collected and why, as of this session) as a starting point. Before publishing, a licensed attorney should review at minimum:
- Whether a GDPR-specific addendum (data subject rights, a named EU/UK representative if required, a legal basis table) is needed given talent/clients may be located in or connected to the EU/UK, even though the primary market is developing countries.
- Whether state-specific US privacy law disclosures (e.g., California's CCPA/CPRA) are triggered once there are US-based users of any kind.
- The data-residency placeholder in Section 5 — this must match whatever the actual product policy is at publication time, not be a blanket promise made by this document alone.
- Whether a Data Processing Agreement (DPA) template is needed for institutional/government clients who require one contractually before onboarding — common for the government/enterprise segment
docs/DEVELOPMENT_PLAN.mddescribes.