Privacy Policy
Version 1.0·Effective 1 September 2026
Chamber of Commerce no. 86371479 · VAT no. NL863945910B01
Privacy Policy
Before you start
This policy explains what Lanced does with personal data. It is long, because Lanced does a lot of different things with data and we would rather be complete than short.
If you only read one section, read Section 2. It explains the single most important thing about how data works on Lanced: your information sits in two separate places, looked after by two different organisations. That affects what you can ask us to do, and what you have to ask a company to do.
- "you" means whoever is reading it — an artist, someone working at a company that uses Lanced, or a visitor to the site.
- "artist" means an individual holding a Lanced artist account.
- "company" means an organisation using Lanced Business — a theatre, dance company, casting agency, ensemble or similar.
- "we", "us", "Lanced" means Lanced B.V.
Who is responsible for your data
Lanced B.V. is a private limited company registered in the Netherlands, at Lutonhof 481, 1043 JJ Amsterdam, Chamber of Commerce number 86371479.
For the processing described in this policy, Lanced B.V. is the controller — the organisation that decides why and how your personal data is used — except where Section 2 says otherwise.
How to reach us about data protection
| Contact | |
|---|---|
| Privacy and data protection | privacy@lancedhq.com |
| General support | support@lancedhq.com |
| Security issues and vulnerability reports | security@lancedhq.com |
| Post | Lanced B.V., Lutonhof 481, 1043 JJ Amsterdam, the Netherlands |
Data Protection Officer. We have not appointed a Data Protection Officer. Data protection questions and requests are handled directly by our own team, and you can reach us at privacy@lancedhq.com. We keep the question of whether a Data Protection Officer is required under review as Lanced grows.
We are established in the Netherlands, so our lead supervisory authority is the Dutch Autoriteit Persoonsgegevens. Section 16 explains how to complain to them.
The two layers — the thing to understand first
Personal data about an artist exists on Lanced in two separate layers. Different organisations are responsible for each, and this determines who you go to when you want something done.
Layer 1 — Your Lanced account. We are responsible.
Your account, your artist profile, your media library, your works, portfolios and Studio site, and your presence in the Lanced network are ours to look after. Lanced is the controller. We decide how that data is stored, secured, shown and deleted, and you exercise your rights over it directly with us.
This layer is what this Privacy Policy is mainly about.
Layer 2 — An application you send to a company. The company is responsible.
When you apply to a call, the application you send, the answers you give, the materials you attach, and everything the company writes about you while reviewing it — notes, scores, labels, votes, shortlist decisions, messages, scheduling records, and any contract or onboarding records — belong to that company. The company is the controller. Lanced is its processor, holding and handling that data on the company's instructions.
- The company decides how long to keep your application, what to do with it, and who inside its organisation sees it.
- We cannot delete it on our own initiative, and we cannot decide questions about it on your behalf.
- If you want that data accessed, corrected or deleted, the request has to reach the company. You can send it to us and we will forward it to them without undue delay, or you can go to them directly.
- The Autoriteit Persoonsgegevens' guideline for how long an unsuccessful applicant's data should be kept is four weeks after the procedure ends, extendable to a maximum of one year with the applicant's explicit consent. That guideline applies to the company, not to Lanced. If you think a company is keeping your application longer than is justified, that is a question for them, and ultimately for the supervisory authority.
The contract governing what we may and may not do with Layer 2 data is our Data Processing Addendum, which every company using Lanced Business is bound by.
Layer 3 — Copies a company has downloaded
Companies on paid plans can export application material and print CVs and résumés. Once they do, that copy sits in their own systems, or on paper in their own office. We have no access to it, no visibility of it, and no ability to delete it. From that point the company alone is responsible for it, including for answering any request you make about it.
Deleting one layer does not delete the others
Deleting your Lanced account removes Layer 1. It does not remove applications you have already sent (Layer 2), or copies a company has downloaded (Layer 3). Section 13 explains this in more detail, and what you can do about it.
If you work at a company
The same split applies to you, in a slightly different shape. Your own Lanced account — your name, email, login credentials, sessions, settings, support correspondence — is ours, and we are the controller for it. Your activity inside your employer's workspace — the notes you write, the votes you cast, your role and permissions, the workspace activity log — is your employer's, and we process it on their behalf. Questions about the first go to us. Questions about the second go to your employer.
What personal data we collect
When you create an account
- Name, email address, and the authentication identifier issued by our authentication provider.
- Pronouns, language, time zone and account settings, where you provide them.
- Date of birth. We collect this when you create an artist account. We use it to confirm you are old enough to use Lanced and, where relevant, to apply the protections and requirements that exist for younger performers. It is not shown on your public profile.
We do not receive or store your password. Credentials are held by our authentication provider (see Section 8).
Your artist profile
Display name, handle, city and country, artist types and disciplines, styles, artistic identity and interests, special skills, languages, training and career record, biography, and external links.
You control whether your profile is public, unlisted or private, whether you appear in network search, and whether your location is displayed at all.
Special category data and other sensitive fields
Four fields are held separately from the rest of your profile, in a dedicated, access-restricted store:
- Ethnicity — this is special category personal data under Article 9 GDPR and receives additional protection.
- Date of birth
- Nationality
- Gender
Nationality, gender and ethnicity are optional. You can leave them blank, or select "prefer not to say" where that option is available. Section 5 explains the legal basis, and Section 6 explains how and when they can be disclosed to a company.
Physical characteristics
Height, weight, measurements, hair and eye colour, and sizes — the comp-card data that is genuinely part of a casting brief in some disciplines. These are held in their own separate, access-restricted store, and you complete them only if your discipline calls for it.
Media and files
Photographs, headshots, video, self-tapes, audio, portfolio material, documents and CVs that you upload, together with technical metadata about those files.
Applications and reviews
Motivation letters, answers to application questions, the materials you selected for an application, availability data, and the record of which sensitive fields you chose to share for that particular application. On the company's side: reviewer notes, votes, scores, labels, review status, and round and shortlist decisions.
Most of this is Layer 2 data. See Section 2.
Messages and scheduling
Conversations, messages, attachments, broadcasts, audition slot bookings, session and group assignments, and notification and email delivery records.
Contracts and engagements
Where a company issues a contract through Lanced: signer name and email address, the contract document, signature state, and related engagement records.
We do not provide functionality for identity documents. Companies are contractually prohibited from asking you to upload passports, identity cards, residence permits or a Dutch burgerservicenummer (BSN) through Lanced. If a company asks you to, tell us at support@lancedhq.com.
Payment and billing
Subscription and entitlement state, and a reference to your customer record held by our payment provider. Card details never reach Lanced. Our payment provider collects your card details, billing address and tax identifier directly, through its own hosted checkout.
Technical and usage data
- IP addresses, user agent strings, referring pages and session records.
- Server access logs at our web layer, which contain IP addresses.
- Audit records of significant actions taken in the product, each carrying the actor, the target, an IP address and a user agent.
- Records of interaction with promoted or featured content within the product, which include IP address, user agent and referring page.
- Product analytics events — the pages you view, the features you use and the actions you take within the product, linked to an identifier for your device or your account. See Section 7.2.
- Error and diagnostic reports when something goes wrong (see Section 8).
Company profile data
For companies: company name, logo, media, published updates, and any personnel a company chooses to display on its profile. Where a company displays its own people, the company is responsible for informing those individuals and for having a lawful basis to do so. Lanced then publishes and displays the profile as an independent controller.
What we do not collect
We do not collect or ask for identity documents, national identification numbers, financial account details, criminal record data, or biometric templates. We do not run facial recognition, emotion recognition or biometric categorisation on any media you upload. See Section 10.
Where the data comes from
Almost everything we hold comes from you — you type it in, upload it, or generate it by using the product.
We also receive data:
- From companies, where they write notes, scores or decisions about you inside their workspace, or where they add records about you to their own talent pool after you have consented to being saved there.
- From our authentication provider, which confirms a successful sign-in and returns basic account identifiers.
- From our payment provider, which confirms payment and subscription state.
- Automatically, from your device and browser when you use the site — IP address, user agent, and the pages you request.
We do not buy personal data, and we do not enrich profiles from third-party data brokers.
Why we use your data, and our legal basis
Under the GDPR we need a lawful basis for every purpose. Here is ours, purpose by purpose.
| What we do | Why | Legal basis |
|---|---|---|
| Create and run your account; let you build a profile, upload media, apply to calls, message, schedule, and use Studio | To deliver the service you signed up for | Article 6(1)(b) — performance of a contract with you |
| Make your profile discoverable to companies through network search, subject to the visibility settings you have chosen | Being findable is the core of what an artist account is for | Article 6(1)(b) — performance of a contract with you |
| Verify your age using your date of birth, and apply protections that exist for performers under 18 | To operate an age-appropriate service and to meet obligations relating to young performers | Article 6(1)(b) and Article 6(1)(f) — our legitimate interest in operating the service lawfully and safely |
| Hold your optional nationality and gender fields | Only where you have chosen to provide them | Article 6(1)(a) — your consent |
| Hold your ethnicity field | Only where you have chosen to provide it | Article 6(1)(a) and Article 9(2)(a) — your explicit consent |
| Disclose a sensitive field to a specific company as part of a specific application | Only where you have separately chosen to share it for that application | Article 6(1)(a) and, for special category data, Article 9(2)(a) — your explicit consent |
| Save you to a company's talent pool | Only where you have agreed | Article 6(1)(a) — your consent |
| Take payment and manage subscriptions | To perform the paid contract | Article 6(1)(b) |
| Keep accounting and tax records | Dutch tax law requires records to be kept for seven years (Article 52 Algemene wet inzake rijksbelastingen) | Article 6(1)(c) — legal obligation |
| Send you service messages — confirmations, notifications, security alerts, changes to terms | These are part of running your account, and are not marketing | Article 6(1)(b) and Article 6(1)(f) |
| Send marketing email about Lanced | Only with your consent, or on the basis of an existing customer relationship where Dutch law permits it | Article 6(1)(a) — your consent, or Article 6(1)(f) read with Article 11.7 Telecommunicatiewet. You can unsubscribe at any time |
| Secure the platform: detect and prevent fraud, abuse, credential compromise, scraping and attacks; keep audit trails | We and our users have a strong interest in a platform that is not abused | Article 6(1)(f) — legitimate interests |
| Review every call before it is published, moderate content, and act on reports | To keep the platform genuine and safe, and to meet our obligations as an online platform under the Digital Services Act | Article 6(1)(c) and Article 6(1)(f) |
| Provide support, investigate faults and investigate reports — including staff access to an account where necessary (Section 9) | We cannot support a product we cannot look at | Article 6(1)(f) — legitimate interests |
| Measure how the product is used, through product analytics | To see what works, what is confusing, and what nobody uses | Article 6(1)(a) — your consent. Analytics is not necessary to run Lanced, so we ask before we start, and you can withdraw at any time |
| Fix faults and improve features using error reports, support correspondence and your feedback | To build a service that works | Article 6(1)(f) — legitimate interests |
| Develop and improve search, discovery and matching (see Section 10) | To help the right opportunities reach the right artists | Article 6(1)(f) — legitimate interests |
| Establish, exercise or defend legal claims | To protect ourselves and our users | Article 6(1)(f) |
| Comply with lawful requests from authorities and courts | Because we must | Article 6(1)(c) |
Where we rely on legitimate interests, we have weighed our interest against your rights and freedoms. You have the right to object to that processing at any time — see Section 15. If you object, we stop, unless we can demonstrate compelling legitimate grounds that override your interests, or we need the data to establish, exercise or defend legal claims.
Where we rely on consent, you can withdraw it at any time. Withdrawing consent does not affect the lawfulness of what we did before you withdrew it, and it does not automatically reach back into an application you have already submitted — see Section 6.
Who else processes your data
We use a small number of service providers. Each processes personal data only on our instructions and under a written data processing agreement, and each is listed with its purpose, location and transfer mechanism on our Sub-Processor Register, which is the authoritative and current list. In summary:
Where the data actually lives
Two providers carry substantially all of it:
- DigitalOcean, LLC — application hosting, the managed PostgreSQL database, and database backups. Amsterdam, the Netherlands. This holds every record: accounts, profiles including the sensitive fields, applications and answers, messages, reviewer notes, votes and outcomes, audit trails and billing state.
- Cloudflare, Inc. — object storage, media delivery and media processing, with the storage region pinned to the EU. European Union. This holds every file: headshots, portfolio media, self-tapes, audio, documents, CVs and signed contracts.
Everything else is narrow
One function each, and most receive only a name and an email address.
| Provider | What it does | Where |
|---|---|---|
| WorkOS, Inc. | Authentication, identity management and credential hosting. Holds hashed passwords, magic-link tokens, basic profile data and session metadata | United States |
| Resend | Transactional email — the messages the product sends when you do something | Ireland for sending; United States for account data, delivery logs and metadata |
| Brevo SA | Marketing email and customer service, including the content of support conversations | France |
| Stripe Payments Europe Ltd., with Stripe, Inc. (US) as onward sub-processor | Payments and subscription billing. Collects card details, billing address and tax identifier directly | Ireland; United States |
| Zoho Corporation (Zoho Sign) | Electronic signature of contracts. Receives signer name, email address and the contract document | European Union |
| Functional Software, Inc. (Sentry) | Error monitoring. Receives technical error reports, which can incidentally contain personal data appearing inside an error message | European Union (EU data region) |
| Google Ireland Ltd. (Maps Platform) | Location autocomplete. Receives only the text typed into a location field. The request is made by our servers, so your IP address is not sent to Google by this feature | Ireland; global Google infrastructure including the United States |
| PostHog, Inc. (EU Cloud) | Product analytics, where you have agreed to it. Receives usage events, a device or account identifier, IP address and user agent | European Union (Frankfurt) |
| GitHub, Inc. | Source code hosting and deployment infrastructure. Does not process user personal data | United States |
Committed, but not yet in use
We publish planned providers in advance, so there is notice before any data moves to them. Today this is Google Calendar (optional calendar integration), which does not process any personal data at present.
Others we may share with
- Companies you apply to or interact with, as described in Sections 2 and 6.
- Other users, where you have chosen to be publicly visible. Your public profile, Studio site, works and portfolios are visible to whoever you have made them visible to.
- Professional advisers — lawyers, accountants, auditors — under confidentiality.
- Authorities, courts and regulators, where we are legally required to disclose, or where disclosure is necessary to establish, exercise or defend legal claims.
- A buyer or successor, if Lanced is acquired, merges or reorganises. We would tell you before your data became subject to a different privacy policy.
When Lanced staff can see your account
Sometimes our staff need to look at an account to fix a fault, investigate a report, or deal with a security problem. This includes the ability to view the product in the context of your account, so that we can see what you are seeing.
We think you should know this plainly, rather than find it in a technical annex.
How it is constrained:
- Access requires an internal staff account type, an assigned administrative role, a specific per-action permission, and a non-disabled administrative flag. It is not available to staff generally.
- Support-level staff can read and assist, but cannot alter accounts, billing or published content.
- A session viewing the product as a user expires after 60 minutes on the server, is bound to the individual staff member who opened it, and is ignored if anyone else signs in.
- Such a session is blocked from the administration tools entirely, and never carries the staff member's own workspace into your view.
- Start and end are always recorded, and every action taken during the session carries the responsible staff member's identity in its audit record.
You can ask for the record. Write to privacy@lancedhq.com and we will tell you when your account was accessed in this way.
Artificial intelligence and automated processing
Your likeness is yours
We do not use the photographs, videos, audio or performance material you upload to train generative AI models designed to recreate people, generate synthetic performers, imitate your likeness, reproduce your voice, or create new media based on your artistic identity. We do not sell or licence your media to anyone else for that purpose.
This does not prevent us from using the ordinary technical systems needed to run the service — storing, transcoding, resizing, delivering, searching, displaying and moderating your media.
No biometric or emotion inference
We do not use biometric analysis of your photographs or videos to infer sensitive characteristics such as racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, health, sex life or sexual orientation. We do not use AI to infer your emotions or personality for recruitment or workplace decision-making.
Where we do use machine learning
We may use machine learning and recommendation techniques to improve search, discovery, matching and the organisation of large applicant pools — in short, to help the right people find each other. Where we do, these systems are built primarily on declared, structured professional information — discipline, roles, skills, styles, experience, training, location, availability — and on how the platform is used, rather than on computer vision or analysis of your appearance.
Our legal basis is our legitimate interest in providing and improving the service (Article 6(1)(f)). You can object — see Section 15.
People decide, not machines
Where a company uses AI-assisted tools on Lanced to help review applications, those tools support the company's review. They do not accept or reject anyone. The company makes the decision and is responsible for it. Our Business Terms require companies to exercise meaningful human oversight, to consider the wider eligible applicant pool rather than only recommended candidates, and not to substitute such tools for human judgement where that would be unlawful.
Recommendations, rankings and search results are informational. They are not determinations of your ability, suitability, professional quality or artistic value.
Automated decision-making under Article 22
Lanced does not make decisions producing legal effects concerning you, or similarly significantly affecting you, based solely on automated processing within the meaning of Article 22 GDPR.
Some ordinary automated checks do run — for example fraud, abuse and security signals that may flag an account for human review. Where such a signal leads to a restriction, a person reviews it, and you can challenge the outcome under Section 15 and through the appeal route in our Terms.
If this changes
We will update this policy, and tell you, before launching AI-assisted functionality that materially changes how your data is processed. Any third-party AI provider we engage will be added to the Sub-Processor Register before any processing begins.
Sending data outside the EEA
Our core infrastructure is in Europe. The database, application infrastructure and database backups are hosted in Amsterdam, the Netherlands. Uploaded media and contract documents are stored in EU-jurisdiction object storage, with the EU setting enforced when the application starts, rather than left as a deployment option that can be forgotten.
Some limited categories do go outside the European Economic Area:
| Where | What goes there | Safeguard |
|---|---|---|
| United States — WorkOS, Inc. | Authentication and credential data: hashed passwords, magic-link tokens, basic profile data, session metadata | Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914) |
| United States — Resend | Account data, email delivery logs and metadata, which include recipient email addresses. Sending itself is from Ireland | Standard Contractual Clauses |
| United States — Stripe, Inc., as onward processor to Stripe Payments Europe Ltd. | Billing and payment data | Standard Contractual Clauses |
| Global Google infrastructure including the United States — Google Ireland Ltd. | The text typed into a location field. No IP address and no user identifier | Google Cloud Data Processing Addendum incorporating Standard Contractual Clauses |
| United States — GitHub, Inc. | No user personal data | Standard Contractual Clauses |
| United States — Google Fonts and jsDelivr, loaded in your browser (Section 7.4) | Your IP address, user agent and referring page | These are not contracted providers. We are removing both dependencies by serving the resources from our own infrastructure |
Sentry is used in its EU data region, and is additionally certified under the EU–U.S. Data Privacy Framework.
You can ask us for a summary of our transfer assessments, and for a copy of the relevant Standard Contractual Clauses, at privacy@lancedhq.com.
How long we keep things
Periods enforced by the platform
| What | How long |
|---|---|
| Message attachments | Deleted 30 days after the last conversation referencing them closes |
| Candidate conversations | 30 days after closure |
| Media you delete | Permanently removed from storage within 7 days |
| Abandoned uploads | Expire rather than persisting as orphaned files |
| Staff support sessions viewing an account | Expire after 60 minutes |
| Signed links to private media and contracts | Expire after 10 minutes |
| Pre-deployment database snapshots | The most recent 14 are kept |
| A company workspace after a deletion request | 30-day grace period, then finalised |
| Company workspace data after stepping down to a free profile | 12 months, with export reminders at 9 and 11 months, then permanently deleted |
| Accounting and tax records | 7 years, as Dutch tax law requires |
Your account
We keep your account and profile data for as long as your account exists. When you delete your account, Section 13 explains what happens and when.
Applications and company records
These are the company's to decide — see Section 2. We do not currently apply a platform-wide maximum retention period to applications, review records or saved artist records. We expect to introduce one, and we will give companies notice before it takes effect.
In the meantime, if you want an application deleted, Section 2 explains the route.
Logs and audit records
| What | How long |
|---|---|
| Workspace and artist audit trails | 24 months |
| Internal staff audit trail | 24 months |
| Session records | 90 days after the session expires |
| Records of interaction with promoted or featured content | 90 days |
| Product analytics events | 12 months |
Server access logs and container logs rotate on a size basis rather than a time basis, and are not held in a central log store.
The general rule
Where no specific period is stated, we keep personal data only as long as we need it for the purpose it was collected for, plus any period we are required to keep it by law, or need it to establish, exercise or defend a legal claim.
Deleting your account
You can delete your artist account at any time from your settings.
What happens. Before you confirm, we show you a preview of what will be affected. You then confirm by email. There is a 30-day grace period, during which you can cancel with a one-click link.
When the grace period ends, your account is erased. Your name and email address are replaced with an anonymised placeholder, pronouns and settings are cleared, the account is marked deleted and disabled, and every session is revoked. On your profile, display name, handle, headshot, banner, biographies and location are cleared, and visibility is forced to private. The four sensitive fields — date of birth, nationality, ethnicity and gender — are emptied. Your media and message attachments are marked for deletion and are physically removed from storage within seven days. In conversations, your identity is replaced with a non-identifying placeholder, so that the other participants are not left with broken threads.
On timing, precisely: erasure at the end of the grace period is carried out by our privacy team rather than fully automatically. It completes within 30 days of the grace period ending. If it has not, tell us at privacy@lancedhq.com.
One case where we may hold a request. If a contract is actively awaiting your signature, we will tell you which contract is blocking the request. Once that contract is signed, declined, withdrawn or expired, the erasure proceeds.
What deleting your account does not do. It does not delete applications you have already sent to companies, or copies companies have downloaded or printed. See Section 2. If you want an application deleted too, tell us and we will forward the request to the company; in most cases they will have to delete it, though there are limited situations in which they can refuse — for example where they need the record to defend a legal claim. If the call is still open, withdrawing your application is quicker, and removes the materials you submitted with it.
Backups. Data held in routine backups is deleted in the ordinary course of the backup cycle, rather than immediately.
How we protect your data
The full detail is in our Security Statement. In outline:
- In transit, everything runs over TLS 1.2 or 1.3 with strict transport security. At rest, the database and object storage are encrypted with AES-256 using provider-managed keys.
- Your sensitive fields and physical characteristics are held in dedicated tables protected by database-enforced row-level security, scoped to you. The application connects to the database as a restricted role, and refuses to start if that role could bypass those protections.
- Contracts are held in a separate private store from ordinary media, with no public route, readable only through short-lived authenticated links. The application refuses to start if the two stores are configured to the same place.
- Application materials, self-tapes and message attachments are held in a private scope, and served only through links that expire after ten minutes, or through authenticated endpoints.
- Publicly reachable media — what you have chosen to publish on your profile or portfolio — is served over long, random, unguessable web addresses that are not indexed by search engines. To be precise rather than reassuring: a link of this kind is protected by being unguessable, so anyone you share such a link with can open it, and it remains valid until the file is deleted.
- Audit trails record significant actions with the actor, target, IP address and user agent.
- Incident response follows a written procedure with defined severity levels, a named owner and a triage target, reviewed at least annually.
Certifications. Lanced does not currently hold SOC 2, ISO 27001 or an equivalent third-party attestation. We would rather say so than imply one.
No system is perfectly secure. If you believe your account has been compromised, contact us at security@lancedhq.com.
Your rights
Under the GDPR you have the following rights over data for which Lanced is the controller (Layer 1). For Layer 2 data the same rights apply, but they are exercised against the company — see Section 2, and we will forward your request.
- Access (Article 15) — a copy of your personal data, and information about how it is used.
- Rectification (Article 16) — correction of inaccurate or incomplete data. Most profile data you can correct yourself.
- Erasure (Article 17) — deletion, in the circumstances the GDPR provides for. See Section 13.
- Restriction (Article 18) — to have processing paused while a dispute about accuracy or lawfulness is resolved.
- Portability (Article 20) — data you gave us, in a structured, commonly used, machine-readable format, where processing is based on consent or contract and carried out by automated means.
- Objection (Article 21) — to processing based on legitimate interests, including profiling. You can object to direct marketing at any time, and we will stop, without exception.
- Withdraw consent (Article 7(3)) — at any time, for anything we do on the basis of consent.
- Not to be subject to a solely automated decision (Article 22) — see Section 10.5.
How to exercise them. Some are self-service in the product. Otherwise, write to privacy@lancedhq.com. We log every request, and we will respond within one month, extendable by two further months for complex or numerous requests — in which case we will tell you within the first month, and explain why.
About access and export, specifically. The self-service export currently assembles your account record, application grants, organisation memberships, artist profile, applications and any previous privacy requests. It does not yet include the sensitive fields, uploaded media, messages, application answers and materials, the per-application consent records, or the audit trails. Those are compiled by our team on request, within the same deadline, and we are extending the automated export to cover them. If you want everything, ask at privacy@lancedhq.com and say so — we will not give you the partial version and call it complete.
We may need to verify who you are before acting, and we will ask for no more than is necessary to do that.
Exercising your rights is free. We may charge a reasonable fee, or decline, only where a request is manifestly unfounded or excessive — and we will explain why.
Complaints
If you are unhappy with how we have handled your personal data, please tell us first, at privacy@lancedhq.com. We would rather fix it.
You also have the right to lodge a complaint with a supervisory authority. In the Netherlands that is:
Autoriteit Persoonsgegevens
Postbus 93374, 2509 AJ Den Haag, the Netherlands
autoriteitpersoonsgegevens.nl
If you live or work in another EU or EEA country, you can complain to your own national supervisory authority instead. You also have the right to an effective judicial remedy.
Children and young people
You must be at least 16 to hold a Lanced account. This matches the age at which, under Dutch law implementing Article 8 GDPR, a young person can consent to information society services on their own behalf.
If you are under 18:
- You can use Lanced, but you cannot purchase a subscription without the consent of a parent or guardian.
- If a company wants to engage you, additional legal rules apply to your work, and the company is responsible for complying with them.
We do not knowingly collect data from anyone under 16. If you believe a child under 16 holds an account, tell us at privacy@lancedhq.com and we will remove it.
Changes to this policy
We update this policy when the product, our providers, or the law change.
For material changes — anything that meaningfully affects how your data is used — we will give you at least 30 days' notice by email and inside Lanced before the change takes effect. For minor changes, such as corrections and clarifications, we update the date at the top.
Previous versions are kept at lanced.tech/privacy-policy.
Lanced B.V. · Privacy Policy · Version 1.0 · Effective 1 September 2026