1.02 Get Repped Ltd ("us", "we", or "our") operates the website www.getrepped.co.uk (the "Service").
1.03 This Privacy Policy governs your use of the Service and explains how we collect, safeguard, and disclose information that results from your use.
1.04 We use your data to provide and improve the Service. By using the Service, you agree to the practices described here.
1.05 Unless otherwise defined, terms in this Privacy Policy have the same meanings as in our Terms and Conditions.
1.06 Our Terms and Conditions ("Terms") and this Privacy Policy together form our agreement with you ("Agreement").
1.07 Get Repped Ltd is incorporated in England & Wales. Registered office: 124 City Road, London, EC1V 2NX, United Kingdom.
2. Definitions
2.01SERVICE: www.getrepped.co.uk operated by Get Repped Ltd.
2.02PERSONAL DATA: Information relating to an identified or identifiable natural person.
2.03USAGE DATA: Data collected automatically through the Service (e.g. page-visit duration).
2.04COOKIES: Small text files stored on your device.
2.05DATA CONTROLLER: The entity that determines purposes and means of processing Personal Data (Get Repped Ltd).
2.06DATA PROCESSOR: A third party processing data on behalf of the Data Controller.
2.07USER / DATA SUBJECT: The individual using the Service and to whom Personal Data relates.
3. Information Collection and Use
3.01 We collect several types of information to provide and improve our Service.
4. Types of Data Collected
4.01Personal Data you provide: Email address; first & last name; phone number; postal address (country, county/state, city, postcode); and similar identifiers.
_gcl_au – Google Ads conversion tracking – expires 3 months
Advertising Cookies (Meta Pixel):
_fbp – Facebook Pixel for tracking and ad targeting – expires 3 months
_fbc – Facebook click identifier – expires 2 years
fr – Facebook advertising and measurement – expires 3 months
4.05Cookie Management: You can control and delete cookies through your browser settings. However, disabling certain cookies may affect your ability to use some features of the Service. You can also manage cookie preferences through our cookie consent banner.
4.06Other Data (optional): Demographic or professional details you choose to supply (e.g. date of birth, education, employment agreements, NDAs, bonuses, marital status, taxpayer ID).
4.07AI Feature Data: When you use our AI-powered features, we collect and process the following data:
Strategy Review: Your publicly available Spotlight profile data (retrieved using the Spotlight PIN or URL you provide), your email templates stored within the Service, and your outreach performance metrics (including send counts, open rates, click rates, recipient targeting data, and timing patterns).
Typecast Me: The headshot image you upload for analysis. This may be collected from both registered users and unregistered visitors to the Service.
4.08AI Feature Outputs: We store the outputs generated by AI Features, including Strategy Review reports (text-based analysis and recommendations) and Typecast Me result images (the generated casting type card overlaid on your uploaded headshot).
5. Use of Data
5.01 Provide and maintain the Service.
5.02 Notify you about changes to the Service.
5.03 Enable interactive features at your request.
5.04 Provide customer support.
5.05 Gather analysis to improve the Service.
5.06 Monitor usage.
5.07 Detect, prevent, and address technical issues.
5.08 Fulfil the purpose for which you provide data.
5.09 Enforce contractual rights (e.g. billing, collection).
5.10 Send account or subscription notices.
5.11 Send marketing or promotional material you have opted in to receive (opt-out anytime).
5.12 Legitimate interests, balanced against your rights (analytics, security, improvement).
5.13 Compliance with UK legal obligations.
5.14 Any other purpose described when you provide information, or with your consent.
5.15 Send emails on your behalf to talent agents and casting directors when you use our email functionality.
5.16 Create and manage email drafts in your connected email account.
5.17 Maintain email sending reputation and deliverability for your professional communications.
5.18 Deliver targeted advertising and measure advertising effectiveness through Meta Pixel and Google Ads.
5.19 Track conversions and optimize our marketing campaigns.
5.20 Generate AI-powered Strategy Reviews by transmitting your Spotlight profile data, email templates, and outreach performance metrics to our AI provider (Anthropic) for analysis, followed by human editorial review before publication.
5.21 Generate AI-powered Typecast Me results by transmitting your uploaded headshot image to our AI provider (Anthropic) for casting type analysis.
5.22 Store AI-generated outputs (Strategy Review reports and Typecast Me result images) within your account or temporarily on our servers to enable you to access, review, and share your results.
5.23 Use anonymised and aggregated data derived from AI Features to monitor, maintain, and improve the quality of those features and the Service generally. No individually identifiable data is used for this purpose.
6. Retention of Data
6.01 Personal Data is retained only as long as necessary for the purposes above or as required by law.
6.02 Usage Data is generally kept for a shorter period unless needed for security or Service improvement.
6.03Strategy Review Data: Strategy Review reports and the underlying analysis are stored indefinitely within your account so that you may access them at any time. If you wish to have this data deleted, you may request deletion by contacting us in writing at support@getrepped.co.uk. We will process deletion requests within a reasonable timeframe, and no later than thirty (30) days from receipt of a valid request.
6.04Typecast Me Data: Uploaded headshot images and generated result images are retained for up to ninety (90) days from the date of upload to allow you to re-access and share your results. After this period, all associated data is automatically and permanently deleted via an automated lifecycle policy applied to our storage infrastructure.
6.05AI Provider Retention: Data transmitted to our AI provider (Anthropic) for processing is retained by Anthropic for up to seven (7) days for trust and safety monitoring purposes, after which it is automatically deleted. Anthropic does not retain your data beyond this period and does not use it for any purpose other than providing the requested AI analysis and enforcing their usage policies.
6.06Anonymised Data: We may retain anonymised and aggregated data derived from AI Features for an indefinite period for the purposes of service improvement and internal analytics. This data cannot be used to identify you.
7. Transfer of Data
7.01 If you are outside the UK, your data will be transferred to—and processed in—the UK. By submitting data, you agree to this transfer.
7.02 We ensure appropriate safeguards (e.g. adequacy decisions or standard contractual clauses) for any onward transfer outside the UK.
7.03 When using Google Tag Manager and Meta Pixel, your data may be transferred to servers in the United States and other countries where Google and Meta operate. Both companies participate in frameworks designed to ensure adequate data protection for international transfers.
7.04 When you use our AI Features (Strategy Review and Typecast Me), your data is transmitted to Anthropic, PBC, which is headquartered in the United States. Anthropic processes this data under their commercial API terms, which include a Data Processing Addendum with Standard Contractual Clauses to ensure adequate protection for international data transfers in compliance with UK GDPR. Anthropic does not use data submitted through their commercial API to train AI models, and API data is automatically deleted within seven (7) days of processing.
8. Disclosure of Data
8.01Law Enforcement: We may disclose Personal Data if required by law or valid request.
8.02Business Transaction: Personal Data may be transferred in a merger, acquisition or asset sale.
8.03Other Cases:
To subsidiaries and affiliates
To contractors and service providers supporting our business
To third-party OAuth providers (Google, Microsoft) solely for authentication and authorized email functionality
OAuth tokens and email access permissions are never shared with other third parties
To Google (via Google Tag Manager) for analytics and advertising measurement
To Meta/Facebook (via Meta Pixel) for advertising targeting and conversion tracking
To fulfil the purpose for which you provide it
To include your company's logo on our site (if you supply it)
As disclosed when you provide the data
With your consent
To protect rights, property or safety of Get Repped Ltd, users or others
To Anthropic, PBC (our AI provider) for the purpose of generating Strategy Review analyses and Typecast Me results. Anthropic processes this data under their commercial API terms and does not use it for model training.
9. Security of Data
9.01 We use commercially acceptable security measures (encryption, access control). No method of transmission or storage is 100% secure.
10. Authentication and OAuth
10.01 Our Service may let you log in or register using third-party authentication providers (e.g. Google or Microsoft OAuth). When you connect, we receive information (such as name and email) as allowed by that provider's privacy settings. We use this only to facilitate your login and use of the Service.
10.02Security of OAuth Tokens: Any OAuth tokens or credentials that allow our Service to interact with your third-party account are stored securely in encrypted form. Administrators cannot view these tokens and cannot use them to access your accounts. Tokens are used only as needed to provide authorised functionality.
10.03User Responsibility to Revoke Access: You may revoke our Service's access to your third-party account at any time (e.g. via Google or Microsoft account settings). It is your responsibility to revoke access if you stop using the integration or believe your account security is at risk.
10.04Google OAuth Permissions and Use:
email scope: To identify and authenticate your account and ensure emails are sent from your verified email address
profile scope: To personalize your experience with your name and provide account identification
https://www.googleapis.com/auth/gmail.send: To send emails on your behalf to talent agents and casting directors through our platform
10.05Microsoft OAuth Permissions and Use:
User.Read: To authenticate your account and access basic profile information (name, email)
Mail.Send: To send emails on your behalf to talent agents and casting directors through our platform
10.06Email Sending Functionality: Our core service allows you to send professional emails to talent agents and casting directors from our curated database. When you use this feature:
Emails are sent directly from your connected email account (Gmail or Microsoft)
This ensures emails appear to come from you personally, not from our platform
We do not store copies of sent emails on our servers
You maintain full control over your email reputation and sending history
All emails include proper unsubscribe mechanisms and comply with anti-spam regulations
10.07Data Processing Location: When you connect your Google or Microsoft account, your authentication data may be processed on Google's or Microsoft's global server infrastructure. Your email data is processed only as necessary to send emails on your behalf and is not stored permanently on our servers.
10.08Revoking Email Access: You can revoke our access to your email account at any time through:
Revoking access will prevent our platform from sending emails on your behalf but will not affect your existing Get Repped account
11. Your Data Protection Rights (UK GDPR)
11.01Access – request a copy of your Personal Data.
11.02Rectification – correct inaccurate or incomplete data.
11.03Erasure – request deletion ("right to be forgotten").
11.04Restriction – limit processing.
11.05Portability – receive data in machine-readable format.
11.06Objection – object to processing based on legitimate interests.
11.07Withdraw Consent – at any time without affecting prior processing.
11.08Complain – lodge a complaint with the UK ICO (ico.org.uk).
12. Service Providers
12.01 We employ third-party companies and individuals to facilitate the Service, perform Service-related services or assist in analysis. They access Personal Data only to perform tasks on our behalf and are contractually bound to confidentiality.
13. AI Data Processing
13.01AI Provider: We use Anthropic's commercial API to power our AI Features (Strategy Review and Typecast Me). Anthropic, PBC is an AI safety and research company headquartered in San Francisco, California, United States.
13.02What Data is Shared with Anthropic:
Strategy Review: Your publicly available Spotlight profile information (as retrieved using the PIN or URL you provide), your email templates, and your outreach performance data (send counts, open rates, click rates, recipient categories, and timing data). We do not share your name, email address, or other direct identifiers with Anthropic unless they are contained within the Spotlight profile data or email templates you have created.
Typecast Me: The headshot image you upload. No other personal data is transmitted alongside the image unless it is embedded within the image file metadata.
13.03How Anthropic Processes Your Data: Data is transmitted to Anthropic's API via encrypted HTTPS connections. Anthropic processes the data solely to generate the requested AI analysis and returns the output to our servers. Under Anthropic's commercial API terms: (i) your data is not used to train, improve, or develop AI models; (ii) your data is retained by Anthropic for up to seven (7) days for trust and safety monitoring and abuse prevention, after which it is automatically and permanently deleted; and (iii) your data is not shared by Anthropic with any third party.
13.04Lawful Basis for Processing: We process your data through AI Features on the following lawful bases under UK GDPR:
Consent (Article 6(1)(a)): You provide explicit consent each time you submit data to an AI Feature. For Strategy Reviews, consent is given by submitting your Spotlight PIN or URL via the request form, with a visible disclosure on the portal page. For Typecast Me, consent is given by uploading your headshot image. You may withdraw consent at any time by ceasing to use AI Features, and for Strategy Reviews, by requesting deletion of your review data.
Legitimate Interest (Article 6(1)(f)): Processing is also necessary for our legitimate interest in providing the core functionality of the Service, namely delivering AI-assisted career strategy analysis and casting type assessment to our users. We have assessed that this interest is not overridden by your rights and freedoms, particularly given that: the data processed is either publicly available (Spotlight profiles) or voluntarily submitted by you (headshots, email templates); processing is transparent and disclosed; and you retain the right to opt out at any time.
13.05Human Review: Strategy Reviews are generated with the assistance of AI and are subsequently reviewed and may be edited by a member of our team before being published to your account. This human review process means that members of our team will view your Spotlight profile data, email templates, and outreach metrics as part of the editorial process. Typecast Me results are generated entirely by AI and are not subject to human review.
13.06Data Protection Impact: We have conducted a data protection impact assessment for our AI Features and have determined that appropriate safeguards are in place, including: encrypted data transmission; contractual restrictions on Anthropic's use of your data; automated deletion by Anthropic within seven (7) days; defined retention periods within our own systems; and clear user consent mechanisms.
13.07Your Rights: In addition to the rights set out in section 11 of this Privacy Policy, you have the following specific rights in relation to AI Features:
You may request a copy of the data we have shared with Anthropic on your behalf by contacting support@getrepped.co.uk.
You may request deletion of your Strategy Review data at any time by contacting us in writing. We will comply within thirty (30) days.
You may request deletion of your Typecast Me data at any time prior to its automatic deletion at ninety (90) days.
You may choose not to use AI Features without any impact on your access to other parts of the Service.
13.08Changes to AI Provider: We reserve the right to change our AI provider at any time. If we do so, the replacement provider will be subject to equivalent or stronger data protection commitments. We will update this Privacy Policy to reflect any such change.
14. Analytics
14.01Google Tag Manager: We use Google Tag Manager to manage and deploy analytics and marketing tags on our website. Through Google Tag Manager, we implement Google Analytics to monitor and analyse Service usage patterns.
14.02Google Analytics: Google Analytics collects information about your use of the Service including pages visited, time spent, and actions taken. This helps us understand how users interact with our Service and improve user experience.
14.03Opt-Out: You can opt-out of Google Analytics tracking by installing the Google Analytics opt-out browser add-on or by adjusting your cookie preferences.
14.04 For more information on Google's privacy practices, visit Google Privacy Policy.
15. CI/CD Tools
15.01 We use third-party Continuous Integration / Continuous Deployment platforms to automate development; these process code and infrastructure, not Personal Data.
16. Behavioural Remarketing
16.01Meta Pixel (Facebook Pixel): We use Meta Pixel to deliver targeted advertising and measure advertising effectiveness on Facebook, Instagram, and other Meta platforms. The Meta Pixel tracks your interactions with our Service to help us understand which marketing campaigns are most effective.
16.02How It Works: When you visit our Service, the Meta Pixel may place cookies on your device and collect information about your browsing activity. This information is used to:
Show you relevant advertisements on Meta platforms
Measure the effectiveness of our advertising campaigns
Build audiences for advertising based on your website activity
Track conversions and optimize ad delivery
16.03Opt-Out: You can control ad preferences and opt-out of personalized advertising through:
16.04Google Ads Remarketing: We may also use Google Ads remarketing services to advertise on third-party websites after you visit our Service. We and our vendors use cookies to inform, optimize and serve ads based on your past visits to our Service.
16.05 For more information on Meta's data practices, visit Meta Privacy Policy.
17. Payments
17.01 If we provide paid products or services, payments are processed by PCI-DSS-compliant third-party processors. We do not store card details.
18. Links to Other Sites
18.01 Our Service may contain links to external sites not operated by us. We are not responsible for their content or privacy practices; please review their policies.
19. Children's Privacy
19.01 The Service is prohibited for children under 13.
19.02 Users aged 13–17 may use the Service only with parental or guardian supervision.
19.03 If you become aware that a child has provided us with Personal Data, contact support@getrepped.co.uk; we will promptly delete such data.
20. Changes to This Privacy Policy
20.01 We may update this policy periodically. We will post the new version and update the "Effective date".
20.02 Where required, material changes will be notified by email or prominent notice.
21.02 Post: Get Repped Ltd, 124 City Road, London, EC1V 2NX, United Kingdom
22. Email Communication and Anti-Spam Policy
22.01 Our platform facilitates email communication between users and talent industry professionals. All email communications sent through our Service must comply with applicable anti-spam laws including CAN-SPAM Act, GDPR, and UK regulations.
22.02User Responsibilities:
You are solely responsible for the content of emails sent through our platform
You must only send emails to recipients who have a legitimate business interest in receiving them
You must include accurate sender identification in all emails
You must honor all unsubscribe requests immediately
22.03Prohibited Email Practices:
Sending unsolicited bulk emails or spam
Using misleading subject lines or sender information
Sending emails to purchased or harvested email lists
Continuing to email recipients who have unsubscribed
22.04Email Monitoring: We reserve the right to monitor email sending patterns to prevent abuse of our platform and maintain good sending reputation with email providers.
22.05Account Suspension: Accounts that violate email best practices or applicable laws may be suspended or terminated immediately.
Our platform uses cookies
Our platform uses cookies to improve user experience and improve the site.
To manage your preferences at any time, please select Cookie Settings.
Our platform uses cookies
Our platform uses cookies to improve user experience and help us make improvements.
To manage your preferences at any time, please select “Cookie Settings” in the footer below.
For more information please read our Privacy Policy.
Strictly necessary cookies allow core website functionality such as user login
and account management. The website cannot be used properly without strictly
necessary cookies.
Performance cookies are used to see how visitors use the website, e.g. analytics cookies.
Those cookies cannot be used to directly identify a certain visitor.
Cookies are small text files that are placed on your computer by websites that you visit.
Websites use cookies to help users navigate efficiently and perform certain functions.
Cookies that are required for the website to operate properly are allowed to be set
without your permission. All other cookies need to be approved before they can be set
in the browser.
You can change your consent to cookie usage at any time.