Privacy

How judged.systems handles personal data for an account, and how it handles personal data inside a ticket you submit to be judged.

7 October 2026

Who we are

Oleksandr Halashevskyi (“we”) is the controller for account and website data. We are established in the Netherlands at Nijverheidsweg 28, 7122 AB Aalten, KvK 96439637, VAT NL005211172B92.

Privacy requests go to legal@judged.systems.

Two roles

For your account, we decide why the data is processed. We are the controller.

For personal data inside a ticket, a pack, a label, or a dataset you submit, you decide the purpose. You are the controller and we are the processor. We process that data only on your instructions, which are these terms of processing and the settings of your account. The instructions are in the Terms.

People mentioned in a ticket should contact the customer who sent it. We help that customer answer.

Account data

We process the following as controller:

  • Name, email address, and a password hash, or a GitHub account identifier if you sign in with GitHub.
  • A session cookie, and the IP address and browser string stored with the session.
  • API key hashes, pack configuration, webhook URLs, and the fact that a call was made.
  • Mail we send you about the account, including password reset and the welcome message. We do not send marketing mail.

An email address and either a password or a GitHub sign-in are required to open an account. Without them there is no account. Ticket content is not required to hold an account.

Ticket data

As processor we handle the ticket you submit, the redacted copy of that ticket, the judgment, labels, and datasets you store. Email addresses, phone numbers, and card-like tokens are removed before the ticket is stored and before it is sent to the model. The model receives the redacted ticket, not the original.

Why

We rely on these bases in article 6 of the AVG:

  • Contract, article 6(1)(b): creating the account, keeping you signed in, judging tickets you submit, and sending mail the account needs.
  • Legitimate interest, article 6(1)(f): securing the service, limiting abuse, and keeping a short record that a call failed. The interest is a reliable service. It does not include reading ticket bodies for our own purposes. You can object.
  • Consent, article 6(1)(a), where a cookie or similar storage is not strictly necessary. You can withdraw that consent without losing the account.

Who else receives it

These providers process data only for the job named:

  • Vercel hosts the service and runs the AI Gateway that calls the evaluation model.
  • The model provider behind that gateway receives the redacted ticket.
  • Neon stores the database.
  • Resend delivers account mail.
  • PostHog records product use and errors when analytics is enabled.
  • GitHub, when you choose GitHub to sign in.

We do not sell personal data, and we do not share it for another company’s marketing.

Outside the EEA

Some of those providers process data outside the European Economic Area. Where they do, the transfer uses an adequacy decision or the European Commission’s standard contractual clauses, with further measures where the transfer needs them.

How long

Account data, judgments, and labels stay while the account is open. After you close the account we delete them within 30 days, unless a legal duty requires a record to be kept longer. Session records are deleted when the session expires or you sign out. Password-reset links expire within one hour. Operational logs are kept for up to 30 days.

Cookies

A session cookie keeps you signed in. It is strictly necessary to provide the service you asked for, so the Telecommunicatiewet does not require consent for it.

When analytics is enabled, PostHog may store an identifier in the browser to measure use and to report errors. That storage is not strictly necessary. We place it only with your consent, and ticket text, secrets, and model state are not included. Refusing or withdrawing consent does not close the account.

Security

Passwords and API keys are stored as hashes. Ticket text is redacted before it is stored and before it is sent to the model. Access to an account’s data is limited to that account. No measure is perfect. If we learn of a breach of ticket data, we tell you without undue delay. Where we are the controller and article 33 requires it, we notify the Autoriteit Persoonsgegevens within 72 hours of becoming aware of the breach.

Your rights

You can ask us for access, correction, deletion, restriction, or a portable copy of the personal data we hold as controller. You can object to processing based on legitimate interest, including to analytics. You can withdraw consent. We reply within one month. If a request is complex or numerous, we may extend that by two months and we will tell you why.

You can complain to the Autoriteit Persoonsgegevens, Postbus 93374, 2509 AJ Den Haag, autoriteitpersoonsgegevens.nl. You can also go to a court.

Judgments

The model returns evidence. Your pack’s thresholds turn that into accept, review, or reject. A failed or invalid model call becomes review. We do not ourselves take a step that changes the legal position of the person in the ticket. If you apply an output to someone with no human review, and that has a legal or similarly serious effect, you are the controller of that decision and article 22 of the AVG applies to you.

Children

The service is for businesses. It is not directed at anyone under 16.

Changes

If this notice changes in a way that affects you, the date above changes with it. The text on this page is the current notice.