Privacy notice
Three groups of people are affected, and they are affected differently.
Account users, journalists and newsroom staff held in the corpus, and recipients of campaign mail. Lumping them into one notice would hide the fact that only the first group ever agreed to anything.
Updated 31 August 2026
Draft status. A review draft: not indexed, and not final until checked by qualified counsel.
01
Who is responsible for the data?
The controller is Entro314 Labs SINGLE MEMBER P.C. (Entro314 Labs), a single-member private company (Ι.Κ.Ε.) registered in Greece, seat Cheimarras 3, 13561 Agioi Anargyroi, Attica, Greece, Γ.Ε.ΜΗ. 193782603000. Full registration details are in the legal notice.
Because the controller is established in Greece, the lead supervisory authority is the Hellenic Data Protection Authority, and a complaint may also be made to the authority where you live. No data protection officer is appointed; the Article 37 appointment criteria are among the assessments still outstanding.
Privacy requests go to hello@pressdb.co or, for a record in the corpus, the take-down form.
02
What is collected from account users?
- Account identifier, email address, name and profile image supplied through Clerk.
- Workspace membership, saved lists, pipeline notes and campaign records you create.
- Sender identities you configure, and the domain-verification state that goes with them.
- Prompts and documents you submit to the planning and drafting features. See AI transparency for where they go.
03
What is held about journalists and newsroom staff?
Professional contact data: name, outlet, role or beat, a work address where one was published or derived from an outlet pattern, and public profile links used as corroboration. It is obtained from public directories, Wikidata, mastheads, impressum pages, bylines and crawls of outlets’ own editorial pages — not from the people concerned, which is why Article 14 applies and why this notice exists at that URL rather than behind a login.
The basis relied on is legitimate interests in maintaining a professional media-contact directory, balanced against the interests of people whose job is to be contactable by people with news. The balancing test is not yet written down, which is one reason this document is a draft. The page for journalists states the same facts from the other side.
04
What happens when a campaign mail is sent to me?
- One append-only recipient record per campaign and address, holding the send state and the token behind your one-click unsubscribe.
- Open tracking — a message can contain an image that records that it was opened.
- Click tracking — links can be rewritten through a redirect that records the click before forwarding you.
- Bounces, complaints and unsubscribes reported by the mail provider, which are written to a global do-not-send list.
- Whether those two tracking mechanisms are lawful without prior consent varies by member state under the ePrivacy rules. That analysis is open, and until it is settled this notice does not assert that they are.
06
What can I ask for?
Access, correction, erasure, restriction, portability, and objection to processing based on legitimate interests — which, for a media-contact record, is an objection that will simply be honoured. You may withdraw consent where consent is the basis, and complain to a supervisory authority.
For a record in the corpus, the take-down form is the fastest route. Everything else goes to hello@pressdb.co. The written identity-verification procedure — how a requester is confirmed to be who they say they are before data is disclosed or erased — is still to be produced, and is one of the records this notice remains a draft for.
07
Can I export or delete my data?
Register views and saved lists export as CSV, as does a campaign’s recipient log with its per-address outcomes; release copy is already a document you hold. No switching, egress or exit charge is made or contemplated. Authentication records — account identity, sessions — are held by Clerk and may have to be requested there.
To delete rather than export, delete the authentication account through the account controls and write to hello@pressdb.co for workspace data. One exception survives deletion: suppression entries. The record that somebody asked not to be contacted is the only thing that stops them being contacted again, so it is retained rather than erased.
Whether Press Hub is a data processing service covered by the EU Data Act’s switching regime has not been established, so no claim is made that the full set of switching obligations is complete.
08
Is personal information sold or shared?
There is no advertising network, no cross-context behavioural tracking and no Global Privacy Control handler anywhere in the code. Whether signed-in access to a professional contact corpus falls within a US state-law definition of sale or sharing depends on facts and thresholds that have not been established; neither an exemption nor a completed opt-out process is claimed here.
09
How long is it kept?
There is no published retention schedule yet, and inventing periods here would be worse than admitting that. Two things are already true and permanent: a take-down honoured against a publication sets a flag that keeps it unpublished for good, and a suppression entry is deliberately retained rather than deleted — the record that somebody asked not to be contacted is the only thing that stops them being contacted again.