Part 1 — Privacy Policy (GDPR)
1. Introductory Provisions and Scope
1.1 Controller Identification
BLUE SHIFT TECHNOLOGY LLC (hereinafter "ScamNemesis," "we," "us," "our," or the "Company")
Registered address: 2125 BISCAYNE BLVD, MIAMI, FL 33137, USA
E-mail: info@scamnemesis.com
ScamNemesis operates the web platform scamnemesis.com (the "Platform," the "Service," or the "Website").
1.2 Nature of the Service and Core Principles
ScamNemesis.com is exclusively a community information platform (the "Community Platform") that functions as a:
- Technology intermediary enabling user-to-user communications;
- Hosting provider for user-generated content;
- Passive service without active editorial control over user content; and
- Tool for sharing information created by third parties.
IMPORTANT: ScamNemesis does not act as a publisher, editor, author, or verifier of content. We are solely a technological provider of infrastructure.
1.3 GDPR Applicability
This Policy applies to:
- All users located in the European Union (EU);
- Processing of personal data of EU citizens; and
- Cross-border data processing,
in accordance with Regulation (EU) 2016/679 (GDPR) and related legislation.
1.4 US Law Compliance
As a US-based company, ScamNemesis operates in accordance with:
- Federal laws of the United States;
- Florida state laws;
- Communications Decency Act Section 230;
- Digital Millennium Copyright Act (DMCA); and
- Other applicable US regulations.
2. Scope of Personal Data Collected
2.1 Data Provided Directly by Users
During MANDATORY REGISTRATION we collect:
| Data Category | Purpose of Processing | Legal Basis |
|---|---|---|
| First and last name | User identification | Consent + Contract performance |
| E-mail address | Communication, account verification | Consent + Contract performance |
| Username | System identification | Consent + Contract performance |
| Password (hashed) | Account security | Consent + Contract performance |
| Country | Service localization | Legitimate interest |
| Preferred language | Interface customization | Legitimate interest |
| Profile picture (optional) | Profile personalization | Consent |
| Registration date | Administrative purposes | Legitimate interest |
2.2 Optional Data Provided During Use
- Posts, comments, reports on the Platform ("User Content");
- Additional optional profile information; and
- Attachments, links, and files uploaded by the user.
2.3 Automatically Collected Technical Data
| Data Type | Purpose | Legal Basis |
|---|---|---|
| IP address | Security, fraud prevention, analytics | Legitimate interest |
| Browser type and version | Service optimization | Legitimate interest |
| Operating system | Technical support, compatibility | Legitimate interest |
| Device information | Display optimization | Legitimate interest |
| Timestamp of visit | Activity monitoring, security | Legitimate interest |
| Referral source (referrer URL) | Marketing analysis | Legitimate interest |
| Pages visited | Traffic analysis | Legitimate interest |
| Language preferences | Localization | Legitimate interest |
| Session ID | Session maintenance | Legitimate interest |
3. Purposes and Legal Bases for Processing
3.1 Primary Processing Purposes
| Processing Purpose | Legal Basis (GDPR) | Description |
|---|---|---|
| Account creation and management | Article 6(1)(b) — Contract performance | Enabling basic service functionality |
| Communication with users | Article 6(1)(b) + (f) — Contract + Legitimate interest | Notifications, support, updates |
| Security and fraud prevention | Article 6(1)(f) — Legitimate interest | Protection of platform integrity |
| Service improvement | Article 6(1)(f) — Legitimate interest | Analytics, optimization |
| Legal compliance | Article 6(1)(c) — Legal obligation | Response to legal requests, compliance with US and EU laws |
| Marketing (optional) | Article 6(1)(a) — Consent | Newsletter, promotional communications (opt-in) |
3.2 Legitimate Interest Assessment
When we process data based on legitimate interest (Article 6(1)(f) GDPR), we balance our interests against your rights:
- Security: Protecting users and platform from fraud, abuse, spam;
- Analytics: Understanding usage patterns to improve service quality;
- Technical optimization: Ensuring platform stability and performance; and
- Business operations: Maintaining sustainable operations under US business law.
You may object to processing based on legitimate interest at any time by contacting info@scamnemesis.com.
4. Data Retention Periods
| Data Category | Retention Period | Reason |
|---|---|---|
| Active account data | Duration of account existence | Service provision |
| Deleted account data | 30 days (backups: up to 90 days) | Technical necessity, recovery option |
| User content (posts, comments) | Until user deletion or account closure | Platform functionality |
| Server logs | 90 days | Security, technical troubleshooting |
| IP addresses | 90 days (longer if legal dispute) | Fraud prevention, security |
| Communication history (support) | 3 years from last contact | Support continuity, legal protection |
| Anonymized analytics data | Indefinitely | No personal data remains |
| Legal/compliance data | As required by US law (typically 3-7 years) | Legal obligation compliance |