1. Commitment to European Data Protection Standards
OffClicks Network Inc. is fully committed to upholding the rigorous privacy, transparency, and personal data protection standards mandated by the General Data Protection Regulation (GDPR). This Compliance Statement sets forth our operational safeguards, legal processing grounds, and user rights governing individuals residing within the European Economic Area (EEA) and the United Kingdom.
2. Lawful Bases for Processing (Article 6 GDPR)
We collect and process personal data strictly in accordance with defined legal bases established under Article 6 of the GDPR:
- Contractual Performance (Art. 6(1)(b)): Processing necessary to execute our publisher agreements, calculate earned commissions, and disburse weekly funds to your designated payout method.
- Legitimate Interests (Art. 6(1)(f)): Processing telemetry data to protect the network from click-fraud, bot attacks, and trademark bidding, while ensuring attribution accuracy.
- Legal Obligations (Art. 6(1)(c)): Retaining financial transaction ledgers, invoicing details, and tax documentation in compliance with statutory corporate and accounting requirements.
- Consent (Art. 6(1)(a)): Where applicable, processing voluntary communications such as daily trending deal newsletters, where consent can be withdrawn at any time.
3. Fundamental Data Subject Rights (Chapter III GDPR)
EEA and UK creators, merchants, and visitors are entitled to exercise the full suite of rights granted under European data privacy legislation:
- Right of Access (Art. 15): You have the right to request confirmation of whether your personal data is being processed and obtain a free copy of the stored data.
- Right to Rectification (Art. 16): You may correct inaccurate or incomplete profile or financial information directly inside your dashboard.
- Right to Erasure / 'Right to be Forgotten' (Art. 17): You may request the permanent deletion of your account and personal records, subject to mandatory statutory tax retention periods.
- Right to Restriction of Processing (Art. 18): You may request that we temporarily suspend the processing of your data while an audit or dispute is pending.
- Right to Data Portability (Art. 20): You may request an export of your personal information and commission transaction records in a structured, commonly used, machine-readable format (e.g., JSON or CSV).
- Right to Object (Art. 21): You may object at any time to data processing carried out under our legitimate interests.
4. International Data Transfers & Safeguards (Chapter V GDPR)
Because OffClicks operates globally, personal data collected within the EEA may be transferred to, and processed on, secure servers located in the United States or other jurisdictions outside the European Economic Area. To ensure adequate protection:
- We implement standard Standard Contractual Clauses (SCCs) adopted by the European Commission for cross-border data transfers.
- All data transfers are encrypted in transit using 256-bit Transport Layer Security (TLS 1.3).
- Our hosting infrastructure maintains SOC-2 Type II and ISO 27001 certifications to prevent unauthorized third-party access.
5. ePrivacy Directive & Affiliate Attribution Cookies
In accordance with the ePrivacy Directive (Directive 2002/58/EC), our tracking mechanisms are engineered to minimize privacy intrusion:
- Pseudonymous Tracking IDs: Attribution cookies contain only anonymous alphanumeric identifiers mapped to creator referral accounts. They do not store personal consumer names, payment credentials, or home addresses.
- Server-to-Server (S2S) Architecture: Where integrated, direct server postbacks transmit verified order numbers and basket values directly between merchant and OffClicks servers without relying on third-party cross-site trackers.
6. Data Breach Protocol & Supervisory Authority Rights
In the unlikely event of a personal data breach posing a risk to user rights and freedoms, OffClicks maintains an incident response protocol designed to notify the relevant European Supervisory Authority within 72 hours of becoming aware of the breach, in accordance with Article 33 of the GDPR.
If you believe our processing of your personal data infringes GDPR provisions, you have the right to lodge a formal complaint with an official Data Protection Authority (DPA) in your EU member state of residence.
7. Exercising Your GDPR Rights
To submit a formal Data Subject Access Request (DSAR), request data deletion, or contact our designated Data Protection Officer (DPO), please email our compliance department directly:
Email: support@offclicks.com
Subject Line: GDPR Data Subject Request - [Your Account Name]
Attention: Data Protection Officer (DPO)
We respond to all verified GDPR requests within thirty (30) calendar days without charge.