The controller is Amin Pira, c/o IP-Management #9232, Ludwig-Erhard-Straße 18, 20459 Hamburg, Germany. Privacy email: support@fanxplode.com. No data protection officer has been appointed.
This Policy covers fanxplode.com, contact, applications, contracting, campaign delivery, payment and reporting. Depending on the purpose, we rely on Article 6(1)(b) GDPR for pre-contractual and contractual processing, Article 6(1)(c) for legal obligations, Article 6(1)(f) for legitimate interests such as security, abuse prevention, business communication and legal claims, and Article 6(1)(a) where consent is requested. Consent may be withdrawn for the future at any time.
The website is delivered through Vercel Inc., 440 N Barranca Avenue #4133, Covina, CA 91723, USA. Vercel may process IP address, date and time, requested URL, referrer, browser, device, status and log data for secure and reliable website delivery. The basis is Article 6(1)(f) GDPR. Vercel states that US transfers rely on the EU-US Data Privacy Framework and supplementary safeguards. Details: https://vercel.com/legal/privacy-notice
Logs are retained only as needed for operations, security, troubleshooting or legal claims, unless a legal obligation or incident requires longer storage.
We use Cloudflare, Inc., 101 Townsend St, San Francisco, CA 94107, USA for domain and DNS management. The main domain is currently delivered directly by Vercel; Cloudflare is additionally enabled as a proxy, security and delivery service for selected subdomains and technical records. Cloudflare may process IP address, requested domain or URL, time, browser and device information, routing, security and log data. The basis is Article 6(1)(f) GDPR. Our legitimate interest is reliable domain management and secure, uninterrupted delivery of the relevant domains and subdomains. Cloudflare states that EEA-US transfers rely on the EU-US Data Privacy Framework or Standard Contractual Clauses and supplementary measures. Details: https://www.cloudflare.com/privacypolicy/
We use Usercentrics GmbH, Sendlinger Straße 7, 80331 Munich, Germany to store and respect consent choices. It may process consent status, timestamps, a random identifier, language, device and browser details and technical connection data and place a necessary device storage item. Bases are Article 6(1)(c) and (f) GDPR; necessary device access is based on section 25(2) TDDDG. Choices can be changed in the website’s privacy settings. Details: https://usercentrics.com/privacy-policy/
Necessary cookies or similar storage are used only for security, consent, navigation or requested functions under section 25(2) TDDDG and Article 6(1)(b) or (f) GDPR. We currently do not use optional analytics, marketing or retargeting tools. Any such service will be activated only after any required consent has been obtained, and this Policy and the consent banner will be updated before activation. Images and videos are currently delivered through our own hosting infrastructure without connecting to YouTube or Vimeo.
The contact form may collect name or creator name, email, optional telephone, optional profile URL, message and technical transmission data. We use EmailJS, a service of EmailJS Pte. Ltd., Singapore, to transmit submissions to our Google Workspace inbox. EmailJS processes the form content and request metadata required for transmission and may temporarily process IP and security data. EmailJS states that its service infrastructure is located in the United States and that transfers rely in particular on Standard Contractual Clauses under Article 46(2)(c) GDPR. Details: https://www.emailjs.com/legal/privacy-policy/ and https://www.emailjs.com/legal/data-protection-agreement/
Email is provided through Google Workspace by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, potentially involving Google LLC in the US. Details: https://policies.google.com/privacy
Article 6(1)(b) GDPR applies to contract-related requests and Article 6(1)(f) to other business communication. Our legitimate interest is efficient communication and business development.
We use Tally BV, August Van Lokerenstraat 71, 9050 Ghent, Belgium for campaign applications. Tally processes the requested contact, profile, business, campaign and potentially VAT information and technical usage data. The basis is Article 6(1)(b) GDPR and, for security and abuse checks, Article 6(1)(f). Tally states that form data is encrypted and stored in Europe. Details: https://tally.so/help/privacy-policy
Incomplete or rejected applications are generally deleted six months after assessment unless legal defence, abuse prevention or law requires longer retention.
Where we receive a creator’s personal data from an agency, manager or other customer, the data originate from that source or from the publicly accessible creator profile. The submitting customer must make this Privacy Policy available to the creator before submission. Where Article 14 GDPR requires additional direct information, we provide it within the statutory period, generally no later than one month.
We do not request health, religious or political beliefs, biometric data, sexual orientation or other special-category data under Article 9 GDPR, and do not request nude or sexually explicit images or videos. Please do not submit such data. If a public professional creator profile incidentally reveals sensitive information, we process only public profile information necessary for the requested business assessment or campaign and do not intentionally analyse irrelevant sensitive details.
We process names, business contacts, address, company and representative details, billing data, VAT ID, target markets, communications, payment status and bank-reference data for application, agreement and billing under Article 6(1)(b) and (c) GDPR. We do not receive card or wallet data because payment is currently by bank transfer only. Data may go to banks, accountants, tax advisers, tax authorities, legal or collection providers where required.
Contract and accounting records are held for statutory commercial and tax periods. Other contract data is deleted after applicable limitation periods unless a dispute justifies longer storage.
We process creator or brand name, public profile URL, niche, keywords, target territories, social and tracking links, approved non-explicit material and campaign status. Necessary data may be disclosed to selected publishers, advertising networks, distribution and traffic partners. They generally receive only campaign data needed for the placement, not billing, bank or VAT data. Depending on their role, partners act as processors or independent controllers.
From the advertising networks used, we generally receive only campaign-related aggregate metrics such as impressions, clicks, click-through rate, cost and geographic distribution. We do not request the names or direct contact details of individual advertising viewers.
The basis is Article 6(1)(b) GDPR and Article 6(1)(f) for security, quality and fraud checks. Transfers outside the EEA comply with Articles 44 et seq. GDPR, such as through adequacy decisions or Standard Contractual Clauses.
If you voluntarily contact us through WhatsApp or Telegram, or choose them for campaign communication, we process your identifier, phone number or username, profile details, messages, attachments and metadata. WhatsApp is provided in the EEA by WhatsApp Ireland Limited. Telegram is a cloud service of Telegram Messenger Inc. Both process data under their own policies and may process data outside the EEA:
Our basis is Article 6(1)(b) GDPR for contract-related communication, otherwise Article 6(1)(f). Use is voluntary and email remains available.
Reports may include campaign period, status, placements, impressions, reach, click-through rate, cost per click, keywords and geographic distribution. They may be sent as PDF or image by email, agreed messenger, protected link or, in the future, a customer portal. The basis is Article 6(1)(b) GDPR. Protected links may process IP, time and access data for security. A live portal will be added to this Policy before real customer data is processed there.
We may contact prospective business customers through lawfully usable published business contact details by email, phone or messenger, subject to applicable privacy and marketing law. We process business contact details, source, industry, profile relevance, communication and objection status. Article 6(1)(f) GDPR may apply; our interest is relevant B2B direct marketing. Channel-specific marketing laws remain applicable.
You may object to direct marketing at any time via support@fanxplode.com. Marketing leads without a contract are generally deleted six months after the last substantive contact unless consent, an ongoing relationship, legal defence or a minimal suppression record justifies longer storage.
Recipients may include hosting, security, form, communication, IT, accounting, tax, bank, legal, reporting, publisher, advertising-network and traffic providers and authorities where legally required. Processor agreements are concluded where Article 28 GDPR applies.
Outside-EEA transfers occur only under Articles 44 et seq. GDPR, particularly an adequacy decision, valid EU-US Data Privacy Framework certification or Standard Contractual Clauses with supplementary measures.
We retain data only for the relevant purpose. Rejected or incomplete applications and general enquiries without an agreement are generally deleted six months after review or the last substantive communication. Campaign data and reports are generally deleted three years after the agreement ends. Contract, invoice and tax records remain for the applicable statutory periods. Marketing objections are kept in a minimal suppression list for as long as needed to prevent further outreach. Longer retention applies only where required by law, legal defence or documented abuse prevention. Optional fields are voluntary; information needed for assessment, contracting, compliant billing and performance must be supplied or we may be unable to proceed.
We do not make solely automated decisions producing legal or similarly significant effects. Applications are currently reviewed by people.
Subject to legal conditions, individuals have rights of access, rectification, erasure, restriction, portability and objection. Consent can be withdrawn for the future. Where Article 6(1)(f) applies, you may object based on your particular situation; direct marketing can be opposed at any time without reasons.
Requests: support@fanxplode.com. We may request identity verification.
You may lodge a complaint with a competent supervisory authority. For the controller’s actual establishment, you may in particular contact the State Commissioner for Data Protection and Freedom of Information of North Rhine-Westphalia, P.O. Box 20 04 44, 40102 Düsseldorf, Germany, telephone +49 211 38424-0, https://www.ldi.nrw.de/.
We use appropriate technical and organisational safeguards, including encrypted transmission, access restrictions and provider review. No system is completely risk-free. We update this Policy when services, data flows or law change; the current website version applies.
