AFFLU WEBAPP PRIVACY POLICY


Last updated: 29.06.2026


1. DATA CONTROLLER


AFFLU S.r.l., with registered office at Piazza Santiago del Cile No. 8, 00197 Rome (RM), Italy, VAT No. 18294811007 (“Afflu”, “we”, “us”, or “our”).


Contact: privacy@afflu.eu


2. SCOPE OF APPLICATION


This privacy policy explains how Afflu processes personal data through the web application available at app.afflu.eu, including the Afflu dashboard, restricted area, onboarding flows, account forms, platform functionalities and related services.


This notice applies to users who:


(a) create an account;

(b) request access to the Dashboard;

(c) access the restricted area;

(d) complete onboarding, business, tax, audience, performance or promotional information forms;

(e) interact with WebApp functionalities;

(f) use the Platform or Services;

(g) where applicable, enter into Commercial Terms, a Legacy Agreement or any other agreement with Afflu.


The WebApp is intended exclusively for persons and entities acting for professional, commercial, entrepreneurial or business purposes and may only be used by users who have reached the age of majority.


Account creation does not automatically entail the conclusion of a contract or the activation of all Platform functionalities or Services.


Afflu generally acts as data controller for personal data processed for account registration, onboarding, verification, user management, platform administration, billing, security, pre-contractual and contractual management, legal compliance and related business operations.


Where Afflu processes personal data on behalf of a user or organization in connection with specific Services, Afflu may also act as data processor pursuant to Article 28 GDPR, in accordance with the applicable Data Processing Agreement.


3. CATEGORIES OF PERSONAL DATA PROCESSED


3.1 Data provided during registration


Afflu may process first name, last name, email address, password, organization indication and any other information provided during account registration.


Passwords are stored in protected form using hashing mechanisms and are not accessible in plain text.


3.2 Data processed during WebApp use


Afflu may process authentication logs, successful and failed login attempts, account status, operation timestamps, internal technical identifiers, user actions, access history, acceptance logs relating to Terms and Privacy Policy, and information necessary to manage account access and use of the Platform.


3.3 Technical data


Afflu may process IP address, device information, browser information, operating system information, session metadata, security logs, infrastructure logs and other technical metadata necessary for system security, fraud prevention, access control, troubleshooting, service stability and platform maintenance.


3.4 Onboarding, business and tax data


Where required for onboarding, verification, account activation, Network and Merchant applications, payment administration, invoicing, tax checks, compliance and provision of the Services, Afflu may process business, tax and onboarding data, including:


(a) company name;

(b) VAT number;

(c) tax code or equivalent identifier;

(d) tax residence;

(e) fiscal address;

(f) city, ZIP or postal code, country and state;

(g) legal representative details;

(h) date and place of birth;

(i) residence;

(j) professional or business contact details;

(k) information relating to authority to act on behalf of an organization.


3.5 Promotional, channel, audience and performance data


Afflu may process information relating to promotional activities and channels, including:


(a) promotional activity description;

(b) main promotional website, blog, magazine, social account or other channel URL;

(c) frequency of sponsored content publication;

(d) traffic sources and visitor acquisition methods;

(e) use of SEO, advertising or promotion on other websites;

(f) unique monthly visitors;

(g) monthly page views;

(h) audience gender distribution;

(i) main age range;

(j) main country or audience geography;

(k) Instagram, YouTube, TikTok, Substack or similar account information;

(l) monthly views, monthly reach, subscribers, average open rate and other social, audience or performance metrics.


3.6 Payment and bank details


Bank details are not collected through the WebApp registration form. Where required for payment administration, invoicing, reconciliation or commercial relationship management, bank details may be collected separately through Commercial Terms, bank-details forms or other secure onboarding or administrative channels.


3.7 Information collected or processed through third-party Networks, Merchants and platforms


In connection with the Services, Afflu may process data made available through affiliate networks, merchant dashboards, APIs, reports, exports, tracking systems, payout statements, performance reports and other third-party systems, including affiliate account identifiers, tracking data, payout information, commission status, performance data, transaction data and settlement or adjustment information.


3.8 Data submitted on behalf of the user


Where Afflu completes, transmits, confirms, signs, submits or updates onboarding forms, Network forms, Merchant forms, platform forms, payment forms, tax-status declarations or equivalent documentation on behalf of the user, Afflu processes the personal data and information provided or approved by the user for such purposes.


4. PURPOSES AND LEGAL BASES


4.1 Account creation and management


Purpose: creating, managing and maintaining the user account and enabling access to the Platform.


Legal basis: Article 6(1)(b) GDPR, performance of a contract or pre-contractual measures.


4.2 Pre-contractual management and user contact


Purpose: reviewing applications, contacting users, managing onboarding requests, requesting additional information and assessing eligibility for the Platform or Services.


Legal basis: Article 6(1)(b) GDPR.


These communications are service or pre-contractual communications and do not constitute marketing.


4.3 Onboarding, verification and activation


Purpose: verifying user identity, professional status, organization details, authority to act, promotional channels, tax information, business information and eligibility for Networks, Merchants, platforms or Services.


Legal basis: Article 6(1)(b) GDPR, and where applicable Article 6(1)(c) GDPR for legal obligations or Article 6(1)(f) GDPR for Afflu’s legitimate interest in preventing fraud, protecting the Platform and verifying commercial reliability.


4.4 Contract performance and service provision


Purpose: providing the Platform and Services, managing Affiliate Accounts, preparing Network or Merchant applications, configuring tracking systems, generating links, providing reporting, managing operational support, verifying commissions and administering the commercial relationship.


Legal basis: Article 6(1)(b) GDPR.


4.5 Reporting, invoicing, payment administration and accounting


Purpose: preparing reports, calculating fees, issuing invoices, reconciling payments, managing bank details where collected separately, maintaining accounting records and complying with tax, bookkeeping and legal obligations.


Legal basis: Article 6(1)(b) GDPR and Article 6(1)(c) GDPR.


4.6 Compliance with legal obligations


Purpose: complying with tax, accounting, corporate, regulatory, data protection, legal retention and authority-request obligations.


Legal basis: Article 6(1)(c) GDPR.


4.7 Security, system protection and fraud prevention


Purpose: protecting the Platform, infrastructure, users, Afflu, Networks, Merchants and third parties from unauthorized access, abuse, fraud, invalid traffic, security incidents, technical issues or unlawful conduct.


Legal basis: Article 6(1)(f) GDPR, legitimate interest.


4.8 Establishment, exercise or defense of legal claims


Purpose: managing disputes, enforcing Terms, Commercial Terms or Legacy Agreements, recovering unpaid amounts, preserving evidence and defending Afflu’s rights.


Legal basis: Article 6(1)(f) GDPR, legitimate interest.


4.9 Promotional communications


Purpose: sending newsletters, marketing or promotional communications, where applicable.


Legal basis: Article 6(1)(a) GDPR, consent.


The WebApp does not provide for automatic subscription to newsletters or promotional communications.


5. METHODS OF PROCESSING AND SECURITY MEASURES


Personal data are processed by electronic and telematic tools in compliance with the principles of lawfulness, fairness, transparency, purpose limitation, data minimization, accuracy, storage limitation, integrity and confidentiality.


Afflu adopts appropriate technical and organizational measures pursuant to Article 32 GDPR, including, where applicable:


(a) encryption in transit;

(b) encryption at rest;

(c) credential protection through hashing;

(d) access controls;

(e) role-based permissions;

(f) backup systems;

(g) logging and monitoring;

(h) infrastructure security measures;

(i) secure management of API tokens and access keys.


Technical credentials, including API tokens and access keys, are processed through security measures designed to prevent plain-text access where technically feasible.


6. DATA RETENTION


Without an activated contractual relationship, account and registration data are retained for a maximum period of 24 months from registration, unless earlier deletion is requested or longer retention is required to protect Afflu’s rights or comply with legal obligations.


With a contractual relationship, personal data are retained for the duration of the relationship and thereafter for the period necessary to comply with legal, tax, accounting and contractual obligations and for the establishment, exercise or defense of legal claims.


Accounting, invoicing, tax and payment-related records may be retained for the period required by applicable law.


Operational logs and security logs are retained for the period reasonably necessary for security, troubleshooting, fraud prevention, legal compliance and platform protection.


Deleted data may remain in backup systems for a limited period, generally no longer than 30 days, unless a longer period is technically necessary or legally required.


In the event of account deletion, data may be deleted, anonymized or retained in limited form in accordance with Afflu’s internal technical procedures and applicable law.


7. RECIPIENTS OF PERSONAL DATA


Personal data may be disclosed to or processed by third parties acting on behalf of Afflu, including:


(a) cloud service providers;

(b) hosting providers;

(c) database management providers;

(d) security, CDN and infrastructure protection providers;

(e) transactional email providers;

(f) communication service providers;

(g) software development, repository, deployment and platform maintenance providers;

(h) analytics, logging and technical monitoring providers;

(i) professional advisers, accountants, tax consultants, legal advisers and auditors;

(j) payment, invoicing, accounting and administrative service providers.


Where required, such providers are appointed as data processors pursuant to Article 28 GDPR.


Personal data may also be disclosed to Networks, Merchants, affiliate platforms, agencies, technology providers, payment providers, payers, withholding agents or other third parties where necessary for onboarding, account activation, Network or Merchant applications, tax-status verification, payment administration, reporting, compliance or provision of the Services.


Personal data may be disclosed to public authorities, courts, regulators or other competent bodies where required by law or necessary to protect Afflu’s rights.


8. DATA TRANSFERS OUTSIDE THE EEA


Personal data are processed mainly through providers and infrastructures located in the European Economic Area. However, certain providers used by Afflu, including infrastructure, hosting, database, email, security, development, repository, deployment and technical service providers, may be established outside the EEA or may process data from countries outside the EEA, including the United States.


Where personal data are transferred outside the EEA, Afflu ensures that such transfers take place in compliance with Articles 44 et seq. GDPR, including through adequacy decisions, the EU-U.S. Data Privacy Framework where applicable, Standard Contractual Clauses or other lawful transfer mechanisms.


9. RIGHTS OF DATA SUBJECTS


Data subjects may exercise the rights provided under Articles 15 to 22 GDPR, including:


(a) right of access;

(b) right to rectification;

(c) right to erasure;

(d) right to restriction of processing;

(e) right to data portability;

(f) right to object;

(g) right to withdraw consent, where processing is based on consent.


Requests may be sent to: privacy@afflu.eu.


Data subjects also have the right to lodge a complaint with the Italian Data Protection Authority, Garante per la Protezione dei Dati Personali, or with any other competent supervisory authority.


10. AUTOMATED DECISION-MAKING


The WebApp does not use automated decision-making processes producing legal effects or similarly significant effects on users pursuant to Article 22 GDPR.


11. AMENDMENTS TO THIS PRIVACY POLICY


Afflu reserves the right to update this privacy policy for legal, technical, operational or organizational reasons.


Amendments will be published on the WebApp with the relevant update date. Where required by applicable law, Afflu may also provide additional notice or request renewed acknowledgment.