GDPR Compliance
Effective date: 1 July 2026 · Last updated: 1 July 2026
Our Commitment
Proflynk is committed to full compliance with the General Data Protection Regulation (GDPR) for users in the European Union and European Economic Area. We take your data rights seriously and have implemented technical and organisational measures to protect your personal data.
Data Controller
Proflynk acts as the data controller for personal data collected through the platform. Our Data Protection Officer (DPO) can be reached at [email protected].
Lawful Basis for Processing
We process personal data under the following lawful bases:
- Contract: Processing necessary to provide the services you signed up for
- Legitimate interests: Improving the platform, preventing fraud, security monitoring
- Consent: Marketing communications and optional features (you can withdraw at any time)
- Legal obligation: Complying with applicable laws and regulations
Your Rights Under GDPR
Right of Access
Request a copy of all personal data we hold about you
Right to Rectification
Correct inaccurate or incomplete personal data
Right to Erasure
Request deletion of your personal data ('right to be forgotten')
Right to Restriction
Limit how we process your data in certain circumstances
Right to Portability
Receive your data in a machine-readable format
Right to Object
Object to processing based on legitimate interests or for direct marketing
Right to Withdraw Consent
Withdraw consent at any time without affecting past processing
Right to Complain
Lodge a complaint with your local Data Protection Authority
How to Exercise Your Rights
To exercise any of the above rights, you can:
- Use the self-service tools in Settings → Data & Privacy
- Contact our DPO at [email protected]
We will respond to all requests within 30 days. Complex requests may take up to 90 days; we will notify you if additional time is needed.
International Data Transfers
If we transfer personal data outside the EEA, we ensure adequate protection through:
- EU Standard Contractual Clauses (SCCs)
- Adequacy decisions by the European Commission
- Other approved transfer mechanisms
Data Retention
We retain personal data only for as long as necessary. Once your account is deleted, personal data is removed within 30 days from our production systems and within 90 days from backups.
Data Breach Notification
In the event of a data breach that poses a risk to your rights and freedoms, we will notify the relevant supervisory authority within 72 hours and affected users without undue delay.
Contact Our DPO
Data Protection Officer, Proflynk
Email: [email protected]
You also have the right to contact your local Data Protection Authority if you believe your rights have been violated.