EU Regulation 2016/679

GDPR Compliance

Effective date: 1 July 2026  ·  Last updated: 1 July 2026

Our Commitment

Proflynk is committed to full compliance with the General Data Protection Regulation (GDPR) for users in the European Union and European Economic Area. We take your data rights seriously and have implemented technical and organisational measures to protect your personal data.

Data Controller

Proflynk acts as the data controller for personal data collected through the platform. Our Data Protection Officer (DPO) can be reached at [email protected].

Lawful Basis for Processing

We process personal data under the following lawful bases:

  • Contract: Processing necessary to provide the services you signed up for
  • Legitimate interests: Improving the platform, preventing fraud, security monitoring
  • Consent: Marketing communications and optional features (you can withdraw at any time)
  • Legal obligation: Complying with applicable laws and regulations

Your Rights Under GDPR

Right of Access

Request a copy of all personal data we hold about you

Right to Rectification

Correct inaccurate or incomplete personal data

Right to Erasure

Request deletion of your personal data ('right to be forgotten')

Right to Restriction

Limit how we process your data in certain circumstances

Right to Portability

Receive your data in a machine-readable format

Right to Object

Object to processing based on legitimate interests or for direct marketing

Right to Withdraw Consent

Withdraw consent at any time without affecting past processing

Right to Complain

Lodge a complaint with your local Data Protection Authority

How to Exercise Your Rights

To exercise any of the above rights, you can:

  • Use the self-service tools in Settings → Data & Privacy
  • Contact our DPO at [email protected]

We will respond to all requests within 30 days. Complex requests may take up to 90 days; we will notify you if additional time is needed.

International Data Transfers

If we transfer personal data outside the EEA, we ensure adequate protection through:

  • EU Standard Contractual Clauses (SCCs)
  • Adequacy decisions by the European Commission
  • Other approved transfer mechanisms

Data Retention

We retain personal data only for as long as necessary. Once your account is deleted, personal data is removed within 30 days from our production systems and within 90 days from backups.

Data Breach Notification

In the event of a data breach that poses a risk to your rights and freedoms, we will notify the relevant supervisory authority within 72 hours and affected users without undue delay.

Contact Our DPO

Data Protection Officer, Proflynk
Email: [email protected]

You also have the right to contact your local Data Protection Authority if you believe your rights have been violated.