1) Overview & Data Protection Philosophy
Ad2Click (“we”, “us”, “our”) operating at ad2click.co is strictly committed to protecting the privacy, confidentiality, and data sovereignty of all individuals who use our rewards and advertising services, in full accordance with the European Union General Data Protection Regulation (EU) 2016/679 (GDPR) and the UK Data Protection Act 2018 (UK GDPR).
We believe privacy is a fundamental human right. Even if you reside outside the European Economic Area (EEA), Ad2Click provides equivalent high-grade privacy protections, data transparency, and control across all account operations.
2) Core Principles of GDPR Processing
In adherence to Article 5 of the GDPR, all personal data is collected and processed according to the following foundational principles:
- Lawfulness, Fairness, and Transparency: Data is collected lawfully, transparently, and fairly with clear explanations of why it is needed.
- Purpose Limitation: Personal data is collected strictly for specified, explicit, and legitimate reward fulfillment and account management purposes.
- Data Minimisation: We collect only the minimum information necessary to maintain your account, process payouts, and prevent malicious fraud.
- Accuracy: We ensure data is kept accurate and up to date. Users can review and edit their account profile settings at any time.
- Storage Limitation: Data is retained only for as long as necessary for the purposes for which it was gathered, after which it is deleted or anonymized.
- Integrity and Confidentiality: Data is safeguarded with robust security controls, TLS encryption, and secure database safeguards against accidental loss or unauthorized access.
3) Legal Bases for Processing
Under Article 6 of the GDPR, our processing of personal data is grounded in the following lawful bases:
- Contractual Necessity (Art. 6(1)(b)): Necessary to provide our core services, credit balances for completed tasks and video views, and process cashouts.
- Legitimate Interests (Art. 6(1)(f)): Necessary to protect platform security, detect bots and multi-accounting, prevent payment fraud, and improve usability.
- Consent (Art. 6(1)(a)): Where explicitly required, such as for voluntary surveys, optional promotional notices, or non-essential cookies. Consent may be withdrawn at any time.
- Legal Obligation (Art. 6(1)(c)): Retaining transaction and payment accounting records as mandated by financial, taxation, and anti-fraud regulations.
4) Your Statutory Rights Under GDPR
Individuals in the EEA and UK possess enforceable statutory privacy rights under the GDPR:
- Right of Access (Art. 15): You have the right to request confirmation of data processing and obtain a copy of all personal data we hold about you.
- Right to Rectification (Art. 16): You have the right to update or correct inaccurate or incomplete personal data.
- Right to Erasure ("Right to be Forgotten", Art. 17): You may request the permanent deletion of your account and personal information when no longer needed for lawful purposes.
- Right to Restrict Processing (Art. 18): You have the right to request the temporary limitation of processing while an accuracy dispute or objection is investigated.
- Right to Data Portability (Art. 20): You may request an export of your personal information in a structured, commonly used, machine-readable format.
- Right to Object (Art. 21): You may object at any time to the processing of your data based on legitimate interests or direct marketing.
5) Exercising Your Rights (DSAR Workflow)
To submit a Data Subject Access Request (DSAR), request data erasure, or exercise any statutory rights:
- Direct Email Request: Send a request from your registered email address to our Data Protection desk at support@ad2click.co with the subject line "GDPR Data Request".
- Member Help Desk: Authenticated users can open an official support ticket via the Member Help Desk selecting the "Account / Privacy" category.
- Response Timeline: We respond to and fulfill all verified statutory requests within 30 calendar days, completely free of charge.
6) International Data Transfers & Safeguards
Ad2Click uses secure cloud infrastructure distributed globally. When data originating from the EEA or UK is transferred internationally, we implement European Commission-approved Standard Contractual Clauses (SCCs) and strict end-to-end cryptographic encryption standards.
7) Automated Decisions & Human Intervention
Under Article 22 of the GDPR, members have the right not to be subject to decisions based solely on automated processing that significantly affect them. Where automated security telemetry flags an account or withdrawal, users may request human review by contacting our compliance desk.
8) Data Retention Periods
We do not retain personal data longer than necessary for our operational, accounting, and legal requirements:
- Active Accounts: Maintained for the duration of your membership to track balances, task earnings, and referral trees.
- Deleted Accounts: When an account is terminated or an erasure request is executed, personal data is permanently deleted or irreversibly anonymized within 30 days, except where financial transaction records must be archived for tax compliance.
- Security Logs: Server logs and anti-fraud telemetry are rotated and purged automatically every 90 days.
9) Supervisory Authorities & Complaints
If you believe our data processing infringes GDPR provisions, you have the right to lodge a complaint with your local EU Data Protection Authority (DPA) or the UK Information Commissioner's Office (ICO). We encourage you to contact us first so we can resolve any issue promptly.
10) Contact Data Protection Team
Ad2Click Ltd
United States
Privacy Office: support@ad2click.co
Contact: ad2click.co/contact