Legal

Privacy Policy

Version 1.0 — effective 10 September 2026. This policy describes how personal data is processed on the cyteclick website and platform.

1. Controller

Digital Media Group OÜ

Sepapaja 6, Tallinn 15551, Estonia

Registry No.: 16363874 — VAT ID: EE102435340

Email: support@cyteclick.com

cyteclick is operated by Digital Media Group OÜ. Any reference to “cyteclick”, “we” or “us” in this policy refers to Digital Media Group OÜ as controller.

2. Scope

This policy covers the public cyteclick website, the publisher registration and publisher dashboard, the internal administration interface, the affiliate click redirect service used for cyteclick tracking links, and the conversion and commission processing that supports the affiliate platform.

It does not describe the independent data processing of advertisers or upstream affiliate networks, which act as separate controllers for their own purposes.

3. Data processed when visiting the website

The public marketing pages contain no analytics, advertising, remarketing or social-media tracking technologies, and set no non-essential cookies.

As with any website, technical connection data (such as IP address, requested resource, timestamp and browser identification) is processed transiently by our hosting and content-delivery infrastructure to deliver the pages and protect the service against abuse. cyteclick does not build visitor profiles from this data.

4. Publisher registration and account data

When you register as a publisher, we process the information you submit: first and last name, email address, password (see section 5), company or account name, country, phone number, website, publisher type, traffic sources and indicative monthly visitor volume.

We create a publisher record with an internal publisher code and an account status (pending, active, suspended or rejected). Internal review notes and review metadata are used only by cyteclick staff and are never disclosed to other publishers.

Legal basis: Art. 6(1)(b) GDPR (pre-contractual steps and performance of the publisher agreement) and Art. 6(1)(f) GDPR (assessing applications, preventing fraud and abuse).

5. Authentication and account security

Authentication runs on Lovable Cloud infrastructure (built on Supabase). Processed data includes your email address, account identifiers, authentication session data, and email confirmation, password-recovery, email-change and re-authentication events.

Passwords are never stored in plain text. They are handled by the authentication provider and stored only as cryptographic hashes; cyteclick staff cannot read your password.

Legal basis: Art. 6(1)(b) GDPR (providing access to your account) and Art. 6(1)(f) GDPR (account and platform security).

6. Publisher websites and program applications

Publishers may register websites (name, URL, traffic type, country, indicative monthly visitors) and apply to advertiser programs. We process the application, an optional application message, the associated website, the application status and the review timestamp. Website and program approval decisions are made by cyteclick and cannot be set by publishers themselves.

We also store versioned records of accepted legal documents. Each acceptance record contains the account (user) ID, the publisher/company ID where available, the document type, the document version, a server-generated acceptance timestamp and the acceptance context (for example, publisher signup). No IP address and no user-agent string are stored as part of a legal acceptance record.

Legal basis: Art. 6(1)(b) GDPR (performance of the agreement), Art. 6(1)(c) GDPR (evidence of accepted terms) and Art. 6(1)(f) GDPR (program administration and abuse prevention).

7. Affiliate tracking and click processing

When an end user follows a cyteclick tracking link, the request is processed server-side and redirected to the affiliate destination. cyteclick does not set tracking cookies in the visitor's browser as part of this redirect; cookies may be set by the advertiser or the upstream affiliate network under their own responsibility.

For each click, cyteclick stores: a unique cyteclick click ID, the timestamp, a country value derived from the request headers, a coarse device type, the referring host only (not the full referring URL), a truncated browser identification string, the destination URL, any publisher SubID values passed in the link, and the relationship to the publisher, program, tracking link and registered website.

cyteclick does not store the visitor's IP address in its click records. Technical redirect outcomes are logged internally for diagnostics and abuse detection.

Legal basis: Art. 6(1)(f) GDPR (attribution of affiliate traffic, correct commission calculation, fraud prevention and security) and Art. 6(1)(b) GDPR in relation to the publisher agreement.

8. Conversion and transaction processing

When an advertiser or upstream network reports a transaction, we process the transaction identifier, the conversion timestamp, the order value, the currency, attribution data (in particular the cyteclick click ID), the conversion status (pending, approved, rejected or reversed), the status history, the commission type and value, the publisher commission and internal reconciliation data.

Upstream commission amounts, the internal margin and raw notification payloads are retained internally for reconciliation, dispute resolution, security and audit purposes and are accessible only to cyteclick staff. Notifications that cannot be validated or attributed are retained separately in an internal staging area and never generate publisher commission.

Legal basis: Art. 6(1)(b), Art. 6(1)(c) and Art. 6(1)(f) GDPR.

9. Affiliate networks, advertisers and other recipients

cyteclick operates as an affiliate sub-network and therefore interacts with external affiliate networks and advertisers in order to redirect affiliate traffic, attribute transactions, receive conversion and transaction notifications, validate commissions, prevent fraud and administer affiliate programs.

AWIN is currently integrated as an upstream affiliate network. cyteclick passes its own click identifier to AWIN through the AWIN “clickref” mechanism, and AWIN may return transaction and conversion information to cyteclick through transaction notifications. Advertisers and networks process the data they receive as independent controllers under their own privacy policies.

Further recipients may include our hosting and platform infrastructure provider, our email delivery infrastructure, and — where legally required — tax advisors, auditors or public authorities.

10. Commission and payment administration

For payouts we process commission records, payout periods, amounts, currencies, payment method, payment status, payment date and invoice references, together with the billing details you provide (such as legal name, VAT ID and country).

Legal basis: Art. 6(1)(b) GDPR (payment of commissions) and Art. 6(1)(c) GDPR (accounting and tax obligations).

11. Transactional and authentication emails

Authentication emails — signup and email confirmation, password recovery and reset, and email-change or re-authentication messages where applicable — are sent through Lovable's managed email infrastructure. The visible sender is cyteclick <no-reply@cyteclick.com>; the subdomain notify.cyteclick.com may be used internally as the technical delivery domain.

Data processed for this purpose includes your email address, the message type and delivery status information (for example acceptance, bounce or complaint events) used to protect deliverability.

Legal basis: Art. 6(1)(b) GDPR (account-related messages) and Art. 6(1)(f) GDPR (deliverability and security). We do not send marketing newsletters from this platform.

12. Cookies and browser storage

The public website uses no analytics, advertising or marketing cookies and no consent-requiring tracking technologies.

After you sign in, your authentication session is stored in your browser's local storage by the authentication library so that you stay logged in. The signed-in dashboard also stores a “sidebar_state” cookie remembering whether the navigation sidebar is expanded, and a local “cyteclick.demo” flag that marks the public, non-authenticated dashboard demo view.

All of these are technically necessary for the login and interface functions you request; none of them are used for analytics, profiling or advertising.

13. Legal bases under the GDPR

Art. 6(1)(b) GDPR — performance of a contract and steps taken prior to entering a contract (registration, account access, program participation, commission and payout processing).

Art. 6(1)(c) GDPR — compliance with legal obligations (accounting, tax and record-keeping duties, evidence of accepted terms).

Art. 6(1)(f) GDPR — legitimate interests in platform security, fraud prevention, correct attribution, reconciliation and the operation of the affiliate platform.

Art. 6(1)(a) GDPR — consent, only where a specific processing operation actually relies on it. Normal account and contractual processing does not rely on consent.

14. Processors and international transfers

We use Lovable Cloud (built on Supabase) for application hosting, database, authentication and email delivery infrastructure, acting as processor on our instructions under a data processing agreement.

Where a processor or a recipient such as an affiliate network processes data outside the European Economic Area, transfers are safeguarded by an EU adequacy decision or by EU Standard Contractual Clauses together with appropriate supplementary measures.

15. Data retention

We retain personal data only as long as necessary for the purpose for which it was collected. Account, publisher and website data is retained for the duration of the account relationship.

Click, conversion, commission and payout records are retained for as long as needed for attribution, commission validation, dispute resolution, reconciliation and audit, and thereafter for the periods required by statutory accounting and tax obligations. Legal acceptance records are retained as evidence of the accepted document version for as long as required to establish and defend the contractual relationship.

Internal logs of redirects, notifications and unmatched transactions are retained for security, fraud-prevention and reconciliation purposes and are deleted or aggregated once no longer needed. The platform does not define fixed automated deletion periods for these records; retention is reviewed against the purposes above.

16. Security

Access to platform data is restricted by authentication and row-level database authorisation, so publishers can access only their own account, links, clicks, conversions, commissions and payouts. Upstream network identities, raw notification payloads, upstream commissions and internal margins are restricted to cyteclick staff.

Tracking, conversion and audit records are written only by trusted server-side processes and cannot be created, altered or deleted through the browser. Data is transmitted over encrypted connections (TLS), and credentials are stored as server-side secrets.

17. Your rights

You have the right of access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20) and objection (Art. 21) under the GDPR. Where processing is based on consent, you may withdraw that consent at any time with effect for the future.

To exercise your rights, contact support@cyteclick.com. We may need to verify your identity before acting on a request.

18. Right to lodge a complaint

You may lodge a complaint with a data protection supervisory authority. As the controller is established in Estonia, the competent authority is the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon), Tatari 39, Tallinn, Estonia — www.aki.ee.

You may also contact the supervisory authority of your habitual residence or place of work.

19. Changes to this Privacy Policy

We may update this policy to reflect changes to the platform or to legal requirements. Substantive changes are published as a new document version; the version and effective date are shown at the top of this page.

20. Contact

Digital Media Group OÜ, Sepapaja 6, Tallinn 15551, Estonia

Email: support@cyteclick.com