GDPR Compliance

Last updated: March 20, 2026

Ofluence is built with privacy by design. We process data only with a valid legal basis, honor all data subject rights within 30 days, and use Standard Contractual Clauses for international transfers. Our DPO is reachable at dpo@ofluence.io.

1. Our Commitment to GDPR

Ofluence is fully committed to compliance with the General Data Protection Regulation (GDPR). Our systems, processes, and policies are designed with data protection principles at their core, including data minimization, purpose limitation, and privacy by design.

2. Data Controller

Ofluence Inc.
Data Protection Officer: dpo@ofluence.io

3. Lawful Basis for Processing

  • Consent — Marketing communications, optional analytics
  • Contractual necessity — Platform access, campaign workflows, payments
  • Legitimate interests — Product improvement, fraud prevention, security
  • Legal obligation — Tax reporting, legal proceedings

4. Data We Process

  • Account data — Name, email, password (hashed), profile photo, organization details
  • Creator profiles — Display names, bios, content categories, audience demographics
  • Social media metrics — Engagement rates, follower counts, reach, impressions
  • Usage analytics — Pages visited, features used, session duration, device information
  • Payment data — Billing information processed exclusively by Stripe (PCI DSS Level 1)

5. Your Rights as a Data Subject

  • Right of access — Request a copy of your personal data
  • Right to rectification — Correct inaccurate data
  • Right to erasure — Request deletion of your data
  • Right to data portability — Receive data in machine-readable format
  • Right to restrict processing — Limit how we process your data
  • Right to object — Object to processing based on legitimate interests
  • Right to withdraw consent — Withdraw consent at any time
  • Right to lodge a complaint — File with your local supervisory authority

6. How to Exercise Your Rights

Contact our DPO at dpo@ofluence.io. We acknowledge requests within 72 hours and respond within 30 calendar days (extendable by 60 days for complex requests).

7. Data Protection Officer

Our DPO oversees all data protection matters. Contact: dpo@ofluence.io

8. Sub-processors

  • Google Cloud Platform — Infrastructure and hosting (EU and US regions)
  • PostHog — Product analytics and session insights
  • Transactional email service — Account notifications and communications
  • Stripe — Payment processing (PCI DSS Level 1 certified)

9. International Data Transfers

For transfers outside the EEA, we use Standard Contractual Clauses (SCCs) and the EU-US Data Privacy Framework where applicable. We regularly assess transfer mechanisms and implement supplementary measures where necessary.

10. Data Breach Notification

We notify the relevant supervisory authority within 72 hours of becoming aware of a breach. High-risk breaches trigger direct notification to affected individuals. We maintain a comprehensive incident response plan and conduct regular security assessments.

11. Data Processing Agreement

We offer a Data Processing Agreement (DPA) to all customers who require one. Contact dpo@ofluence.io to request a copy.