Data & Privacy Policy

Last updated: September 6, 2026

Pinkk ("Pinkk", "we", "us", "our") is an intelligence research tool that generates structured reports and confidence-rated findings about digital profiles. This Policy explains what personal information we collect, why we collect it, how we use and protect it, who we share it with, how long we keep it, and what rights you have over it.

It applies whenever you visit our website, create a Pinkk account, use our dashboards, analysis tools, or contact us. If you do not agree with this Policy, please do not use the Services.

1. Who we are and scope

Pinkk is an intelligence research tool operated from the Republic of South Africa. For the personal information described in this Policy, Pinkk acts as the responsible party (under POPIA) and data controller (under GDPR/UK GDPR) — we determine the purposes and means of processing.

Certain service providers we engage act as operators / processors, handling data only on our documented instructions and under contractual data protection obligations.

This Policy covers: (a) personal information you provide when creating an account or using the Services; (b) technical data collected automatically when you use the Services; (c) payment and billing data processed in connection with subscriptions and credit purchases; (d) publicly available data about third-party social media profiles that you submit for analysis; and (e) communications you send us.

2. Information we collect

Account and identity data

Name and email address. A hashed password if you register with email/password. If you sign in via Google, X (Twitter), Twitch, Discord, Facebook, or Twitch OAuth, we receive your provider-assigned user ID and, where provided, your avatar URL. We store these identifiers to link your account to the OAuth provider and to avoid creating duplicate accounts.

If you enable two-factor authentication (2FA), we store an encrypted TOTP secret key and an encrypted list of hashed single-use recovery codes. We also record a timestamp of when 2FA was confirmed and activated. 2FA is entirely optional and these fields are only populated when you choose to set it up. The TOTP secret is encrypted at rest using Laravel's application-level encryption (AES-256-CBC) before being written to the database, and recovery codes are stored as bcrypt hashes — neither is stored or accessible in plain text.

Session and technical data

IP address at registration (signup_ip), IP address and user agent stored in session records, and basic device and browser information. Log data about how you access and use the Services, including timestamps and interaction events. Session data is stored server-side in our database and expires after approximately 120 minutes of inactivity.

Profile and analysis data

Creator and brand profiles you create, including profile labels, platform handles (Instagram, TikTok, YouTube, X, LinkedIn, Twitch, website, etc.), market, niche, follower counts, engagement rates, internal notes, and uploaded or auto-fetched avatars. Analysis inputs you submit (gene-specific fields and optional analyst notes). Structured analysis reports generated by Pinkk — stored as JSON files on our server, not in the database. Profile comparison and workspace intelligence reports.

AI and system usage data

Every AI API call generates an internal usage record tracking the provider, model, token counts, cost, duration, and a masked API key label. These records are used to operate, monitor, and audit our AI infrastructure. They are stored in a separate logs database and pruned on a configurable schedule (default: 90 days).

Payment and billing data

Subscription and payment records received via webhooks from Polar, our payment processor. This includes your Polar customer ID, subscription ID, plan type, billing period dates, transaction amounts, and currency. We store the full webhook payload for audit and debugging purposes. We do not store payment card numbers — those are handled exclusively by Polar and its payment partners.

Credit and transaction data

A ledger of every credit operation — grants (signup bonus, subscription, purchase, admin adjustment, bonus code redemption), deductions (analysis runs), and refunds. Each transaction records the amount, reason, and entitlement source.

Notification and communication preferences

Your email notification preference and unsubscribe token. Your push notification preference and browser push subscription data (endpoint URL, VAPID public key, auth secret, and user agent) for each device you subscribe from. In-app notification history.

Referral data

If you use or share a referral code, we record the referral relationship between accounts, whether a referral bonus was granted, and any automated signals used to detect suspicious referral activity.

Support and contact data

Name, email, company name, and message content from contact form submissions. Your account ID if you were logged in when you submitted the form.

Verification log data

When anyone uses the public report verification feature at /verify, we log the report reference number, the verifier's IP address, and the timestamp. This data is used to detect abuse and is pruned after 30 days.

Publicly available data about third parties

When you submit social media handles or other public identifiers for analysis, Pinkk retrieves and processes publicly available data about those profiles via our AI intelligence services (You.com, Tavily, Twitch Helix API, YouTube Data API, Brandfetch, Logo.dev). This data relates to third parties, not to you directly. You are responsible for ensuring you have a lawful basis to submit such data where required by applicable law.

We do not intentionally collect sensitive personal information (such as health data, racial or ethnic origin, political opinions, or biometric data) and ask that you do not submit such information through the Services.

3. How we use information

Providing and maintaining the Services

Creating and managing your account, authenticating you, maintaining secure sessions, generating and storing your analysis reports, and serving your historical data.

Processing payments and managing subscriptions

Handling subscription activations, renewals, cancellations, credit pack purchases, and credit balance management via Polar.

Running AI analysis and generating reports

Processing your analysis inputs through our AI agent system and intelligence services to generate structured intelligence reports. Logging AI usage for cost tracking, auditing, and system reliability.

Communicating with you

Sending transactional emails — welcome messages, purchase confirmations, analysis-complete notifications, and password resets — via Resend. Sending in-app and browser push notifications about your account activity. Responding to support requests.

Security, fraud prevention, and abuse detection

Detecting and investigating suspicious activity, including referral fraud, bot activity, and unauthorized access. Enforcing our Terms of Service. Maintaining admin audit logs of all administrative actions.

Operating and improving the platform

Monitoring system health and reliability via BetterStack and Sentry. Aggregating and anonymizing usage data to understand how the product is used and where it can be improved. Running analytics (with your consent) via Google Analytics 4 and Microsoft Clarity.

Legal compliance

Retaining records as required by applicable law, including financial and tax records. Responding to lawful requests from authorities.

5. Cookies, local storage, and tracking

Strictly necessary cookies

A database-backed session cookie keeps you authenticated while you use Pinkk (expires after approximately 120 minutes of inactivity). An optional "remember me" cookie, set when you choose that option at login, keeps you signed in for 90 days. These are strictly necessary to provide the core service and cannot be disabled without breaking authentication.

Local storage (functional)

Your analytics consent preference is stored in localStorage so we can remember whether to load analytics scripts on future visits. This is not a cookie and does not track you across other websites.

Analytics and monitoring tools (consent-based)

The following categories of tool only load after you give consent via the banner. If you decline, none of these tools will load or set cookies.

  • Page analytics — tracks page views and general usage patterns. Configured with IP anonymisation enabled.
  • Session replay and heatmaps — records anonymised interaction sessions to help us understand usability. Configured to mask sensitive input fields and content.
  • Error and performance monitoring — captures application errors and performance traces. Session replay is configured to mask all text and media.

Bot protection

Our contact form uses a third-party bot protection service. It may set cookies or use browser signals to distinguish humans from bots. No personal account data is shared with this service.

You can change or withdraw your analytics consent at any time by adjusting your preferences in the consent banner or by clearing cookies and site data in your browser settings.

6. Automated analysis and AI processing

Pinkk uses automated processing — including large language models (LLMs) — to generate analysis reports, classify patterns, and produce confidence scores. Our AI agent system assembles context from your profile data and submitted inputs, processes it through one or more LLM services, and parses the structured response into a report.

What AI processing involves: Your analysis inputs and profile data are processed by third-party LLM service providers acting as our sub-processors to generate report content. We use a fallback chain — if one service fails, the system tries the next — to keep analysis available. Every AI call is logged internally for operational auditing. A current list of the categories of sub-processors we engage, and information about any specific sub-processor, is available on request — contact us (see section 23).

Nature of outputs: All analysis outputs are designed to support your decision-making. They use cautious, evidence-based language ("may indicate", "suggests", "could be"). Pinkk does not make identity verification claims, fraud judgments, or legally binding determinations about any person or entity. Outputs are informational only.

Your data and AI training: We do not use your content or analysis data to train AI models. We do not sell your data to AI providers. LLM providers receive only the data necessary to process a specific request and are contractually bound not to use it for their own model training.

Automated decision-making and ADMT documentation: Pinkk's AI analysis constitutes Automated Decision-Making Technology (ADMT). We document the nature of this processing as follows: (a) outputs are informational and advisory — they do not constitute binding decisions about any individual's access to services, credit, employment, housing, or legal rights; (b) all outputs include confidence ratings and use cautious, evidence-based framing ("may indicate", "suggests", "could be") — this disclaimer is displayed directly within every generated report; (c) Pinkk does not use ADMT to produce legal or similarly significant effects without human review; (d) customers who receive Pinkk reports remain solely responsible for any downstream decisions they make based on those reports. Where privacy laws on automated decision-making apply — including under GDPR, POPIA, or California's ADMT regulations — you have the right to request human review, express your point of view, or contest a specific outcome. Contact [email protected] with the subject line "ADMT Review Request" to exercise these rights.

Third-party profile data: When you submit social media handles or other public identifiers, Pinkk processes publicly available data about those third parties for intelligence purposes. You are responsible for ensuring you have a lawful basis to submit such data where required by applicable law.

7. How we share information

We do not sell your personal data. We do not sell, rent, or trade your personal information to third parties for their own marketing or commercial purposes.

Service providers (operators/processors)

We share information with a limited set of trusted service providers, only as necessary to operate Pinkk. Each provider is contractually bound to protect your information and may not use it for their own purposes beyond providing their services to us. See section 8 for the full list.

Public report verification

When you or anyone else uses the public report verification feature at /verify, a limited summary of the report (capped at 400 characters) and up to six quality/risk signals are visible to the verifier. No account data is exposed. You control whether a report is publicly verifiable by its reference number.

Private share links

Subscribers can generate token-gated share links for individual reports. Anyone with the link can view the report without logging in. The token is the credential — treat it like a password. You can revoke share links at any time from your account.

Business transfers

If Pinkk is involved in a merger, acquisition, financing, or sale of all or part of our business, personal information may be transferred as part of that transaction. We will notify you via email or in-app notice before your information becomes subject to a materially different privacy policy.

Legal requirements and safety

We may disclose information if required to do so by law, regulation, or enforceable governmental request, or where we reasonably believe disclosure is necessary to: enforce our Terms of Service; protect the rights, property, or safety of Pinkk, our users, or the public; or prevent or investigate fraud, security incidents, or illegal activity.

8. Third-party service providers

We share information with a limited set of service providers, grouped by function below. Each provider is engaged under a data processing agreement or equivalent contractual protections and may not use your data for their own purposes beyond providing their services to us.

Category Purpose Data shared
Payment processor / Merchant of Record Subscription billing and credit pack purchases. Polar (Polar Software, Inc.) acts as our Merchant of Record — the legal seller of Pinkk's digital products — and handles all payment processing, tax compliance, and transaction records on our behalf. Email address, subscription metadata, and transaction amounts. Payment card data is handled exclusively by Polar and its payment partners — we never receive or store card numbers.
Transactional email provider Delivery of account and notification emails Recipient email address, name, and email content
Sable Intelligence — AI analysis layer Powering all AI-generated analysis, report generation, autofill, and intelligence enrichment Analysis inputs and profile context necessary to generate a report or autofill a field. No account identifiers (name, email, or billing data) are included in analysis requests.
Social platform APIs Fetching publicly available creator and brand data for analysis enrichment and avatar retrieval Platform handles you submit for analysis. Only public data is retrieved.
Analytics providers (consent-gated) Page analytics and heatmaps — only loaded after you consent Anonymised page views and interaction events. IP anonymisation enabled. Sensitive fields masked.
Error and performance monitoring (consent-gated) Detecting and diagnosing application errors — only loaded after you consent Error events, stack traces, and performance metrics. Session replay is configured to mask all text and media.
Infrastructure and security provider Content delivery, DDoS protection, and bot detection on forms IP address, request metadata, and browser signals used for bot detection. No personal account data is shared.
Uptime monitoring Monitoring platform availability and alerting on outages Health check endpoint responses only. No personal data is shared.
Social login providers OAuth-based account creation and login (Google, X, Twitch, Facebook) We receive only the provider-assigned user ID and, where available, your avatar URL. We do not receive your password from any OAuth provider.
Avatar generation service Generating a placeholder avatar when no profile image is set Your initials (derived from your display name) sent as a URL parameter. No other data is shared.

We review our provider relationships periodically. If we add a new category of provider that materially changes how your data is handled, we will update this Policy and notify you where required.

9. Data retention schedules

We keep personal information only for as long as necessary for the purposes described in this Policy, to meet legitimate business needs, and to comply with legal obligations. The table below reflects our current retention practices.

Data type Retention period Basis
Active session data ~120 minutes of inactivity; 90 days with "remember me" Contractual necessity
Account data (name, email, preferences) Until account deletion, then promptly deleted Contractual necessity
Analysis reports and report files Until you delete them or your account; orphaned files pruned monthly; files older than 365 days pruned monthly Contractual necessity / legitimate interest
Payment and subscription records Minimum 5 years (financial record-keeping obligations) Legal obligation / legitimate interest
Credit transaction ledger Retained while account is active; deleted with account Contractual necessity / legitimate interest
AI usage events (token/cost logs) 90 days by default (configurable); also capped by max row limit Legitimate interest (operational auditing)
Admin audit logs 90 days by default (configurable); also capped by max row limit Legitimate interest (security and accountability)
Verification logs (IP + reference) 30 days Legitimate interest (abuse detection)
Email logs Retained while account is active; deleted with account Legitimate interest (delivery troubleshooting)
Push subscription data Until you unsubscribe or delete your account Consent / contractual necessity
Contact form submissions Until resolved, then up to 2 years for record-keeping Legitimate interest
Data subject requests (DSARs) Up to 12 months after closure, then deleted Legal obligation / legitimate interest
Signup IP address Retained while account is active; deleted with account Legitimate interest (fraud prevention)

When an account is deleted, we delete or anonymise associated personal data within a reasonable period, except where retention is required by law or for legitimate business purposes (such as payment records). Backups may retain data for a short additional period before being overwritten.

You can request deletion of your account or specific data at any time — see section 11.

10. International transfers

Pinkk is operated from South Africa and our primary infrastructure is hosted in the EU (AWS eu-west-2, London). Some of the service providers listed in section 8 operate in the United States or other jurisdictions that may not provide the same level of data protection as your home country.

Where we transfer personal information outside South Africa, we implement appropriate safeguards as required by POPIA and other applicable laws. For transfers to countries without an adequate level of protection, we rely on standard contractual clauses, binding corporate rules, or other lawful transfer mechanisms.

For EEA and UK residents, transfers to third countries are made under the EU Standard Contractual Clauses (SCCs) or the UK International Data Transfer Agreement (IDTA), as applicable.

You may request information about the specific safeguards in place for any transfer by contacting us (see section 23).

11. Your rights and choices

Depending on your location and applicable law, you may have some or all of the following rights. We honour these rights regardless of where you are located, to the extent technically feasible.

Access

Request a copy of the personal information we hold about you.

Correction

Correct inaccurate or incomplete information. You can update your name, email, and password directly in your account settings.

Deletion (right to be forgotten)

Delete your account and associated personal data. Account deletion is available directly in your account settings. We will delete or anonymise your data within a reasonable period, subject to legal retention obligations.

Data portability

Request a copy of certain data in a portable, machine-readable format where technically feasible.

Restriction of processing

In certain circumstances, request that we restrict processing of your personal information while a dispute is resolved.

Objection

Object to processing based on legitimate interests, including certain profiling or analytics uses. We will stop unless we have compelling legitimate grounds that override your interests.

Withdraw consent

Withdraw consent where processing is based on consent (for example, analytics cookies), without affecting the lawfulness of prior processing. You can do this via the consent banner or by clearing your browser's site data.

Email unsubscribe

Unsubscribe from non-essential email notifications at any time using the unsubscribe link in any email, or by adjusting your notification preferences in your account settings.

Push notification opt-out

Disable browser push notifications at any time from your account notification settings or from your browser's site permissions.

Automated decision-making review

Where applicable law provides, request human review of automated analysis outputs, express your point of view, or contest a specific outcome.

For requests that cannot be completed through in-product controls, contact us at [email protected] or using the details in section 23. We aim to respond within 30 days (or within the timeframe required by applicable law). We may need to verify your identity before processing certain requests.

If you are not satisfied with our response, you have the right to lodge a complaint with your local data protection authority. Most countries with data protection laws have a designated supervisory authority — if you are unsure who that is for your location, contact us at [email protected] and we will help identify the appropriate body.

Regardless of where you are located, you may always contact us at [email protected] to exercise any of the rights listed above. If your local law gives you privacy rights that we have not specifically named in this Policy, tell us and we will respond in good faith.

12. Security measures

We implement reasonable technical and organisational measures to protect personal information from unauthorised access, loss, misuse, alteration, or destruction. These include:

  • HTTPS/TLS encryption for all data in transit
  • Passwords hashed using bcrypt (12 rounds) — we never store plaintext passwords
  • All AI provider API keys and Polar payment credentials encrypted at rest in the database
  • Report content stored as files outside the database, not accessible via direct URL without authentication
  • Session cookies marked Secure and HttpOnly
  • CSRF protection on all state-changing requests
  • Webhook signature verification (HMAC-SHA256) for all Polar payment webhooks
  • Cloudflare CDN and DDoS protection in front of all public endpoints
  • Cloudflare Turnstile bot protection on the contact form
  • Disposable email domain blocking and HaveIBeenPwned password breach checking at registration
  • Password policy: minimum 12 characters, mixed case, numbers, and symbols required
  • Admin audit logs recording all administrative actions with IP address and user agent
  • Access to personal data limited to personnel and providers who need it to perform their role
  • Uptime and error monitoring via BetterStack and Sentry

No method of transmission over the internet or electronic storage is perfectly secure. We cannot guarantee absolute security. In the event of a data breach that is likely to result in a risk to your rights and freedoms, we will notify you and the relevant authorities as required by applicable law.

13. Children's privacy

Pinkk is intended for use by adults aged 18 and over and is not directed at children under 13 (or the equivalent minimum age in your jurisdiction). We do not knowingly collect personal information from children. If we learn that we have collected personal information from a child without appropriate parental consent, we will take reasonable steps to delete it promptly. If you believe we may have collected information from a child, please contact us (see section 23).

14. South African residents — POPIA

Pinkk is operated from South Africa and is subject to the Protection of Personal Information Act 4 of 2013 (POPIA). This section supplements the rest of this Policy with information specific to South African data subjects.

Responsible party

Pinkk acts as the responsible party for personal information processed in connection with the Services. Contact details are in section 23.

Lawful grounds for processing

We process personal information on the following grounds under POPIA: (a) the data subject's consent; (b) necessity for the performance of a contract; (c) compliance with a legal obligation; (d) the legitimate interests of Pinkk or a third party, where those interests are not overridden by your rights.

Your rights under POPIA

As a data subject under POPIA, you have the right to: be notified that your personal information is being collected; access your personal information; request correction or deletion of your personal information; object to the processing of your personal information; and submit a complaint to the Information Regulator.

Information Regulator

If you believe we have processed your personal information in violation of POPIA, you may lodge a complaint with the Information Regulator of South Africa at inforegulator.org.za.

Cross-border transfers

Where we transfer personal information outside South Africa, we do so only to countries or recipients that provide an adequate level of protection, or under appropriate safeguards as required by section 72 of POPIA.

15. EEA and UK residents — GDPR / UK GDPR

If you are located in the European Economic Area (EEA) or the United Kingdom, the General Data Protection Regulation (GDPR) or UK GDPR may apply to our processing of your personal data. This section supplements the rest of this Policy.

Data controller

Pinkk acts as the data controller for personal data processed in connection with the Services. Contact details are in section 23.

Legal bases

See section 4 for the legal bases we rely on. Where we rely on legitimate interests, you have the right to object to that processing.

Your rights under GDPR / UK GDPR

You have the rights described in section 11, including the right to access, rectification, erasure, restriction, portability, and objection. You also have the right not to be subject to solely automated decision-making that produces legal or similarly significant effects, and to request human review of such decisions.

Supervisory authority

EEA residents may lodge a complaint with their national data protection authority. UK residents may contact the Information Commissioner's Office (ICO) at ico.org.uk.

International transfers

Transfers of personal data outside the EEA or UK are made under the EU Standard Contractual Clauses or the UK International Data Transfer Agreement, as applicable. See section 10 for more detail.

16. US residents — California and state privacy rights

This section applies to residents of California and other US states with applicable privacy laws. It supplements the rights described in section 11 and is provided for informational purposes — Pinkk may not currently meet the thresholds that trigger mandatory compliance obligations under all of the laws referenced below, but we extend these rights voluntarily where feasible.

We do not sell or share your personal information

Pinkk does not sell your personal information for monetary consideration. We do not share your personal information with third parties for cross-context behavioural advertising or targeted advertising purposes. We do not use your personal information to build advertising profiles. If this ever changes, we will update this Policy before it takes effect and provide a clear opt-out mechanism.

Your rights under CCPA/CPRA (California residents)

Under the California Consumer Privacy Act (as amended by the CPRA), California residents may have the right to:

  • Know — request disclosure of the categories and specific pieces of personal information we collect, use, disclose, and sell or share.
  • Delete — request deletion of personal information we hold about you, subject to certain exceptions.
  • Correct — request correction of inaccurate personal information.
  • Opt out of sale or sharing — as noted above, Pinkk does not sell or share personal information for advertising purposes. No opt-out mechanism is currently required, but you may contact us to confirm this in writing.
  • Limit use of sensitive personal information — we do not collect sensitive personal information as defined under the CPRA beyond what is strictly necessary to operate the Services.
  • Non-discrimination — we will not discriminate against you for exercising any of these rights.

Automated decision-making technology (ADMT) — California

Pinkk's AI-powered report generation constitutes Automated Decision-Making Technology (ADMT) within the meaning of California's privacy regulations effective January 2026. We have documented our ADMT practices as follows:

  • Nature of outputs — all analysis outputs are informational and advisory only. They do not constitute binding decisions about any individual's access to services, credit, employment, housing, insurance, or legal rights.
  • Confidence ratings and cautious framing — outputs include confidence scores and use evidence-based language ("may indicate", "suggests", "could be") to make their probabilistic nature explicit at the point of delivery.
  • No automated consequential actions — Pinkk does not use ADMT to take automated actions that produce legal or similarly significant effects on individuals without human review.
  • Human review — if you believe a Pinkk analysis output has been used as the basis for a significant decision that affects you, you may request human review of that output, express your point of view, or contest the outcome. Submit requests to [email protected] with the subject line "ADMT Review Request".
  • Customer responsibility — Pinkk's customers remain solely responsible for any downstream decisions they make based on our reports. We do not control how customers use outputs after delivery.

We have conducted an internal risk assessment for our ADMT processing activities and will update this documentation as California's ADMT regulations and guidance develop.

Other US state residents

Residents of Virginia (VCDPA), Colorado (CPA), Connecticut (CTDPA), Texas (TDPSA), and other states with applicable consumer privacy laws have similar rights to access, correct, delete, and port personal information, and to opt out of certain processing activities. We extend the same rights available under GDPR and POPIA to residents of those states — including the right to access, correct, delete, and port your personal information — on a reasonable-efforts basis, regardless of whether we currently meet the mandatory applicability thresholds under those state laws. Submit requests to [email protected] with the subject line "US Privacy Rights Request".

Shine the Light (California)

California Civil Code § 1798.83 permits California residents to request information about personal information disclosed to third parties for their direct marketing purposes. Pinkk does not disclose personal information to third parties for their direct marketing purposes.

Global Privacy Control (GPC)

Several US state privacy laws require businesses to honour the Global Privacy Control (GPC) browser signal as an opt-out of sale or sharing. Because Pinkk does not sell or share personal information for advertising, GPC signals do not currently trigger any additional processing change. We monitor developments in GPC requirements and will implement technical support if and when our processing activities make this necessary.

To exercise any of the rights described in this section, contact us at [email protected] with the subject line "US Privacy Rights Request". We will respond within 45 days (or within the timeframe required by applicable law) and may need to verify your identity before processing your request.

17. Australia and Canada residents

This section supplements the rest of this Policy for users located in Australia or Canada. The rights described in section 11 apply to you in full. This section provides additional context on the specific legal frameworks that may apply.

Australia — Privacy Act 1988 and Australian Privacy Principles

Australia's Privacy Act 1988 and the Australian Privacy Principles (APPs) govern how organisations handle personal information about Australian residents. The Act currently applies to businesses with annual turnover exceeding AU$3 million, and to organisations that trade in personal information — Pinkk does not meet either threshold at this time. Nonetheless, we voluntarily apply the following practices consistent with the APPs to all Australian users:

  • Collection and notification — we collect only the personal information reasonably necessary to provide the Services and notify you of the purposes at the time of collection (this Policy).
  • Use and disclosure — we use personal information only for the primary purpose for which it was collected, or secondary purposes you would reasonably expect, or as otherwise disclosed in this Policy.
  • Data quality and security — we take reasonable steps to ensure personal information is accurate, up to date, and protected from misuse, interference, loss, and unauthorised access. See section 12 for security measures.
  • Access and correction — you may request access to or correction of your personal information using the contact details in section 23. We will respond within 30 days.
  • Cross-border disclosure — some of our service providers are located outside Australia, primarily in the EU and US. We take reasonable steps to ensure overseas recipients handle your information in a manner consistent with the APPs.
  • Notifiable data breaches — although we are currently below the mandatory threshold, we commit to notifying affected Australian users of any data breach that is likely to result in serious harm, consistent with the Notifiable Data Breaches (NDB) scheme.

If you have a complaint about how we handle your personal information, contact us at [email protected]. If you are not satisfied with our response, you may escalate to the Office of the Australian Information Commissioner (OAIC) at oaic.gov.au.

Canada — PIPEDA and Quebec Law 25

Canada's Personal Information Protection and Electronic Documents Act (PIPEDA) governs how private-sector organisations collect, use, and disclose personal information in the course of commercial activity. Quebec's Law 25 (Act 25), in effect since September 2023, imposes additional GDPR-like obligations on organisations that handle personal information of Quebec residents, including data minimisation, privacy impact assessments for high-risk processing, and a 72-hour breach notification requirement to Quebec's Commission d'accès à l'information (CAI).

Our practices under PIPEDA and Quebec Law 25:

  • Consent — we rely on your informed consent (provided at account creation) for collection and use of your personal information, or on other lawful grounds where consent is not required (such as contractual necessity or legal obligation).
  • Limiting collection and use — we collect only what is necessary for the identified purposes described in this Policy and do not use it for other purposes without further consent.
  • Individual access — you have the right to access personal information we hold about you, to challenge its accuracy, and to request correction. Requests can be submitted to [email protected].
  • Cross-border transfers — personal information may be transferred to and processed in countries outside Canada, including South Africa (our primary operating jurisdiction) and the EU. We ensure contractual protections are in place with all overseas service providers.
  • Breach notification — in the event of a breach of security safeguards involving personal information that creates a real risk of significant harm to a Canadian resident, we will notify the affected individual and the Office of the Privacy Commissioner of Canada (OPC), and — for Quebec residents — the CAI, within the required timeframes.
  • De-identification (Quebec) — where we use personal information for analytics or service improvement purposes, we take steps to de-identify or anonymise that information before use where reasonably practicable.

To exercise your rights or make a complaint, contact us at [email protected]. If you are not satisfied with our response, you may contact the Office of the Privacy Commissioner of Canada at priv.gc.ca, or — for Quebec residents — the Commission d'accès à l'information at cai.quebec.ca.

18. Argentine residents — LPDP

This section supplements the rest of this Policy for users located in Argentina. Argentina's Ley de Protección de los Datos Personales (Law 25.326 / LPDP) governs the processing of personal data of Argentine residents. Argentina has been recognised by the European Commission as providing an adequate level of data protection. The rights described in section 11 apply to you in full.

Data controller

Pinkk acts as the data controller (responsable del archivo, registro, base o banco de datos) for personal data processed in connection with the Services. Contact details are in section 23.

Your rights under LPDP

Argentine residents have the following rights in relation to their personal data:

  • Access (derecho de acceso) — you may request, free of charge, a full copy of the personal data we hold about you at any time, or at least every six months.
  • Rectification (derecho de rectificación) — you may request correction of inaccurate, incomplete, or outdated personal data. We will respond within five business days of receiving your request.
  • Deletion (derecho de supresión) — you may request deletion of personal data that is no longer necessary, was processed unlawfully, or where you withdraw consent, subject to legal retention obligations.
  • Confidentiality (derecho de confidencialidad) — you have the right to request that your personal data not be disclosed to third parties for direct marketing or commercial purposes without your consent.

To exercise these rights, contact us at [email protected]. We aim to respond within the timeframes required by applicable law.

Cross-border transfers

Personal data may be transferred to and processed in countries outside Argentina. Our primary infrastructure is hosted in the EU (AWS eu-west-2, London), which provides an adequate level of protection. For transfers to other destinations, we implement appropriate contractual safeguards consistent with LPDP requirements.

Supervisory authority

If you are not satisfied with our response to a request or complaint, you may contact the Agencia de Acceso a la Información Pública (AAIP) at argentina.gob.ar/aaip.

19. Brazilian residents — LGPD

This section supplements the rest of this Policy for users located in Brazil. Brazil's Lei Geral de Proteção de Dados (Law 13.709/2018 — LGPD), fully in force since August 2021, governs the collection, use, processing, and storage of personal data of individuals located in Brazil, regardless of where the data controller is established. The rights described in section 11 apply to you in full.

Data controller

Pinkk acts as the controlador (data controller) for personal data processed in connection with the Services. Contact details are in section 23.

Legal bases for processing (LGPD)

The LGPD requires that all processing of personal data have a lawful basis. We rely on the following bases under Article 7 of the LGPD:

  • Consent (consentimento) — for optional analytics and session-replay tools, as described in section 5.
  • Performance of a contract (execução de contrato) — for account creation, authentication, running analyses, managing subscriptions and credits, and sending transactional notifications.
  • Legitimate interests (legítimo interesse) — for fraud prevention, security, AI usage logging, and operational auditing, balanced against your rights and interests.
  • Legal obligation (obrigação legal ou regulatória) — for financial record-keeping and responding to lawful authority requests.

Your rights under LGPD

In addition to the rights in section 11, Brazilian residents have the following rights under Articles 17–22 of the LGPD:

  • Confirmation of processing — the right to know whether we hold and process your personal data.
  • Access — the right to access the personal data we hold about you.
  • Correction — the right to request correction of incomplete, inaccurate, or outdated personal data.
  • Anonymisation, blocking, or deletion — the right to request anonymisation, blocking, or deletion of unnecessary or excessive personal data, or data processed in non-compliance with the LGPD.
  • Portability — the right to request portability of your personal data to another service provider, subject to regulatory guidance.
  • Information about sharing — the right to be informed about public and private entities with whom we share your personal data.
  • Withdrawal of consent — the right to withdraw consent at any time. Withdrawal does not affect the lawfulness of processing carried out prior to withdrawal.
  • Review of automated decisions — the right to request review of decisions made solely on the basis of automated processing that affect your interests.

To exercise these rights, contact us at [email protected]. We aim to respond within 15 days, consistent with LGPD timeframes.

International transfers

Personal data of Brazilian residents may be transferred to and processed in countries outside Brazil, including South Africa (our primary operating jurisdiction) and the EU (our primary hosting region). For transfers to countries that do not provide an adequate level of protection equivalent to the LGPD, we rely on standard contractual clauses or other safeguards permitted under Article 33 of the LGPD.

Supervisory authority

If you are not satisfied with our response to a request or complaint, you may contact the Autoridade Nacional de Proteção de Dados (ANPD) at gov.br/anpd.

20. Other jurisdictions

Pinkk is a global online service and may be used by residents of countries whose specific privacy laws are not individually addressed in this Policy. This section explains our general approach to users in those jurisdictions.

Our global baseline

Regardless of where you are located, all users of the Services benefit from the same baseline data protection practices described throughout this Policy — including the rights in section 11, the security measures in section 12, the retention schedules in section 9, and our commitment not to sell or share personal information for advertising. This baseline is informed by the GDPR, which represents one of the most comprehensive privacy frameworks in the world. If your local law gives you rights that go beyond this baseline, contact us and we will respond in good faith.

Jurisdictions we monitor

Several other countries have enacted or are developing privacy laws that may affect how we operate as we grow. We monitor the following frameworks and will add dedicated sections to this Policy as our user base and obligations evolve:

  • India — Digital Personal Data Protection Act (DPDP, 2023/2025): applies to online processing of personal data of Indian residents. Introduces data fiduciary obligations, consent requirements, and breach notification duties.
  • Japan — Act on the Protection of Personal Information (APPI, amended 2022): applies to businesses that systematically handle personal information of Japanese residents, including cross-border transfer rules.
  • Switzerland — revised Federal Act on Data Protection (nFADP, 2023): broadly equivalent to the GDPR, applying to processing of Swiss residents' data by organisations that target Switzerland.
  • New Zealand — Privacy Act 2020: applies to any organisation that collects or holds personal information about New Zealand individuals and carries on business in New Zealand.

Threshold and applicability

Most of the laws listed above apply only when a business actively targets residents of that country, processes their data at scale, or exceeds a revenue or volume threshold. As a South African B2B SaaS platform at early stage, we do not currently meet the applicability thresholds for most of these laws. However, we apply our global baseline voluntarily to all users regardless of origin, and we will update this Policy — and implement any required additional measures — as our user base grows or as applicable legal guidance develops.

What to do if your jurisdiction is not listed

If you are located in a country not specifically addressed in this Policy and you have a question, request, or complaint relating to your personal information, please contact us at [email protected]. We will:

  • acknowledge your request promptly;
  • consider the rights available to you under your local law to the best of our knowledge;
  • apply our global baseline protections regardless of whether your local law technically applies to us; and
  • direct you to your local data protection authority if we cannot satisfy your request ourselves.

21. Information for third parties whose public data we process

This section is addressed to individuals whose publicly available social media profile data may have been retrieved and processed by Pinkk as part of an intelligence report generated for one of our business customers. It is provided in compliance with Article 14 of the GDPR (information where personal data has not been obtained directly from the data subject) and equivalent provisions under applicable national law.

Who we are and what we do

Pinkk is a B2B social media intelligence platform. Our customers — typically marketing agencies, brand teams, and researchers — submit public social media profile identifiers (such as usernames or handles) for analysis. We retrieve publicly available data associated with those profiles and generate structured intelligence reports for the submitting customer. We act as an independent data controller for this processing activity.

Legal basis

We process publicly available profile data on the basis of legitimate interests pursuant to Article 6(1)(f) GDPR and equivalent provisions under applicable national law, including POPIA. A Legitimate Interest Assessment (LIA) has been completed and is available on request. The LIA concluded that the processing of publicly available metrics does not materially override data subjects' privacy interests given the nature of the data, the professional B2B context, and the safeguards in place.

Categories of data processed

We process only publicly available profile metrics, which may include: follower counts, engagement rates, posting frequency, and content categories. We do not process special category data (such as health, political opinions, or biometric data), and we do not make credit, employment, or legally significant decisions about individuals.

Sources

Data is retrieved from publicly available sources, including public profiles on platforms such as Instagram, YouTube, TikTok, and Twitch, and via third-party data intelligence services. We do not access private account data, private messages, or data that requires platform authentication.

Your rights

As a data subject, you have the following rights in relation to data processed about you:

  • Right to Object (Article 21 GDPR) — you may object to the processing of your data on legitimate interest grounds. We will review your objection and respond within 30 days.
  • Right of Access (Article 15 GDPR) — you may request confirmation of whether we hold data about you and, if so, a copy of that data.
  • Right to Erasure (Article 17 GDPR) — you may request deletion of personal data we hold about you, subject to applicable legal grounds.

How to exercise your rights

Submit your request to [email protected] or use the data removal form on our website. We will acknowledge and respond within 30 days of receipt.

Right to lodge a complaint

If you are not satisfied with our response, you have the right to lodge a complaint with your local data protection authority. If you are unsure which authority applies to your location, contact us at [email protected] and we will help identify the appropriate body.

22. Changes to this Policy

We may update this Policy from time to time to reflect changes in our practices, technology, legal requirements, or for other operational reasons. When we make material changes, we will update the "Last updated" date at the top of this page and, where appropriate, provide additional notice — such as via email or an in-app notification.

We encourage you to review this Policy periodically. Your continued use of the Services after the effective date of any changes constitutes your acceptance of the updated Policy. If you do not agree to the revised Policy, you should stop using the Services and delete your account.

23. Contact us

If you have questions about this Policy, want to exercise your rights, or have a concern about how we handle your personal information, please contact us via the contact form on our website or using the contact details provided in the app. We aim to respond within 30 days.

For formal data subject requests under POPIA, GDPR, or UK GDPR, please use the subject line "Data Subject Request" so we can route your request appropriately.

Questions about your data?

If you have any questions about this Policy or how we handle your information, get in touch. We aim to respond within 30 days.