Back to ClubAffili

GDPR and data-rights guide

The documents that explain your account, affiliate participation and personal information.

Version 2026-09-10

This guide accompanies the privacy notice; it is not an agreement to waive rights or a separate blanket GDPR consent.

  1. Use the public privacy contact to describe the information or action requested. Never send passwords, private keys or verification codes.
  2. ClubAffili records the request, checks identity proportionately, identifies the responsible controller and routes any tenant-specific part appropriately.
  3. Access and export requests must avoid disclosing another person's or another tenant's information.
  4. Correction, erasure, restriction and objection requests are assessed against the relevant processing and legal obligations. Any refusal or extension needs a reason and complaint route.
  5. Marketing withdrawals must reach the actual sending systems and queued campaigns. A policy update must preserve the withdrawal.
  6. Account closure and retention are separate: explain any records kept, why, and for how long.
  7. An incident involving personal information is escalated immediately to the privacy/security owner. The operator assesses notification duties, including GDPR's 72-hour supervisory-authority deadline where applicable and notification to affected people where required.

The operator must maintain a processing register, retention schedule, processor agreements, transfer assessment where required, rights-request log and incident process. A DPIA or legitimate-interest assessment is completed where appropriate. Documents alone do not establish compliance.

Privacy requests and account help

You can contact support without accepting a new agreement. Never share identity documents, passwords or verification codes in chat.