Privacy Policy
1. Data Controller
{{COMPANY_NAME}} (company number {{COMPANY_NUMBER}}) is the data controller for personal data processed through the AgencyHub platform. Our registered office is at {{REGISTERED_ADDRESS}}.
ICO registration number: {{ICO_REGISTRATION_NUMBER}}
Data Protection Officer / privacy queries: {{DPO_EMAIL}}
2. Categories of Personal Data
We collect and process the following categories of personal data:
- Account data: name, email address, phone number (provided during agency setup or contact form submission)
- Authentication data: hashed passwords, session tokens, OTP codes
- Creator data: TikTok usernames, publicly available profile information (display name, avatar, follower count), streaming statistics (diamonds, hours, viewer counts) obtained via TikTok's public data
- Usage data: pages visited, features used, timestamps, IP addresses, browser user agent
- Communication data: support ticket contents, Telegram/Discord identifiers linked by users
- Cookie data: consent preferences, session identifiers (see our Cookie Policy)
3. Purposes of Processing
| Purpose | Lawful Basis (UK GDPR Art. 6) |
|---|---|
| Providing and maintaining the Platform | Performance of contract (Art. 6(1)(b)) |
| Account authentication and security | Legitimate interest (Art. 6(1)(f)) |
| Creator performance monitoring | Legitimate interest of agency management (Art. 6(1)(f)) |
| Responding to support tickets and enquiries | Performance of contract (Art. 6(1)(b)) |
| Platform analytics and improvement | Legitimate interest (Art. 6(1)(f)) |
| Legal compliance and fraud prevention | Legal obligation (Art. 6(1)(c)) |
| Marketing communications (with consent) | Consent (Art. 6(1)(a)) |
4. Recipients & Third Parties
We may share personal data with:
- Hosting providers: servers located in the United Kingdom
- TikTok: we access publicly available TikTok data; we do not share your data with TikTok
- Telegram / Discord: if you link your account, your username is used to deliver automated messages
- Law enforcement: where required by law or court order
We do not sell personal data.
5. International Transfers
Your data is primarily processed and stored in the United Kingdom. Where data is transferred outside the UK, we ensure appropriate safeguards are in place in accordance with UK GDPR Article 46, such as standard contractual clauses or adequacy decisions.
6. Retention Periods
| Data Category | Retention Period |
|---|---|
| Account data | Duration of account + 12 months after deletion |
| Creator statistics | Duration of agency membership + 6 months |
| Support tickets | 2 years from resolution |
| Audit logs | 12 months |
| Contact form submissions | 12 months |
| Session data | 24 hours |
7. Your Rights
Under UK GDPR, you have the following rights:
- Right of access (Art. 15) — request a copy of your personal data
- Right to rectification (Art. 16) — correct inaccurate data
- Right to erasure (Art. 17) — request deletion of your data
- Right to restrict processing (Art. 18)
- Right to data portability (Art. 20) — receive your data in a machine-readable format
- Right to object (Art. 21) — object to processing based on legitimate interest
- Right to withdraw consent — where processing is based on consent
To exercise any of these rights, contact {{DPO_EMAIL}}. We will respond within one calendar month.
8. Right to Lodge a Complaint
You have the right to lodge a complaint with the Information Commissioner's Office (ICO):
- Website: ico.org.uk
- Helpline: 0303 123 1113
- Address: Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF
9. Children's Data
The Platform is not intended for individuals under the age of 18. We do not knowingly collect personal data from children. If we become aware that we have collected data from a child, we will take steps to delete it promptly.
10. Changes to This Policy
We may update this policy from time to time. We will notify you of material changes via email or a notice on the Platform. The “last updated” date at the top of this page indicates when the policy was last revised.
11. Contact
For privacy-related enquiries:
- Email: {{DPO_EMAIL}}
- Address: {{REGISTERED_ADDRESS}}
