1. INTRODUCTION
This Privacy Policy explains how Infee collects, processes, stores, and protects personal data in connection with the use of the Infee platform available at infee.io and app.infee.io (the “Platform”).
The Platform is operated by:
PIXEL ART, Marko Popović s.p.
Agrokombinatska cesta 6c, 1000 Ljubljana, Slovenia (“Infee”, “we”, “us”).
This Privacy Policy forms an integral part of the Master Terms of Use and related agreements.
2. ROLE UNDER DATA PROTECTION LAW
Depending on context, Infee may act as:
- Data Controller (e.g., for user account data, compliance data, billing data),
- Data Processor (e.g., when processing merchant customer data for tracking and attribution purposes).
Where Infee acts as processor, processing is governed by the Data Processing Agreement (DPA).
3. CATEGORIES OF PERSONAL DATA
Infee may collect and process the following categories of data:
3.1 Account Data
- Full name
- Email address
- Username
- Company name (if applicable)
- Business registration number
- VAT number (if applicable)
3.2 Tax & Regulatory Data
- Tax Identification Number (TIN)
- Country of tax residence
- Date of birth (for individuals)
- Beneficial ownership information (where applicable)
3.3 Payment & Payout Data
- Bank account details
- Transaction history
- Commission records
- Payment processing identifiers
Payment card data is processed directly by the relevant payment processor and is not stored by Infee.
3.4 Technical & Usage Data
- IP address
- Device information
- User agent
- Login timestamps
- Click tracking data
- Cookie identifiers
- Log files
3.5 Compliance Data
- Identity verification documents
- Fraud review data
- Communication records
4. PURPOSES OF PROCESSING
Personal data is processed for the following purposes:
- Account creation and management
- Commission calculation and payout processing
- Tracking and attribution
- Fraud detection and prevention
- Compliance with DAC7 and other legal obligations
- AML and identity verification
- Security and system monitoring
- Platform performance improvement
- Customer support
5. LEGAL BASIS FOR PROCESSING
Processing is based on:
- Article 6(1)(b) GDPR – performance of contract
- Article 6(1)(c) GDPR – compliance with legal obligations
- Article 6(1)(f) GDPR – legitimate interests (fraud prevention, platform security, business analytics)
Where required, consent may be obtained for specific processing activities.
6. DATA SHARING
Personal data may be shared with:
- Payment processing providers
- Hosting and infrastructure providers
- Fraud detection service providers
- Tax authorities (where legally required)
- Public authorities (where legally required)
Infee does not sell personal data.
7. INTERNATIONAL TRANSFERS
Where personal data is transferred outside the European Economic Area (EEA), appropriate safeguards are implemented, including:
- Standard Contractual Clauses (SCC)
- Transfers to jurisdictions with adequacy decisions
8. DATA RETENTION
Personal data is retained as follows:
- Account and business records: up to 5 years (or as required by law)
- Commission and financial records: as required under accounting law
- DAC7-related data: as required by tax legislation
- Technical logs: up to 12 months
- Cookie data: as defined in the Cookie Policy
Data may be retained longer where required for legal defense or regulatory compliance.
9. USER RIGHTS
Under GDPR, users have the right to:
- Access their personal data
- Rectify inaccurate data
- Request erasure (“right to be forgotten”)
- Restrict processing
- Data portability
- Object to processing based on legitimate interest
- Lodge a complaint with a supervisory authority
Requests may be submitted to the contact email provided below.
10. SECURITY MEASURES
Infee implements appropriate technical and organizational measures, including:
- Encrypted communication (HTTPS)
- Access control mechanisms
- Role-based system access
- Monitoring and logging
- Fraud detection tools
No system can guarantee absolute security; however, reasonable industry-standard measures are applied.
11. AUTOMATED DECISION-MAKING
Infee may use automated systems for:
- fraud detection,
- anomaly detection,
- traffic validation.
Such systems may impact commission eligibility. Users may request human review where applicable.
12. THIRD-PARTY LINKS
The Platform may contain links to external websites. Infee is not responsible for the privacy practices of third-party services.
13. POLICY UPDATES
This Privacy Policy may be updated periodically.
Updated versions will be published on the Platform.
Continued use of the Platform constitutes acceptance of updates.
14. CONTACT
For privacy-related inquiries, users may contact: [email protected] (or official contact address published on the Platform)
