1Operator
The processing of account data is organised by representatives of the Oflly company (hereinafter "we", "the Operator"). For any questions about data: oflly@proton.me, Telegram @andyowner.
2Roles: controller and processor
Oflly is a B2B service for agencies, so our role depends on the category of data:
| Data category | Who is the controller | Our role |
|---|---|---|
| Accounts, login, notifications, company settings | Operator | Controller |
| Data the client company enters about its models, staff and operations | Client company | Processor (Art. 28 GDPR) |
We process data of the second category only on the client's instructions and only to provide the Service. The client is itself responsible for the legal basis of processing and for informing the people whose data it enters. The terms are set out in the offer and the data processing agreement (DPA), which is provided on request.
3What data is processed
Account data
- login and password hash — the password itself is not stored in plain text;
- role and access rights within the company;
- Telegram chat identifier — for 2FA codes, password recovery and notifications;
- login time and a log of significant actions.
Company data (entered by the client)
- models and their profiles: aliases, links to platform profiles, goals, socials;
- financial records: income, commissions, expenses, pay periods, payouts, advances and penalties;
- payout details (for example, wallets), content requests and their attachments.
Technical data
- IP address, browser information, server logs;
- login attempt log — to protect against password guessing;
- session cookies and localStorage data (section 5).
4Purposes and legal bases
| Purpose | Basis (GDPR) |
|---|---|
| Providing CRM functions, operating accounts | Performance of a contract — Art. 6(1)(b) |
| Security: 2FA, login limits, logging | Legitimate interest — Art. 6(1)(f); obligation to ensure security — Art. 32 |
| Processing data entered by a client about its people | Instruction of the client-controller — Art. 28 |
| Support and communication with the client | Performance of a contract / legitimate interest |
| Responses to mandatory requests from authorities | Legal obligation — Art. 6(1)(c) |
6Sub-processors
We do not sell or rent data. To operate the Service we engage providers acting under a contract:
| Provider | Purpose | Where |
|---|---|---|
| Hosting provider (orangewebsite) | Hosting the Service and storing data | Iceland (EEA) |
| Telegram Messenger | Delivery of 2FA codes and notifications via a bot | Outside the EEA (section 7) |
| OnlyMonster | Revenue sync via an API key — only if the client has connected the integration | Per the provider's terms |
7Transfers outside the EEA
Primary data storage is in the EEA (Iceland). Individual providers (for example, Telegram) may process data outside the EEA; such transfers rely on the mechanisms provided by the GDPR — in particular, standard contractual clauses (SCC) — in accordance with those providers' documentation.
8Retention periods
- account and company data — while the agreement is in force; after termination it is deleted or anonymised within a reasonable period, unless the law requires longer retention;
- attachments to content requests — deleted automatically after 60 days;
- security logs and login attempts — a limited period necessary to protect the Service;
- at a client's request, its company data is deleted in full (section 11).
9Security
We apply technical and organisational measures (Art. 32 GDPR):
- passwords are stored only as a hash; login is confirmed by a 2FA code in Telegram;
- connection over HTTPS; CSRF protection; a limit on the number of login attempts;
- full isolation of each company's data (multi-tenant architecture);
- separation of access rights (RBAC): each user sees only the sections and profiles permitted to them;
- logging of significant team actions.
10Incidents
If a personal data breach occurs that creates a risk to people's rights and freedoms, we will notify the supervisory authority within 72 hours of becoming aware of it, and where the risk is high — also the affected individuals and client-controllers (Art. 33–34 GDPR).
11Your rights
Under Art. 15–22 GDPR you may request:
- access — to find out what data about you is processed, and to receive a copy;
- rectification of inaccurate data;
- erasure ("the right to be forgotten");
- restriction of processing and objection to it;
- portability — company data is exported in JSON/CSV;
- withdrawal of consent — if processing is based on consent;
- to lodge a complaint with a data protection supervisory authority.
Requests are accepted at oflly@proton.me; the response time is up to one month. If your data was entered into the Service by our client (we being the processor), we will forward the request to it as the controller and help it comply.
12Age 18+
The Service is intended for business in the adult industry and is not designed for persons under 18; we do not knowingly collect their data. The client warrants that all persons whose data it enters are of full legal age — this condition is set out in the offer and the Rules.
13Changes
We may update this Policy. The current version is always available on this page; the date is in the header. We will give advance notice of material changes by reasonable means.
14Contacts
Questions about data processing: oflly@proton.me · Telegram @andyowner · Operator: representatives of the Oflly company.