Legal document

Privacy Policy

Version of 22 July 2026 · Prepared with regard to the GDPR (EU Regulation 2016/679)
This describes what data the Oflly service processes, for what purposes, on what legal grounds, who it may be shared with and what rights you have. In short: we collect only what the CRM needs to work, we do not sell data and we use no advertising trackers. This is a translation; in case of any discrepancy, the Russian version prevails.
Offer Privacy Service Rules

1Operator

The processing of account data is organised by representatives of the Oflly company (hereinafter "we", "the Operator"). For any questions about data: oflly@proton.me, Telegram @andyowner.

2Roles: controller and processor

Oflly is a B2B service for agencies, so our role depends on the category of data:

Data categoryWho is the controllerOur role
Accounts, login, notifications, company settingsOperatorController
Data the client company enters about its models, staff and operationsClient companyProcessor (Art. 28 GDPR)

We process data of the second category only on the client's instructions and only to provide the Service. The client is itself responsible for the legal basis of processing and for informing the people whose data it enters. The terms are set out in the offer and the data processing agreement (DPA), which is provided on request.

3What data is processed

Account data

  • login and password hash — the password itself is not stored in plain text;
  • role and access rights within the company;
  • Telegram chat identifier — for 2FA codes, password recovery and notifications;
  • login time and a log of significant actions.

Company data (entered by the client)

  • models and their profiles: aliases, links to platform profiles, goals, socials;
  • financial records: income, commissions, expenses, pay periods, payouts, advances and penalties;
  • payout details (for example, wallets), content requests and their attachments.

Technical data

  • IP address, browser information, server logs;
  • login attempt log — to protect against password guessing;
  • session cookies and localStorage data (section 5).
We follow the principle of minimisation: special categories of data are not requested. If a client enters excessive data into free-text fields, the obligation to ensure a legal basis rests with it as the controller.

4Purposes and legal bases

PurposeBasis (GDPR)
Providing CRM functions, operating accountsPerformance of a contract — Art. 6(1)(b)
Security: 2FA, login limits, loggingLegitimate interest — Art. 6(1)(f); obligation to ensure security — Art. 32
Processing data entered by a client about its peopleInstruction of the client-controller — Art. 28
Support and communication with the clientPerformance of a contract / legitimate interest
Responses to mandatory requests from authoritiesLegal obligation — Art. 6(1)(c)

5Cookies and localStorage

The Service uses only strictly necessary technologies:

  • session cookies — to keep you logged in after signing in;
  • CSRF token — protection of forms against request forgery;
  • localStorage — application data cache for speed and your interface settings.

There are no advertising cookies, pixels or third-party web analytics — which is why no tracking consent banner is needed: there is no tracking. Blocking essential cookies in the browser will make logging into the Service impossible.

6Sub-processors

We do not sell or rent data. To operate the Service we engage providers acting under a contract:

ProviderPurposeWhere
Hosting provider (orangewebsite)Hosting the Service and storing dataIceland (EEA)
Telegram MessengerDelivery of 2FA codes and notifications via a botOutside the EEA (section 7)
OnlyMonsterRevenue sync via an API key — only if the client has connected the integrationPer the provider's terms
The OnlyMonster API key is stored encrypted. There are no web analytics systems or advertising networks in the Service.

7Transfers outside the EEA

Primary data storage is in the EEA (Iceland). Individual providers (for example, Telegram) may process data outside the EEA; such transfers rely on the mechanisms provided by the GDPR — in particular, standard contractual clauses (SCC) — in accordance with those providers' documentation.

8Retention periods

  • account and company data — while the agreement is in force; after termination it is deleted or anonymised within a reasonable period, unless the law requires longer retention;
  • attachments to content requests — deleted automatically after 60 days;
  • security logs and login attempts — a limited period necessary to protect the Service;
  • at a client's request, its company data is deleted in full (section 11).

9Security

We apply technical and organisational measures (Art. 32 GDPR):

  • passwords are stored only as a hash; login is confirmed by a 2FA code in Telegram;
  • connection over HTTPS; CSRF protection; a limit on the number of login attempts;
  • full isolation of each company's data (multi-tenant architecture);
  • separation of access rights (RBAC): each user sees only the sections and profiles permitted to them;
  • logging of significant team actions.

10Incidents

If a personal data breach occurs that creates a risk to people's rights and freedoms, we will notify the supervisory authority within 72 hours of becoming aware of it, and where the risk is high — also the affected individuals and client-controllers (Art. 33–34 GDPR).

11Your rights

Under Art. 15–22 GDPR you may request:

  • access — to find out what data about you is processed, and to receive a copy;
  • rectification of inaccurate data;
  • erasure ("the right to be forgotten");
  • restriction of processing and objection to it;
  • portability — company data is exported in JSON/CSV;
  • withdrawal of consent — if processing is based on consent;
  • to lodge a complaint with a data protection supervisory authority.

Requests are accepted at oflly@proton.me; the response time is up to one month. If your data was entered into the Service by our client (we being the processor), we will forward the request to it as the controller and help it comply.

12Age 18+

The Service is intended for business in the adult industry and is not designed for persons under 18; we do not knowingly collect their data. The client warrants that all persons whose data it enters are of full legal age — this condition is set out in the offer and the Rules.

13Changes

We may update this Policy. The current version is always available on this page; the date is in the header. We will give advance notice of material changes by reasonable means.

14Contacts

Questions about data processing: oflly@proton.me · Telegram @andyowner · Operator: representatives of the Oflly company.