How Affilobase collects and uses personal data, under the GDPR and the Belgian Data Protection Act.
Startup Solutions BV, Kortrijk, Belgium, company number BE 0XXX.XXX.XXX, operates Affilobase and is the controller for the personal data described here. Questions and requests go to info@affiliatemarketingprograms.net; we answer within 30 days.
We have not appointed a Data Protection Officer — our processing does not meet the criteria in Article 37 GDPR. The mailbox above is monitored by the people who can actually act on a request.
We do not collect special categories of data, we do not buy personal data from third parties, and we do not build advertising profiles.
When you open a program's website from Affilobase, the link may carry a tracking parameter that identifies us — not you — as the referrer. The advertiser or network then sets its own cookie under its own privacy policy, which we do not control and cannot read. We log that a click happened on a listing; we do not tie outbound clicks to your account.
We use a small number of processors, each under a data processing agreement: hosting and CDN, transactional and newsletter email, error monitoring, and privacy-friendly analytics. They act only on our instructions. We do not sell personal data and we do not share it with advertisers.
Our hosting and primary storage sit inside the EU. Where a processor operates outside the EEA, the transfer runs on the European Commission's Standard Contractual Clauses, plus an adequacy decision where one exists. A current list of processors and their locations is available on request.
You can request access, correction, erasure, restriction or portability, and you can object to processing based on legitimate interest. Consent can be withdrawn at any time without affecting what happened before. Mail info@affiliatemarketingprograms.net — we may ask one question to confirm it is your account before we act.
Not happy with the outcome? You can lodge a complaint with the Belgian Data Protection Authority, Drukpersstraat 35, 1000 Brussels, gegevensbeschermingsautoriteit.be, or with the authority in your own country.
Traffic runs over TLS, passwords are stored hashed and salted, access to production data is limited to the people who need it, and backups are encrypted. No system is perfect: if a breach is likely to put your rights at risk, we will tell you and the authority within 72 hours.
Material changes are announced on this page and, for account holders, by email at least 14 days before they take effect. The date at the top of the page is always the date of the version you are reading.