LEGAL
Privacy Policy
Effective date: [TO BE COMPLETED]
1. Controller and contact details
The controller is Utopia Online OÜ [CONFIRM], registration number 12179748 [CONFIRM], registered at [LEGAL ADDRESS], operating the MobItEasy network.
Privacy contact: [PRIVACY EMAIL]
Data Protection Officer, if appointed: [DPO CONTACT OR “NOT APPLICABLE”]
2. Data we collect
- Account and identity: name, login, email, company, registration and VAT numbers, country and verification documents.
- Communication: messenger service, username, profile link, support requests and correspondence.
- Campaign and traffic: clicks, conversions, placements, traffic source, device, IP address, user agent, identifiers, timestamps, GEO and fraud indicators.
- Financial: payment method, account details, invoices, balances, tax information and transaction history.
- Technical: login events, security logs, cookies, session data and platform usage.
- Third-party data: validation, conversion and fraud data received from advertisers, tracking providers, payment services and verification providers.
Please confirm the final list: [ADD OR REMOVE DATA CATEGORIES].
3. Purposes and legal bases
| Purpose | Typical legal basis |
|---|---|
| Create and administer partner accounts; provide tracking, reporting and support. | Performance of a contract. |
| Validate conversions, prevent fraud, protect accounts and enforce campaign rules. | Legitimate interests; legal obligations where applicable. |
| Process invoices, payments, accounting and tax records. | Contract and legal obligation. |
| Send essential service and campaign communications. | Contract and legitimate interests. |
| Send optional marketing communications. | Consent or legitimate interests, subject to applicable law and opt-out rights. |
| Analytics and non-essential cookies. | [CONSENT / OTHER BASIS — CONFIRM]. |
4. Fraud prevention and automated analysis
We may analyse IP addresses, devices, identifiers, traffic patterns, conversion behaviour and advertiser feedback to identify invalid traffic, duplicate activity, account abuse and security threats. This may include automated risk scoring followed by manual review.
If a decision produces legal or similarly significant effects solely through automated processing, describe the logic, significance, consequences and available human review here: [AUTOMATED DECISION DETAILS OR “NOT APPLICABLE”].
6. Recipients and processors
Data may be shared where necessary with advertisers, tracking and hosting providers, fraud-prevention and KYC vendors, professional advisers, payment providers, banks, accounting services and public authorities. Insert the principal vendors or link to a processor list: [VENDOR LIST OR URL].
We do not sell personal data for money. If “sale” or “sharing” has a broader meaning under an applicable law, complete the relevant disclosure: [CONFIRM].
7. International transfers
Data may be processed in the EEA and in [COUNTRIES]. Where data leave the EEA, specify the safeguard used, such as an adequacy decision, Standard Contractual Clauses or another lawful transfer mechanism: [TRANSFER SAFEGUARDS].
8. Retention
We retain data only as long as necessary for the stated purpose and applicable legal, accounting, tax, fraud and dispute requirements.
- Account and contract records:
[PERIOD] - Payment and tax records:
[PERIOD] - Traffic and fraud logs:
[PERIOD] - Support correspondence:
[PERIOD] - Cookie data:
[PERIOD]
9. Your rights
Subject to applicable law, you may request access, correction, deletion, restriction, portability or objection; withdraw consent at any time; and object to direct marketing. Withdrawal does not affect earlier lawful processing.
Send requests to [PRIVACY EMAIL]. We may verify your identity. You may lodge a complaint with the Estonian Data Protection Inspectorate or the supervisory authority in your country.
10. Security
We use appropriate organisational and technical safeguards designed to protect personal data. No system is completely secure. Add relevant measures without disclosing security-sensitive detail: [ACCESS CONTROLS / ENCRYPTION / BACKUPS / INCIDENT PROCESS].
11. Children
The Services are intended for business users aged 18 or older and are not directed to children. If we learn that a child provided personal data, we will take appropriate steps to delete it.
12. Updates and contact
We may update this Policy to reflect legal, technical or operational changes. Material changes will be communicated through the website, platform or registered email.
Privacy enquiries: [PRIVACY EMAIL]
Postal address: [LEGAL ADDRESS]
