Last updated: 12 February 2026
1. Data Controller
Knoxlink, established in Houten, the Netherlands, and registered with the Dutch Chamber of Commerce under number 90900626 (hereinafter: “Knoxlink”), is the controller responsible for the processing of personal data described in this Privacy Policy.
Knoxlink processes personal data in accordance with the General Data Protection Regulation (GDPR).
2. Personal Data We Process – Creators
We may process the following personal data:
- Name
- Email address
- Date of birth
- Country of establishment
- Address details where required for payouts
- Bank account details where required for payouts
- Identity documents for verification or KYC
- IP address
- Usage and analytics data
- Data relating to revenue, transactions and payouts
3. Personal Data We Process – Users
We may process the following personal data:
- Email address
- Account data relating to account and platform use
- Date of birth where provided
- Country for geographic targeting
- IP address
- Usage and analytics data
4. Purposes and Legal Bases
We process personal data on the following bases:
- Performance of a contract, including account management, payouts, subscriptions and support
- Legal obligations, including tax retention requirements, KYC and sanctions legislation
- Legitimate interests, including fraud prevention, security and optimisation
- Consent for non-essential cookies where required
5. Cookies and Tracking
Knoxlink uses:
- Google Analytics
- Affiliate tracking scripts
- Server logs
- Custom tracking technologies
These technologies are used for analysis, platform improvement, fraud prevention and the accurate recording of affiliate transactions.
Where legally required, we request consent for non-essential cookies.
6. Retention Periods
- Account data: for as long as the account remains active.
- Financial data: 7 years in accordance with tax retention requirements.
- Analytics data: up to 14 months.
Data may be retained for longer where required by law or necessary for dispute resolution or fraud prevention.
7. Transfers Outside the EEA
Personal data may be processed outside the European Economic Area.
Where this occurs, Knoxlink implements appropriate safeguards such as Standard Contractual Clauses or other legally recognised protection mechanisms.
8. Data Subject Rights
Data subjects have the right to:
- Access
- Rectification
- Erasure
- Restriction of processing
- Data portability
- Object to processing
- Withdraw consent
A complaint may also be submitted to the Dutch Data Protection Authority (Autoriteit Persoonsgegevens).
9. Security
Knoxlink takes appropriate technical and organisational measures, including:
- A secured EU server environment
- SSL/TLS encryption
- Access restrictions
- Fraud monitoring
No system can guarantee complete security.
10. Minors
The Platform is not intended for persons under the age of 18 acting as Creators.
If personal data relating to minors has been collected unlawfully, it will be deleted as soon as possible.
11. Changes
Knoxlink reserves the right to amend this Privacy Policy.
The latest version is always available through the Platform.