Data Controller
The data controller responsible for personal data processed through the PHV Affiliate Program (phv-affiliate.com) is:
PHV Solutions d.o.o.
Zagreb, Republic of Croatia
Email: info@phv-solutions.com
Website: phv-solutions.com
This Privacy Policy applies to personal data collected through phv-affiliate.com in the context of our affiliate programme. It does not govern data collected by our other platforms (CreaticoAI, Lumina Events) as end-user products, which have their own privacy notices.
What Data We Collect
We collect the following categories of personal data from affiliate applicants and active affiliates:
| Category | Examples | Source |
|---|---|---|
| Identity data | First name, last name, username | You — during application |
| Contact data | Email address, website URL, social profile | You — during application |
| Payment data | PayPal email or bank account details (IBAN) | You — in Refersion dashboard |
| Tax data | VAT number, tax identification (if applicable) | You — upon request for invoicing |
| Performance data | Clicks, conversions, commissions earned, referral codes | Automatically — via Refersion tracking |
| Technical data | IP address, browser type, device, pages visited, time on site | Automatically — via cookies and server logs |
| Communications | Emails or messages exchanged with our team | You — via email or contact form |
How We Collect Data
- Directly from you — when you apply for the programme, set up your Refersion account, or contact us by email
- Automatically — through cookies, Refersion tracking pixels, and server logs when you use our website or affiliate links are clicked
- From third parties — from Refersion (affiliate management), Stripe (payment processing), and Google Analytics (web analytics)
Why We Process Your Data
We process your personal data on the following legal bases under GDPR:
Contractual necessity (Art. 6(1)(b) GDPR)
- Managing your affiliate account and application
- Tracking referrals and calculating commissions
- Processing and paying commissions
- Communicating with you about your account and earnings
Legitimate interests (Art. 6(1)(f) GDPR)
- Fraud prevention and detecting violations of our Terms of Service
- Improving our affiliate programme and website experience
- Analysing programme performance via aggregated analytics
Legal obligation (Art. 6(1)(c) GDPR)
- Maintaining payment and tax records as required by Croatian law
- Responding to lawful requests from regulatory authorities
Consent (Art. 6(1)(a) GDPR)
- Setting non-essential cookies (analytics, marketing) — you can withdraw consent at any time via our cookie settings
- Sending optional marketing communications about programme updates
Who We Share Data With
We do not sell your personal data. We share it only with trusted service providers acting as data processors under appropriate agreements:
| Recipient | Purpose | Location |
|---|---|---|
| Refersion Inc. | Affiliate tracking, dashboard, commission management | USA (SCCs apply) |
| Stripe Inc. | Commission payment processing | USA / EU (SCCs apply) |
| Google LLC | Analytics (GA4), advertising measurement | USA (SCCs apply) |
| Brevo (Sendinblue) | Transactional and programme emails | EU (France) |
| Vercel Inc. | Website hosting and delivery | USA / EU (SCCs apply) |
We may also disclose data to competent authorities when required by applicable law or to protect our legal rights.
International Data Transfers
Some of our service providers are located outside the European Economic Area (EEA), primarily in the United States. Where we transfer personal data to countries without an EU adequacy decision, we rely on Standard Contractual Clauses (SCCs) approved by the European Commission as the appropriate safeguard.
You can request a copy of the relevant transfer safeguards by contacting us at info@phv-solutions.com.
Data Retention
- Active affiliate account data — retained for the duration of your participation in the Programme
- Payment and commission records — retained for 7 years following the last transaction, as required by Croatian accounting and tax law
- Application data (rejected applicants) — deleted within 90 days of rejection
- Analytics data — retained for up to 26 months in Google Analytics, in line with GA4 default settings
- Email communications — retained for 3 years from last interaction unless a legal obligation requires longer retention
After the applicable retention period, data is securely deleted or anonymised.
Your Rights
As a data subject under the GDPR, you have the following rights regarding your personal data:
👁 Right of Access
Request a copy of the personal data we hold about you.
✏️ Right to Rectification
Request correction of inaccurate or incomplete data.
🗑 Right to Erasure
Request deletion of your data where there is no legal basis to retain it.
⏸ Right to Restriction
Request that we restrict processing while a dispute is resolved.
📦 Right to Portability
Receive your data in a structured, machine-readable format.
🚫 Right to Object
Object to processing based on legitimate interests or for direct marketing.
To exercise any of these rights, contact us at info@phv-solutions.com. We will respond within 30 days. You also have the right to lodge a complaint with the Croatian Data Protection Authority (AZOP) or the supervisory authority in your country of residence.
Cookies
We use cookies and similar tracking technologies on phv-affiliate.com. For full details of which cookies we use, their purpose, and how to control them, please see our Cookie Policy.
The most significant cookie from a privacy perspective is the Refersion tracking cookie (rfsn), which persists for 60 days and is essential to the operation of the affiliate programme.
Children's Privacy
Our affiliate programme is intended solely for adults aged 18 and over. We do not knowingly collect personal data from individuals under 18. If we become aware that we have inadvertently collected data from a minor, we will delete it promptly. If you believe we have collected data from a child, please contact us immediately at info@phv-solutions.com.
Changes to This Policy
We may update this Privacy Policy from time to time. When we make material changes, we will notify active affiliates via email and update the "Last updated" date at the top of this page. We encourage you to review this policy periodically.
Your continued use of phv-affiliate.com or participation in the Programme after any changes constitutes your acknowledgement of the updated policy.
Contact & DPO
For any questions, requests, or concerns regarding this Privacy Policy or your personal data, please contact us:
PHV Solutions d.o.o. — Data Privacy
Zagreb, Croatia · info@phv-solutions.com
Supervisory authority: AZOP — Croatian Personal Data Protection Agency