GDPR
Compliance
Complete legal, privacy, and compliance policies
GDPR
Effective Date: June 18, 2025
Last Updated: June 18, 2025
This GDPR Notice provides additional information for users located in the European Economic Area (EEA), United Kingdom (UK), and Switzerland about how PopHop Technologies, Inc. processes your personal data under the General Data Protection Regulation (GDPR) and UK Data Protection Act.
This notice supplements our main Privacy Policy and should be read together with our Terms of Service and Cookie Policy.
Data Controller: PopHop Technologies, Inc.
2648 International Boulevard Ste 115 #1108
Oakland, CA 94601, US
Email: legal@pophopmail.us
EU Representative: We do not currently have a designated EU representative. As we grow our European operations, we will appoint one if required under GDPR Article 27.
Data Protection Officer: We do not currently have a designated Data Protection Officer. As our data processing activities expand, we will appoint one if required under GDPR Article 37.
What Personal Data We Process
Under GDPR, "personal data" means any information relating to you as an identified or identifiable person. We process the following categories of your personal data:
Identity and Contact Data
- Full name, username, email address
- Profile information and preferences
- Account authentication credentials
- Communication preferences
Community and Content Data
- Community memberships and participation history
- Posts, comments, messages, and other content you create
- Digital products and services you create or purchase
- Course materials and educational content access
- Event registrations and participation records
Transaction and Financial Data
- Payment information (processed securely through Stripe)
- Purchase history and transaction records
- Seller earnings and payout information
- Tax information where required by law
Technical and Usage Data
- IP address and general location data
- Device information and browser details
- Platform usage patterns and interaction data
- Performance and analytics information
Communication Data
- Messages sent through our platform
- Customer support interactions
- Marketing communication engagement
- Survey responses and feedback
Legal Bases for Processing
Under GDPR Article 6, we process your personal data based on the following legal grounds:
Legitimate Interests (Article 6(1)(f))
We process your data based on our legitimate interests for:
- Platform Security: Detecting fraud, preventing abuse, ensuring platform safety
- Service Improvement: Analytics, performance optimization, feature development
- Community Management: Enabling community creators to manage their members effectively
- Business Operations: Customer support, technical maintenance, business analytics
We have conducted legitimate interest assessments and believe these interests are not overridden by your fundamental rights and freedoms.
Contract Performance (Article 6(1)(b))
We process your data to perform our contract with you:
- Account Management: Creating and maintaining your user account
- Service Delivery: Providing community access, course delivery, marketplace functionality
- Transaction Processing: Facilitating payments between members and creators
- Platform Features: Enabling real-time messaging, notifications, and core functionality
Consent (Article 6(1)(a))
We process your data based on your consent for:
- Marketing Communications: Promotional emails and newsletters (you can withdraw consent anytime)
- Non-Essential Cookies: Analytics and marketing cookies as described in our Cookie Policy
- Optional Features: Additional services or features you explicitly opt into
Legal Obligations (Article 6(1)(c))
We process your data to comply with legal requirements:
- Tax Compliance: Maintaining transaction records for tax purposes
- Regulatory Requirements: Financial services and payment processing compliance
- Law Enforcement: Responding to valid legal requests and court orders
Your Rights Under GDPR
As a data subject under GDPR, you have the following rights:
Right of Access (Article 15)
You can request:
- Confirmation that we process your personal data
- A copy of your personal data in a structured, commonly used format
- Information about how we use your data and who we share it with
- Details about data retention periods and your other rights
Right to Rectification (Article 16)
You can request that we:
- Correct inaccurate personal data
- Complete incomplete personal data
- Update outdated information in your profile
Right to Erasure / "Right to be Forgotten" (Article 17)
You can request deletion of your personal data when:
- The data is no longer necessary for the original purpose
- You withdraw consent and no other legal basis applies
- You object to processing and no overriding legitimate grounds exist
- The data has been unlawfully processed
Exceptions: We may retain data when required for:
- Legal compliance and regulatory obligations
- Establishing, exercising, or defending legal claims
- Payout history for sellers (maintained for legal and financial reasons)
Right to Restrict Processing (Article 18)
You can request that we limit processing of your data when:
- You contest the accuracy of the data
- Processing is unlawful but you don't want erasure
- We no longer need the data but you need it for legal claims
- You have objected to processing pending verification of legitimate grounds
Right to Data Portability (Article 20)
You can request a copy of your data in a structured, machine-readable format and have it transmitted to another service provider when:
- Processing is based on consent or contract
- Processing is carried out by automated means
Right to Object (Article 21)
You can object to processing based on legitimate interests:
- General Right: Object to any processing based on legitimate interests
- Direct Marketing: Object to all direct marketing activities (absolute right)
- Automated Decision-Making: Object to solely automated decision-making
Rights Related to Automated Decision-Making (Article 22)
You have the right not to be subject to automated decision-making, including profiling, which produces legal effects or significantly affects you.
Current Status: We do not currently use automated decision-making systems. Future Development: When we implement AI features in Version 2, we will:
- Provide explicit notice of automated decision-making
- Obtain appropriate consent where required
- Provide meaningful information about the logic involved
- Offer the right to human intervention
How to Exercise Your Rights
Making a Request
To exercise your GDPR rights, contact us at:
- Email: legal@pophopmail.us
- Subject Line: "GDPR Rights Request"
- Include: Your full name, account email, and specific request details
Identity Verification
For security purposes, we may need to verify your identity before processing requests:
- Account login verification
- Additional identification for sensitive requests
- No Fees: Identity verification is always free of charge
Response Timeline
- Standard Response: Within 14 days (faster than the GDPR requirement of 30 days)
- Complex Requests: May take up to 30 days with advance notice
- Free of Charge: All requests are processed free of charge
- Excessive Requests: We may charge reasonable fees for manifestly unfounded or excessive requests
Request Tracking
We will:
- Acknowledge receipt of your request within 2 business days
- Provide status updates for complex requests
- Explain any delays or additional requirements
- Confirm completion of your request
International Data Transfers
Transfer Mechanisms
Your personal data may be transferred from the EEA/UK to the United States and other countries. We ensure adequate protection through:
Standard Contractual Clauses (SCCs):
- EU-approved standard contractual clauses for EEA transfers
- UK International Data Transfer Agreement (IDTA) for UK transfers
- Additional safeguards with third-party processors
Adequacy Decisions:
- We rely on European Commission adequacy decisions where available
Your Consent:
- In some cases, we may rely on your explicit consent for specific transfers
Third-Party Transfers
Our service providers in non-adequate countries are contractually required to:
- Implement appropriate technical and organizational measures
- Process data only on our instructions
- Notify us of any government access requests
- Assist with data subject rights requests
Transfer Details
For information about specific transfers or to request copies of safeguards, contact legal@pophopmail.us.
Data Retention Under GDPR
General Retention Principles
We retain personal data only as long as necessary for the purposes for which it was collected:
Active Accounts:
- Retained while your account is active and you use our services
- Regular review of data necessity and accuracy
Deleted Accounts:
- 14-day grace period for account reactivation
- Permanent deletion after grace period expires
Transaction Data:
- Seller payout history retained for legal and regulatory compliance
- Financial records maintained per applicable law requirements
Backup Systems:
- Deleted data removed from backups within 14 days
- Technical restoration may take additional time for complete removal
Specific Retention Periods
| Data Type | Retention Period | Legal Basis |
|---|---|---|
| Account Information | Account lifetime + 14 days | Contract performance |
| Community Content | Account lifetime + 14 days | Contract performance |
| Transaction Records | 7 years (sellers only) | Legal obligations |
| Support Communications | 3 years | Legitimate interests |
| Marketing Data | Until consent withdrawn | Consent |
| Security Logs | 12 months | Legitimate interests |
Cookies and Tracking
Cookie Consent
Under GDPR, we obtain your consent for non-essential cookies:
- Cookie Banner: Displayed on first visit with granular options
- Essential Cookies: Used without consent based on legitimate interests
- Analytics/Marketing Cookies: Require explicit consent
- Cookie Management: Update preferences anytime in account settings
For detailed information, see our Cookie Policy.
Tracking Technologies
We use various tracking technologies with appropriate legal bases:
- Essential Tracking: Platform functionality (legitimate interests)
- Analytics: User behavior analysis (consent or legitimate interests)
- Marketing: Advertising and social media integration (consent)
Data Security Measures
Technical Safeguards
- Encryption: Data encrypted in transit and at rest
- Access Controls: Role-based access to personal data
- Authentication: Multi-factor authentication for sensitive operations
- Network Security: Firewalls, intrusion detection, and monitoring
Organizational Measures
- Staff Training: Regular privacy and security training for all employees
- Data Minimization: Collect and process only necessary personal data
- Regular Audits: Quarterly security assessments and compliance reviews
- Incident Response: Documented procedures for data breach response
Breach Notification
In case of a personal data breach that poses risks to your rights and freedoms:
- Supervisory Authority: Notified within 72 hours
- Individual Notification: Notified without undue delay if high risk
- Mitigation: Immediate steps to address and minimize impact
Children's Data Protection
Age Requirements
- Minimum Age: 18 years old (above GDPR's digital consent age)
- Verification: Age verification during account registration
- No Children's Data: We do not knowingly process data of individuals under 18
Parental Rights
If we discover we have processed a child's data:
- Immediate deletion of the account and associated data
- Notification to parents/guardians where possible
- Review of verification procedures to prevent future occurrences
Supervisory Authority Rights
Your Right to Complain
If you believe we have not handled your personal data appropriately, you have the right to lodge a complaint with:
Your Local Supervisory Authority:
- Contact details available at: https://edpb.europa.eu/about-edpb/board/members_en
Lead Supervisory Authority (if applicable):
- We will determine our lead supervisory authority as our EU operations develop
Complaint Process
Before filing a complaint, we encourage you to:
- Contact us directly at legal@pophopmail.us
- Allow us to address your concerns
- Escalate to supervisory authority if unsatisfied
We are committed to resolving data protection concerns promptly and transparently.
Updates to This Notice
Amendment Process
We may update this GDPR Notice to reflect:
- Changes in data processing activities
- New legal requirements or guidance
- Enhanced privacy protections
- User feedback and improvements
Notification Methods
Material changes will be communicated through:
- Email notification to registered users
- Prominent notice on our platform
- Updated "Last Updated" date on this page
- Cookie banner updates where relevant
Continued Processing
Continued use of our services after notice of changes constitutes acceptance of the updated terms, except where additional consent is required.
Contact Information
Data Protection Inquiries
Email: legal@pophopmail.us
Subject: GDPR Inquiry
Response Time: Within 2 business days
Rights Requests
Email: legal@pophopmail.us
Subject: GDPR Rights Request
Response Time: Within 14 days
General Support
Email: support@pophopmail.us
Platform: In-app support feature
Postal Address
PopHop Technologies, Inc.
GDPR Compliance Team
2648 International Boulevard Ste 115 #1108
Oakland, CA 94601, US
Last Updated: June 18, 2025
We are committed to protecting your privacy rights under GDPR and providing transparent information about our data processing practices. This notice ensures you have complete information about your rights and how to exercise them.