## Compliance

#### Complete legal, privacy, and compliance policies

## GDPR

**Effective Date:** June 18, 2025

**Last Updated:** June 18, 2025

This GDPR Notice provides additional information for users located in the European Economic Area (EEA), United Kingdom (UK), and Switzerland about how PopHop Technologies, Inc. processes your personal data under the General Data Protection Regulation (GDPR) and UK Data Protection Act.

This notice supplements our main [Privacy Policy](/content/compliance/privacy-policy/index.html) and should be read together with our [Terms of Service](/content/compliance/terms-of-service/index.html) and [Cookie Policy](/content/compliance/cookie-policy/index.html).

**Data Controller:** PopHop Technologies, Inc.

2648 International Boulevard Ste 115 #1108

Oakland, CA 94601, US

Email: legal@pophopmail.us

**EU Representative:** We do not currently have a designated EU representative. As we grow our European operations, we will appoint one if required under GDPR Article 27.

**Data Protection Officer:** We do not currently have a designated Data Protection Officer. As our data processing activities expand, we will appoint one if required under GDPR Article 37.

## What Personal Data We Process

Under GDPR, "personal data" means any information relating to you as an identified or identifiable person. We process the following categories of your personal data:

### Identity and Contact Data

- Full name, username, email address
- Profile information and preferences
- Account authentication credentials
- Communication preferences

### Community and Content Data

- Community memberships and participation history
- Posts, comments, messages, and other content you create
- Digital products and services you create or purchase
- Course materials and educational content access
- Event registrations and participation records

### Transaction and Financial Data

- Payment information (processed securely through Stripe)
- Purchase history and transaction records
- Seller earnings and payout information
- Tax information where required by law

### Technical and Usage Data

- IP address and general location data
- Device information and browser details
- Platform usage patterns and interaction data
- Performance and analytics information

### Communication Data

- Messages sent through our platform
- Customer support interactions
- Marketing communication engagement
- Survey responses and feedback

## Legal Bases for Processing

Under GDPR Article 6, we process your personal data based on the following legal grounds:

### Legitimate Interests (Article 6(1)(f))

We process your data based on our legitimate interests for:

- **Platform Security:** Detecting fraud, preventing abuse, ensuring platform safety
- **Service Improvement:** Analytics, performance optimization, feature development
- **Community Management:** Enabling community creators to manage their members effectively
- **Business Operations:** Customer support, technical maintenance, business analytics

We have conducted legitimate interest assessments and believe these interests are not overridden by your fundamental rights and freedoms.

### Contract Performance (Article 6(1)(b))

We process your data to perform our contract with you:

- **Account Management:** Creating and maintaining your user account
- **Service Delivery:** Providing community access, course delivery, marketplace functionality
- **Transaction Processing:** Facilitating payments between members and creators
- **Platform Features:** Enabling real-time messaging, notifications, and core functionality

### Consent (Article 6(1)(a))

We process your data based on your consent for:

- **Marketing Communications:** Promotional emails and newsletters (you can withdraw consent anytime)
- **Non-Essential Cookies:** Analytics and marketing cookies as described in our [Cookie Policy](/content/compliance/cookie-policy/index.html)
- **Optional Features:** Additional services or features you explicitly opt into

### Legal Obligations (Article 6(1)(c))

We process your data to comply with legal requirements:

- **Tax Compliance:** Maintaining transaction records for tax purposes
- **Regulatory Requirements:** Financial services and payment processing compliance
- **Law Enforcement:** Responding to valid legal requests and court orders

## Your Rights Under GDPR

As a data subject under GDPR, you have the following rights:

### Right of Access (Article 15)

You can request:

- Confirmation that we process your personal data
- A copy of your personal data in a structured, commonly used format
- Information about how we use your data and who we share it with
- Details about data retention periods and your other rights

### Right to Rectification (Article 16)

You can request that we:

- Correct inaccurate personal data
- Complete incomplete personal data
- Update outdated information in your profile

### Right to Erasure / "Right to be Forgotten" (Article 17)

You can request deletion of your personal data when:

- The data is no longer necessary for the original purpose
- You withdraw consent and no other legal basis applies
- You object to processing and no overriding legitimate grounds exist
- The data has been unlawfully processed

**Exceptions:** We may retain data when required for:

- Legal compliance and regulatory obligations
- Establishing, exercising, or defending legal claims
- Payout history for sellers (maintained for legal and financial reasons)

### Right to Restrict Processing (Article 18)

You can request that we limit processing of your data when:

- You contest the accuracy of the data
- Processing is unlawful but you don't want erasure
- We no longer need the data but you need it for legal claims
- You have objected to processing pending verification of legitimate grounds

### Right to Data Portability (Article 20)

You can request a copy of your data in a structured, machine-readable format and have it transmitted to another service provider when:

- Processing is based on consent or contract
- Processing is carried out by automated means

### Right to Object (Article 21)

You can object to processing based on legitimate interests:

- **General Right:** Object to any processing based on legitimate interests
- **Direct Marketing:** Object to all direct marketing activities (absolute right)
- **Automated Decision-Making:** Object to solely automated decision-making

### Rights Related to Automated Decision-Making (Article 22)

You have the right not to be subject to automated decision-making, including profiling, which produces legal effects or significantly affects you.

**Current Status:** We do not currently use automated decision-making systems. **Future Development:** When we implement AI features in Version 2, we will:

- Provide explicit notice of automated decision-making
- Obtain appropriate consent where required
- Provide meaningful information about the logic involved
- Offer the right to human intervention

## How to Exercise Your Rights

### Making a Request

To exercise your GDPR rights, contact us at:

- **Email:** legal@pophopmail.us
- **Subject Line:** "GDPR Rights Request"
- **Include:** Your full name, account email, and specific request details

### Identity Verification

For security purposes, we may need to verify your identity before processing requests:

- Account login verification
- Additional identification for sensitive requests
- **No Fees:** Identity verification is always free of charge

### Response Timeline

- **Standard Response:** Within 14 days (faster than the GDPR requirement of 30 days)
- **Complex Requests:** May take up to 30 days with advance notice
- **Free of Charge:** All requests are processed free of charge
- **Excessive Requests:** We may charge reasonable fees for manifestly unfounded or excessive requests

### Request Tracking

We will:

- Acknowledge receipt of your request within 2 business days
- Provide status updates for complex requests
- Explain any delays or additional requirements
- Confirm completion of your request

## International Data Transfers

### Transfer Mechanisms

Your personal data may be transferred from the EEA/UK to the United States and other countries. We ensure adequate protection through:

**Standard Contractual Clauses (SCCs):**

- EU-approved standard contractual clauses for EEA transfers
- UK International Data Transfer Agreement (IDTA) for UK transfers
- Additional safeguards with third-party processors

**Adequacy Decisions:**

- We rely on European Commission adequacy decisions where available

**Your Consent:**

- In some cases, we may rely on your explicit consent for specific transfers

### Third-Party Transfers

Our service providers in non-adequate countries are contractually required to:

- Implement appropriate technical and organizational measures
- Process data only on our instructions
- Notify us of any government access requests
- Assist with data subject rights requests

### Transfer Details

For information about specific transfers or to request copies of safeguards, contact legal@pophopmail.us.

## Data Retention Under GDPR

### General Retention Principles

We retain personal data only as long as necessary for the purposes for which it was collected:

**Active Accounts:**

- Retained while your account is active and you use our services
- Regular review of data necessity and accuracy

**Deleted Accounts:**

- 14-day grace period for account reactivation
- Permanent deletion after grace period expires

**Transaction Data:**

- Seller payout history retained for legal and regulatory compliance
- Financial records maintained per applicable law requirements

**Backup Systems:**

- Deleted data removed from backups within 14 days
- Technical restoration may take additional time for complete removal

### Specific Retention Periods

| Data Type                | Retention Period               | Legal Basis               |
|--------------------------|-------------------------------|---------------------------|
| Account Information      | Account lifetime + 14 days    | Contract performance       |
| Community Content        | Account lifetime + 14 days    | Contract performance       |
| Transaction Records      | 7 years (sellers only)       | Legal obligations          |
| Support Communications    | 3 years                       | Legitimate interests       |
| Marketing Data           | Until consent withdrawn        | Consent                   |
| Security Logs            | 12 months                     | Legitimate interests       |

## Cookies and Tracking

### Cookie Consent

Under GDPR, we obtain your consent for non-essential cookies:

- **Cookie Banner:** Displayed on first visit with granular options
- **Essential Cookies:** Used without consent based on legitimate interests
- **Analytics/Marketing Cookies:** Require explicit consent
- **Cookie Management:** Update preferences anytime in account settings

For detailed information, see our [Cookie Policy](/content/compliance/cookie-policy/index.html).

### Tracking Technologies

We use various tracking technologies with appropriate legal bases:

- **Essential Tracking:** Platform functionality (legitimate interests)
- **Analytics:** User behavior analysis (consent or legitimate interests)
- **Marketing:** Advertising and social media integration (consent)

## Data Security Measures

### Technical Safeguards

- **Encryption:** Data encrypted in transit and at rest
- **Access Controls:** Role-based access to personal data
- **Authentication:** Multi-factor authentication for sensitive operations
- **Network Security:** Firewalls, intrusion detection, and monitoring

### Organizational Measures

- **Staff Training:** Regular privacy and security training for all employees
- **Data Minimization:** Collect and process only necessary personal data
- **Regular Audits:** Quarterly security assessments and compliance reviews
- **Incident Response:** Documented procedures for data breach response

### Breach Notification

In case of a personal data breach that poses risks to your rights and freedoms:

- **Supervisory Authority:** Notified within 72 hours
- **Individual Notification:** Notified without undue delay if high risk
- **Mitigation:** Immediate steps to address and minimize impact

## Children's Data Protection

### Age Requirements

- **Minimum Age:** 18 years old (above GDPR's digital consent age)
- **Verification:** Age verification during account registration
- **No Children's Data:** We do not knowingly process data of individuals under 18

### Parental Rights

If we discover we have processed a child's data:

- Immediate deletion of the account and associated data
- Notification to parents/guardians where possible
- Review of verification procedures to prevent future occurrences

## Supervisory Authority Rights

### Your Right to Complain

If you believe we have not handled your personal data appropriately, you have the right to lodge a complaint with:

**Your Local Supervisory Authority:**

- Contact details available at: https://edpb.europa.eu/about-edpb/board/members_en

**Lead Supervisory Authority (if applicable):**

- We will determine our lead supervisory authority as our EU operations develop

### Complaint Process

Before filing a complaint, we encourage you to:

1. Contact us directly at legal@pophopmail.us
2. Allow us to address your concerns
3. Escalate to supervisory authority if unsatisfied

We are committed to resolving data protection concerns promptly and transparently.

## Updates to This Notice

### Amendment Process

We may update this GDPR Notice to reflect:

- Changes in data processing activities
- New legal requirements or guidance
- Enhanced privacy protections
- User feedback and improvements

### Notification Methods

Material changes will be communicated through:

- Email notification to registered users
- Prominent notice on our platform
- Updated "Last Updated" date on this page
- Cookie banner updates where relevant

### Continued Processing

Continued use of our services after notice of changes constitutes acceptance of the updated terms, except where additional consent is required.

## Contact Information

### Data Protection Inquiries

**Email:** legal@pophopmail.us

**Subject:** GDPR Inquiry

**Response Time:** Within 2 business days

### Rights Requests

**Email:** legal@pophopmail.us

**Subject:** GDPR Rights Request

**Response Time:** Within 14 days

### General Support

**Email:** support@pophopmail.us

**Platform:** In-app support feature

### Postal Address

PopHop Technologies, Inc.

GDPR Compliance Team

2648 International Boulevard Ste 115 #1108

Oakland, CA 94601, US

**Last Updated:** June 18, 2025

_We are committed to protecting your privacy rights under GDPR and providing transparent information about our data processing practices. This notice ensures you have complete information about your rights and how to exercise them._
