Our approach. We collect only the data we actually need to run FlixTok, we keep it no longer than necessary, and we do not sell it. This preamble is provided for readability and does not replace the sections below.
1. Who We Are; Scope
1.1 This Privacy Policy (the “Policy”) describes how FlixTok Inc OÜ processes the personal data of Users in connection with the use of the FlixTok platform: the website flixtok.com, the FlixTok mobile applications and any related services (the “Platform”).
1.2 FlixTok Inc OÜ is the controller of personal data within the meaning of Regulation (EU) 2016/679 (the “GDPR”). The processing of Creators’ data in the Myflixtok service is described in the separate Myflixtok Privacy Policy.
1.3 Contact for personal data matters: legal@flixtok.com. A Data Protection Officer (DPO) has not been appointed.
1.4 This Policy is an information document provided pursuant to Articles 13–14 GDPR and does not require your consent.
2. What Data We Process
2.1 Account data: email, username (nickname), settings; where you sign in via third-party services (Google, Apple) — basic profile data received from the relevant provider in accordance with your settings.
2.2 Usage data: Content viewed, interaction history, Comments and reactions.
2.3 Transaction data: status, date and amount of payments, access purchased. We do not store payment card details — these are processed by payment providers and application stores.
2.4 Consent records: records of your consent to the immediate supply of digital content and your acknowledgement of the loss of the 14-day right of withdrawal (time, version of the consent text, transaction identifier).
2.5 Age data: confirmation of having reached a certain age (e.g. 18) for access to the relevant Content, without collecting a full date of birth unless required by law.
2.6 Technical data: IP address, device type, operating system and browser, unique device identifiers, network data, access logs, error and performance data.
2.7 Communications and complaints: support requests, infringement notices, refund requests and related correspondence; deleted or hidden Comments — in archival storage (Section 6).
3. Purposes and Legal Bases of Processing
3.1 Creating and maintaining the account, providing access to the Platform and Content — performance of a contract (Art. 6(1)(b) GDPR).
3.2 Processing payments and providing access to paid Content — performance of a contract.
3.3 Recording and storing consent records (clause 2.4) — legal obligation (Art. 6(1)(c)) and legitimate interest in defending against claims (Art. 6(1)(f)).
3.4 Personalization and recommendations, analytics and improvement of the Platform — legitimate interest (Art. 6(1)(f)); you have the right to object (Section 7). The main parameters of our recommender systems are described pursuant to Art. 27 of Regulation (EU) 2022/2065 (the “DSA”) in the help center.
3.5 Security, detection and investigation of fraud and violations of the Terms — legitimate interest and legal obligation.
3.6 Handling complaints and notices of illegal content, providing statements of reasons, reporting on moderation decisions (DSA) — legal obligation.
3.7 Accounting for transactions and tax obligations — legal obligation (Art. 6(1)(c)).
3.8 Service messages (account, changes to terms, security) — performance of a contract and legitimate interest.
3.9 Marketing communications — exclusively with consent (Art. 6(1)(a)); consent may be withdrawn at any time without affecting prior processing.
4. Who We Share Data With
4.1 Processors (process data on our instructions): hosting and data storage, content delivery (CDN), email/communication services, analytics, support tools. A data processing agreement (Art. 28 GDPR) is concluded with each.
4.2 Independent controllers: payment providers (including Stripe) and application stores (App Store, Google Play) process your payment data under their own policies.
4.3 Public authorities: courts, law enforcement, tax and supervisory authorities — on the basis of lawful requests or legal obligations, including notifications under Art. 18 DSA of suspected criminal offences involving a threat to the life or safety of persons.
4.4 Successors: in the event of a reorganization, merger or sale of the business, data may be transferred to a successor in compliance with data protection requirements.
4.5 We do not sell personal data and do not share it with third parties for their own marketing.
5. International Transfers
5.1 Data may be processed outside the EEA. In such cases we apply the mechanisms provided for by the GDPR: European Commission adequacy decisions, standard contractual clauses (SCCs) with supplementary measures, or other lawful transfer mechanisms. A copy of the relevant safeguards can be requested via the contact in clause 1.3.
6. Retention Periods
6.1 We keep data only for as long as necessary for the purposes of processing, after which we delete it or irreversibly anonymize it. Specific periods:
(a) Account data and account content
Retention period: For the life of the account; after a deletion request — deactivation and final deletion under the Account Deletion Policy (30-day grace period)
Basis: Art. 6(1)(b) GDPR
(b) Deleted Comments, moderation logs (archive)
Retention period: Up to 3 years from deletion (general limitation period in Estonia)
Basis: Art. 6(1)(f), 17(3)(e) GDPR
(c) Complaint, dispute and investigation files
Retention period: Only the files of the relevant dispute: until proceedings are completed or limitation periods expire (up to 10 years for intentional violations, § 146(4) of the General Part of the Civil Code Act (TsÜS))
Basis: Art. 6(1)(f), 17(3)(e) GDPR
(d) Consent records (immediate supply, loss of right of withdrawal)
Retention period: 3 years from the transaction date (limitation period)
Basis: Art. 6(1)(c), 6(1)(f) GDPR
(e) Accounting records of transactions
Retention period: 7 years (Estonian Accounting Act)
Basis: § 12 of the Estonian Accounting Act; Art. 6(1)(c) and Art. 17(3)(b) GDPR
(f) Technical and access logs
Retention period: 12 months
Basis: Art. 6(1)(f) GDPR
(g) Backups
Retention period: Rotation cycle — up to 90 days after deletion of the primary data
Basis: Art. 6(1)(f) GDPR
(h) Marketing data
Retention period: Until consent is withdrawn
Basis: Art. 6(1)(a) GDPR
6.2 The procedure for deleting an account, and retention after deletion, is described in the Account Deletion Policy.
7. Your Rights
7.1 You have the rights provided by the GDPR: access to your data and a copy of it; rectification of inaccurate data; erasure (the “right to be forgotten”); restriction of processing; data portability in a machine-readable format; objection to processing based on legitimate interest (including objection to personalization); withdrawal of consent at any time; and the right not to be subject to a decision based solely on automated processing with significant effects.
7.2 Exercise of rights: send a request to legal@flixtok.com or use your account settings. We may ask you to confirm your identity. We respond within one month (this may be extended by two months for complex requests, with notice).
7.3 Limitations: the rights to erasure and objection do not apply to data we are obliged or entitled to retain under Art. 17(3) GDPR (legal obligations, defence of legal claims) — see the list in Section 6.
7.4 Complaint: you may contact the Estonian supervisory authority — Andmekaitse Inspektsioon (AKI), Tatari 39, 10134 Tallinn, www.aki.ee — or the supervisory authority of your place of residence in the EU/EEA.
8. Cookies and Similar Technologies
8.1 The Platform uses cookies, SDKs, pixels and local storage of the following categories: necessary (site operation, sessions, security — without consent), analytics, functional and marketing (with consent given via the banner; consent may not be pre-ticked).
8.2 The current list of cookies, with providers and retention periods, is available in the Cookie Settings on flixtok.com, where consent can be changed or withdrawn at any time. Details are set out in the Cookie Policy, which forms part of this Policy.
8.3 Cookies can also be managed via browser or device settings; refusing necessary cookies may limit the operation of the Platform.
9. Security
9.1 We apply technical and organizational measures: encryption in transit (TLS) and of sensitive data at rest, access restrictions on a need-to-know basis, access logging, and regular testing and updating of protections. Archival storage is isolated from public access.
9.2 No method of transmission or storage is absolutely secure. In the event of a personal data breach that creates a risk to your rights, we will notify the supervisory authority within 72 hours and, if the risk is high, notify you directly (Arts. 33–34 GDPR).
10. Children’s Data
10.1 The Platform is not intended for persons under 13; we do not knowingly collect their data, and we delete such data when identified. Persons aged 13–18 use the Platform with parental/guardian consent in accordance with the Terms of Use; certain Content and features are available only from 18.
11. Automated Decisions
11.1 We may apply automated checks to prevent fraud and protect payments. Where an automated decision has significant effects (e.g. blocking an account), you have the right to human review of the decision, to express your point of view and to contest the decision (Art. 22 GDPR; for moderation decisions — under the Complaints Policy).
12. Changes to This Policy
12.1 We may update this Policy. We will give notice of material changes at least 15 (fifteen) days in advance (in line with Section 18 of the Terms of Use) via the application, the website or email. An archive of previous versions is available on request.
12.2 Questions about this Policy: legal@flixtok.com.