Политика конфиденциальности

Обновлено: апрель 2026

1. Data Controller

EyeLikeeIt ("we", "us") is the data controller for personal data processed through this platform. We operate as a B2B search engine indexing publicly available data from the Likee platform.

2. Data We Collect

User data (account holders): email address, name, organization name, billing information, usage logs.

Creator data (indexed from Likee): public profile information (username, nickname, bio, avatar), engagement metrics (fans, likes, video counts), and video metadata (hashtags, descriptions, post times).

Internal operational signals: platform staff may use restricted enrichment signals such as media URLs, creator-linked contact references, and monetization indicators for quality control, fraud analysis, and abuse prevention. These signals are not exposed to customer accounts, public APIs, or exports.

We do NOT collect: private messages, passwords, creator bank/payment account data, or data from accounts marked as private on Likee.

3. Legal Basis — GDPR Art. 6(1)(f) Legitimate Interest

We process publicly available Creator Data under GDPR Article 6(1)(f) — legitimate interest. Our legitimate interest is providing a B2B search engine and analytics service for the influencer marketing industry. This processing is analogous to web search engines indexing publicly available web pages.

We have conducted a Legitimate Interest Assessment (LIA) confirming that our processing is proportionate and does not override the fundamental rights of data subjects, given that: (a) all indexed data is publicly available; (b) creators voluntarily published this data; (c) we provide an opt-out mechanism.

4. Purpose of Processing

  • Providing creator search and discovery for B2B users
  • Calculating analytics (engagement rate, trust scores, growth trends)
  • Detecting fraudulent engagement patterns
  • Sending transactional and marketing emails to registered users
  • Processing payments for subscription services

5. Data Sharing

We share data with: (a) payment processors (Stripe, YooKassa) for billing; (b) email provider (Resend) for transactional and outreach email delivery; (c) OpenAI for batch content categorization; and (d) Google Gemini for fallback content categorization. The OpenAI batch contains public creator bio text, country, hashtags, and recent public video descriptions. Google Gemini receives the creator nickname, public bio, country, and internal numeric profile ID. Public creator text may contain names, contact details, or other personal information that a creator chose to publish; we do not describe this text as anonymized. We do NOT send registered-user passwords or payment credentials to OpenAI or Google Gemini, and we do NOT sell personal data to third parties.

6. Creator Opt-out (Right to Object)

Likee creators whose public data is indexed on our platform may request removal by emailing privacy@eyelikee.it with their Likee username. We will remove the profile within 30 days and add it to our exclusion list to prevent re-indexing.

7. Cookies

We use essential cookies only: (a) session cookie (HttpOnly, server-side session in Redis, no tracking); (b) a short-lived CSRF request-verification cookie that same-origin page code reads to attach a separate token to forms and requests; (c) locale preference (localStorage, not a cookie); (d) dark mode preference (localStorage). We do NOT use third-party tracking cookies, analytics trackers, or advertising pixels.

8. Data Retention

User accounts: account and organization records are retained while the account exists. Deletion and statutory-retention requests are handled through the privacy contact above; this policy does not promise an automated fixed deletion period that the product does not currently enforce.

Creator profile data: the current searchable profile remains in PostgreSQL until it is refreshed, removed through the creator opt-out process, or removed operationally. Historical time-series profile snapshots in ClickHouse automatically expire two years after their snapshot date.

Activity logs: a scheduled daily cleanup removes entries older than 90 days.

Audit logs: retained indefinitely with a tamper-evident hash chain. The runtime database role can append records but cannot update, delete, truncate, disable the protection, or own protected objects. This detects and blocks application-level tampering; it is not a claim that a database superuser or infrastructure administrator is cryptographically unable to alter stored data.

9. Security Measures

We implement: HTTPS/TLS, bcrypt password hashing (cost=12), server-side sessions (no JWT in cookies), AES-256-GCM encryption for sensitive system settings, PostgreSQL Row-Level Security for tenant isolation, rate limiting, and CSRF protection for state-changing browser requests. Payment and email-provider webhooks are excluded from CSRF because they use provider-specific authenticity checks. The unsubscribe action is excluded because every request requires a scoped, expiring signed token.

Baseline browser security headers are enforced. Content Security Policy is currently deployed in report-only monitoring mode while existing inline and approved external resources are inventoried and tested; enforcement is enabled only after browser regression checks show no blocked application resources.

10. Changes to This Policy

We may update this Privacy Policy from time to time. Material changes will be communicated via email to registered users at least 14 days before taking effect. Continued use of the Platform after changes constitutes acceptance.

Contact: privacy@eyelikee.it

↑↓ навигация выбрать esc закрыть