> LEGAL DOCUMENTATION

PRIVACY POLICY

Last updated: August 11, 2026

01. INTRODUCTION

ProtectPPC ("we," "us," or "our") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our click fraud protection service.

Please read this Privacy Policy carefully. By using the Service, you consent to the data practices described in this policy.

02. INFORMATION WE COLLECT

Account Information:

  • Name and email address
  • Company name and billing address
  • Payment information (processed securely by Paddle)
  • Account preferences and settings

Click Data:

  • IP addresses of visitors to your landing pages
  • Device fingerprints and browser information
  • Geographic location data
  • Behavioral data (mouse movements, scroll patterns, time on page)
  • Referrer and campaign information

Processor role: Click Data describes visitors of our customers' websites. For this data ProtectPPC acts as a data processor under Article 28 GDPR, processing it solely on documented instructions of the customer (the data controller). The terms of this processing are set out in our Data Processing Agreement.

Technical Data:

  • Browser type and version
  • Operating system
  • Access times and dates
  • Pages viewed within our dashboard

03. HOW WE USE YOUR INFORMATION

We use the collected information for:

  • Fraud Detection: Analyzing click patterns to identify and block fraudulent traffic
  • Service Provision: Operating, maintaining, and improving our Service
  • Account Management: Managing your account and subscription
  • Communication: Sending service updates, alerts, and marketing communications (with consent)
  • Analytics: Understanding how users interact with our Service
  • Legal Compliance: Meeting legal obligations and protecting our rights

04. DATA SHARING

We may share your information with:

  • Service Providers: Third parties that help us operate our Service (hosting, payment processing, analytics)
  • Advertising Platforms: Google, Microsoft, and Meta for IP exclusion synchronization (only IP addresses)
  • Legal Requirements: When required by law or to protect our rights
  • Business Transfers: In connection with a merger, acquisition, or sale of assets

Sub-processors we currently use:

  • IPQualityScore (USA): IP address reputation lookups (VPN/proxy/bot detection)
  • MaxMind: IP geolocation — resolved against a local database copy, no data is transmitted
  • Paddle: Payment processing (merchant of record)
  • Zoho ZeptoMail (EU): Transactional e-mail delivery
  • Sentry: Error monitoring (technical diagnostics)
  • Google Ads API: Synchronization of blocked IP addresses (IP addresses only)

WE DO NOT SELL YOUR PERSONAL DATA TO THIRD PARTIES.

05. DATA RETENTION

We retain your data for as long as necessary to provide the Service and fulfill the purposes outlined in this policy:

  • Account Data: Retained while your account is active, plus 30 days after deletion
  • Click Data: Retained for 90 days by default (configurable in settings)
  • Billing Records: Retained for 7 years for tax and legal compliance

06. DATA SECURITY

We implement industry-standard security measures to protect your data:

  • Encryption in transit (TLS 1.3) and at rest (AES-256)
  • Regular security audits and penetration testing
  • Access controls and authentication mechanisms
  • Secure data centers with physical security
  • Regular backups and disaster recovery procedures

However, no method of transmission over the Internet is 100% secure. We cannot guarantee absolute security.

07. YOUR RIGHTS

Depending on your location, you may have the following rights:

  • Access: Request a copy of your personal data
  • Correction: Request correction of inaccurate data
  • Deletion: Request deletion of your data
  • Portability: Receive your data in a portable format
  • Objection: Object to certain processing activities
  • Withdrawal: Withdraw consent for marketing communications

To exercise these rights, please contact us at [email protected]

Legal bases (GDPR): performance of a contract (Art. 6(1)(b)) for account and billing data; legitimate interest (Art. 6(1)(f)) — fraud prevention — for click data processed on behalf of our customers.

Complaints: You also have the right to lodge a complaint with a supervisory authority — in Poland, the President of the Personal Data Protection Office (PUODO, uodo.gov.pl), or the authority in your EU member state.

08. COOKIES AND TRACKING

We use cookies and similar tracking technologies. For detailed information, please see our Cookie Policy.

09. INTERNATIONAL TRANSFERS

Your data may be transferred to and processed in countries other than your own. We ensure appropriate safeguards are in place for such transfers, including Standard Contractual Clauses approved by relevant authorities.

10. CHILDREN'S PRIVACY

Our Service is not directed to individuals under 18. We do not knowingly collect personal information from children. If you become aware that a child has provided us with personal information, please contact us.

11. CHANGES TO THIS POLICY

We may update this Privacy Policy from time to time. We will notify you of any material changes by email or through a prominent notice on our Service. Your continued use of the Service after such changes constitutes acceptance of the updated policy.

12. DATA CONTROLLER

The data controller for your personal data is:

Nutrigen Sp. z o.o.

ul. Tadeusza Kościuszki 25/5

50-011 Wrocław, Poland

NIP: 8971881125

KRS: 0000851334

If you have questions about this Privacy Policy or our data practices, please contact us at the email address above.