Privacy Policy
Chattersea DATA PROTECTION & PRIVACY POLICY
Effective Date: 11/09/2026
Version 1.0
1. Purpose
This document sets out the data protection and privacy principles and procedures applicable to Chattersea (“Agency”) in connection with its business activities. The Agency acts as an intermediary between advertisers, brands, agencies and content creators/influencers in connection with advertising, marketing and content-creation collaborations. The Agency is committed to processing personal data lawfully, fairly and transparently and to implementing appropriate technical and organisational measures to protect personal data.
2. Applicable
Legislation: The Agency processes personal data in accordance with the applicable data protection legislation, including:
Regulation (EU) 2016/679 of 27 April 2016 (General Data Protection Regulation – GDPR/RGPD); and
Organic Law 3/2018 of 5 December, on the Protection of Personal Data and Guarantee of Digital Rights (LOPDPGDD).
The Agency shall also comply with any other applicable legislation relating to the processing and protection of personal data.
3. Scope
This Policy applies to personal data processed by the Agency in connection with:
advertisers, brands and clients;
content creators, influencers and their representatives;
suppliers and service providers;
business contacts and prospective clients or collaborators;
individuals whose personal data is provided to the Agency in connection with a campaign or collaboration;
and the Agency’s employees, contractors or other personnel, where applicable.
4. Categories of Personal Data
Depending on the relationship and the services provided, the Agency may process:
identification and professional contact details;
email addresses and telephone numbers;
company and professional information;
social-media handles and publicly available professional information;
contractual and campaign-related information;
invoicing and payment information;
communications and correspondence;
information necessary to organise and manage advertising campaigns;
any other information strictly necessary for the relevant business purpose.
The Agency shall avoid collecting or processing special categories of personal data unless there is a specific lawful basis and a genuine business necessity to do so.
5. Purposes of Processing
Personal data may be processed for the following purposes:
managing relationships with clients and content creators;
identifying and introducing suitable content creators to advertisers;
negotiating and coordinating advertising and content-creation collaborations;
managing campaigns and commercial agreements;
communicating with clients, creators and other business contacts;
managing invoices, payments and accounting;
complying with legal and regulatory obligations;
maintaining business records;
and protecting the Agency’s legitimate business interests and exercising or defending legal claims where applicable.
Personal data shall not be used for purposes incompatible with those for which it was originally collected.
6. Lawful Basis
The Agency shall identify and document an appropriate legal basis for each processing activity, as applicable, including:
performance of a contract or taking steps at the request of the data subject prior to entering into a contract;
compliance with a legal obligation;
legitimate interests, where applicable and following the required balancing assessment;
and consent, where consent is legally required.
Consent shall not be treated as the default legal basis where another appropriate legal basis applies.
7. Data Minimisation and Accuracy
The Agency shall only collect and process personal data that is adequate, relevant and limited to what is necessary for the relevant purpose. Reasonable measures shall be taken to ensure that personal data is accurate and kept up to date where necessary.
8. Data Retention
Personal data shall not be retained for longer than necessary for the purposes for which it was collected. Retention periods shall take into account:
the purpose of the processing;
contractual and business requirements;
applicable accounting and tax obligations;
potential legal claims;
and any other applicable statutory retention requirements.
Once personal data is no longer required, it shall be securely deleted, anonymised or otherwise appropriately disposed of.
9. Sharing of Personal Data
The Agency may share relevant personal data with advertisers, clients, content creators, representatives, suppliers, professional advisers and service providers where this is necessary for the relevant business purpose and legally permitted. The Agency shall limit such disclosures to the information reasonably necessary for the relevant purpose. Where a third-party service provider processes personal data on behalf of the Agency, the Agency shall assess whether the provider acts as a data processor and, where required, establish the appropriate contractual arrangements.
10. International Transfers
Where personal data is transferred outside the European Economic Area, the Agency shall ensure that the transfer is carried out in accordance with the GDPR and applicable requirements concerning international transfers. Appropriate safeguards shall be implemented where required.
11. Data Subject Rights
Individuals whose personal data is processed by the Agency may exercise their applicable rights under data protection legislation, including:
access;
rectification;
erasure;
restriction of processing;
objection;
data portability, where applicable;
and withdrawal of consent where processing is based on consent.
Requests may be submitted to: team@chattersea.com
The Agency shall handle such requests in accordance with the applicable legal requirements.
12. Confidentiality and Security
The Agency shall implement appropriate technical and organisational measures designed to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure or access. Such measures may include:
access controls;
appropriate password and authentication practices;
secure storage and transmission of information;
confidentiality obligations;
appropriate use of cloud and third-party services;
regular review of access permissions;
and secure deletion of information when no longer required.
Access to personal data shall be limited to persons who require such access for legitimate business purposes.
13. Personal Data Breaches
Any suspected loss, unauthorised disclosure, unauthorised access or other personal-data security incident shall be reported internally as soon as reasonably possible.
The Agency shall assess the incident and, where required, notify the competent supervisory authority and/or affected individuals in accordance with applicable legislation.
14. Records of Processing Activities
The Agency shall maintain appropriate records of its processing activities where required by the GDPR. The records shall reflect the Agency’s actual processing activities and shall be reviewed and updated when material changes occur.
15. Data Protection by Design and by Default
Where new processes, services, tools or technologies involve the processing of personal data, the Agency shall consider data-protection requirements from the outset and shall seek to minimise the amount of personal data collected and processed. Where a processing activity is likely to result in a high risk to individuals’ rights and freedoms, the Agency shall assess whether a Data Protection Impact Assessment (DPIA/EIPD) is required.
16. Accountability and Review
The Agency shall maintain appropriate documentation and evidence demonstrating its compliance with applicable data protection requirements. This Policy shall be reviewed periodically and whenever there are material changes to the Agency’s activities, processing operations, applicable legislation or relevant risks.
Last reviewed: 11/09/2026
Approved by: CEG [Founder]
