Back
Zinkly Zinkly

Privacy Policy

Last updated 2026-10-10

Last updated: 25 August 2026

1. Who is responsible for your data

Zinkly is operated from Corfu, Greece and acts as the data controller for the personal data described in this notice, contactable at zinklystudio@gmail.com ("we", "us"). See our Legal Notice for our current operating status. This notice explains what personal data Zinkly processes, why, on what legal basis, and what rights you have under the EU General Data Protection Regulation (GDPR) and Greek data protection law.

2. What data we collect

  • Account data: username, name, email address, password (hashed), date of birth (for age verification), profile details you choose to add (bio, location, website, avatar/cover images).
  • Content: posts, comments, reactions, stories, reels, messages, media you upload, hashtags, polls.
  • Technical data: IP address at registration and login, device/browser user-agent, session data, login history, and (if your platform supports it) online/last-seen status.
  • Usage data: interactions such as likes, follows, views, notification preferences.
  • Communications data: support requests, reports you file or that are filed against you, moderation and appeal correspondence.
  • Payment data (VIP subscriptions): we do not store full card numbers; payments are processed via PayPal or bank transfer, and we retain only transaction references, amounts, and status needed for our own records and tax obligations.
  • Cookies and similar technologies: see our Cookie Policy.

3. Why we process your data and our legal basis

PurposeLegal basis (GDPR Art. 6)
Creating and operating your account, delivering the core service (feed, messaging, notifications)Performance of a contract (Art. 6(1)(b))
Trust & safety: content moderation, spam/fraud prevention, enforcing our TermsLegitimate interests (Art. 6(1)(f)) and legal obligation (Art. 6(1)(c)) where applicable
Responding to legal requests, illegal-content notices, and law-enforcement requestsLegal obligation (Art. 6(1)(c)) and legitimate interests
Non-essential cookies, analytics, personalisation, advertising (where enabled)Consent (Art. 6(1)(a)) — withdrawable at any time via Cookie settings
Sending you service notifications and (opt-in) marketingContract / legitimate interests for service messages; consent for marketing
Processing VIP subscription paymentsPerformance of a contract; legal obligation for accounting/tax records

4. Who we share data with

We do not sell your personal data. We share data only with:

  • Service providers acting on our instructions (hosting/infrastructure, email delivery, push notifications, payment processing) under data-processing agreements;
  • Other users, to the extent your profile, posts, or activity are visible per your privacy settings;
  • Third-party integrations you choose to use (e.g. "Login via Google", music-preview search), limited to what's needed for that feature and governed by that provider's own privacy terms for their part of the processing;
  • Authorities, where legally required — see our Law Enforcement Requests Policy; we scrutinise every request and disclose only what the law requires.

5. International transfers

Where any service provider we use is located outside the European Economic Area, we ensure an appropriate safeguard is in place (such as the European Commission's Standard Contractual Clauses or an adequacy decision) before transferring personal data there.

6. How long we keep your data

See our Data Retention Policy for full detail. In summary: account and content data is kept while your account is active; upon deletion, most personal data is erased or anonymised within 30 days, except where we must retain limited records longer for legal, tax, fraud-prevention, or dispute-resolution purposes.

7. Your rights

Under the GDPR, you have the right to:

  • Access the personal data we hold about you;
  • Rectify inaccurate or incomplete data;
  • Erase your data ("right to be forgotten"), subject to legal retention exceptions;
  • Export/port your data in a structured, machine-readable format;
  • Restrict processing in certain circumstances;
  • Object to processing based on legitimate interests, including profiling for direct marketing;
  • Withdraw consent at any time where processing is based on consent, without affecting prior lawful processing.

Most of these can be exercised directly in Settings → Privacy & Data (download your data, correct your profile, delete your account, manage cookie and advertising preferences). For anything not self-serviceable, email zinklystudio@gmail.com; we will respond within one month as required by GDPR Art. 12(3).

You also have the right to lodge a complaint with a supervisory authority — in Greece, the Hellenic Data Protection Authority (Αρχή Προστασίας Δεδομένων Προσωπικού Χαρακτήρα), or the supervisory authority of your own EU member state.

8. Automated decision-making

Some content moderation involves automated classification (see our Content Moderation Policy). Automated actions that significantly affect you (such as account suspension) are subject to human review on appeal — see our Appeals Policy. We do not use fully automated decision-making with legal or similarly significant effect without a human-review safeguard.

9. Children

Zinkly is for people aged 18 and over and is not directed at children. We do not knowingly collect personal data from minors — see our Child & Minor Safety Policy.

10. Security

We use technical and organisational measures appropriate to the risk, including encrypted connections (HTTPS), hashed passwords, access controls, and monitoring. See our internal Data Retention and incident-response commitments below.

11. Changes to this notice

We will post updates here and, for material changes, notify you in-app or by email in advance of the change taking effect.

12. Contact

Data Protection queries: zinklystudio@gmail.com. General contact: Legal Notice.