Introduction and Commitment to Privacy
This Privacy Policy (hereinafter referred to as the "Policy") describes how yFlix (hereinafter referred to as "Administrator," "we," "us," or "our") collects, uses, processes, stores, discloses, and protects information, including personal data, in connection with your access to and use of the website located at https://yflix.pl and all associated subpages, features, and services. The Administrator is committed to protecting the privacy and security of all Users and ensuring that any personal data processing activities are conducted in full compliance with applicable data protection laws and regulations, including but not limited to the General Data Protection Regulation (EU) 2016/679 ("GDPR") and other relevant national and international data protection legislation.
By accessing, browsing, or otherwise using this website, you acknowledge that you have read, understood, and agree to the terms of this Privacy Policy. If you do not agree with any aspect of this Policy, you must immediately cease using the website. This Privacy Policy should be read in conjunction with our Terms of Service, Cookie Policy, and any other applicable policies referenced herein. We encourage you to review this Policy periodically, as we may update it from time to time to reflect changes in our practices, technologies, legal requirements, and other factors.
Data Controller Information
For the purposes of applicable data protection legislation, the data controller responsible for the processing of personal data collected through this website is the operator of yFlix. The Administrator has implemented appropriate technical and organizational measures to ensure that all data processing activities comply with applicable data protection laws and to protect the rights and freedoms of data subjects. If you have any questions, concerns, or requests regarding the processing of your personal data, or if you wish to exercise any of your rights under applicable data protection legislation, please contact us through our Contact Us page or via the email address provided therein.
Nature of the Service and Data Processing Context
It is essential for Users to understand the nature of yFlix and how this affects the scope and purposes of personal data processing. This website operates exclusively as an informational, editorial, and affiliate marketing platform focused on content related to films, television series, streaming services, and the entertainment industry. We do not provide video-on-demand services, media streaming, content hosting, or any similar services. We do not require user registration, account creation, subscription services, or payment processing. Consequently, our data processing activities are significantly limited compared to typical online service providers.
yFlix does not collect, process, or store any of the following categories of data: user account credentials, login information, or authentication data; payment information, credit card numbers, bank account details, or any financial data; subscription preferences, viewing history, watch lists, or content consumption patterns; detailed user profiles, preferences, or personalization data; or any special categories of personal data (sensitive data) as defined under Article 9 of the GDPR. The data we process is limited to what is technically necessary for the operation of the website and the functioning of our affiliate marketing activities, as detailed in the following sections.
Categories of Data Processed
In the course of operating this website, we may process the following categories of data:
Server Log Data
Like most websites, our servers automatically collect and store certain information in server log files whenever you access the website. This data is collected automatically by our hosting infrastructure and includes: your Internet Protocol (IP) address, which may be anonymized or truncated depending on our server configuration; the date and time of your visit and each request made to our servers; the Uniform Resource Locator (URL) of the pages you access on our website; the referring URL, meaning the address of the webpage from which you navigated to our website; information about your web browser, including browser type, version, and language settings; information about your operating system and device type; and the amount of data transferred during your visit. This server log data is processed for the purposes of ensuring the technical functionality, security, and stability of our website infrastructure; detecting, preventing, and investigating potential security threats, attacks, or unauthorized access attempts; analyzing website performance and identifying technical issues or errors; and generating aggregated, non-identifying statistical information about website usage patterns. The legal basis for this processing is our legitimate interest in maintaining a secure, functional, and efficient website (Article 6(1)(f) GDPR).
Affiliate Tracking Data
As an affiliate marketing website, we work with third-party affiliate partners and networks. When you click on affiliate links on our website, certain data may be processed to track the referral and enable the calculation of affiliate commissions. This may include: a unique identifier or tracking code associated with our affiliate account; the timestamp of your click on the affiliate link; general information about the referring page on our website; and any additional parameters required by the specific affiliate program. It is important to note that this affiliate tracking is primarily handled by our affiliate partners through their own systems and cookies. We do not receive personally identifiable information about you from these affiliate tracking activities. The data we receive is limited to aggregated statistics about clicks, conversions, and commissions. The legal basis for any affiliate tracking data processed through our website is our legitimate interest in operating our affiliate marketing business model (Article 6(1)(f) GDPR) and, where applicable, your consent to the use of affiliate cookies (Article 6(1)(a) GDPR).
Contact Form Data
If you contact us through our Contact Us page or via email, we will process the personal data you voluntarily provide in your communication. This typically includes: your name or pseudonym, if provided; your email address; the subject and content of your message; and any other information you choose to include in your communication. This data is processed solely for the purpose of responding to your inquiry, addressing your concerns, and maintaining records of our communications. The legal basis for this processing is our legitimate interest in responding to communications from Users and potential Users (Article 6(1)(f) GDPR), or the performance of pre-contractual measures at your request (Article 6(1)(b) GDPR).
Cookies and Similar Technologies
This website uses cookies and similar technologies to ensure proper functionality and to support our affiliate marketing operations. Cookies are small text files that are placed on your device when you visit a website. For comprehensive information about the types of cookies we use, the purposes for which we use them, and how you can manage your cookie preferences, please refer to our dedicated Cookie Policy. In summary, we use strictly necessary cookies that are essential for the operation of our website and affiliate cookies placed by our partners to track referrals and enable commission calculations. We do not use cookies for behavioral advertising, user profiling, or cross-site tracking for marketing purposes.
Data Sharing and Disclosure
We do not sell, rent, trade, or otherwise transfer your personal data to third parties for their own marketing purposes. However, we may share data with the following categories of recipients in the circumstances described below:
Hosting and Infrastructure Providers
Our website is hosted on servers provided by third-party hosting companies. These providers may have access to server log data as part of their hosting services. We select hosting providers that offer adequate data protection guarantees and process data only on our instructions.
Affiliate Partners and Networks
When you click on affiliate links, our affiliate partners may collect data through their own tracking mechanisms, including cookies. This data is collected by the affiliate partners directly and is subject to their own privacy policies. We encourage you to review the privacy policies of any third-party services you access through our affiliate links.
Legal and Regulatory Requirements
We may disclose your data if required to do so by law or in response to valid requests by public authorities, such as courts or government agencies. We may also disclose data to protect and defend our legal rights, to prevent fraud or other illegal activities, or to protect the safety of our Users or the public.
Business Transfers
In the event of a merger, acquisition, reorganization, bankruptcy, or other similar event, your data may be transferred to a successor entity as part of the transferred business assets. We will provide notice of any such transfer and any choices you may have regarding your data.
International Data Transfers
Our website may be accessed from various countries around the world. Your data may be transferred to and processed in countries other than your country of residence, including countries that may not provide the same level of data protection as your home country. When we transfer data outside the European Economic Area (EEA), we ensure that appropriate safeguards are in place to protect your data, such as Standard Contractual Clauses approved by the European Commission, adequacy decisions, or other legally recognized transfer mechanisms.
Data Retention
We retain personal data only for as long as necessary to fulfill the purposes for which it was collected, as described in this Privacy Policy, or as required by applicable law. Server log data is typically retained for a limited period necessary for security monitoring and technical troubleshooting, after which it is automatically deleted or anonymized. Contact form data is retained for as long as necessary to address your inquiry and for a reasonable period thereafter to maintain records of our communications. We periodically review our data retention practices to ensure that we do not retain data longer than necessary.
Your Rights Under Data Protection Law
Under applicable data protection legislation, including the GDPR, you have certain rights regarding your personal data. Subject to applicable conditions and exceptions, these rights include:
Right of Access
You have the right to obtain confirmation as to whether or not personal data concerning you is being processed, and, where that is the case, access to the personal data and certain information about the processing, as specified in Article 15 of the GDPR.
Right to Rectification
You have the right to obtain the rectification of inaccurate personal data concerning you without undue delay. Taking into account the purposes of the processing, you also have the right to have incomplete personal data completed, including by means of providing a supplementary statement.
Right to Erasure (Right to Be Forgotten)
You have the right to obtain the erasure of personal data concerning you without undue delay in certain circumstances, such as when the data is no longer necessary for the purposes for which it was collected, when you withdraw consent on which the processing is based, or when the data has been unlawfully processed.
Right to Restriction of Processing
You have the right to obtain restriction of processing in certain circumstances, such as when you contest the accuracy of the data, when the processing is unlawful but you oppose erasure, or when you have objected to processing pending verification of legitimate grounds.
Right to Data Portability
You have the right to receive the personal data concerning you, which you have provided to us, in a structured, commonly used, and machine-readable format, and to transmit that data to another controller without hindrance, in certain circumstances.
Right to Object
You have the right to object, on grounds relating to your particular situation, to processing of personal data concerning you which is based on legitimate interests. We will cease processing unless we demonstrate compelling legitimate grounds for the processing which override your interests, rights, and freedoms, or for the establishment, exercise, or defense of legal claims.
Right to Withdraw Consent
Where processing is based on your consent, you have the right to withdraw that consent at any time, without affecting the lawfulness of processing based on consent before its withdrawal.
Right to Lodge a Complaint
You have the right to lodge a complaint with a supervisory authority, in particular in the Member State of your habitual residence, place of work, or place of the alleged infringement, if you consider that the processing of personal data relating to you infringes applicable data protection law.
To exercise any of these rights, please contact us through the means provided in this Policy. We will respond to your request within the timeframes required by applicable law. We may need to verify your identity before processing your request.
Data Security
We implement appropriate technical and organizational security measures designed to protect personal data against unauthorized access, alteration, disclosure, or destruction. These measures include, but are not limited to: secure hosting infrastructure with firewalls and intrusion detection systems; encryption of data in transit using HTTPS/TLS protocols; regular security assessments and updates to our systems; access controls limiting who can access personal data; and employee training on data protection and security practices. However, no method of transmission over the Internet or method of electronic storage is completely secure. While we strive to use commercially acceptable means to protect your data, we cannot guarantee its absolute security.
Children's Privacy
This website is not intended for children under the age of 16, and we do not knowingly collect personal data from children under 16. If we become aware that we have collected personal data from a child under 16 without verification of parental consent, we will take steps to delete that information. If you believe we might have any information from or about a child under 16, please contact us immediately.
Third-Party Websites
This website contains links to third-party websites, including our affiliate partners. This Privacy Policy applies only to yFlix and does not apply to any third-party websites. We are not responsible for the privacy practices, content, or security of any third-party websites. We encourage you to read the privacy policies of every website you visit, particularly before providing any personal information.
Changes to This Privacy Policy
We reserve the right to modify, amend, or update this Privacy Policy at any time and at our sole discretion. Any changes will be effective immediately upon posting the updated Policy on this page, and the date of the most recent revision will be indicated at the top or bottom of this document. Your continued use of the website following the posting of any changes constitutes your acceptance of those changes. We encourage you to review this Policy periodically to stay informed about how we are protecting your data.
Contact Information
If you have any questions, concerns, or requests regarding this Privacy Policy or our data processing practices, please do not hesitate to contact us through our Contact Us page. We are committed to addressing any concerns you may have and will endeavor to respond to your inquiries within a reasonable timeframe.