Privacy Policy
1. Who we are
Targetly S.A.S. (“Targetly”, “we”), domiciled in Barranquilla, Colombia, operates the Targetly platform for creator marketing campaigns. For questions about this policy or your data, write to admin@usetargetlyapp.com
2. Our two roles
- Controller. For the data of platform users — brands, agencies, and creators — Targetly is the data controller (in Colombia, “responsable del tratamiento”).
- Processor. When an agency or brand uploads personal data of its own clients or contacts, that customer is the controller and Targetly processes the data on its behalf under the Data Processing Annex at the end of this policy.
3. Data we collect
- Account and profile data: name, email, phone, company, and role. For creators: public profile information, portfolio, audience data (country, followers), and compensation preferences.
- Campaign data: briefs, shortlists, approvals, deliverables, and usage rights.
- Communications: messages sent within the platform and with our support team.
- Payment data: amounts, escrow status, invoices, and payout details. Card and bank details are collected and processed by our payment providers; we do not store full card numbers.
- Technical data: device, log, and cookie data (see Section 10).
We collect this data from you, from the organization that invites you, and — for public creator metrics — from publicly available sources.
4. Why we use your data, and on what legal basis
Where the EU General Data Protection Regulation (GDPR) applies, our legal bases are:
- Performance of a contract: providing the platform, running campaigns, and processing escrow payments.
- Legitimate interests: securing, improving, and supporting the platform, and preventing fraud.
- Consent: marketing emails and optional cookies. You can withdraw consent at any time.
- Legal obligation: invoicing, tax, and anti-money-laundering duties.
Under Colombian Law 1581 of 2012, we process your personal data with your prior authorization — which you grant when creating your account — or on another lawful basis, and in line with this policy, which serves as our data processing notice.
5. Who we share data with
- Other platform users, as needed to run campaigns: for example, agencies and brands see creator profiles, proposals, and deliverables.
- Service providers for hosting, payments, analytics, and support, bound by contracts that protect your data.
- Authorities, when the law requires it.
We do not sell personal data.
6. International transfers
Our providers may process data outside your country, including outside Colombia and the European Economic Area. When we transfer data of EU/EEA users, we rely on safeguards such as the European Commission’s Standard Contractual Clauses or adequacy decisions. Transfers of data collected in Colombia comply with Law 1581 of 2012 and its rules on international transfers.
7. How long we keep data
We keep your data while your account is active. Afterwards, we keep only what is needed for legal, accounting, or dispute-resolution purposes, and then delete or anonymize it.
8. Security
We protect data with measures including encryption in transit, access controls, per-user permissions, and escrow payment safeguards. No system is completely secure; if you detect an issue, contact us immediately.
9. Your rights
- If you are in the EU/EEA (GDPR): access, rectification, erasure, restriction, portability, objection, withdrawal of consent, and the right to complain to your supervisory authority.
- If your data is processed under Colombian Law 1581 of 2012: to know, update, rectify, and delete your data, revoke your authorization, and complain to the Superintendencia de Industria y Comercio (SIC).
To exercise your rights, write to admin@usetargetlyapp.com. We respond within the legal deadlines (GDPR: one month; Colombia: 10 business days for inquiries and 15 for claims).
10. Cookies
We use essential cookies to operate the platform and, with your consent, optional analytics cookies. You can manage optional cookies through the cookie banner or your browser settings.
With your consent, we use Hotjar by Contentsquare for heatmaps and session recordings. Recording starts only after you opt in. It collects a pseudonymous identifier, the pages you visit, and how you interact with them. Text you type into forms, and areas that contain sensitive information, are masked. You can change this choice at any time from Cookie preferences.
11. Minors
The platform is for users aged 18 or older. We do not knowingly process minors’ data; if we learn that we have, we will delete it without exception unless otherwise authorized by a parent or guardian.
12. Changes to this policy
We may update this policy. We will post the new version here and, for material changes, notify you by email or within the platform.
13. Contact
Targetly S.A.S., Barranquilla, Colombia — admin@usetargetlyapp.com
Data Processing Annex (business customers and agencies)
This Annex applies when a brand or agency (the “Customer”) uses the platform to process personal data for which the Customer is the controller — for example, contact data of its clients or creator lists it uploads. It forms part of the agreement between the Customer and Targetly and is drafted to the standard of Article 28 GDPR.
Under Colombian law, the Customer acts as “responsable” and Targetly as “encargado del tratamiento”.
A1. Details of the processing
Subject matter and duration: provision of the platform during the term of the agreement.
Nature and purpose: hosting, campaign management, in-platform communications, escrow payments, and reporting.
Data subjects: representatives and contacts of the Customer’s clients, and creators or contacts uploaded by the Customer.
Data types: identification and contact data, professional data, and campaign and payment data. The platform is not intended for special categories of data.
A2. Instructions
Targetly processes such data only on the Customer’s documented instructions — including this Annex and the settings the Customer configures — unless the law requires otherwise, in which case Targetly informs the Customer unless legally prohibited.
A3. Confidentiality and security
Persons authorized to process the data are bound by confidentiality. Targetly implements appropriate technical and organizational measures (Article 32 GDPR), including encryption in transit, access controls, logging, backups, and per-user permissions.
A4. Subprocessors
The Customer authorizes the use of subprocessors for hosting, payments, communications, and support. The current list is available upon request. Targetly will give 15 days’ notice of changes; the Customer may object on reasonable data protection grounds. Targetly remains responsible for its subprocessors.
A5. Assistance and breach notification
Taking into account the nature of the processing, Targetly assists the Customer with data subject requests, security, data protection impact assessments, and consultations with authorities. Targetly notifies the Customer without undue delay after becoming aware of a personal data breach affecting the Customer’s data, providing the information reasonably available.
A6. Transfers, deletion, and audits
International transfers follow Section 6 of this policy, incorporating Standard Contractual Clauses where required. At the end of the services, Targetly deletes or returns the data, at the Customer’s choice, unless the law requires further storage. Targetly makes available the information necessary to demonstrate compliance and allows audits on reasonable notice, at the Customer’s cost, and without endangering other customers’ data.
A7. Liability
Liability under this Annex is subject to the limitations agreed in the main agreement between the Customer and Targetly.