Privacy Policy
Last updated: August 5, 2026
1. Introduction
1.1. The protection of personal data is a fundamental priority of the Company. This Privacy Policy describes how the Company collects, uses, stores, discloses and otherwise processes the personal data of Users of the Platform.
1.2. This Privacy Policy applies to all Users of the Platform, whether acting as Creators or Businesses.
By creating an Account, connecting a social media account or otherwise using the Platform, each User acknowledges that they have read and understood this Privacy Policy.
1.3. This Privacy Policy forms an integral part of the Terms and Conditions of the Platform. Capitalised terms used in this Privacy Policy, unless otherwise defined herein, shall have the meanings assigned to them in the Terms and Conditions.
2. Data Controller
2.1. The Data Controller responsible for the processing of personal data described in this Privacy Policy is:
Company: THE HYPE NETWORK P.C.
Registered Office: Papaioakeim Pesmatzoglou 4, Nea Ionia, 14231 Attiki Greece,
Email: privacy@thehypenetwork.io
2.2. Where required by Applicable Law, the Company may appoint a Data Protection Officer (DPO). If appointed, the DPO’s contact details will be published on the Platform.
3. Scope of this Privacy Policy
3.1. This Privacy Policy applies to all processing of personal data carried out through the Platform, including, without limitation, processing relating to:
- Account registration;
- authentication through Instagram or TikTok;
- use of the Platform’s services;
- publication of Collaboration Offers;
- publication of Creator Service Offers;
- communications between Users;
- Ratings and Reviews;
- subscription management;
- customer support;
- communications with the Company; and
- any other activity carried out through the Platform.
4. Legal Framework
4.1. The Company processes personal data in accordance with:
- Regulation (EU) 2016/679 (General Data Protection Regulation – GDPR);
- Greek Law 4624/2019, as amended;
- any other applicable Greek and European data protection legislation;
- the decisions and guidelines of the Hellenic Data Protection Authority; and
- the guidelines and recommendations of the European Data Protection Board (EDPB).
5. Data Protection Principles
5.1. The Company processes personal data in accordance with the principles set out in Article 5 of the GDPR, namely:
-
lawfulness;
-
fairness;
-
transparency;
-
purpose limitation;
-
data minimisation;
-
accuracy;
-
storage limitation;
-
integrity and confidentiality; and
-
accountability.
5.2. The Company implements appropriate technical and organisational measures designed to ensure and demonstrate ongoing compliance with the above principles and with all applicable data protection legislation.
6. Categories of Data Subjects
The Company processes personal data relating to the following categories of data subjects:
(a) Creators;
(b) Businesses and their authorised representatives, directors or account administrators;
(c) visitors to the Platform;
(d) individuals who contact the Company; and
(e) individuals whose personal data is lawfully included in connection with Collaborations carried out through the Platform.
7. Categories of Personal Data We Collect
7.1. General Categories of Personal Data
The Company collects and processes personal data that is:
-
provided directly by Users;
-
obtained through connected social media accounts; and
-
generated through the User’s use of the Platform.
7.2. The categories of personal data processed depend on the type of Account (Creator or Business) and the services and features used by the User.
8. Personal Data Collected for All Users
For every User Account, regardless of Account type, the Company may process the following categories of personal data:
- email address;
- unique user identifier generated by the authentication provider (such as Auth0 or any equivalent authentication service);
- Account type;
- Account status (including active, inactive, suspended or similar status);
- Account creation date;
- date of last profile update;
- profile picture;
- selected interface language;
- in-app notification history;
- information indicating whether notifications have been viewed and when;
- notification preferences; and
- technical session identifiers necessary for authentication and Platform security.
9. Personal Data Collected for Creators
In addition to the data described above, the Company may process the following personal data relating to Creators:
- display name;
- biography;
- city;
- country;
- content niches;
- content formats and services offered;
- Creator Tier;
- photographs and other media uploaded to the Platform;
- Collaboration History;
- Ratings and Reviews;
- overall rating;
- Platform activity statistics; and
- information relating to Creator Service Offers published through the Platform.
The Company does not collect or store the residential address of Creators or any precise geolocation data.
10. Personal Data Collected for Businesses
For Business Accounts, the Company may process the following categories of personal data:
- trading name;
- business description;
- business categories;
- business address;
- postcode;
- city;
- country;
- photographs and other content uploaded to the Platform;
- subscription tier;
- bookmarked Creators;
- Collaboration History;
- Ratings and Reviews; and
- Platform activity statistics.
The email address associated with a Business Account belongs to the natural person who created or administers the Account on behalf of the relevant Business.
11. Personal Data Obtained from Connected Instagram and TikTok Accounts
11.1. With the User’s explicit consent provided during the account connection process, the Company may receive personal data from Instagram and TikTok in accordance with the permissions granted by the User.
11.2. Such data may include, without limitation:
-
account identifiers;
-
display name;
-
username;
-
profile picture;
-
public biography;
-
website or bio link;
-
follower count;
-
following count;
-
number of posts or videos;
-
engagement statistics;
-
post or video metadata;
-
links to published content;
-
publication dates;
-
information required to verify the completion of Collaborations; and
-
any other information made available through the official APIs of Instagram, TikTok or any successor service.
11.3. The Company does not determine which data is made available through the official APIs of Meta or TikTok and shall not be responsible for any changes, restrictions or limitations imposed by those providers.
12. Authorisation Tokens and Technical Data
12.1. The Company may store:
- access tokens;
- refresh tokens;
- unique account identifiers;
- technical session identifiers; and
- technical log files,
to the extent necessary for:
-
maintaining the User’s authenticated session;
-
refreshing connected account information;
-
verifying Collaborations;
-
ensuring the security of the Platform; and
-
diagnosing and resolving technical issues.
12.2. Such information is protected through appropriate technical and organisational security measures and is processed solely for the purposes described in this Privacy Policy.
13. Personal Data We Do Not Collect
13.1. The Company applies the principle of data minimisation and does not collect or process personal data that is not necessary for the operation of the Platform.
In particular, during the ordinary operation of the Platform, the Company does not collect or store:
-
telephone numbers;
-
dates of birth;
-
national identity card or passport details;
-
tax identification numbers;
-
company registration numbers;
-
VAT registration numbers;
-
credit or debit card details;
-
bank account details;
-
precise geolocation (GPS) data; or
-
special categories of personal data within the meaning of Article 9 GDPR, unless required by Applicable Law or provided with the explicit consent of the data subject.
13.2. The Company does not use advertising or behavioural tracking technologies, including Google Analytics, Meta Pixel or any similar third-party tracking technologies.
13.3. The only cookies or similar technologies used by the Platform are those that are strictly necessary for its operation, including cookies required to maintain the User’s authenticated session, remember the selected interface language and store essential functional preferences.
14. Purposes of Processing Personal Data
14.1. The Company processes personal data solely for lawful, specified and legitimate purposes connected with the operation, provision and continuous improvement of the Platform and its services.
In particular, personal data may be processed for one or more of the following purposes:
14.2. Account Creation and Management
To create, activate, maintain and administer User Accounts, verify Users’ identities and provide secure access to the Platform.
14.3. Provision of Platform Services
To provide and operate the Platform, including:
-
displaying User Profiles;
-
publishing Collaboration Offers;
-
publishing Creator Service Offers;
-
matching Creators and Businesses;
-
managing Applications and Invitations;
-
maintaining Collaboration History;
-
operating the Ratings and Reviews system;
-
operating the Hype Score and User Tier system; and
-
providing all other Platform functionalities.
14.4. Instagram and TikTok Integration
To connect and synchronise Users’ Instagram and TikTok Accounts, retrieve information authorised by the User, update Profile information and verify completed Collaborations.
14.5. Communications with Users
To send in-app notifications relating to:
-
new Collaborations;
-
Applications;
-
Invitations;
-
status updates;
-
Account activity;
-
security notifications;
-
changes to the Terms and Conditions or this Privacy Policy; and
-
other operational communications relating to the Platform.
14.6. Subscription Management
To manage Business subscriptions, including subscription activation, renewal, cancellation, billing status and subscription administration.
14.7. Platform Security
To protect the Platform and its Users against:
-
fraud;
-
unauthorised access;
-
misuse of the Platform;
-
bots and automated abuse;
-
fake or fraudulent Accounts;
-
cyber-attacks; and
-
other unlawful or malicious activities.
14.8. Analytics and Service Improvement
To analyse Platform usage, generate statistical information, evaluate the performance of the Platform and continuously improve the User experience.
Where reasonably possible, such analysis is carried out using aggregated, anonymised or pseudonymised data.
14.9. Compliance with Legal Obligations
To comply with Applicable Law, lawful requests from competent authorities, court orders and regulatory obligations, and to establish, exercise or defend the Company’s legal rights.
15. Legal Bases for Processing
15.1. The Company processes personal data only where a valid legal basis exists under Article 6 of the GDPR.
15.2. Performance of a Contract
Processing is necessary for the performance of the agreement between the User and the Company, including the creation and management of User Accounts, provision of Platform services, Profile management and subscription administration.
15.3. Consent
Where required by Applicable Law, the Company processes personal data on the basis of the User’s prior consent.
This may include, without limitation:
- connecting Instagram or TikTok Accounts;
- accessing specific information made available through the official APIs of those platforms; and
- any other processing activities for which consent constitutes the appropriate legal basis.
Users may withdraw their consent at any time. Such withdrawal shall not affect the lawfulness of any processing carried out before consent was withdrawn.
15.4. Legitimate Interests
The Company may process personal data where such processing is necessary for the purposes of its legitimate interests, provided that those interests are not overridden by the rights and freedoms of the relevant data subjects.
Legitimate interests may include, without limitation:
-
maintaining Platform security;
-
preventing fraud;
-
detecting malicious or abusive activity;
-
handling complaints;
-
maintaining audit logs;
-
improving the Platform and its services; and
-
establishing, exercising or defending legal claims.
15.5. Compliance with Legal Obligations
The Company may process personal data where such processing is necessary to comply with obligations imposed by Applicable Law.
16. Disclosure of Personal Data
16.1. The Company does not sell, rent or otherwise disclose Users’ personal data to third parties for marketing or commercial advertising purposes.
16.2. Personal data is disclosed only where necessary for the operation of the Platform, the provision of its services, or where required by Applicable Law.
16.3. Recipients of personal data may include, without limitation:
-
identity and authentication service providers (such as Auth0 or equivalent providers);
-
payment service providers (including Stripe or any successor provider). The Company does not receive, process or store Users’ credit card, debit card or bank account details;
-
cloud storage and file hosting providers (including Cloudinary or equivalent providers);
-
application logging and monitoring providers;
-
cloud hosting and infrastructure providers;
-
professional advisers, auditors or legal representatives, where necessary; and
-
competent judicial, regulatory, administrative or other public authorities.
16.4. Personal data may be disclosed to courts, law enforcement authorities, regulatory authorities or other competent public bodies where such disclosure is required by Applicable Law, a legally binding request or order, or where necessary for the establishment, exercise or defence of legal claims.
17. International Transfers of Personal Data
17.1. The Company may transfer personal data outside the European Economic Area (EEA) where such transfer is necessary for the provision of the Platform or for the use of third-party service providers.
17.2. Such transfers may include, without limitation, transfers to:
-
Meta Platforms, Inc. and its affiliated companies, in connection with Instagram integration;
-
TikTok and its affiliated companies, in connection with TikTok integration;
-
Stripe;
-
cloud hosting, cloud storage and other technology service providers used by the Company; and
-
any other service provider engaged by the Company for the operation of the Platform.
17.3. In all cases, the Company implements appropriate safeguards to ensure that any international transfer of personal data complies with the requirements of Chapter V of the GDPR.
17.4. Where required, such transfers are based on one or more of the following legal mechanisms:
-
an Adequacy Decision adopted by the European Commission;
-
the European Commission’s Standard Contractual Clauses (SCCs); or
-
any other lawful transfer mechanism permitted under Articles 45 to 49 of the GDPR.
18. Retention of Personal Data
18.1. The Company retains personal data only for as long as necessary to fulfil the purposes for which it was collected or for as long as required by Applicable Law.
18.2. The principal retention periods are as follows:
Category of DataRetention Period
Account informationFor as long as the User Account remains active
Subscription recordsFor the period required under applicable tax, accounting and commercial laws
Collaboration OffersUntil the relevant Account is deleted or the data is anonymised
ApplicationsUntil the relevant Account is deleted or for as long as necessary to protect the Company’s legitimate interests
Collaboration HistoryFor as long as the Account remains active and, following Account deletion, for as long as necessary to establish, exercise or defend legal claims
Ratings and ReviewsFor as long as the relevant User Account remains active
Technical logsUp to twelve (12) months, unless a longer retention period is required for security, fraud prevention or legal claims
Audit logsFor as long as reasonably necessary for security, regulatory compliance and the protection of the Company’s legitimate interests
18.3. Upon expiry of the applicable retention period, personal data will be securely deleted or irreversibly anonymised unless continued retention is required by Applicable Law or is necessary for the establishment, exercise or defence of legal claims.
19. Security of Personal Data
19.1. The Company implements appropriate technical and organisational measures designed to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure or unauthorised access.
19.2. Depending on the nature of the processing, such measures may include:
-
access controls;
-
user authentication mechanisms;
-
encryption of data in transit;
-
secure storage of personal data;
-
audit logging;
-
role-based access restrictions;
-
regular software updates and security patching; and
-
incident detection and response procedures.
19.3. While the Company implements appropriate safeguards to protect personal data, no method of electronic transmission or electronic storage can be guaranteed to be completely secure. Accordingly, the Company cannot guarantee the absolute security of any information system or data transmission.
20. Data Subject Rights
Subject to the conditions and limitations set out in the GDPR and Applicable Law, every individual whose personal data is processed by the Company is entitled to exercise the following rights:
- the right of access;
- the right to rectification;
- the right to erasure (“right to be forgotten”);
- the right to restriction of processing;
- the right to data portability;
- the right to object to processing;
- the right to withdraw consent at any time where processing is based on consent;
- the right not to be subject to a decision based solely on automated processing, including profiling, where applicable; and
- the right to lodge a complaint with the competent supervisory authority.
20.1. Right of Access
Every data subject has the right to obtain confirmation as to whether the Company processes personal data relating to them and, where that is the case, to obtain access to such personal data and receive a copy thereof.
20.2. Right to Rectification
Every data subject has the right to request the correction of inaccurate personal data and the completion of incomplete personal data concerning them.
20.3. Right to Erasure
Every data subject has the right to request the erasure of their personal data where the conditions set out in Article 17 of the GDPR are satisfied.
20.4. Right to Restriction of Processing
Every data subject has the right to request the restriction of the processing of their personal data in the circumstances provided for under the GDPR.
20.5. Right to Data Portability
Every data subject has the right to receive the personal data they have provided to the Company in a structured, commonly used and machine-readable format and, where technically feasible, to request that such data be transmitted directly to another data controller.
20.6. Right to Object
Every data subject has the right to object to the processing of personal data based on the Company’s legitimate interests, unless the Company demonstrates compelling legitimate grounds for the processing which override the interests, rights and freedoms of the data subject or where the processing is necessary for the establishment, exercise or defence of legal claims.
20.7. Right to Withdraw Consent
Where the processing of personal data is based on the User’s consent, the User may withdraw that consent at any time. Withdrawal of consent shall not affect the lawfulness of any processing carried out prior to such withdrawal.
21. Exercising Your Rights
21.1. Requests relating to the exercise of any of the rights described in this Privacy Policy may be submitted by email to:
or to any other contact details published by the Company from time to time.
21.2. The Company shall respond to such requests without undue delay and, in any event, within one (1) month of receipt, unless that period is lawfully extended in accordance with Article 12 of the GDPR.
21.3. Where necessary, the Company may request additional information to verify the identity of the person submitting the request before taking any action on the request, in order to protect personal data and prevent unauthorised disclosures.