GDPR

Last updated: January 2, 2025 | cacaFly Group and LeapUp Social Marketing Co., Ltd.

The cacaFly Group (including cacaFly Inc., Adgeek Inc., FastTek Creative Inc., and LeapUp Social Marketing Co., Ltd.) is committed to complying with the EU General Data Protection Regulation (GDPR). When collecting, processing, or using personal data of customers within the EU, we strive to comply with these regulations and work collaboratively with our partners throughout the entire data-processing lifecycle. By choosing to work with the cacaFly Group, customers agree to jointly pursue GDPR compliance with us. To this end, the cacaFly Group will:

Privacy Policy and Contractual Safeguards

When acting as a data processor, the cacaFly Group provides data-processing terms in accordance with standard contractual clauses for personal data processing, reflecting the relationship between controller and processor. The advertising platform services for which cacaFly Group acts as processor, and their related privacy policies, are listed below:

  • Seedling Digital Marketing Marketplace
  • LeapUp Pay
  • Privacy Notice (https://www.cacafly.com/)

In accordance with EU requirements for data transfers, the cacaFly Group establishes standard contractual clauses for personal data processing and signs them when working with customers, ensuring conformity with the standard contractual clauses published by the EU.

The cacaFly Group updates its privacy policy in line with GDPR requirements and contractually requires partners who provide personal data to comply with the GDPR — for example, ensuring disclosure to users and control over how data is used, obtaining appropriate consent within the scope required by the GDPR, keeping proper system records, and cooperating with partners and supervisory authorities.

Incident Response

The cacaFly Group abides by standard contractual clauses for personal data processing. In the event of any incident involving a threat to personal data, we will immediately notify the data exporter or publish an announcement on our official website. We are committed to maintaining and continuing to invest in threat detection and remediation technology so that any security or privacy incident (any personal data breach as defined by the GDPR) is identified and addressed at the earliest possible moment.

Disclosure to Users

The cacaFly Group continues to work toward greater transparency in how data is used in our advertising products. We require user authorization — or require advertisers to obtain appropriate authorization — before personal data is used to serve ads. Our privacy policy pages explain how data is processed. We also inform users that they can view and manage their data, privacy, and security settings in their browser, and control ad personalization features.

Cross-Border Data Transfers

For customers in the EU and other cross-border data transfers, the cacaFly Group complies with GDPR requirements on international data transfer mechanisms, provides standard contractual clauses for personal data processing, and strives to comply with data protection regulations to establish a lawful basis for data transfers.

Last updated: January 2, 2025