EU Regulation 2016/679 & UK GDPR

GDPR Compliance

DollarHuge is committed to protecting data privacy for all European Union (EU), European Economic Area (EEA), and United Kingdom (UK) residents. Review our GDPR governance and exercise your statutory rights below.

verified EU GDPR (2016/679)
security UK Data Protection Act 2018
timer 30-Day Response SLA
support_agent Dedicated DPO Appointed
delete_forever

Right to Erasure

Request complete erasure ("Right to be Forgotten") of your account, telemetry, and personal identifier records.

file_download

Data Portability

Receive a machine-readable JSON archive containing your transaction logs, earning milestones, and profile data.

gavel

Article 6 Lawful Bases

Every piece of processed information is bound strictly to contract execution, legal obligations, or legitimate interests.

verified_user

Sub-Processor Audits

Rigorous vetting and Standard Contractual Clauses (SCCs) govern all third-party hosting, caching, and payment partners.

apartment

1. Overview & Data Controller

Under Regulation (EU) 2016/679 of the European Parliament and of the Council (General Data Protection Regulation) and the UK Data Protection Act 2018, DollarHuge operates as the Data Controller for personal information collected through our website, rewards systems, and application programming interfaces.

As Data Controller, we determine the legitimate purposes and technical means of processing personal data. We are dedicated to the foundational principles of GDPR Article 5: lawfulness, fairness, transparency, purpose limitation, data minimisation, accuracy, storage limitation, integrity, and confidentiality.

balance

2. The 6 Lawful Bases for Processing

We never process personal data without establishing an explicit lawful basis pursuant to GDPR Article 6(1):

  • Contractual Necessity (Art. 6(1)(b)): Processing your login credentials, task tracking, and withdrawal requests is indispensable to perform the contract formed when you agree to our Terms of Service.
  • Legitimate Interests (Art. 6(1)(f)): Processing telemetry data (such as IP addresses, browser signatures, and connection latency) is necessary to protect our rewards economy from bot networks, multi-account syndicates, and fraudulent VPN abuses.
  • Legal Obligations (Art. 6(1)(c)): Preserving financial disbursement ledgers to comply with anti-money laundering (AML), tax reporting, and accounting standards.
  • Consent (Art. 6(1)(a)): Used for optional marketing emails and non-essential analytical cookies. Consent can be revoked instantly at any time.
assignment_ind

3. The 8 Fundamental Data Subject Rights

If you reside within the European Union or United Kingdom, you are invested with 8 legally enforceable rights concerning your personal information:

visibility 1. Right to be Informed

You have the right to clear, transparent, and easily accessible explanations of how your data is collected and processed.

folder_shared 2. Right of Access

You may submit a Subject Access Request (SAR) to obtain a verified copy of all personal records we maintain about you.

edit 3. Right to Rectification

You have the right to promptly correct inaccurate, outdated, or incomplete account records.

delete 4. Right to Erasure

You may request the complete and permanent deletion of your data when retention is no longer legally mandated.

pause_circle 5. Right to Restrict Processing

You may request that we temporarily suspend data processing while accuracy disputes are actively examined.

cloud_download 6. Right to Data Portability

You have the right to receive your personal data in an organized, commonly used, machine-readable format (JSON).

block 7. Right to Object

You have the absolute right to object to direct marketing communications and processing based on legitimate interests.

smart_toy 8. Automated Decision Rights

You have the right to request human review of automated fraud flags and to express your viewpoint.

send

4. Data Subject Access Request (DSAR) Portal

To submit a formal request under GDPR or UK Data Protection regulations, please fill out the verified portal form below. Our Data Protection Officer guarantees an acknowledgment within 48 hours and full resolution within 30 calendar days.

Submit a Data Subject Request
All requests are processed without administrative charge. Proof of account ownership is required to protect unauthorized disclosure.
public

5. International Data Transfers & SCCs

Because DollarHuge's server fleet operates in globally distributed Tier-IV data facilities, data originating in the European Economic Area may be transferred and processed in the United States and other international jurisdictions.

To guarantee that your data retains equivalent protections wherever processed, all cross-border data transfers are executed pursuant to the European Commission's Standard Contractual Clauses (SCCs) (Commission Implementing Decision (EU) 2021/914). In addition, we execute supplementary technical measures including in-transit TLS 1.3 encryption, database field salting, and automated access audit logging.

corporate_fare

6. Sub-Processor Registry

Pursuant to GDPR Article 28, we maintain a public registry of third-party sub-processors utilized to deliver core hosting, telemetry security, and payout operations:

Sub-Processor Role / Service Data Processing Location Transfer Safeguard
Cloudflare, Inc. DDoS mitigation, CDN caching, Turnstile human verification Global Edge Network (EU & USA) EU-US DPF & SCCs
Amazon Web Services (AWS) Encrypted cloud database storage & compute instances United States & Germany SCCs & ISO 27001
PayPal Holdings, Inc. Payout fulfillment & electronic cash redemptions United States & EU Binding Corporate Rules
Certified Offerwall Partners Task verification postbacks (AdGate, Torox, BitLabs, Revlum) Global (United States / EU) Standard Contractual Clauses
notification_important

7. Data Breach Notification Protocol

In accordance with GDPR Articles 33 and 34, DollarHuge maintains an active Security Incident Response Team (SIRT). In the event of a confirmed security incident posing a risk to the rights and freedoms of individuals:

  • We will notify the competent Lead Supervisory Authority within 72 hours of becoming aware of the incident.
  • If a breach represents a high risk to personal rights, affected users will be informed directly via their registered email address without undue delay, accompanied by clear mitigation recommendations.
contact_emergency

8. DPO Contact & Supervisory Authorities

For all questions, DSAR follow-ups, or privacy complaints, our designated Data Protection Officer can be reached directly:

  • DPO Direct Email: support@dollarhuge.co (Subject: Attention: Data Protection Officer)
  • Support Phone: +49 30 12345678
  • Office Address: DollarHuge Compliance & DPO Office, Hauptstraße 27, Leipzig, 04109, Germany.

Right to Lodge a Complaint: If you believe our processing of your personal data infringes upon the General Data Protection Regulation, you have the right to lodge a formal complaint with a supervisory authority, in particular in the EU Member State of your habitual residence, place of work, or place of the alleged infringement.