Privacy Policy

Effective 23 August 2026 · Last updated 23 August 2026

This policy explains what personal data Outsourcing Software Development SLLC, UIC 206793987, VAT number BG-206793987, Izgrev 92, app. 19, Burgas 8000, Bulgaria (“we”, “us”) collects about affiliates and visitors of the affiliate portal at affiliate.outsourcing-software-development.com (the “Portal”), why we hold it, who else sees it, how long we keep it and what you can ask us to do with it. For this processing we are the data controller.

What this policy does not cover

It does not cover the customers you refer. When someone follows your referral link and signs up or buys, their personal data is collected by the product they used — TimeSaverBot or KeeBooks — and is governed by that product's own privacy policy. Ask them, not us, about that data.

The attribution records those products send us can include a customer's email address. It is stored only so a sale can be matched to the right affiliate and reconciled, it is visible to our administrators only, and it is never shown to affiliates — you see your registrations and sales without any customer identity.

1. What we collect

We collect only what the programme needs to run.

Category What it includes
Account and identity Full name, email address, password (stored only as a hash), account status, affiliate tier, time zone, your affiliate ID.
Payout and billing Bank details for the transfer — account holder, bank name, IBAN or account number, SWIFT/BIC, bank country and payout currency — billing street, city, state, postal code and country, VAT number and tax status, and the invoices you send us.
Programme records Registrations and sales attributed to your affiliate ID, sale amounts and currency, commission amounts, rates and statuses, payout transactions and their references.
Correspondence Emails and support messages you send us, and our replies.
Technical data Your IP address, browser and device information, and the times of requests, processed by our server and kept in its logs when you use the Portal. Our event API also checks the IP address of the partner server sending each registration or sale against an allowlist; that address belongs to the product's server, not to you.

We do not collect special categories of data, we do not profile you automatically, and no decision with a legal or similarly significant effect on you is made by automated means alone. Approval, suspension and payout decisions are taken by a person.

2. Why we use it, and on what legal basis

Purpose Legal basis (GDPR art. 6)
Reviewing your application and running your account Performance of a contract, or steps before entering one — art. 6(1)(b)
Attributing registrations and sales, calculating commission, paying you Performance of a contract — art. 6(1)(b)
Issuing and keeping accounting and tax records, complying with VAT and anti-money-laundering rules Legal obligation — art. 6(1)(c)
Detecting invalid or fraudulent traffic, securing the Portal and the event API, keeping records of what happened Our legitimate interest in a working, fraud-free programme — art. 6(1)(f)
Sending you transactional email: password resets, application decisions, payout notifications Performance of a contract — art. 6(1)(b)
Notifying you of changes to the terms or the programme Legal obligation and legitimate interest — art. 6(1)(c), 6(1)(f)
Establishing, exercising or defending legal claims Legitimate interest — art. 6(1)(f)

We do not send marketing email to affiliates. If we ever start, it will be on the basis of your consent and every message will let you unsubscribe.

3. Cookies and tracking

3.1. The Portal uses strictly necessary storage only: a session cookie and browser storage set by our authentication layer so that you stay signed in. Without it you cannot use the Portal, so no consent banner is required for it.

3.2. The Portal contains no analytics, advertising, retargeting or profiling technology. There is no Google Analytics, no advertising pixel and no session recording.

3.3. Portal pages load web fonts from Google Fonts and one JavaScript library from the jsDelivr content delivery network. These services do not set cookies here, but your browser must contact them to fetch the files, and in doing so your IP address and browser details reach them.

3.4. Your referral links carry your affiliate ID as a URL parameter to the product websites. Those sites may store that ID — in a cookie or in their own storage — so that a later registration or sale can be attributed to you. That storage happens on the product's site and is described in its own privacy and cookie notices, not here.

4. Who else receives your data

We do not sell your personal data and we do not share it with advertising networks or data brokers. It reaches these recipients only:

  • Our hosting provider. The Portal and its database run on a server we operate in France; the data-centre operator holds the infrastructure on our behalf as a processor.
  • Our own mail server. Transactional email — password resets, application decisions, payout notices — and the messages you send to our programme addresses, invoices included, are handled and stored on a mail server we operate ourselves in Germany. We use no third-party bulk-email, newsletter or delivery provider, so that correspondence does not pass through one.
  • Our bank, your bank and any intermediary or correspondent bank in the payment chain. To make a transfer they receive the account holder's name, the account details you gave us, the amount and the payment reference. Each bank acts as its own controller for that payment and is bound by its own banking and anti-money-laundering rules.
  • Our accountants and auditors, for bookkeeping, invoicing and statutory reporting.
  • Tax and public authorities, including the Bulgarian National Revenue Agency, where the law requires us to report or to respond.
  • Google Fonts and jsDelivr, which receive your IP address when your browser loads the fonts and library described in section 3.3.
  • Legal advisers, courts or law enforcement, where necessary to establish, exercise or defend legal claims, or where we are legally compelled.

If our business or a part of it is ever transferred to another company, your data may pass to the acquirer, which would remain bound by this policy until it gives you a new one.

5. Where your data is stored

5.1. Your account, payout and programme records are stored on our server in France, inside the European Economic Area.

5.2. Your correspondence with us, and the invoices you send for payout, are held on our mail server in Germany. Both countries are inside the European Economic Area.

5.3. Some recipients listed in section 4 may process data outside the EEA. Where that happens, the transfer relies on an adequacy decision of the European Commission — for the United States, the EU–US Data Privacy Framework — or on the European Commission's standard contractual clauses, or on another safeguard permitted by chapter V of the GDPR. Write to us at the address in section 12 for a copy of the safeguard that applies to a given transfer.

6. How long we keep it

Data Retention
Account profile and payout settings While the account is open, then 5 years after it closes, so that claims arising from the programme can be handled.
Invoices, payouts and other accounting records 10 years from the end of the financial year they belong to, as required by Bulgarian accounting and tax law.
Registration and sale records While needed for attribution and settlement; those that feed a payout are then kept with the accounting records above.
Applications we rejected 12 months from the decision.
Server and security logs Up to 12 months.
Correspondence Up to 3 years from the last message, longer if it relates to a dispute. An invoice you sent us is also kept with the accounting records above, for their full period.

When a period ends we delete the data or anonymise it so that it can no longer be linked to you.

7. How we protect it

7.1. Traffic to the Portal is encrypted in transit. Passwords are stored only as hashes and can be reset but never read.

7.2. Access is limited by role. An affiliate account can read only its own registrations, sales, payouts and settings; customer identities in attribution records are restricted to administrators.

7.3. The event API that receives registrations and sales accepts a request only from an allowlisted server address presenting a valid integration key; anything else is rejected.

7.4. No system is perfectly secure. If a breach occurs that is likely to put your rights at risk, we notify the competent supervisory authority within 72 hours and tell you without undue delay where the GDPR requires it.

8. Your rights under the GDPR

If the GDPR or the UK GDPR applies to you, you have the right to:

  • ask for a copy of the personal data we hold about you;
  • have inaccurate data corrected and incomplete data completed;
  • have data deleted, where we no longer have a reason to keep it — note that accounting records must stay for their statutory period;
  • ask us to restrict processing while a question about accuracy or legitimacy is resolved;
  • receive the data you gave us in a structured, machine-readable format, and have it sent to another controller where technically feasible;
  • object to processing based on our legitimate interests, on grounds relating to your situation;
  • withdraw consent at any time, where processing rests on consent, without affecting what was done before.

Write to privacy@outsourcing-software-development.com. We answer within one month and may ask you to confirm your identity first. Exercising a right is free; we may charge a reasonable fee only for a manifestly unfounded or excessive request.

You can also complain to a supervisory authority — in Bulgaria the Commission for Personal Data Protection (Комисия за защита на личните данни, Sofia, cpdp.bg), in the UK the Information Commissioner's Office, or the authority of your own country of residence.

9. Rights in the United States

9.1. If you are a resident of California or of another US state with comparable privacy law, you may ask us what personal information we have collected about you and where it came from, ask for a copy of it, ask us to correct it, and ask us to delete it, subject to the record-keeping exceptions in section 6.

9.2. In the twelve months before this policy we have not sold or shared personal information as those terms are used in the CCPA/CPRA, and we do not use it for cross-context behavioural advertising. There is therefore nothing to opt out of, but you may still tell us that you object.

9.3. We do not discriminate against anyone for exercising these rights. You may use an authorised agent; we will ask for proof of the authorisation. Send requests to privacy@outsourcing-software-development.com.

10. Rights in other countries

Affiliates elsewhere have the rights their own law gives them — in Israel, for example, the right to review and correct your data under the Protection of Privacy Law, 5741-1981. Whatever your country, the practical route is the same: write to privacy@outsourcing-software-development.com and we will apply whichever standard gives you more protection.

11. Children

The programme is for adults. We do not knowingly collect data about anyone under 18. If we learn that we have, we delete the account and the data.

12. Changes and contact

12.1. We may update this policy. For a material change we give at least 30 days' notice by email to the address on your account before it takes effect; smaller corrections take effect when published, and the date at the top always shows the current version.

12.2. Questions, requests and complaints about your data:

Outsourcing Software Development SLLC

Izgrev 92, app. 19, Burgas 8000, Bulgaria

UIC 206793987 · VAT number BG-206793987

Data protection: privacy@outsourcing-software-development.com

Legal notices: legal@outsourcing-software-development.com

Programme support: affiliates@outsourcing-software-development.com