Your data, in plain language (GDPR for contest participants)

We get the same question almost every week. It usually arrives at 11pm, from someone who entered a Polish brand's photo contest three days ago and is now wondering what happens to their phone number if they hire us to run a small ad campaign pointing at their entry page.

Good question. Here is the honest answer.

This page explains what we collect, what we refuse to collect, where it lives, how long we keep it, and how you make it disappear. No legal jargon for its own sake. We are a small agency in Minsk working with EU-based contest participants, so GDPR applies to us when we process your data. We act like it does.

The short version

You give us four things: your name, an email, a link to your contest entry, and a payment record. That is the baseline. Sometimes more, if you ask us to write copy referencing your bio. Never your contest-platform password. Never a spreadsheet of your friends' contacts. We store the data for 30 days after the campaign ends, then delete it on a scheduled job that runs every Sunday at 03:00 Minsk time. If you want it gone sooner, email us and it is gone within 72 hours.

That is the whole story. The rest of this page is the boring detail that makes the short version trustworthy.

What we actually collect from you

When you fill out the form on /contact.html or send us a message on Telegram, we end up holding the following:

  • Name and email address. So we can reply to you and send invoices.
  • The URL of your contest entry. So we know where to send traffic.
  • The contest's public rules page. We read it. We will not run a campaign for a contest whose rules forbid paid promotion, and yes, roughly 1 in 6 briefs we receive end here.
  • Your country and city, usually inferred from your timezone or asked directly, because ad targeting needs a geographic anchor.
  • Payment record. A transaction ID, the amount, the date, the method. We do not store card numbers — our payment processor does that, and we never see the full PAN.
  • Sometimes: a short bio or a few sentences you write about yourself, if we are drafting ad copy for you. This is optional and you control what goes in it.

That is it. The list is short on purpose.

What we refuse to collect, ever

This is the part most agencies skip, so we will be direct.

  1. Your contest-platform login credentials. Username, password, two-factor codes, "just the password for a minute" — no. If someone asks for these, they are not running a marketing campaign, they are running a fraud. We have turned away clients who insisted on giving us their logins. Politely, but firmly.
  2. Your friends' or family's personal data. No phone-number lists, no email exports from your contacts, no "here is everyone who might vote for me" spreadsheets. Custom audiences built from contact lists you do not control are a Meta policy violation and a GDPR Article 6 problem with no clean lawful basis. We will not upload them.
  3. Documents you do not need to share. Passport scans, ID cards, utility bills. We have no use for them. If a payment provider asks for KYC, that is between you and the provider — we are not in the chain.
  4. Browsing data from anyone who is not you. We do not install pixels on contest pages we do not own. We do not scrape voter lists. We do not buy "contest interest" data from brokers.

If our refusal to do any of this loses us your business, we are at peace with that. Read our boundaries in detail on /services.html.

The lawful basis we rely on (Article 6, demystified)

GDPR says we need a legal reason to process your data. There are six. We rely on two.

Article 6(1)(b) — contract performance. You hired us to run a campaign. To do that, we obviously need your email and your entry URL. This basis covers the operational core of the engagement.

Article 6(1)(f) — legitimate interests. For things like keeping a 30-day audit log of what ad creatives ran (so we can answer questions if Meta or Google flags something), we rely on legitimate interests, balanced against your rights. We documented this balancing test once, in 2024, and we reread it every spring.

We do not use Article 6(1)(a) consent as our main basis, because consent under GDPR has to be freely given and easily withdrawn, and bundling it with a paid service muddies that. Consent is the right basis for things like a newsletter — which we do not run. The official text lives at eur-lex.europa.eu/eli/reg/2016/679/oj if you want to read Article 6 yourself. It is shorter than people think.

Where the data lives

This matters because GDPR cares about international transfers. Here is the truth:

  • Email correspondence: on a mailbox hosted in the EU.
  • Project notes and briefs: on encrypted disk on a workstation in Minsk, with offsite encrypted backup in Frankfurt.
  • Invoices: in our accounting software, which is hosted in the EU.
  • Ad-platform data: obviously, on Meta, Google, and TikTok servers. We do not control where they put it; you accepted their terms when you used those platforms. We minimize what we send them.

Belarus is not an "adequacy" country under GDPR. We know. That is why we use Standard Contractual Clauses with EU-based subprocessors and document our processing activities. If you want the documentation, we will send it. Few people ask, but the offer stands.

Retention: 30 days, then it is gone

Most agencies hold client data forever "in case you come back." We do not. Our default retention is 30 days after a campaign ends.

Here is what happens on day 31. A scheduled task on our server runs every Sunday at 03:00 Minsk time. It checks every project marked "completed" and counts days since the campaign close. If the count exceeds 30, the project folder is moved to a quarantine directory. Seven days later, another job deletes the quarantine. So in practice, your data is gone within 30 to 37 days, depending on what day of the week your campaign ended.

Exceptions we keep longer:

  • Invoices. Belarusian tax law requires 5 years. We are not lawyers and this is not advice — it is what our accountant tells us, and we follow it.
  • Refund records. Same 5 years, same reason. The refund policy itself is on /refund.html.
  • Anything you explicitly ask us to keep, for example because you want us to run a second campaign next month. In that case we ask you to confirm in writing, and we set a calendar reminder for the new retention date.

If you ask us to delete everything sooner — including the stuff we would normally keep for legal reasons — we will delete what we legally can and tell you exactly what we cannot, and why. No pretending.

The right to erasure, mechanically

GDPR Article 17 gives you the right to have your personal data erased. Most articles about this make it sound like a bureaucratic ordeal. With us it is not.

You send an email to the address on /contact.html with the subject line "Erasure request" or the equivalent in any language you prefer. We reply within one business day. Within 72 hours of confirming your identity (we just need you to send it from the email address we have on file, or to confirm a payment reference), we:

  1. Delete your project folder from working storage.
  2. Purge the entry from our encrypted backup at the next backup rotation, which happens nightly.
  3. Pause any active ad campaigns immediately and remove your entry URL from ad sets within 24 hours.
  4. Tell our subprocessors (the EU mailbox, the accounting software) to delete what they hold, where the law permits.
  5. Send you a written confirmation listing what was deleted and what we had to keep, with the legal basis for keeping it.

GDPR formally allows up to 30 days, extendable to 90 in complex cases. We do not need 30 days for the kind of work we do. If you ever hear from us "we need more time," it is because we hit something genuinely complicated and we will explain it.

One honest limitation. If your campaign data has already been ingested by Meta's or Google's systems, we cannot reach inside their databases and pull it out. You have to request erasure from them directly. Meta's process is at facebook.com/help/contact/540977946302970; Google's is via your Google account privacy settings. We can give you the direct link relevant to your situation if you ask. We have done this for 11 clients in the last 18 months. It works.

What we got wrong once

Honesty section. In early 2024 we kept a project's brief in a draft email for six weeks after the campaign ended — past our own 30-day rule — because we had been writing a follow-up proposal and forgot to delete the draft. Nothing leaked. No one was harmed. The client noticed in a casual conversation, asked, we admitted it, deleted the draft on the call, and changed our process so drafts are scanned by the same Sunday cleanup job. We mention it because every agency claims a perfect record and almost none have one.

Subprocessors, named

We are required to tell you who else touches your data. The current list:

  • Our EU email host (we will name them in writing on request; we do not want this page to be a phishing target).
  • Our accounting software vendor, EU-based.
  • Meta, Google, and TikTok ad platforms, when you authorize a campaign with them.
  • Our payment processor, which handles invoicing and never shares full card details with us.

We do not use a CRM. We do not use a marketing-automation suite. We do not use an AI vendor that ingests client data for training. If we ever change that, we will update this page and email every active client first.

Your rights, as a checklist

Under GDPR you have the right to: access your data, correct it, erase it, restrict processing, port it to another provider, and object to processing based on legitimate interests. For everything except portability (we do not hold enough data for that to be meaningful), one email to us starts the process. We respond in one business day, finish in three.

If you think we are mishandling your data and our response is not good enough, you can complain to your national data protection authority. In Poland that is UODO (uodo.gov.pl). We would rather you tell us first so we can fix it — but we will never discourage you from going to the regulator.

What this page does not cover

This is the plain-language version. The formal privacy policy with all the section headings GDPR likes to see is at /privacy.html. If the two ever conflict, the formal version controls — but we work hard to keep them aligned. If you spot a contradiction, email us. We will fix it the same day.

For how we actually run the work after the data conversation is settled, see /process.html. For who we are, /about.html. For costs, /pricing.html. For the questions clients ask before signing, /faq.html.

One last thing

We are deliberately a small team. That is a feature, not an apology. It means fewer people touch your data, the data inventory above is the actual inventory (not a sanitized summary), and you can usually identify by name the person who answers your erasure request. If that sounds old-fashioned, fine. It also sounds like the kind of agency we would want to hire if the roles were reversed.

Free for new clients

Get a free contest analysis in 1–2 hours

Send us your contest URL and a one-sentence goal. We reply with which channels make sense, projected reach for typical budgets, and an honest yes/no recommendation.

Get my free analysis →

Faster on Telegram or WhatsApp.