TiiDON GDPR Compliance Policy
Last Updated: 11/14/2025
TiiDON Marketplace (“TiiDON”, “we”, “our”, “us”), operated by TiiDON Innovations Limited (company Reg# 120241003919), is committed to protecting the privacy and personal data of all users including Zambians and European Union (EU), European Economic Area (EEA).
This GDPR and Zambia Data Protection Act (DPA 2021) Policy explains how we collect, process, store, and protect personal data in accordance with:
- The General Data Protection Regulation (EU) 2016/679 (GDPR), and
- The Zambia Data Protection Act No. 3 of 2021 (DPA).
This policy applies to all Users, Buyers, Sellers/Authors, Affiliates, and Visitors located in the EU/EEA and Zambia, and to any individual whose personal data is processed by TiiDON Marketplace under these legal frameworks.
1. Legal Basis for Processing Personal Data (Expanded)
TiiDON processes personal data only when there is a lawful basis to do so. These bases are required under both GDPR and the Zambia Data Protection Act.
Below is a full explanation of each legal ground.
1.1. Contractual Necessity
We process your personal data when it is required to provide services you have requested, including:
- Creating, securing, and managing your TiiDON account
- Enabling purchases, downloads, and product access
- Processing author payouts (bank, mobile money, crypto)
- Tracking affiliate referrals and calculating commissions
- Providing access to dashboards, support tools, and marketplaces
- Enabling KYC (where required to complete transactions)
- Operating technical features such as login sessions and email notifications
- This means we must process certain data to fulfill our contractual obligation when you register or use the platform.
1.2. Legitimate Interests
We process data for purposes that improve your overall experience and protect the platform, as long as these do not override your rights.
Our legitimate interests include:
Security & Fraud Prevention
- Preventing unauthorized access
- Detecting suspicious behavior
- Protecting user accounts
- Monitoring server logs and security events
Platform Functionality & Performance
- Improving marketplace features
- Analyzing system performance
- Fixing bugs and optimizing speed
- Preventing abuse of downloads, refunds, or commissions
User Experience Enhancements
- Tailoring content
- Enhancing search, navigation, and recommendations
- Improving product listings and author tools
- Offering faster customer support
Business Operations
- Marketplace analytics
- Reporting and insights
- Product quality review and moderation
- These activities are essential to provide a safe, efficient, and continuous service.
1.3. Legal Obligations
TiiDON must comply with multiple regulatory frameworks under GDPR and Zambia’s DPA.
We may process or retain personal data to fulfill:
Financial & Tax Requirements
- Transaction records
- Payout records
- Compliance with accounting and tax authorities
Anti-Fraud, AML & KYC Requirements
Required when:
- Verifying authors
- Preventing financial crime
- Protecting marketplace integrity
Data Retention Laws
Some data must be kept for a legally defined period.
Law Enforcement Requests
We may disclose or preserve data when legally compelled, such as:
- Court orders
- Regulatory investigations
- Cybercrime reports
Consumer Protection & Digital Marketplace Laws
- Ensuring transparency, fairness, and accountability.
- We only process the minimum amount of data required to meet these obligations.
1.4. Consent (GDPR & DPA Requirement)
In situations where data processing is not strictly required for contracts or legal compliance, we rely on user consent.
This includes:
- Optional marketing emails
- Cookie tracking (analytics, ads, affiliate tracking)
- Social login integrations (Google, Facebook, GitHub, etc.)
- Optional newsletter subscriptions
- Optional personalization features
Users have the right to withdraw consent at any time without affecting the lawfulness of prior processing.
1.5. Public Interest & Regulatory Compliance (DPA 2021 Specific)
Under Zambia’s Data Protection Act, data may also be processed when necessary for:
- Public interest functions
- National security matters
- Cybercrime prevention
- Regulatory oversight
- Protection of the rights and freedoms of others
TiiDON will always ensure these are lawful, proportionate, and documented.
1.4. Consent
For:
- Marketing communications
- Cookie tracking
- Affiliate tracking
- Social login integrations
- Optional analytics
Users may withdraw consent at any time.
2. Your GDPR Rights
Under the General Data Protection Regulation (GDPR), users located in the European Union (EU) and the European Economic Area (EEA) have strong rights over their personal data.
TiiDON respects and fully supports these rights.
You may exercise any of the rights listed below at any time by contacting:
📧 support@tiidon.com
TiiDON will respond to GDPR-related requests within 30 days, as required by law.
2.1. Right of Access
You have the right to request:
- A confirmation of whether TiiDON is processing your personal data
- A copy of all personal data we hold about you
- Information about how and why your data is processed
- Details of third parties who may have received your data
- The period for which your data is stored
- Details of your data protection rights
- Upon request, we will provide:
- A digital copy of your data (JSON, CSV, or PDF)
- A summary of processing activities connected to your account
We may require identity verification to protect your privacy.
2.2. Right to Rectification
You have the right to request that TiiDON:
- Correct inaccurate or outdated information
- Complete incomplete or missing information
- Update profile details, payout information, or account data
- This applies to all personal data, including:
- Profile information
- Payout/billing information
- Account login details
- Documentation (KYC)
- Author profile data
In many cases, you can update this information directly in your TiiDON dashboard.
For data that cannot be modified manually, contact our support team.
2.3. Right to Erasure (“Right to Be Forgotten”)
You may request that TiiDON delete your personal data in any of the following situations:
- The data is no longer necessary for the purposes for which it was collected
- You withdraw consent (for cases where processing is based on consent)
- You object to processing and no overriding legal grounds exist
- The data has been processed unlawfully
- The data must be erased to comply with a legal obligation
- You no longer wish to maintain a TiiDON account
Important Legal Exceptions
We may refuse or delay deletion if your data is required for:
- Transaction records
- Fraud prevention
- Financial audits
- Tax laws (minimum retention periods)
- AML/KYC obligations
- Ongoing legal claims
- Investigation of policy violations
Once the retention period is over, your data will be fully erased or anonymized.
Deletion Effects
If your account is deleted:
- You will lose access to all purchased products
- Author earnings and products will be removed or anonymized
- Affiliate records may be deactivated
- Support tickets and communications may be anonymized
- Legal or financial records may be retained for statutory periods
- Account deletion is irreversible.
Request deletion of your data unless legal or financial obligations require retention.
2.4. Right to Restrict Processing
You have the right to request that TiiDON limit the way we process your personal data.
This means your data may be stored but not actively used until the restriction is lifted.
You may request restriction when:
- You contest the accuracy of the data (pending verification).
- The processing is unlawful, but you prefer restriction over deletion.
- TiiDON no longer needs the data, but you require it for legal claims.
- You have objected to processing and a decision is pending.
- During restriction:
- Your data will not be used for analytics, marketing, or personalization.
- Access to certain features may be limited for security reasons.
- Only essential processing (fraud prevention, account security, legal needs) will continue.
You will be informed before any restriction is lifted.
2.5. Right to Data Portability
You have the right to receive your personal data in a structured, commonly used, machine-readable format, such as:
- CSV
- JSON
- XML
- You may also request that TiiDON transfer your data directly to another service provider when technically feasible.
- This right applies to:
- Data you provided directly
- Data generated by your activity
- Data processed based on consent or contractual necessity
- Portability does not include:
- Internal analytics
- Fraud detection signals
- Security logs
- Third-party data
We will complete portability requests within 30 days.
2.6. Right to Object
You have the right to object at any time to processing based on legitimate interests, including:
- Security-based behavioral analysis
- Analytics and improvement activities
- Personalized content or recommendations
- Marketing communications
- Profiling related to marketing
- If you object:
- TiiDON will stop processing your data for the specific purpose unless we have compelling legitimate grounds (e.g., fraud prevention, legal obligations).
You will always be able to opt out of marketing emails, which are immediately stopped upon request.
2.7. Right to Withdraw Consent
Where processing is based on consent, you may withdraw it at any time.
This applies to:
- Marketing emails
- Cookie tracking
- Affiliate tracking cookies
- Newsletter subscriptions
- Optional analytics
- Social login authorization (Google, Facebook, GitHub, etc.)
- Withdrawal does not affect the legality of processing performed before the withdrawal.
- You can withdraw consent by:
- Clicking “unsubscribe” in emails
- Changing your browser cookie settings
- Contacting support@tiidon.com
- Adjusting privacy settings (where available)
Some features may become unavailable after consent withdrawal, especially those requiring cookies or tracking.
2.8. Right to Lodge a Complaint
If you believe TiiDON has violated your privacy or processed your data unlawfully, you have the right to file a complaint with your local EU Data Protection Authority (DPA).
Examples of EU DPAs:
- Germany: Der Bundesbeauftragte für den Datenschutz
- France: CNIL
- Ireland: Data Protection Commission
- Netherlands: Autoriteit Persoonsgegevens
- Spain: AEPD
- Italy: Garante per la protezione dei dati personali
- You may also contact:
- The supervisory authority in your country of residence
- The authority where the alleged violation occurred
- Before filing a complaint, we encourage users to contact us so we can resolve issues promptly:
- 📧 support@tiidon.com
- TiiDON will cooperate fully with all EU and EEA supervisory authorities as required by GDPR.
All GDPR requests can be submitted to:
📧 support@tiidon.com
3. Data We Collect
We collect personal data necessary to operate the marketplace securely, including:
- Name, email, username
- Country and profile details
- Billing information
- Author payout details
- KYC documents (if applicable)
- Login timestamps & IP addresses
- Device and usage analytics
- Purchase history
- Uploaded products
- Support correspondence
Full details are listed in our Privacy Policy.
4. Why We Collect Your Data (GDPR Purposes)
We process data for:
- Account creation and authentication
- Order processing & digital product delivery
- Author payouts (bank/mobile money/crypto)
- Affiliate tracking & commissions
- Security monitoring & fraud prevention
- KYC/AML verification
- Tax and compliance reporting
- Platform improvement & analytics
- Customer support
- We never sell personal data to third parties.
5. Automated Decision-Making & Profiling
TiiDON uses limited automated systems for:
- Fraud detection
- Payment risk scoring
- Affiliate tracking
- IP/geolocation verification
- Suspicious account behavior detection
- These systems are designed to protect users and marketplace integrity.
- Users can request human review by contacting support.
6. Data Storage and Retention
Personal data is stored:
- On secure servers
- In encrypted databases
- With access restricted to authorized staff
- Data is retained:
- As long as your account is active
- As required by financial, tax, or legal obligations
- For fraud prevention and security
Users may request deletion, except where retention is legally required.
7. International Data Transfers
Your data may be transferred outside the EU/EEA, including to:
- Zambia (TiiDON Headquarters)
- Countries where service providers are located
- Cloud infrastructure regions
- We ensure compliance through:
- Standard Contractual Clauses (SCCs)
- GDPR-compliant service agreements
- Secure encrypted data transfer mechanisms
Your data is treated with the same protection regardless of location.
8. Cookies and Tracking Technologies (GDPR-Compliant)
TiiDON uses cookies for:
- Essential login/session functionality
- Analytics & performance
- Affiliate tracking
- Fraud prevention
- Preference storage (e.g., language, theme)
Users may manage cookie preferences via browser settings or our cookie banner.
9. Data Sharing Under GDPR
We may share data with:
9.1. Service Providers
- Payment processors
- Cloud hosting
- Email platforms
- Anti-fraud services
- Analytics providers
- Identity verification services
All partners are GDPR compliant and bound by strict contracts.
9.2. Authors/Sellers
Only limited necessary data is shared, such as:
- Username
- Purchase code
- Support request details
9.3. Legal or Regulatory Authorities
Only when required by law.
We do not sell personal data to advertisers or third parties.
10. Data Security Measures
TiiDON implements comprehensive security protections:
- HTTPS/SSL encryption
- Password hashing (bcrypt/argon2)
- Role-based access controls
- Suspicious activity monitoring
- Regular audits & penetration testing
- Secure data centers
- Optional two-factor authentication (2FA)
No system is 100% secure, but TiiDON follows industry best practices.
11. Data Protection Officer / GDPR Contact
For GDPR inquiries, data access, or deletion requests, contact:
Data Protection Officer (DPO)
TiiDON Innovations Limited
📧 Email: support@tiidon.com
🌐 Website: www.tiidon.com
12. Updates to This GDPR Policy
TiiDON may update this GDPR Policy to reflect changes in law, platform features, or security practices.
Users will be notified via:
- Email
- Platform notification
- Updated “Last Updated” date
- Continued use of the platform confirms acceptance of changes.