Home
ClikBy
ClikBy Knowledge Base
Compliance

Personal data and cookies: BY / GDPR / CCPA

How roles are set, what data a click writes, and which consent controls exist in the product — not a substitute for legal advice.

14–18 min Updated: July 2026
99-3Belarus
GDPRBarcelona
CCPAopt-out

Key takeaways

  • For clicks on the client's links: Customer = controller (operator), ClikBy = processor (authorized person) — as in privacy-policy §1.9.
  • visits store IP, geo, UA fields, referer, UTM, fbclid, engagement, statuses, fingerprint_*, and more; stats hold aggregates without IP.
  • Jurisdictions: Belarus Law No. 99-3, GDPR (EU representative in Barcelona), CCPA/CPRA guidance via product consent controls.
  • Extended map of regimes (Law 25, Privacy Act AU, FADP, DMA/DSA) — privacy-regulations-map.
  • No automatic visits cleanup by the pii_cleaned_at field was found in the code — do not promise «auto-anonymization on a timer».

Important: not legal advice

This article is help for a marketer and account owner: how the product is built and how Policy wording maps to features. It does not replace a contract, DPA, or lawyer advice.

Disputed wording and local state/country requirements — check against the full Privacy Policy and the contract. Below is an overview from product facts and the published policy.

Roles: Customer and ClikBy

If you are a registered account client — you are the service customer. The ClikBy platform operator (Proactive Technology LLC, Belarus) processes account data under its Policy.

If a person simply clicked your short link (without an account), ClikBy processes their technical data on your behalf: you are the Data Controller / personal-data operator for clickers, ClikBy is the Data Processor / authorized person (Authorized Person). Deletion or consent-withdrawal requests must go to the link sender (you), not «into the void».

Source of the role wording: §1.9 privacy-policy.html. If needed, conclude/update a DPA with ClikBy.

What data is actually collected

Visits (visits) on click

A typical visit field set includes: IP; country/city; browser, platform, device; referer; utm_source…utm_content; fbclid; time_on_site; scroll_depth; engagement events; status (bot/pending/confirmed); fingerprint_*; conversion_score and related antifraud/quality metrics.

Aggregates (stats)

Summary statistics for reports are built without storing IP in aggregates — convenient for operational Dashboards, but it does not cancel the fact that a raw visit may have contained an IP.

Cookies and consents

  • On the redirect of a link with pixels: cookie consent{link_id} after the pixel_notification window.
  • Product «Cookie notice window» (/cookies): accepted / declined / ignored decisions and banner settings for the client's sites.
  • Third-party pixels (Meta, Google, VK…) set their own cookies under their policies — see config/pixels.php and vendor policies.
CategoryПримерыWhere it appears
TechnicalIP, UA → browser/device, referervisits / antifraud
Marketing tagsUTM×5, fbclidvisits, reports
Behavioraltime_on_site, scroll_depth, events_*visits / quality
Consentsconsent{link_id}, Cookie Consent decisionscookie / account /cookies
Aggregatesclicks by day, devices without IPstats, export

Belarus: Law No. 99-3

The ClikBy Policy is drafted with regard to the Law of the Republic of Belarus of 07.05.2021 No. 99-3 «On Personal Data Protection» (and GDPR — see below). The operator is Proactive Technology LLC.

Legal bases and purposes (overview)

The policy for the site/service states, among other things, the data subject's consent and separate bases for statistics under strict anonymization (guidance of Art. 5 / cl. 19 of Art. 6 of the Law — as set out in the Policy). For clicks on the client's links, legal bases and notice to data subjects are the controller's responsibility (yours); ClikBy acts on your instructions in a processor role.

Data-subject rights

The right to information, withdrawal of consent, deletion/rectification and other rights under 99-3 are exercised through the operator responsible for the processing purpose. A clicker of your link contacts you; an account client contacts ClikBy using the Policy contacts.

Cross-border transfer

The Policy describes possible transfer of technical data (IP, cookies) abroad in connection with analytics and service operation, with notice via the cookie banner. When you connect foreign pixels, you yourself initiate the transfer to vendors — account for this in your policy and consents.

Exact wording of legal bases, retention periods, and operator contacts — only in the current privacy-policy / PDF.

GDPR

  • Controller / Processor: for clickers of the client's links — Customer controller, ClikBy processor (§1.9).
  • Lawful basis: depends on your purpose (advertising, campaign analytics, security). Technical data for the redirect often rely on legitimate interest / necessity of the service; marketing cookies and pixels — usually consent. Record the basis in your policy.
  • Data-subject rights: access, rectification, erasure, restriction, objection, portability — route requests: clicker → you; account data → ClikBy.
  • EU representative: the Policy lists the office / representative: Av. Diagonal, 468, Gràcia, 08006 Barcelona, Spain.
  • DPA: when processing clickers' personal data through ClikBy, agree a processing mandate / DPA with the platform.

Enabling Meta/Google/VK pixels makes those vendors separate data recipients — describe them in your policy and banner.

Full GDPR block: what GDPR is · consent and cookies · rights and checklist.

CCPA / CPRA (product overview)

The California Consumer Privacy Act / CPRA operates with personal information categories, sale/share, and the service provider role. Below is a product projection, not a legal opinion.

Categories (typical for a click)

Identifiers and internet activity: IP, cookie ID, device/browser, referer, UTM, interactions with the redirect page/pixels. The exact category list for your notice is on the controller's side.

Sale / Share vs service provider

ClikBy as processor for clicks acts to provide the service to the client. Transfer to ad pixels (Meta, Google Ads, etc.) that you enable may qualify on your side as share/sale in the CPRA sense — that is your assessment and disclosures. Do not rely on «since ClikBy is there, there is no sale».

Opt-out and product controls

  • ClikBy Cookie Consent product banner: Accept / Reject / Manage; categories tech (required), analytics, marketing; defaults analytics_default / marketing_default; gtag Consent Mode.
  • Refusing marketing cookies on your site reduces loading of marketing tags (if you correctly embedded the embed and honor the decision).
  • On the link redirect: Reject in pixel_notification → cookie consent{link_id}=0 → pixels do not fire when consent is checked.
  • For data-subject requests about click data — contact the controller (you). For ClikBy account data — contacts from the Policy. GDPR/CCPA badges on the ClikBy site do not replace your «Do Not Sell or Share» notice.

«Do Not Sell/Share» and GPC wording — confirm with a lawyer for your states and stack.

Full block: what CCPA is · Do Not Sell or Share · CCPA vs GDPR.

Pixel notice on the redirect

The pixel_notification flag on the link: a consent view is shown before tracking. Decision → cookie consent{link_id}. This is a separate mechanism from the /cookies banner on your landing page.

Recommendation: for ad pixels, enable the notice and duplicate the meaning in the policy on the destination.

Storage and deletion

The data model has a field like pii_cleaned_at, but automatic visits cleanup by this field was not found in the code at the time the article was prepared. Do not promise clients and data subjects «automatic IP deletion after N days» based only on the field existing.

  • Retention periods — per the Policy, the contract, and your instructions to the processor.
  • Requests to delete clicker data: first you as controller, then escalation to ClikBy under the support/DPA procedure.
  • Withdrawal of marketing consent: Reject in the /cookies banner and/or refusal on pixel_notification; plus vendor tools (for example ad-platform opt-out).

Honest wording for clients: «storage and cleanup of raw visits — per the contract and Policy; confirm with the operator/support», not «the system itself zeroes PII on a timer».

What’s next?

Update the policy and banner

Align controller/processor roles, enable Cookie Consent and pixel_notification where you load ad pixels.