REACH COMPANY; Privacy Policy

This Privacy Policy (“Policy”) outlines how REACH TECHNOLOGIES OPERATIONS EUROPE Single Member P.C. (“We,” “Us,” “Our”) collects, uses, processes, and protects user data. By using the Reach Application (“App”) and the website www.reach-app.co, you acknowledge and agree to the terms of this Policy. REACH TECHNOLOGIES OPERATIONS EUROPE Single Member P.C. is registered in Greece with a GEMI no. 187449403000 and VAT no. EL803015684 and is headquartered at 75 Thessalonikis Street, Moschato, Attica, Greece.

1. Types of Data Collected

REACH collects personal data that users provide directly when registering and using the platform. This includes name, email address, age, gender, profile picture, Instagram handle, and any other information provided during onboarding or use of the App. We also collect usage data automatically, such as device information, IP address, app interactions, and engagement activity.

2. Purpose of Data Collection

We use the data we collect to provide and improve our services, manage your account, match Members with Businesses, send communications related to your use of the platform, ensure platform safety and compliance, and fulfil our legal obligations.

3. Communication Preferences

‍As part of using REACH, you may receive communications from us related to your account, onboarding, engagement activities, and platform updates.

Transactional and Service Emails: These include essential updates about your account, security notifications, or important changes to our services. These communications are necessary to provide our services and cannot be opted out of.

Engagement and Marketing Emails: These include notifications about collaborations, influencer engagement, gamification rewards, and occasional promotional content.

Unsubscribing: You may manage your preferences for engagement and marketing communications at any time. You can unsubscribe either by clicking the “unsubscribe” link included in every email, or by adjusting your communication preferences directly in your profile settings within the app.

4. Third-Party Services

‍We utilize services provided by Google Cloud EMEA Limited, Meta Platforms Ireland Ltd, Stripe Technology Europe, Limited ("Stripe PSP") as payment processors, Wrapp S.A. as our invoice management software, and East West International Marketing Ltd. (CreatorDB) for creator data and network analytics. We strictly limit the data provided to these services to what is absolutely necessary.

5. Retention Periods

‍User data is retained for a minimum of 5 years.

6. Data Security Measures

‍We implement rigorous processes to safeguard user data. While we take every precaution, please be aware that no method of transmission over the internet or electronic storage is fully secure.

7. Data Deletion and Anonymization

‍Upon a user’s request for data deletion, we will do so within 60 days.

8. Data Subject Rights

‍Users can exercise their rights by contacting us at support@reach-app.co

Under the GDPR - Regulation (EU) 2016/679, you have the following rights:

The right to be informed

The right of access

The right to rectification

The right to erasure

The right to restrict processing

The right to data portability

The right to object

Rights in relation to automated decision-making and profiling

9. International Data Transfers

‍All personal data collected and processed by REACH TECHNOLOGIES OPERATIONS EUROPE Single Member P.C. is stored and processed within the European Union. We do not transfer identifiable personal data outside the EU.

For internal business reporting and governance purposes, REACH TECHNOLOGIES INCORPORATED (United States), the group's parent company, may have access to strictly anonymised and aggregated statistical information — such as overall platform usage metrics — that by its nature cannot be used to identify any individual user. This information does not constitute personal data under GDPR Regulation (EU) 2016/679.

REACH TECHNOLOGIES INCORPORATED is the group's intellectual property holding company. It does not process, access, or control any personal data of European users, and is not a Data Controller or Data Processor under GDPR.

Our third-party service providers (listed in Section 4) may operate infrastructure located outside the EU. In such cases, REACH ensures that appropriate contractual safeguards are in place in accordance with applicable data protection law.

10. Children's Data

We may cross-examine the data provided with META to ensure compliance with regulations related to children's data.

11. Updates to Privacy Policy

‍Users can always find the updated version of our privacy policy on our website. Additionally, we may notify users of updates within the application downloaded from Apple App Store and Google Play Store.

12. GDPR Compliance

REACH TECHNOLOGIES OPERATIONS EUROPE Single Member P.C. is committed to complying with the General Data Protection Regulation (GDPR) as set forth by the European Union regarding the collection, use, and retention of personal data from European Union member countries. All personal data is processed within the European Union by REACH TECHNOLOGIES OPERATIONS EUROPE Single Member P.C. as Data Controller. For information on any limited data sharing with group entities, see Section 9.

Contact Information: For inquiries, concerns, or requests related to data protection, contact us at support@reach-app.co

‍Updated on April 21, 2026