011. Legal Basis for Processing
We process personal data only where we have a valid legal basis, such as consent, contractual necessity, or legitimate interest, and we document the basis relied on for each processing activity.
022. Data Subject Rights
Individuals in scope of GDPR have the right to access, correct, delete, restrict, or port their personal data, and to object to certain processing. Requests can be made through our privacy contact.
033. International Transfers
Where personal data is transferred outside the EEA, we rely on recognized transfer mechanisms such as Standard Contractual Clauses, and we document these transfers in our records of processing activity.
044. Data Protection by Design
Client-facing systems we build are designed with data minimization, purpose limitation, and appropriate retention periods considered from the outset of the project.
055. Breach Notification
In the event of a personal data breach affecting EU data subjects, we notify affected controllers without undue delay, in line with the 72-hour notification expectation set by GDPR.
