How we protect your data rights under the EU General Data Protection Regulation
The General Data Protection Regulation (GDPR) is a comprehensive data protection law enacted by the European Union (EU), which became effective on May 25, 2018. It aims to give EU citizens and residents more control over their personal data and to simplify the regulatory environment for international business.
The GDPR applies to all organizations that process personal data of EU citizens or residents, regardless of where the organization is located. It establishes rules for data protection, privacy, and the transfer of personal data inside and outside the EU.
GDPR is founded on principles of lawfulness, fairness, transparency, purpose limitation, data minimization, accuracy, storage limitation, integrity, confidentiality, and accountability.
GDPR grants individuals specific rights regarding their personal data, including access, rectification, erasure, restriction of processing, data portability, and objection to processing.
At DataConcerto.AI, we are committed to protecting the privacy and rights of our users. We have implemented comprehensive measures to ensure compliance with the GDPR and to protect the personal data of all our users, including EU citizens and residents.
Our commitment to GDPR compliance includes:
We may collect and process the following types of personal data:
We process personal data only when we have a lawful basis for doing so under GDPR. The lawful bases we rely on include:
We process personal data for various purposes, including:
Under the GDPR, if you are an EU citizen or resident, you have several rights regarding your personal data. We are committed to honoring these rights and facilitating their exercise.
You have the right to request copies of your personal data. We may charge a reasonable fee when a request is manifestly unfounded, excessive, or repetitive.
You have the right to request that we correct any information you believe is inaccurate or complete information you believe is incomplete.
You have the right to request that we erase your personal data, under certain conditions. Also known as the "right to be forgotten."
You have the right to request that we restrict the processing of your personal data, under certain conditions.
You have the right to request that we transfer the data we have collected to another organization, or directly to you, under certain conditions.
You have the right to object to our processing of your personal data, under certain conditions, including for direct marketing purposes.
You have the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects or similarly significantly affects you.
You have the right to withdraw your consent at any time where we are relying on consent to process your personal data.
We have implemented straightforward processes to help you exercise your rights under GDPR. You can exercise your rights by:
You can submit a request to exercise your GDPR rights through our secure online form. We will respond to your request within one month.
Submit RequestAlternatively, you can exercise your rights by:
When submitting a request, please provide:
We may need to request specific information from you to help us confirm your identity and ensure your right to access your personal data (or to exercise any of your other rights). This is a security measure to ensure that personal data is not disclosed to any person who has no right to receive it.
DataConcerto.AI is based in the United States, and we may transfer personal data from the EU to the US and other countries outside the EU. We ensure that any such transfers comply with GDPR requirements by implementing appropriate safeguards.
For transfers of personal data outside the EU, we use one or more of the following mechanisms to ensure compliance with GDPR:
We may share your personal data with third-party service providers who help us operate our services. We ensure that these providers offer appropriate guarantees regarding data protection and GDPR compliance.
We maintain a list of our third-party service providers, including their locations and the safeguards we have implemented. You can request this information by contacting our Data Protection Officer.
We have implemented appropriate technical and organizational measures to protect your personal data and ensure a level of security appropriate to the risk. These measures include:
We regularly review and update our security measures to ensure continued effectiveness. However, no method of transmission over the Internet or method of electronic storage is 100% secure. While we strive to use commercially acceptable means to protect your personal data, we cannot guarantee its absolute security.
We have implemented procedures to detect, report, and investigate personal data breaches in line with GDPR requirements. In the event of a data breach that is likely to result in a risk to your rights and freedoms, we will:
Our notification will include:
We have appointed a Data Protection Officer (DPO) who is responsible for overseeing questions in relation to this GDPR policy and our overall data protection strategy. The DPO's responsibilities include:
Our DPO operates independently and reports directly to the highest level of management.
If you have any questions about this GDPR policy or our data protection practices, please contact our Data Protection Officer:
Email: dpo@dataconcerto.ai
If you are located in the EU, you also have the right to make a complaint at any time to your local supervisory authority for data protection issues. However, we would appreciate the chance to deal with your concerns before you approach the supervisory authority, so please contact us in the first instance.
Effective Date: May 1, 2025