Your Data Rights
Under GDPR and similar regulations, you have specific rights regarding your personal data.
You can request a copy of all personal data we hold about you.
How: Submit a data export request through your account settings or the data request form.
You can request correction of inaccurate personal data.
How: Update your profile directly or submit a rectification request.
You can request deletion of your personal data (with some exceptions).
How: Submit a deletion request through your account settings.
You can receive your data in a structured, machine-readable format.
How: Request a data export in JSON format.
You can request we limit how we use your data.
How: Submit a restriction request through the data request form.
You can object to certain types of processing, including marketing.
How: Update your communication preferences or submit an objection request.
How We Protect Your Data
We implement industry-standard security measures to keep your data safe.
Encryption
All data is encrypted in transit using TLS 1.3 and at rest using AES-256 encryption.
Access Control
Role-based access control (RBAC) ensures users only access data they need.
Secure Infrastructure
Hosted on SOC 2 compliant cloud infrastructure with 24/7 monitoring.
Data Backup
Automated daily backups with point-in-time recovery capabilities.
Audit Logging
Comprehensive logging of all data access and system changes.
Authentication
Secure password hashing (bcrypt) and optional multi-factor authentication.
Data Retention Policy
We only keep your data for as long as necessary.
active accounts
Data retained while account is active
deleted accounts
Data deleted within 30 days of deletion request
backup retention
Backups purged within 90 days
legal requirements
Some data may be retained longer for legal compliance
Data Controller
We respond to all GDPR requests within 30 days.