1. GDPR Compliance Commitment
ADZY is committed to compliance with the General Data Protection Regulation (GDPR) (EU) 2016/679, which protects the privacy and personal data of individuals in the European Union (EU) and the European Economic Area (EEA). This policy explains how ADZY handles personal data in accordance with GDPR requirements.
2. Definition of Personal Data
Under GDPR, personal data means any information relating to an identified or identifiable natural person ("data subject"). This includes names, identification numbers, location data, online identifiers, or factors specific to identity.
3. Legal Basis for Processing
ADZY processes personal data under the following legal bases:
- Consent: We obtain explicit consent before processing personal data for specific purposes
- Contract: Processing is necessary to fulfill a contract with the data subject
- Legal Obligation: Processing is required by applicable law
- Legitimate Interests: Processing is necessary for our legitimate business interests
4. Data Subject Rights
Under GDPR, data subjects have the following rights:
- Right to Access: Request access to personal data we process about you
- Right to Rectification: Request correction of inaccurate personal data
- Right to Erasure: Request deletion of personal data ("Right to be Forgotten")
- Right to Restrict Processing: Request limitation of data processing
- Right to Data Portability: Request your data in a portable format
- Right to Object: Object to processing based on legitimate interests
5. Data Protection Officer
While not required by GDPR, ADZY has appointed a Data Protection Officer (DPO) to oversee data protection compliance. For GDPR-related inquiries, please contact us using the contact information below.
6. Data Retention
ADZY retains personal data only as long as necessary to fulfill the purposes outlined in this policy or as required by applicable law. Generally, client data is retained for 7 years after the conclusion of services to comply with accounting and tax requirements.
7. Data Transfers
If ADZY transfers personal data outside the EU/EEA, we implement appropriate safeguards including Standard Contractual Clauses (SCCs) and adequacy decisions to ensure protection equivalent to GDPR requirements.
8. Data Security Measures
ADZY implements appropriate technical and organizational security measures including encryption, firewalls, secure servers, access controls, and staff training to protect personal data against unauthorized access, alteration, or destruction.
9. Data Breach Notification
In the event of a confirmed personal data breach, ADZY will notify affected data subjects and relevant authorities without undue delay and no later than 72 hours after becoming aware of the breach, as required by GDPR Article 33.
10. Processing Activities
ADZY maintains a Record of Processing Activities (ROPA) documenting:
- Purpose of processing
- Categories of personal data processed
- Categories of data subjects
- Storage periods
- Safeguards and security measures
- Recipients of personal data
11. Data Processing Agreements
For clients with EU/EEA data subjects, ADZY enters into Data Processing Agreements (DPAs) as required by GDPR Articles 26 and 28, clearly defining the roles and responsibilities of controllers and processors.
12. Third-Party Services
ADZY only works with third-party data processors that offer sufficient guarantees of GDPR compliance. All data processing activities are governed by appropriate contractual safeguards.
13. Exercising Your Rights
To exercise any of your GDPR rights, please submit a written request to us using the contact information below. We will respond to legitimate requests within 30 days, with the possibility of a 60-day extension for complex requests.
14. Legal Compliance
ADZY complies with all applicable GDPR requirements, including the Data Protection Act 2018 (for UK entities) and equivalent regulations in other jurisdictions.
15. Supervisory Authority
You have the right to lodge a complaint with the appropriate supervisory authority (Data Protection Authority) in your country if you believe ADZY has violated your GDPR rights.
16. Contact
For GDPR-related inquiries or to exercise your data protection rights, please contact us at hello@adzy.ae or via WhatsApp at +971 58 500 3219.