GDPR Compliance

Last updated: 8/27/2025

Introduction

The General Data Protection Regulation (GDPR) is a European Union regulation that governs how personal data is processed and protected. At Surfolks, we are committed to complying with GDPR requirements and protecting your privacy rights.

Your Rights Under GDPR

If you are a resident of the European Economic Area (EEA), you have the following rights regarding your personal data:

Right to Information

You have the right to be informed about how we collect and use your personal data. This information is provided in our Privacy Policy.

Right of Access

You have the right to request access to the personal data we hold about you. You can request a copy of your data by contacting us.

Right to Rectification

You have the right to request correction of inaccurate or incomplete personal data. You can update most of your information through your account settings.

Right to Erasure (Right to be Forgotten)

You have the right to request deletion of your personal data in certain circumstances, such as when the data is no longer necessary for the original purpose.

Right to Restrict Processing

You have the right to request that we restrict the processing of your personal data in certain situations, such as when you contest the accuracy of the data.

Right to Data Portability

You have the right to receive your personal data in a structured, commonly used, and machine-readable format, and to transmit that data to another controller.

Right to Object

You have the right to object to the processing of your personal data in certain circumstances, particularly for direct marketing purposes.

Rights Related to Automated Decision Making

You have the right not to be subject to decisions based solely on automated processing, including profiling, which produces legal effects or significantly affects you.

Legal Basis for Processing

We process your personal data based on the following legal grounds:

  • Consent: When you have given clear consent for us to process your data for specific purposes
  • Contract: When processing is necessary for the performance of a contract with you
  • Legal Obligation: When we need to comply with legal requirements
  • Legitimate Interest: When we have a legitimate business interest that doesn't override your rights

Data Protection Officer

We have appointed a Data Protection Officer (DPO) to oversee our data protection activities. You can contact our DPO at:

  • Email: dpo@surfolks.com
  • Address: [DPO Address]

Data Transfers

When we transfer your personal data outside the EEA, we ensure appropriate safeguards are in place, such as:

  • Standard Contractual Clauses approved by the European Commission
  • Adequacy decisions by the European Commission
  • Certification schemes and codes of conduct

Data Retention

We retain your personal data only for as long as necessary to fulfill the purposes for which it was collected, including:

  • Account data: Until you delete your account or request deletion
  • Transaction data: As required by law (typically 7 years)
  • Marketing data: Until you withdraw consent or object to processing
  • Log data: Typically 12-24 months for security and performance purposes

Data Breach Notification

In the event of a data breach that poses a risk to your rights and freedoms, we will:

  • Notify the relevant supervisory authority within 72 hours
  • Inform affected individuals without undue delay if the risk is high
  • Document the breach and our response measures

How to Exercise Your Rights

To exercise any of your GDPR rights, please contact us using the following methods:

  • Email: gdpr@surfolks.com
  • Through your account settings (for some requests)
  • Written request to our postal address

We will respond to your request within one month. In complex cases, we may extend this period by two additional months, and we will inform you of any such extension.

Complaints

If you believe we have not handled your personal data in accordance with GDPR, you have the right to lodge a complaint with your local supervisory authority.

Contact Information

For any questions about GDPR compliance or to exercise your rights, please contact us at:

  • Email: gdpr@surfolks.com
  • Data Protection Officer: dpo@surfolks.com
  • Address: [Your Company Address]