GDPR Notice | TermsandWhat

GDPR Notice

Last updated: January 2025

πŸ‡ͺπŸ‡Ί This notice applies to individuals in the European Economic Area (EEA) and UK regarding their rights under the General Data Protection Regulation (GDPR).

1. Roles

Data Controller

For account information, billing data, and service communications, TermsandWhat acts as the data controller.

Data Processor

For documents you upload for AI analysis, we act as a data processor on your behalf (you remain the controller of your document content).

3. Your Rights

Under GDPR, you have the following rights regarding your personal data:

βœ… Right of Access

Request a copy of your personal data

✏️ Right to Rectification

Correct inaccurate or incomplete data

πŸ—‘οΈ Right to Erasure

Request deletion of your data

⏸️ Right to Restriction

Limit how we process your data

πŸ“¦ Right to Portability

Receive your data in a structured format

🚫 Right to Object

Object to processing based on legitimate interests

4. Data Subject Requests

How to Submit a Request

Email us at mateocardonarios@gmail.com

Include: Your name, email address, and specific request details

⏱️Response time: Within 30 days (may extend to 60 days for complex requests)
πŸ†”Identity verification: We may request additional information to verify your identity
πŸ’°Cost: Generally free (small fee may apply for excessive requests)

5. International Transfers

When transferring your personal data outside the EEA/UK, we ensure adequate protection through:

  • β€’Standard Contractual Clauses (SCCs) approved by the European Commission
  • β€’Adequacy decisions for countries with equivalent data protection
  • β€’Additional safeguards such as encryption and access controls

6. Sub-processors

We work with carefully selected sub-processors who are bound by Data Processing Agreements:

Cloud Infrastructure

Secure hosting and data processing services

Payment Processing

Secure billing and subscription management

Analytics Services

Performance monitoring and service improvement

A complete list of sub-processors is available upon request.

7. Security Measures

We implement appropriate technical and organizational measures to protect your data:

Technical Measures

  • β€’ End-to-end encryption
  • β€’ Access controls and authentication
  • β€’ Regular security audits
  • β€’ Automated threat detection

Organizational Measures

  • β€’ Staff training and awareness
  • β€’ Incident response procedures
  • β€’ Data minimization practices
  • β€’ Regular policy reviews

8. Supervisory Authority

Right to Lodge a Complaint

You have the right to lodge a complaint with your local data protection supervisory authority if you believe we have not handled your personal data in accordance with GDPR.

Find your local authority at edpb.europa.eu

9. Contact

For GDPR-related questions or to exercise your rights, contact us at mateocardonarios@gmail.com

Exercise Your GDPR Rights

Contact us at mateocardonarios@gmail.com

We respond to GDPR requests within 30 days.