GDPR Compliance Policy

Last Updated:

1. Introduction

This GDPR Compliance Policy explains how CxStat ("we," "our," or "us") complies with the General Data Protection Regulation (GDPR) (Regulation (EU) 2016/679) and your rights as a data subject.

The GDPR is a comprehensive data protection law that applies to organizations processing personal data of individuals in the European Economic Area (EEA). We are committed to protecting your personal data and ensuring full compliance with GDPR requirements.

Our Commitment: We process your personal data lawfully, fairly, and transparently, and only for specified, explicit, and legitimate purposes.

2. Legal Basis for Processing

Under GDPR, we must have a legal basis for processing your personal data. We process your data based on the following legal grounds:

2.1 Consent

You have given clear consent for us to process your personal data for specific purposes, such as:

You can withdraw your consent at any time by contacting us or adjusting your account settings.

2.2 Contractual Necessity

Processing is necessary for the performance of a contract to which you are a party, including:

2.3 Legitimate Interests

Processing is necessary for our legitimate interests, such as:

We always balance our legitimate interests against your rights and freedoms and will not process your data if your interests override ours.

2.4 Legal Obligation

Processing is necessary for compliance with legal obligations, such as:

3. Your Rights Under GDPR

As a data subject under GDPR, you have the following rights:

Right of Access

You have the right to obtain confirmation as to whether we process your personal data and access to that data, including copies of your data.

Right to Rectification

You have the right to have inaccurate personal data corrected and incomplete data completed.

Right to Erasure

You have the right to request deletion of your personal data in certain circumstances ("right to be forgotten").

Right to Restrict Processing

You have the right to restrict the processing of your personal data in certain circumstances.

Right to Data Portability

You have the right to receive your personal data in a structured, commonly used, and machine-readable format and to transmit it to another controller.

Right to Object

You have the right to object to processing of your personal data based on legitimate interests or for direct marketing purposes.

Right to Withdraw Consent

Where processing is based on consent, you have the right to withdraw consent at any time.

Right to Lodge a Complaint

You have the right to lodge a complaint with a supervisory authority if you believe your rights have been violated.

3.1 How to Exercise Your Rights

To exercise any of these rights, please contact us using the information provided in the "Contact Us" section. We will:

4. Data Controller and Data Processor

Data Controller: CxStat is the data controller responsible for determining the purposes and means of processing your personal data.

Data Processors: We use the following data processors who process your data on our behalf:

We have data processing agreements in place with all processors to ensure they handle your data in accordance with GDPR requirements.

5. Personal Data We Process

We process the following categories of personal data:

5.1 Identity Data

5.2 Account Data

5.3 Project Data

5.4 Technical Data

5.5 Credential Data

6. Data Processing Principles

We adhere to the following GDPR data processing principles:

6.1 Lawfulness, Fairness, and Transparency

We process personal data lawfully, fairly, and in a transparent manner. We clearly inform you about what data we collect and how we use it.

6.2 Purpose Limitation

We collect personal data only for specified, explicit, and legitimate purposes and do not process it in a manner incompatible with those purposes.

6.3 Data Minimization

We collect and process only the personal data that is adequate, relevant, and limited to what is necessary for the purposes for which it is processed.

6.4 Accuracy

We take reasonable steps to ensure personal data is accurate and kept up to date. You can update your information through your account settings.

6.5 Storage Limitation

We retain personal data only for as long as necessary to fulfill the purposes for which it was collected, unless a longer retention period is required by law.

6.6 Integrity and Confidentiality

We implement appropriate technical and organizational measures to ensure personal data is processed securely, including protection against unauthorized access, loss, or destruction.

6.7 Accountability

We are responsible for demonstrating compliance with GDPR principles and maintaining records of our data processing activities.

7. Data Security Measures

We implement comprehensive security measures to protect your personal data:

7.1 Technical Measures

7.2 Organizational Measures

7.3 Data Breach Notification

In the event of a personal data breach that is likely to result in a high risk to your rights and freedoms, we will:

8. International Data Transfers

Your personal data may be transferred to and processed in countries outside the EEA, including the United States, where our service providers (Google Firebase, Google Analytics) are located.

We ensure that appropriate safeguards are in place for such transfers, including:

By using CxStat, you consent to the transfer of your data to these countries with the safeguards described above.

9. Data Retention

We retain your personal data only for as long as necessary to fulfill the purposes outlined in this policy:

When data is no longer needed, we securely delete or anonymize it in accordance with our data retention policies.

10. Children's Data

CxStat is not intended for use by individuals under the age of 18. We do not knowingly collect personal data from children under 16 years of age without parental consent.

If you are a parent or guardian and believe your child has provided us with personal data, please contact us immediately. If we become aware that we have collected personal data from a child without parental consent, we will take steps to delete that information.

11. Automated Decision-Making and Profiling

We do not use automated decision-making or profiling that produces legal effects or significantly affects you. All decisions regarding your account and data are made with human oversight.

Analytics and usage data are used only for service improvement and do not result in automated decisions that affect your access to services or rights.

12. Supervisory Authority

If you are located in the EEA and believe we have not addressed your concerns or that we have not complied with GDPR requirements, you have the right to lodge a complaint with your local supervisory authority.

You can find contact information for your supervisory authority at: European Data Protection Board

We encourage you to contact us first so we can address your concerns directly.

13. Updates to This Policy

We may update this GDPR Compliance Policy from time to time to reflect changes in our practices, legal requirements, or other factors. We will notify you of any material changes by:

Your continued use of CxStat after any changes constitutes your acceptance of the updated policy.

14. Contact Us - Data Protection

For any questions, concerns, or requests regarding GDPR compliance or your data protection rights, please contact us:

Email: team@cxstat.com
Subject Line: GDPR Inquiry

Response Time: We will respond to your inquiry within one month of receipt. For complex requests, we may extend this period by up to two months and will inform you of the extension and reasons.

Identity Verification: To protect your privacy, we may request verification of your identity before processing certain requests.