Last Updated: 01-Feb-2025
GDPR — What Acriotech is Doing About It
Acriotech has always honored its users' rights to data privacy and protection. We have no need to collect and process users' personal information beyond what is required for the functioning of our enterprise products, and this will never change. We have a privacy-conscious culture and view GDPR not as a compliance burden, but as an opportunity to demonstrate our values.
What is GDPR?
The General Data Protection Regulation (EU) 2016/679 is a comprehensive EU-wide privacy and data protection law that came into effect on May 25, 2018. It significantly increases the obligations placed on organizations that process the personal data of EU and EEA residents, and dramatically strengthens the rights of those individuals.
GDPR applies to any globally operating company — not just EU-based businesses. Because Acriotech serves enterprise clients across Europe, Asia, and North America, GDPR compliance is our baseline standard for all global operations. We apply these protections to all users, regardless of their location.
What is Personal Data?
Personal data is any information that relates to an identified or identifiable natural person. GDPR covers a broad spectrum, including:
Note that special category data (health, biometric, genetic, racial origin, political opinions, religious beliefs, sexual orientation, trade union membership) requires an elevated level of protection and an explicit lawful basis for processing.
Acriotech's Role Under GDPR
Depending on context, Acriotech assumes different roles under GDPR:
When we collect personal data from visitors to our website, prospective clients, or our own employees. We determine the purposes and means of processing this data.
When we process personal data on behalf of our enterprise clients as part of our software engineering services. The client is the data controller; Acriotech acts only on their documented instructions.
How Acriotech Has Prepared for GDPR
We have conducted GDPR awareness programs across all departments, with mandatory annual training for engineers, sales, and operations staff. Employees handling personal data complete role-specific data protection training and sign confidentiality agreements.
We maintain a comprehensive record of all personal data we process, including the category of data, the processing purpose, the legal basis, data retention periods, and the internal teams and third-party sub-processors with access. This register is reviewed quarterly.
Our engineering teams integrate data protection controls at the design stage of every product and system. This includes data minimization (only collecting what is strictly necessary), pseudonymization where possible, and privacy-friendly defaults in all user-facing settings.
We maintain a vetted register of all third-party sub-processors (cloud providers, SaaS tools, payment processors) with whom we share personal data. All sub-processors have signed DPAs incorporating the EU Standard Contractual Clauses. Our sub-processor list is available to enterprise clients upon request.
We conduct DPIAs for any new processing activity that is likely to result in a high risk to the rights and freedoms of natural persons — including large-scale processing, systematic monitoring, and novel AI-based systems. DPIA outcomes drive technical and organizational controls.
We have appointed an internal Data Protection Officer responsible for overseeing our GDPR compliance program, advising on data protection matters, acting as the point of contact for supervisory authorities, and handling individual rights requests. Contact: privacy@acriotech.com
Our Security Incident Response Plan includes a 72-hour breach notification workflow. If we become aware of a personal data breach affecting EU residents, we will notify the relevant supervisory authority within 72 hours. Affected individuals will be notified without undue delay when the breach is likely to result in a high risk to their rights and freedoms.
For transfers of EU personal data to third countries, we rely on the European Commission-approved Standard Contractual Clauses (SCCs) and conduct Transfer Impact Assessments (TIAs) for transfers to jurisdictions that may not provide adequate protection.
Your Rights Under GDPR
If Acriotech is the data controller for your personal data, you have the following enforceable rights. All requests are handled within 30 days (extendable by 2 months for complex requests, with notification):
- Art. 15 — Right of Access: Receive a copy of your personal data and information about how it is processed.
- Art. 16 — Right to Rectification: Have inaccurate data corrected without undue delay.
- Art. 17 — Right to Erasure ("Right to be Forgotten"): Have your data deleted when it is no longer necessary for the original purpose.
- Art. 18 — Right to Restriction: Request that processing be temporarily halted in certain circumstances.
- Art. 20 — Right to Data Portability: Receive your data in a structured, machine-readable format (JSON or CSV).
- Art. 21 — Right to Object: Object to processing based on legitimate interests or for direct marketing.
- Art. 22 — Rights related to Automated Decision-Making: Not be subject to decisions based solely on automated processing that produce significant legal effects, without human review.
Frequently Asked Questions
A: Yes, if you process the personal data of EU or EEA residents — even if you are located outside Europe — GDPR applies to your organization. As your software engineering partner, Acriotech will help ensure that the systems we build for you incorporate appropriate data protection controls.
A: Supervisory authorities can impose fines of up to €20 million or 4% of total global annual turnover (whichever is higher) for the most serious infringements (e.g., violations of basic processing principles or data subject rights). Less severe infringements carry fines up to €10 million or 2% of global turnover.
A: Yes. Enterprise clients who require a formal DPA (incorporating Standard Contractual Clauses for international transfers) can request one by emailing legal@acriotech.com. We will return a signed DPA within 5 business days.
A: Any AI system we build that produces legally significant automated decisions is designed with a mandatory human-review layer, explainability mechanisms, and override capabilities. We document the logic and risk factors of all AI decision systems in our DPIA register.
Contact Our Data Protection Officer
For GDPR inquiries, to exercise your data subject rights, or to request a DPA, contact our Data Protection Officer at privacy@acriotech.com. If you have unresolved concerns, you have the right to lodge a complaint with your local Data Protection Supervisory Authority.