Solutions

Services

Work

Industries

Insights

Legal & Compliance Center

Acriotech policies, terms, and compliance information.

Last Updated: 01-Feb-2025

GDPR — What Acriotech is Doing About It

Acriotech has always honored its users' rights to data privacy and protection. We have no need to collect and process users' personal information beyond what is required for the functioning of our enterprise products, and this will never change. We have a privacy-conscious culture and view GDPR not as a compliance burden, but as an opportunity to demonstrate our values.


What is GDPR?

The General Data Protection Regulation (EU) 2016/679 is a comprehensive EU-wide privacy and data protection law that came into effect on May 25, 2018. It significantly increases the obligations placed on organizations that process the personal data of EU and EEA residents, and dramatically strengthens the rights of those individuals.

GDPR applies to any globally operating company — not just EU-based businesses. Because Acriotech serves enterprise clients across Europe, Asia, and North America, GDPR compliance is our baseline standard for all global operations. We apply these protections to all users, regardless of their location.

What is Personal Data?

Personal data is any information that relates to an identified or identifiable natural person. GDPR covers a broad spectrum, including:

Name & Email
IP Addresses
Phone Numbers
Location Data
Biometric Data
Financial Records
Health Information
Political Opinions
Genetic Data

Note that special category data (health, biometric, genetic, racial origin, political opinions, religious beliefs, sexual orientation, trade union membership) requires an elevated level of protection and an explicit lawful basis for processing.

Acriotech's Role Under GDPR

Depending on context, Acriotech assumes different roles under GDPR:

Data Controller

When we collect personal data from visitors to our website, prospective clients, or our own employees. We determine the purposes and means of processing this data.

Data Processor

When we process personal data on behalf of our enterprise clients as part of our software engineering services. The client is the data controller; Acriotech acts only on their documented instructions.

How Acriotech Has Prepared for GDPR

1
Organizational Awareness & Training

We have conducted GDPR awareness programs across all departments, with mandatory annual training for engineers, sales, and operations staff. Employees handling personal data complete role-specific data protection training and sign confidentiality agreements.

2
Information Asset Register (IAR)

We maintain a comprehensive record of all personal data we process, including the category of data, the processing purpose, the legal basis, data retention periods, and the internal teams and third-party sub-processors with access. This register is reviewed quarterly.

3
Privacy by Design & by Default

Our engineering teams integrate data protection controls at the design stage of every product and system. This includes data minimization (only collecting what is strictly necessary), pseudonymization where possible, and privacy-friendly defaults in all user-facing settings.

4
Sub-processor Management

We maintain a vetted register of all third-party sub-processors (cloud providers, SaaS tools, payment processors) with whom we share personal data. All sub-processors have signed DPAs incorporating the EU Standard Contractual Clauses. Our sub-processor list is available to enterprise clients upon request.

5
Data Protection Impact Assessments (DPIA)

We conduct DPIAs for any new processing activity that is likely to result in a high risk to the rights and freedoms of natural persons — including large-scale processing, systematic monitoring, and novel AI-based systems. DPIA outcomes drive technical and organizational controls.

6
Data Protection Officer (DPO)

We have appointed an internal Data Protection Officer responsible for overseeing our GDPR compliance program, advising on data protection matters, acting as the point of contact for supervisory authorities, and handling individual rights requests. Contact: privacy@acriotech.com

7
Breach Notification Protocol

Our Security Incident Response Plan includes a 72-hour breach notification workflow. If we become aware of a personal data breach affecting EU residents, we will notify the relevant supervisory authority within 72 hours. Affected individuals will be notified without undue delay when the breach is likely to result in a high risk to their rights and freedoms.

8
International Data Transfers

For transfers of EU personal data to third countries, we rely on the European Commission-approved Standard Contractual Clauses (SCCs) and conduct Transfer Impact Assessments (TIAs) for transfers to jurisdictions that may not provide adequate protection.

Your Rights Under GDPR

If Acriotech is the data controller for your personal data, you have the following enforceable rights. All requests are handled within 30 days (extendable by 2 months for complex requests, with notification):

  • Art. 15 — Right of Access: Receive a copy of your personal data and information about how it is processed.
  • Art. 16 — Right to Rectification: Have inaccurate data corrected without undue delay.
  • Art. 17 — Right to Erasure ("Right to be Forgotten"): Have your data deleted when it is no longer necessary for the original purpose.
  • Art. 18 — Right to Restriction: Request that processing be temporarily halted in certain circumstances.
  • Art. 20 — Right to Data Portability: Receive your data in a structured, machine-readable format (JSON or CSV).
  • Art. 21 — Right to Object: Object to processing based on legitimate interests or for direct marketing.
  • Art. 22 — Rights related to Automated Decision-Making: Not be subject to decisions based solely on automated processing that produce significant legal effects, without human review.

Frequently Asked Questions

Q: Does GDPR apply to my Indian or US company?

A: Yes, if you process the personal data of EU or EEA residents — even if you are located outside Europe — GDPR applies to your organization. As your software engineering partner, Acriotech will help ensure that the systems we build for you incorporate appropriate data protection controls.

Q: What are the penalties for non-compliance?

A: Supervisory authorities can impose fines of up to €20 million or 4% of total global annual turnover (whichever is higher) for the most serious infringements (e.g., violations of basic processing principles or data subject rights). Less severe infringements carry fines up to €10 million or 2% of global turnover.

Q: Can I sign a Data Processing Addendum (DPA) with Acriotech?

A: Yes. Enterprise clients who require a formal DPA (incorporating Standard Contractual Clauses for international transfers) can request one by emailing legal@acriotech.com. We will return a signed DPA within 5 business days.

Q: How does Acriotech handle AI and automated decision-making?

A: Any AI system we build that produces legally significant automated decisions is designed with a mandatory human-review layer, explainability mechanisms, and override capabilities. We document the logic and risk factors of all AI decision systems in our DPIA register.

Contact Our Data Protection Officer

For GDPR inquiries, to exercise your data subject rights, or to request a DPA, contact our Data Protection Officer at privacy@acriotech.com. If you have unresolved concerns, you have the right to lodge a complaint with your local Data Protection Supervisory Authority.