Confidentiality Policy
Introduction
Our company is committed to protecting the confidentiality, integrity, and availability of the personal data of our users. This Confidentiality Policy outlines our approach to managing personal data and ensuring compliance with the General Data Protection Regulation (GDPR).
Scope
This policy applies to all personal data collected, processed, and stored by our company, including data collected through our website, mobile applications, and other online platforms.
Definitions
- Personal Data: Any information relating to an identified or identifiable natural person.
- Processing: Any operation or set of operations performed on personal data, including collection, recording, organization, storage, adaptation, alteration, retrieval, consultation, use, disclosure, transmission, dissemination, or erasure.
- Data Subject: An individual whose personal data is being processed.
Data Collection and Processing
We collect and process personal data for the following purposes:
- To provide our services and products
- To improve our services and products
- To communicate with our users
- To comply with legal and regulatory requirements
We only collect and process personal data that is necessary for the purposes outlined above. We do not collect or process sensitive personal data, such as data related to health, racial or ethnic origin, or political opinions.
Data Protection Principles
We adhere to the following data protection principles:
- Lawfulness, Fairness, and Transparency: We process personal data in a lawful, fair, and transparent manner.
- Purpose Limitation: We only collect and process personal data for specified, legitimate purposes.
- Data Minimization: We only collect and process the minimum amount of personal data necessary for the purposes outlined above.
- Accuracy: We ensure that personal data is accurate and up-to-date.
- Storage Limitation: We only store personal data for as long as necessary for the purposes outlined above.
- Integrity and Confidentiality: We ensure that personal data is processed in a manner that ensures its integrity and confidentiality.
- Accountability: We are responsible for ensuring compliance with this policy and the GDPR.
Data Subject Rights
Data subjects have the following rights:
- Right to Access: The right to access their personal data
- Right to Rectification: The right to rectify inaccurate or incomplete personal data
- Right to Erasure: The right to erase personal data
- Right to Restriction of Processing: The right to restrict the processing of personal data
- Right to Data Portability: The right to transfer personal data to another controller
- Right to Object: The right to object to the processing of personal data
- Right to Withdraw Consent: The right to withdraw consent to the processing of personal data
Security Measures
We implement the following security measures to protect personal data:
- Encryption: We encrypt personal data in transit and at rest
- Access Controls: We implement access controls to ensure that only authorized personnel have access to personal data
- Data Backup: We regularly back up personal data to prevent loss or damage
- Incident Response: We have an incident response plan in place to respond to data breaches
Data Breach Notification
In the event of a data breach, we will notify the relevant authorities and affected data subjects within 72 hours of becoming aware of the breach.
Third-Party Processing
We may engage third-party processors to process personal data on our behalf. We ensure that all third-party processors comply with this policy and the GDPR.
International Data Transfers
We may transfer personal data to countries outside the European Economic Area (EEA). We ensure that all international data transfers comply with the GDPR and are subject to adequate safeguards.
Changes to this Policy
We may update this policy from time to time. We will notify data subjects of any changes to this policy.
Contact Us
If you have any questions or concerns about this policy, please contact us at contact@quantraum.com.
Effective Date
This policy is effective as of September the 9th, 2024.