GDPR Compliance Statement
Table of Contents
Our GDPR Commitment
Full GDPR Compliance
FeedbackPro is fully compliant with the European Union's General Data Protection Regulation (GDPR). We are committed to protecting your privacy and ensuring transparent data processing practices.
As a Romanian company serving EU customers, we strictly adhere to GDPR requirements and have implemented comprehensive policies and technical measures to protect your personal data.
Key Principles
- Lawfulness, fairness and transparency: Processing is lawful, fair and transparent
- Purpose limitation: Data collected for specified, explicit and legitimate purposes
- Data minimisation: Adequate, relevant and limited to what is necessary
- Accuracy: Accurate and kept up to date
- Storage limitation: Kept only as long as necessary
- Integrity and confidentiality: Processed securely
- Accountability: We can demonstrate compliance
Lawful Basis for Processing
| Data Category | Lawful Basis | Purpose |
|---|---|---|
| Account Information | Contract Performance | Provide feedback collection services |
| Payment Data | Contract Performance | Process payments and billing |
| Usage Analytics | Legitimate Interest | Service improvement and optimization |
| Marketing Data | Consent | Send promotional communications |
| Security Logs | Legitimate Interest | Protect against fraud and abuse |
| Support Communications | Contract Performance | Provide customer support |
Your Rights Under GDPR
Under GDPR, you have the following rights regarding your personal data:
Right of Access
You can request a copy of all personal data we hold about you, including how it's processed and who it's shared with.
Right of Rectification
You can request correction of inaccurate or incomplete personal data we hold about you.
Right of Erasure
You can request deletion of your personal data in certain circumstances (the "right to be forgotten").
Right to Restrict Processing
You can request we limit how we process your data while resolving disputes about accuracy or processing.
Right to Data Portability
You can request your data in a structured, machine-readable format for transfer to another service.
Right to Object
You can object to processing based on legitimate interests, including direct marketing.
How to Exercise Your Rights
Contact Methods:
- Email: gdpr@feedbackpro.com
- Online Form: Available in your dashboard under "Privacy Settings"
- Mail: Data Protection Officer, 123 Tech Street, Bucharest, Romania
- Response Time: Within 30 days (may be extended by 2 months for complex requests)
Data Protection Measures
Technical Safeguards
- Encryption: AES-256 encryption for data at rest, TLS 1.3 for data in transit
- Access Controls: Role-based access with multi-factor authentication
- Network Security: Firewalls, intrusion detection, and monitoring
- Regular Updates: Security patches and software updates
- Data Backup: Secure, encrypted backups with access logging
Organizational Measures
- Staff Training: Regular GDPR and data protection training
- Access Management: Least privilege principle for data access
- Confidentiality Agreements: All staff sign data protection agreements
- Regular Audits: Internal and external security assessments
- Incident Response: Documented procedures for data breaches
Privacy by Design
- Privacy considerations integrated into system design
- Data minimization built into our processes
- Default privacy-friendly settings
- Regular privacy impact assessments
International Data Transfers
We may transfer your data outside the EU/EEA for service provision. All transfers are protected by appropriate safeguards:
Transfer Mechanisms
| Destination | Safeguard | Purpose |
|---|---|---|
| United States | Standard Contractual Clauses | Cloud infrastructure (AWS, Google Cloud) |
| UK | Adequacy Decision | Support services |
| Switzerland | Adequacy Decision | Analytics services |
| Canada | Standard Contractual Clauses | Development services |
Transfer Safeguards
- Standard Contractual Clauses: EU-approved contract terms for data protection
- Adequacy Decisions: EU Commission-approved countries with adequate protection
- Binding Corporate Rules: Internal data transfer rules for multinational companies
- Certification Schemes: Industry-standard data protection certifications
Data Breach Procedures
Breach Response Commitment
In the unlikely event of a data breach, we will notify the relevant supervisory authority within 72 hours and affected individuals without undue delay.
Our Breach Response Process
- Detection and Assessment (0-4 hours)
- Automated monitoring systems alert our security team
- Initial assessment of breach scope and impact
- Containment measures implemented immediately
- Investigation and Documentation (4-24 hours)
- Detailed forensic analysis
- Documentation of affected data and individuals
- Assessment of risk to individuals
- Notification (24-72 hours)
- Notification to supervisory authority (ANSPDCP)
- Individual notifications if high risk identified
- Public disclosure if required
- Remediation and Follow-up
- Implementation of additional security measures
- Support for affected individuals
- Review and improvement of security procedures
What We'll Tell You
If we need to notify you of a breach, we'll include:
- Nature of the breach and data involved
- Likely consequences of the breach
- Measures we've taken to address the breach
- Recommended actions for you to take
- Contact information for further questions
Data Protection Officer
We have appointed a Data Protection Officer (DPO) to oversee our GDPR compliance and serve as your point of contact for data protection matters.
DPO Responsibilities
- Monitor compliance with GDPR and other data protection laws
- Conduct privacy impact assessments
- Serve as point of contact for supervisory authorities
- Provide data protection advice and training
- Handle data subject requests and complaints
- Maintain records of processing activities
Contact Our DPO
Email: dpo@feedbackpro.com
Phone: +40 (21) 123-4568
Address: Data Protection Officer
123 Tech Street
Bucharest, Romania
Supervisory Authority
As a Romanian company, we are regulated by the Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP).
Your Right to Complain
If you believe we have not handled your personal data in accordance with GDPR, you have the right to lodge a complaint with:
ANSPDCP Contact Information
Website: www.dataprotection.ro
Email: anspdcp@dataprotection.ro
Phone: +40 (21) 252.5599
Address: B-dul Aviatorilor nr. 109, Sector 1, Bucharest
EU Residents
EU residents may also contact their local supervisory authority:
- Germany: Federal Commissioner for Data Protection
- France: Commission Nationale de l'Informatique et des Libertés (CNIL)
- UK: Information Commissioner's Office (ICO)
- Others: Find your local authority at edpb.europa.eu
Regular Compliance Reviews
Our Ongoing Commitment
- Annual Reviews: Comprehensive GDPR compliance assessments
- Quarterly Audits: Internal data protection audits
- Staff Training: Regular training on GDPR requirements
- Policy Updates: Regular review and update of policies
- Technology Assessments: Evaluation of new technologies for privacy impact
Continuous Improvement
We continuously improve our data protection practices through:
- Regular consultation with privacy experts
- Monitoring of regulatory developments
- Implementation of best practices
- Customer feedback integration
- Industry collaboration and knowledge sharing
Last updated: October 7, 2025 at 10:08 AM