GDPR Compliance

GDPR Compliance

Our commitment to the General Data Protection Regulation and your data rights

Last updated: October 3, 2025

Our GDPR Commitment

Upvave is committed to protecting your personal data and respecting your privacy rights under the General Data Protection Regulation (GDPR). This page outlines our approach to GDPR compliance and your rights as a data subject.

We have implemented appropriate technical and organizational measures to ensure the security of personal data and to demonstrate our compliance with GDPR requirements.

Your Rights Under GDPR

Right to Information

You have the right to be informed about the collection and use of your personal data. Our Privacy Policy provides clear information about how we process your data.

Right of Access

You have the right to request access to your personal data and receive information about how we process it. You can request a copy of your personal data free of charge.

Right to Rectification

You have the right to have inaccurate personal data rectified and incomplete personal data completed without undue delay.

Right to Erasure ('Right to be Forgotten')

You have the right to request the deletion of your personal data when certain conditions are met, such as when the data is no longer necessary for the original purpose.

Right to Restrict Processing

You have the right to request the restriction of processing of your personal data in certain circumstances, such as when you contest the accuracy of the data.

Right to Data Portability

You have the right to receive your personal data in a structured, commonly used, and machine-readable format and to transmit it to another controller.

Right to Object

You have the right to object to processing of your personal data based on legitimate interests, direct marketing, or processing for scientific/research purposes.

Lawful Basis for Processing

We process personal data under the following lawful bases:

Consent

When you have given clear consent for processing for specific purposes.

Contract

Processing necessary for contract performance or pre-contractual steps.

Legal Obligation

Processing required to comply with legal obligations.

Legitimate Interest

Processing necessary for legitimate interests pursued by us or third parties.

Data Protection Measures

We have implemented comprehensive measures to protect your personal data:

Technical Safeguards

Encryption, access controls, secure transmission, and regular security updates.

Organizational Measures

Staff training, data protection policies, and regular compliance reviews.

Data Minimization

We only collect and process data that is necessary for our stated purposes.

Regular Audits

Ongoing assessment of data processing activities and security measures.

International Data Transfers

When we transfer personal data outside the European Economic Area (EEA), we ensure appropriate safeguards are in place:

  • Standard Contractual Clauses (SCCs) approved by the European Commission
  • Adequacy decisions recognizing equivalent data protection standards
  • Binding Corporate Rules for intra-group transfers
  • Certification mechanisms and codes of conduct

Data Retention

We retain personal data only as long as necessary for the purposes for which it was collected:

Contact Inquiries2 years
Project DataDuration of project + 7 years
Marketing ConsentsUntil withdrawn
Website Analytics24 months

Data Breach Notification

In the event of a personal data breach that is likely to result in high risk to your rights and freedoms, we will:

  • Notify the relevant supervisory authority within 72 hours
  • Inform affected individuals without undue delay
  • Provide clear information about the nature of the breach
  • Describe the likely consequences and measures taken
  • Provide contact information for our Data Protection Officer

Exercising Your Rights

To exercise any of your GDPR rights, please contact us using the information below. We will respond to your request within one month, though this may be extended by two months in complex cases.

Required Information for Requests

  • Full name and contact details
  • Description of the personal data concerned
  • Purpose of the request and desired outcome
  • Proof of identity (copy of ID document)

Supervisory Authority

You have the right to lodge a complaint with a supervisory authority if you believe your personal data has been processed in violation of GDPR. You can contact:

Your local data protection authority

Or the authority in the country where the alleged infringement occurred

For EU residents: Find your local authority at edpb.europa.eu

Contact Information

For any GDPR-related questions or to exercise your rights, please contact:

Data Protection Officer: dpo@upvave.com

Privacy Team: privacy@upvave.com

Address: 123 Innovation Drive, San Francisco, CA 94105

Phone: +1 (555) 123-4567