GDPR

GDPR
compliance.

Our commitment to protecting your privacy rights under EU data protection law.

Last updated: January 15, 2025

1. GDPR Overview and Commitment

GridCore is committed to full compliance with the General Data Protection Regulation (GDPR) and protecting the privacy rights of all EU residents. Our GDPR Commitment: • Lawful, fair, and transparent data processing • Purpose limitation and data minimization • Accuracy and storage limitation principles • Integrity, confidentiality, and accountability Scope of Application: • All EU residents and citizens • Data processing within the EU • Services offered to EU individuals • Cross-border data transfers Legal Basis for Processing: • Consent for marketing and non-essential cookies • Contract performance for service delivery • Legitimate interests for business operations • Legal obligations for compliance requirements We have implemented comprehensive policies, procedures, and technical measures to ensure ongoing GDPR compliance.

2. Your Data Protection Rights

Under GDPR, you have the following fundamental rights: Right of Access (Article 15): • Request copies of your personal data • Information about how we process your data • Details about data sharing and transfers • Confirmation of data processing activities Right to Rectification (Article 16): • Correct inaccurate personal data • Complete incomplete information • Update outdated records • Amend incorrect details Right to Erasure - "Right to be Forgotten" (Article 17): • Delete personal data when no longer necessary • Withdraw consent for data processing • Object to unlawful data processing • Remove data when retention period expires Right to Restrict Processing (Article 18): • Limit how we use your data • Suspend processing pending dispute resolution • Object to processing for specific purposes • Mark data as restricted instead of deletion Response Time: We will respond to all rights requests within 30 days (extendable to 60 days for complex requests).

3. Right to Data Portability

You have the right to receive your personal data in a portable format: Data Portability Rights: • Receive data in structured, commonly used format • Machine-readable electronic format (JSON, CSV, XML) • Direct transfer to another data controller • Copy of all personal data we hold about you What's Included: • Personal identification information • Communication records and preferences • Project-related data and specifications • Account settings and preferences Data Format Options: • JSON format for technical users • CSV format for spreadsheet applications • PDF format for human-readable documents • XML format for system integrations Transfer Process: • Secure encrypted delivery methods • Identity verification requirements • Processing within 30 days of request • No charge for first request per year Request Process: 1. Submit written request via email 2. Provide identity verification 3. Specify preferred data format 4. Receive secure download link We facilitate seamless data portability while maintaining security and accuracy.

4. Right to Object and Withdraw Consent

You can object to data processing and withdraw consent: Right to Object (Article 21): • Object to processing based on legitimate interests • Stop direct marketing communications • Halt profiling for marketing purposes • Cease automated decision-making processes Objection Grounds: • Personal situation requires data processing halt • Marketing and promotional activities • Profiling and automated processing • Scientific or historical research purposes Consent Withdrawal: • Withdraw consent at any time • No requirement to provide reasons • Withdrawal doesn't affect previous lawful processing • Easy and accessible withdrawal mechanisms Processing After Objection: • We will stop processing unless compelling legitimate grounds exist • Continued processing only for legal claims or vital interests • Clear notification of our decision and reasoning • Appeal process for disputed decisions Withdrawal Methods: • Email request to contact@gridcore.co • Contact form on our website • Written request by postal mail • Account settings (where applicable) Effect is immediate upon receipt of valid withdrawal request.

5. Data Processing Lawfulness

We process personal data only on lawful grounds under GDPR Article 6: Consent (Article 6(1)(a)): • Marketing communications and newsletters • Non-essential cookies and tracking • Optional data collection for improvements • Third-party service integrations Contract (Article 6(1)(b)): • Service delivery and project execution • Client communication and support • Payment processing and invoicing • Project documentation and records Legal Obligation (Article 6(1)(c)): • Tax and accounting records • Anti-money laundering compliance • Data breach notification requirements • Regulatory reporting obligations Legitimate Interests (Article 6(1)(f)): • Website analytics and performance monitoring • Security and fraud prevention • Business development and planning • Customer relationship management Vital Interests (Article 6(1)(d)): • Emergency contact situations • Health and safety incidents • Critical system security alerts Public Task (Article 6(1)(e)): • Not applicable to our business operations We conduct regular assessments to ensure processing remains lawful and necessary.

6. Data Protection by Design and Default

We implement privacy protection from the ground up: Technical Measures: • Encryption of data in transit and at rest • Access controls and authentication systems • Regular security audits and penetration testing • Automated data retention and deletion Organizational Measures: • Privacy impact assessments for new projects • Staff training on data protection principles • Clear data handling policies and procedures • Regular compliance monitoring and reviews Default Settings: • Minimal data collection by default • Opt-in consent for non-essential processing • Privacy-friendly configuration options • Transparent privacy settings Design Principles: • Purpose limitation in system design • Data minimization in data collection • Storage limitation with automatic deletion • Accuracy through validation and updates Privacy Impact Assessments: • Conducted for high-risk processing activities • Regular review and update procedures • Stakeholder consultation and feedback • Documentation of mitigation measures Vendor Management: • GDPR compliance requirements for all vendors • Data processing agreements with third parties • Regular vendor security and privacy assessments • Incident response coordination procedures

7. International Data Transfers

When transferring data outside the EU, we ensure adequate protection: Transfer Mechanisms: • Standard Contractual Clauses (SCCs) approved by EU Commission • Adequacy decisions for countries with equivalent protection • Binding Corporate Rules for internal transfers • Specific derogations for limited circumstances Adequacy Countries: • Countries deemed adequate by European Commission • No additional safeguards required • Direct transfers permitted • Regular monitoring of adequacy status Standard Contractual Clauses: • Legally binding data protection obligations • Enforceable data subject rights • Local remedy options for data subjects • Regular compliance monitoring and audits Additional Safeguards: • Technical measures like encryption • Organizational measures and access controls • Contractual guarantees and commitments • Regular security assessments Transfer Documentation: • Written agreements with all data recipients • Documentation of transfer lawfulness • Records of adequacy assessments • Data subject notification procedures We regularly review and update our transfer mechanisms to ensure continued compliance with evolving GDPR requirements.

8. Data Breach Notification

Our comprehensive data breach response procedures: Breach Detection: • 24/7 monitoring and alerting systems • Staff training on breach identification • Regular security audits and assessments • Incident reporting procedures Response Timeline: • Immediate containment and assessment (within 1 hour) • Risk evaluation and impact analysis (within 24 hours) • Supervisory authority notification (within 72 hours) • Data subject notification (without undue delay if high risk) Notification Requirements: • Nature and categories of personal data involved • Approximate number of data subjects affected • Likely consequences of the breach • Measures taken to address the breach High-Risk Breach Criteria: • Identity theft or fraud risk • Physical, material, or non-material damage • Discrimination or reputational damage • Financial loss or unauthorized reversal of pseudonymization Breach Response Team: • Data Protection Officer (DPO) • IT Security specialists • Legal and compliance experts • Management and communication teams Documentation: • Comprehensive breach register • Timeline of events and response actions • Risk assessments and impact analyses • Communication records and notifications We maintain detailed breach response procedures and conduct regular incident response drills.

9. Data Protection Officer and Governance

Our data protection governance structure: Data Protection Officer (DPO): • Independent oversight of data protection compliance • Expert knowledge of GDPR and data protection law • Point of contact for supervisory authorities • Data protection impact assessment guidance DPO Responsibilities: • Monitor GDPR compliance across the organization • Conduct data protection training and awareness • Advise on data protection impact assessments • Cooperate with supervisory authority investigations Privacy Governance Committee: • Cross-functional team with privacy expertise • Regular review of privacy policies and procedures • Oversight of privacy impact assessments • Incident response coordination and management Accountability Measures: • Documentation of all processing activities • Regular compliance audits and assessments • Staff training and awareness programs • Vendor and third-party compliance monitoring Records of Processing: • Detailed inventory of all data processing activities • Legal basis and purpose for each processing activity • Data retention periods and deletion schedules • International transfer documentation Contact Information: • DPO Email: contact@gridcore.co • Phone: Available upon request • Address: Available upon request • Response time: Within 48 hours for urgent matters

10. Supervisory Authority and Complaints

Your right to lodge complaints with supervisory authorities: Complaint Rights: • Lodge complaints with any EU supervisory authority • No requirement to exhaust internal remedies first • Right to effective judicial remedy • Compensation for material and non-material damage Relevant Supervisory Authorities: • Your country of habitual residence • Your place of work • Place of alleged infringement • Lead supervisory authority for cross-border processing Complaint Process: • Submit written complaint to supervisory authority • Provide detailed description of alleged violation • Include relevant documentation and evidence • Cooperate with authority's investigation Alternative Dispute Resolution: • Direct contact with our Data Protection Officer • Internal complaint resolution procedures • Mediation and alternative dispute mechanisms • Independent arbitration options Compensation Rights: • Material damage compensation • Non-material damage compensation • Legal costs and representation • Interim measures and injunctive relief Internal Complaint Process: 1. Contact our DPO at contact@gridcore.co 2. Provide detailed description of concern 3. We will investigate within 30 days 4. Written response with resolution or explanation 5. Appeal process if unsatisfied with response We encourage internal resolution but respect your right to direct supervisory authority contact.

11. GDPR Compliance Updates and Monitoring

Our ongoing commitment to GDPR compliance: Regular Compliance Reviews: • Quarterly assessment of data processing activities • Annual review of privacy policies and procedures • Continuous monitoring of regulatory developments • Regular training updates for all staff members Policy Updates: • Immediate updates for regulatory changes • Stakeholder consultation for significant changes • Clear communication of policy modifications • Version control and change documentation Compliance Monitoring: • Regular data protection impact assessments • Vendor and third-party compliance audits • Security testing and vulnerability assessments • Incident response capability testing Training and Awareness: • Mandatory GDPR training for all employees • Specialized training for data handling roles • Regular awareness campaigns and updates • Privacy-by-design culture development Documentation Maintenance: • Current records of processing activities • Up-to-date data mapping and flow diagrams • Regular review of retention schedules • Comprehensive audit trail maintenance Continuous Improvement: • Regular review of privacy practices • Incorporation of best practices and standards • Feedback integration from data subjects • Proactive identification of compliance risks Contact Us: Email: contact@gridcore.co Subject: "GDPR Compliance Inquiry" Response: Within 48 hours Emergency: Immediate response for urgent privacy matters

Exercise Your GDPR Rights

We're committed to honoring your privacy rights. Contact our Data Protection Officer for any requests.