GDPR Compliance
Statement

Regulation (EU) 2016/679 // Legal Documentation

We are committed to protecting personal data and complying with the General Data Protection Regulation (EU) 2016/679 (“GDPR”). This statement explains how we process personal data in connection with our Software-as-a-Service (SaaS) platform.

01

Roles and Scope

Depending on the context, we act as:

  • »Data Controller for account management, billing, website operation, and marketing activities.
  • »Data Processor when we process personal data on behalf of our customers within the SaaS platform.

Where we act as a processor, we process data strictly in accordance with our customers’ instructions and a Data Processing Agreement (DPA).

02

Categories of Data Processed

We may process:

  • »Account Data: name, email address, company details, login credentials
  • »Billing Data: billing address, payment information (processed via secure payment providers)
  • »Usage Data: logs, device information, IP address, interactions with the platform
  • »Customer Data: data uploaded or managed by customers within the platform
  • »Support Data: communications and support requests
03

Lawful Bases for Processing

We rely on:

  • »Contract performance (e.g., providing the SaaS service)
  • »Legal obligations (e.g., tax and accounting requirements)
  • »Legitimate interests (e.g., service improvement, fraud prevention)
  • »Consent (e.g., marketing communications, cookies where required)
04

Data Subject Rights

Individuals have the right to:

  • »Access, rectify, or erase personal data
  • »Restrict or object to processing
  • »Data portability
  • »Withdraw consent at any time

If we process data as a processor, requests should be directed to the relevant customer (controller). We assist our customers in fulfilling these rights.

05

Data Security Measures

We implement appropriate technical and organizational measures, including:

  • »Encryption in transit (TLS) and at rest where applicable
  • »Access controls and authentication mechanisms
  • »Regular security monitoring and vulnerability management
  • »Staff training on data protection
06

Data Retention

We retain personal data only as long as necessary:

  • »Account data: for the duration of the contract and a limited period thereafter
  • »Billing data: as required by applicable tax laws
  • »Customer data: as instructed by the customer or until account termination
07

Subprocessors and Third Parties

We use trusted subprocessors (e.g., cloud hosting, analytics, payment providers) under written agreements that include GDPR-compliant safeguards. A list of subprocessors is available upon request.

08

International Data Transfers

Where personal data is transferred outside the European Economic Area (EEA), we ensure appropriate safeguards such as Standard Contractual Clauses (SCCs) or equivalent mechanisms.

09

Data Processing Agreement (DPA)

We offer a GDPR-compliant DPA governing our role as a processor, including obligations related to confidentiality, security, subprocessors, and data subject rights assistance.

10

Breach Notification

We maintain procedures to detect, investigate, and report personal data breaches. Where required, we notify customers and relevant authorities without undue delay.

11

Cookies and Tracking Technologies

Our website and platform may use cookies and similar technologies for functionality, analytics, and (where applicable) marketing, subject to user consent where required.

12

Contact Information

For GDPR-related inquiries, please contact our Data Protection Officer:

  • »Company: TechFlow Solutions OÜ
  • »Address: Tallinn, Estonia (Enterprise Registry: 12345678)
  • »Email: support@techflowsolutions.eu

We continuously review our practices to ensure ongoing compliance with GDPR and related data protection laws.

End of DocumentLast Updated: 2026