GDPR Compliance Statement

Effective Date: January 1, 2024 | Last Updated: January 1, 2024

Our GDPR Commitment

Full GDPR Compliance

FeedbackPro is fully compliant with the European Union's General Data Protection Regulation (GDPR). We are committed to protecting your privacy and ensuring transparent data processing practices.

As a Romanian company serving EU customers, we strictly adhere to GDPR requirements and have implemented comprehensive policies and technical measures to protect your personal data.

Key Principles

  • Lawfulness, fairness and transparency: Processing is lawful, fair and transparent
  • Purpose limitation: Data collected for specified, explicit and legitimate purposes
  • Data minimisation: Adequate, relevant and limited to what is necessary
  • Accuracy: Accurate and kept up to date
  • Storage limitation: Kept only as long as necessary
  • Integrity and confidentiality: Processed securely
  • Accountability: We can demonstrate compliance

Lawful Basis for Processing

Data Category Lawful Basis Purpose
Account Information Contract Performance Provide feedback collection services
Payment Data Contract Performance Process payments and billing
Usage Analytics Legitimate Interest Service improvement and optimization
Marketing Data Consent Send promotional communications
Security Logs Legitimate Interest Protect against fraud and abuse
Support Communications Contract Performance Provide customer support

Your Rights Under GDPR

Under GDPR, you have the following rights regarding your personal data:

Right of Access

You can request a copy of all personal data we hold about you, including how it's processed and who it's shared with.

Right of Rectification

You can request correction of inaccurate or incomplete personal data we hold about you.

Right of Erasure

You can request deletion of your personal data in certain circumstances (the "right to be forgotten").

Right to Restrict Processing

You can request we limit how we process your data while resolving disputes about accuracy or processing.

Right to Data Portability

You can request your data in a structured, machine-readable format for transfer to another service.

Right to Object

You can object to processing based on legitimate interests, including direct marketing.

How to Exercise Your Rights

Contact Methods:
  • Email: gdpr@feedbackpro.com
  • Online Form: Available in your dashboard under "Privacy Settings"
  • Mail: Data Protection Officer, 123 Tech Street, Bucharest, Romania
  • Response Time: Within 30 days (may be extended by 2 months for complex requests)

Data Protection Measures

Technical Safeguards

  • Encryption: AES-256 encryption for data at rest, TLS 1.3 for data in transit
  • Access Controls: Role-based access with multi-factor authentication
  • Network Security: Firewalls, intrusion detection, and monitoring
  • Regular Updates: Security patches and software updates
  • Data Backup: Secure, encrypted backups with access logging

Organizational Measures

  • Staff Training: Regular GDPR and data protection training
  • Access Management: Least privilege principle for data access
  • Confidentiality Agreements: All staff sign data protection agreements
  • Regular Audits: Internal and external security assessments
  • Incident Response: Documented procedures for data breaches

Privacy by Design

  • Privacy considerations integrated into system design
  • Data minimization built into our processes
  • Default privacy-friendly settings
  • Regular privacy impact assessments

International Data Transfers

We may transfer your data outside the EU/EEA for service provision. All transfers are protected by appropriate safeguards:

Transfer Mechanisms

Destination Safeguard Purpose
United States Standard Contractual Clauses Cloud infrastructure (AWS, Google Cloud)
UK Adequacy Decision Support services
Switzerland Adequacy Decision Analytics services
Canada Standard Contractual Clauses Development services

Transfer Safeguards

  • Standard Contractual Clauses: EU-approved contract terms for data protection
  • Adequacy Decisions: EU Commission-approved countries with adequate protection
  • Binding Corporate Rules: Internal data transfer rules for multinational companies
  • Certification Schemes: Industry-standard data protection certifications

Data Breach Procedures

Breach Response Commitment

In the unlikely event of a data breach, we will notify the relevant supervisory authority within 72 hours and affected individuals without undue delay.

Our Breach Response Process

  1. Detection and Assessment (0-4 hours)
    • Automated monitoring systems alert our security team
    • Initial assessment of breach scope and impact
    • Containment measures implemented immediately
  2. Investigation and Documentation (4-24 hours)
    • Detailed forensic analysis
    • Documentation of affected data and individuals
    • Assessment of risk to individuals
  3. Notification (24-72 hours)
    • Notification to supervisory authority (ANSPDCP)
    • Individual notifications if high risk identified
    • Public disclosure if required
  4. Remediation and Follow-up
    • Implementation of additional security measures
    • Support for affected individuals
    • Review and improvement of security procedures

What We'll Tell You

If we need to notify you of a breach, we'll include:

  • Nature of the breach and data involved
  • Likely consequences of the breach
  • Measures we've taken to address the breach
  • Recommended actions for you to take
  • Contact information for further questions

Data Protection Officer

We have appointed a Data Protection Officer (DPO) to oversee our GDPR compliance and serve as your point of contact for data protection matters.

DPO Responsibilities

  • Monitor compliance with GDPR and other data protection laws
  • Conduct privacy impact assessments
  • Serve as point of contact for supervisory authorities
  • Provide data protection advice and training
  • Handle data subject requests and complaints
  • Maintain records of processing activities
Contact Our DPO

Email: dpo@feedbackpro.com
Phone: +40 (21) 123-4568
Address: Data Protection Officer
123 Tech Street
Bucharest, Romania

Supervisory Authority

As a Romanian company, we are regulated by the Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP).

Your Right to Complain

If you believe we have not handled your personal data in accordance with GDPR, you have the right to lodge a complaint with:

ANSPDCP Contact Information

Website: www.dataprotection.ro
Email: anspdcp@dataprotection.ro
Phone: +40 (21) 252.5599
Address: B-dul Aviatorilor nr. 109, Sector 1, Bucharest

EU Residents

EU residents may also contact their local supervisory authority:

  • Germany: Federal Commissioner for Data Protection
  • France: Commission Nationale de l'Informatique et des Libertés (CNIL)
  • UK: Information Commissioner's Office (ICO)
  • Others: Find your local authority at edpb.europa.eu

Regular Compliance Reviews

Our Ongoing Commitment

  • Annual Reviews: Comprehensive GDPR compliance assessments
  • Quarterly Audits: Internal data protection audits
  • Staff Training: Regular training on GDPR requirements
  • Policy Updates: Regular review and update of policies
  • Technology Assessments: Evaluation of new technologies for privacy impact

Continuous Improvement

We continuously improve our data protection practices through:

  • Regular consultation with privacy experts
  • Monitoring of regulatory developments
  • Implementation of best practices
  • Customer feedback integration
  • Industry collaboration and knowledge sharing

Last updated: October 7, 2025 at 10:08 AM