GDPR Compliance
Last Updated: April 6, 2024
1. Introduction
At Fewzen AI, we are committed to protecting the privacy and security of your personal data. This GDPR Compliance Statement explains how we collect, use, and store personal data in accordance with the General Data Protection Regulation (GDPR).
The GDPR applies to all organizations operating within the European Union (EU) and European Economic Area (EEA), as well as non-EU businesses that offer goods or services to individuals in the EU or monitor the behavior of EU data subjects.
2. Data Controller
Fewzen AI Ltd is the data controller for personal data collected through our website and services. This means we determine the purposes and means of processing personal data.
Our contact details are:
Fewzen AI Ltd
71-75 Shelton Street
London, WC2H 9JQ
United Kingdom
privacy@fewzen.ai
3. Data Protection Officer
We have appointed a Data Protection Officer (DPO) who is responsible for overseeing questions in relation to this GDPR Compliance Statement and our privacy practices. If you have any questions about this statement or how we handle your personal information, please contact our DPO at dpo@fewzen.ai.
4. Lawful Basis for Processing
Under the GDPR, we must have a lawful basis for processing your personal data. We process personal data on the following lawful bases:
- Consent: Where you have given clear consent for us to process your personal data for a specific purpose.
- Contract: Where processing is necessary for the performance of a contract with you or to take steps at your request before entering into a contract.
- Legal Obligation: Where processing is necessary for compliance with a legal obligation to which we are subject.
- Legitimate Interests: Where processing is necessary for the purposes of legitimate interests pursued by us or a third party, except where such interests are overridden by your interests, rights, or freedoms.
5. Your Rights Under GDPR
Under the GDPR, you have the following rights regarding your personal data:
- Right to be informed: You have the right to be informed about the collection and use of your personal data.
- Right of access: You have the right to request a copy of the personal data we hold about you.
- Right to rectification: You have the right to have inaccurate personal data rectified, or completed if it is incomplete.
- Right to erasure: You have the right to request the deletion or removal of personal data in certain circumstances.
- Right to restrict processing: You have the right to request the restriction or suppression of your personal data.
- Right to data portability: You have the right to obtain and reuse your personal data for your own purposes across different services.
- Right to object: You have the right to object to the processing of your personal data in certain circumstances.
- Rights related to automated decision making and profiling: You have rights related to automated decision making and profiling.
To exercise any of these rights, please contact us using the information provided in the "Contact Us" section below.
6. Data Security
We have implemented appropriate technical and organizational measures to ensure a level of security appropriate to the risk, including:
- Encryption of personal data where appropriate
- Regular testing, assessing, and evaluating the effectiveness of technical and organizational measures
- Ensuring the ongoing confidentiality, integrity, availability, and resilience of processing systems and services
- The ability to restore the availability and access to personal data in a timely manner in the event of a physical or technical incident
7. Data Breach Notification
In the event of a personal data breach, we will notify the relevant supervisory authority without undue delay and, where feasible, not later than 72 hours after having become aware of it, unless the breach is unlikely to result in a risk to the rights and freedoms of natural persons.
If the breach is likely to result in a high risk to the rights and freedoms of natural persons, we will also notify the affected individuals without undue delay.
8. International Data Transfers
We may transfer personal data to countries outside the EU/EEA. When we do so, we ensure that appropriate safeguards are in place to protect your personal data, such as:
- Transferring to countries that have been deemed to provide an adequate level of protection by the European Commission
- Using specific contracts approved by the European Commission that give personal data the same protection it has in Europe
- Implementing binding corporate rules
- Using standard contractual clauses
9. Data Retention
We will only retain your personal data for as long as necessary to fulfill the purposes we collected it for, including for the purposes of satisfying any legal, accounting, or reporting requirements.
To determine the appropriate retention period for personal data, we consider the amount, nature, and sensitivity of the personal data, the potential risk of harm from unauthorized use or disclosure of your personal data, the purposes for which we process your personal data, and whether we can achieve those purposes through other means, and the applicable legal requirements.
10. Contact Us
If you have any questions about this GDPR Compliance Statement or our data protection practices, please contact us at:
Fewzen AI Ltd
71-75 Shelton Street
London, WC2H 9JQ
United Kingdom
dpo@fewzen.ai