GDPR Compliance
Last updated: December 1, 2024
Our Commitment to GDPR
A2UI Technologies Pvt. Ltd. is committed to protecting the personal data of all individuals, including those in the European Economic Area (EEA). We comply with the General Data Protection Regulation (EU) 2016/679 and apply GDPR principles to all data processing activities, regardless of the data subject's location.
Lawful Basis for Processing
We process personal data under the following lawful bases:
• Contract Performance: Processing necessary to provide our services to customers (account management, service delivery, billing).
• Legitimate Interest: Processing necessary for our legitimate business interests (analytics, fraud prevention, service improvement), balanced against individual rights.
• Consent: Processing based on explicit consent (marketing communications, analytics cookies, third-party integrations).
• Legal Obligation: Processing required to comply with applicable laws (tax records, regulatory requirements).
Data Subject Rights
Under GDPR, you have the following rights:
• Right of Access (Art. 15): Request a copy of your personal data.
• Right to Rectification (Art. 16): Correct inaccurate or incomplete data.
• Right to Erasure (Art. 17): Request deletion of your data ('right to be forgotten').
• Right to Restriction (Art. 18): Restrict processing of your data.
• Right to Data Portability (Art. 20): Receive your data in a structured, machine-readable format.
• Right to Object (Art. 21): Object to processing based on legitimate interest or direct marketing.
• Rights Related to Automated Decision-Making (Art. 22): Not be subject to automated decisions with legal effects.
To exercise your rights, email privacy@a2ui.io. We will respond within 30 days.
Data Protection Officer
We have appointed a Data Protection Officer (DPO) to oversee GDPR compliance:
Name: Deepa Sharma
Email: dpo@a2ui.io
Address: A2UI Technologies Pvt. Ltd., HSR Layout, Sector 1, Bangalore 560102, India
You may contact the DPO for any data protection concerns.
International Data Transfers
A2UI's primary data centers are located in India (AWS Mumbai). When data is transferred outside the EEA:
• We use Standard Contractual Clauses (SCCs) approved by the European Commission.
• We conduct Transfer Impact Assessments (TIAs) to evaluate data protection in recipient countries.
• We implement supplementary security measures including encryption and access controls.
• For US-based sub-processors, we verify EU-US Data Privacy Framework certification where applicable.
Data Processing Agreement
For customers who process EU personal data through A2UI, we offer a Data Processing Agreement (DPA) that:
• Defines A2UI as a data processor and the customer as a data controller.
• Specifies the nature, purpose, and duration of processing.
• Lists the types of personal data and categories of data subjects.
• Details security measures and breach notification procedures.
• Includes Standard Contractual Clauses for international transfers.
To request a DPA, email legal@a2ui.io.
Data Retention
We retain personal data only for as long as necessary for the purposes it was collected:
• Account data: Duration of the account plus 90 days.
• Billing records: 7 years (legal requirement).
• Analytics data: 26 months (anonymized).
• Marketing consent records: Duration of consent plus 3 years.
• Support communications: 2 years after resolution.
Data Breach Notification
In the event of a personal data breach:
• We will notify the relevant supervisory authority within 72 hours of becoming aware of the breach.
• We will notify affected data subjects without undue delay if the breach is likely to result in high risk to their rights and freedoms.
• We maintain a breach register documenting all incidents.
• Our incident response plan includes containment, assessment, notification, and remediation procedures.
Sub-Processors
We use the following categories of sub-processors:
• Cloud infrastructure: AWS, Google Cloud Platform
• Email delivery: SendGrid, MSG91
• Payment processing: Razorpay, Stripe
• Analytics: Google Analytics, Microsoft Clarity
• Customer support: Internal tools
We maintain an up-to-date list of sub-processors. Customers are notified 30 days before adding new sub-processors.
Supervisory Authority
If you are in the EEA and believe our processing of your data violates GDPR, you have the right to lodge a complaint with your local supervisory authority. We encourage you to contact us first so we can address your concerns directly.