GDPR Compliance
Last Updated: September 22, 2026
General Data Protection Regulation (GDPR)
Atoll Vertex is committed to ensuring that our data collection and processing practices comply with the General Data Protection Regulation (GDPR). This page outlines how we protect the rights of individuals in the European Economic Area (EEA) and beyond.
Legal Basis for Processing
We process personal data based on one or more of the following legal grounds:
- Consent: You have given clear consent for us to process your personal data for specific purposes
- Contract: Processing is necessary to fulfill our contractual obligations to you
- Legal Obligation: Processing is necessary for us to comply with the law
- Legitimate Interests: Processing is necessary for our legitimate interests or those of a third party, provided your interests and rights do not override those interests
Your Rights Under GDPR
As a data subject, you have the following rights:
Right to Access
You have the right to request copies of your personal data. We may charge a reasonable fee for additional copies if you request multiple copies of the same information.
Right to Rectification
You have the right to request that we correct any information you believe is inaccurate or complete information you believe is incomplete.
Right to Erasure
You have the right to request that we erase your personal data under certain conditions, such as when the data is no longer necessary for the purposes for which it was collected.
Right to Restrict Processing
You have the right to request that we restrict the processing of your personal data under certain conditions.
Right to Object
You have the right to object to our processing of your personal data under certain conditions.
Right to Data Portability
You have the right to request that we transfer the data we have collected to another organization, or directly to you, under certain conditions.
Right to Withdraw Consent
Where we rely on consent as the legal basis for processing, you have the right to withdraw your consent at any time. This will not affect the lawfulness of processing based on consent before its withdrawal.
Data Protection Officer
For questions regarding data protection or to exercise your rights, please contact us at:
Data Retention
We retain personal data only for as long as necessary to fulfill the purposes for which it was collected, including any legal, accounting, or reporting requirements. When personal data is no longer needed, we will securely delete or anonymize it.
International Data Transfers
Your personal data may be transferred to and processed in countries outside the EEA. When we transfer data internationally, we ensure appropriate safeguards are in place to protect your information in accordance with GDPR requirements.
Automated Decision-Making
We do not use automated decision-making or profiling that produces legal effects or similarly significantly affects you.
Data Breach Notification
In the event of a data breach that is likely to result in a risk to your rights and freedoms, we will notify the relevant supervisory authority within 72 hours of becoming aware of the breach. If the breach is likely to result in a high risk to your rights, we will also notify you directly.
Supervisory Authority
You have the right to lodge a complaint with a supervisory authority if you believe our processing of your personal data violates the GDPR. You can contact your local data protection authority in the EEA.
How to Exercise Your Rights
To exercise any of your rights under GDPR, please contact us at [email protected] with your request. We will respond to your request within one month, though this period may be extended by two additional months if your request is complex.
Updates to This Information
We may update this GDPR compliance information from time to time to reflect changes in our practices or legal requirements. Please check this page periodically for updates.