GDPR Policy

Introduction

Stridely Solutions is committed to protecting personal data and respecting the privacy rights of individuals. This statement explains how we comply with the European Union General Data Protection Regulation, known as GDPR, when we process personal data of individuals located in the European Economic Area.

This page should be read together with our Privacy Policy, which provides broader information about how we collect and use personal data globally.

Our Role Under GDPR

Depending on the services we provide, Stridely Solutions may act as a data controller or a data processor.

We act as data controllers when we determine the purpose and means of processing personal data, such as for our website, marketing communications, and business development activities.

We act as a data processor when we process personal data on behalf of our clients under a written agreement.

Lawful Basis for Processing

When GDPR applies, we process personal data only where we have a valid legal basis. These may include:

  • Performance of a contract where processing is necessary to deliver services
  • Legitimate business interests, such as improving our services and managing client relationships, are provided; these interests do not override individual rights
  • Compliance with legal obligations
  • Consent, where required, such as for certain marketing communications or cookies

Data Protection Principles

We process personal data in accordance with GDPR principles. This means that personal data is:

  • Processed lawfully, fairly, and in a transparent manner
  • Collected for specified and legitimate purposes
  • Limited to what is necessary for those purposes
  • Kept accurate and up to date where required
  • Retained only for as long as necessary
  • Protected using appropriate technical and organizational security measures

Data Security

We implement appropriate security measures designed to protect personal data against unauthorized access, loss, misuse, or alteration. These measures may include access controls, secure systems, and internal policies that limit access to personal data to authorized personnel only.

While we take reasonable steps to safeguard data, no system can guarantee absolute security.

Data Retention

We retain personal data only for as long as necessary to fulfil the purposes for which it was collected, including to meet legal, regulatory, and contractual requirements. When personal data is no longer required, it is securely deleted or anonymized.

International Data Transfers

As a global organization, we may transfer personal data outside the European Economic Area. Where this occurs, we implement appropriate safeguards in accordance with GDPR to ensure that personal data remains protected. These safeguards may include standard contractual clauses or other approved legal mechanisms.

Use of Third-Party Processors

We may engage trusted third-party service providers to support our operations, such as cloud hosting providers, IT support services, and customer relationship management platforms. Where these providers process personal data on our behalf, we ensure that appropriate contractual and security measures are in place as required under GDPR.

Data Breach Management

We maintain internal procedures to detect, investigate, and respond to personal data breaches. Where required by GDPR, we will notify the relevant supervisory authority and affected individuals within the timelines set by law.

Special Category Data

We do not intentionally collect or process special category data, such as health information or other sensitive personal data, unless it is necessary for a specific lawful purpose and appropriate safeguards are in place.

Your Rights Under GDPR

If you are located in the European Economic Area, you may have the following rights regarding your personal data:

  • The right to access the personal data we hold about you
  • The right to request correction of inaccurate or incomplete data
  • The right to request deletion of your personal data in certain circumstances
  • The right to restrict processing in certain situations
  • The right to object to processing based on legitimate interests or for direct marketing
  • The right to receive your personal data in a structured and machine-readable format, where applicable
  • The right to withdraw consent at any time where processing is based on consent

These rights are not absolute and may be subject to legal limitations.

How to Exercise Your Rights

To exercise any of your GDPR rights, please contact us at:

info@stridelysolutions.com

Please mention GDPR Request in the subject line. We may need to verify your identity before processing your request.

Right to Lodge a Complaint

If you believe that your personal data has been processed in violation of GDPR, you have the right to lodge a complaint with a data protection supervisory authority in your country of residence, place of work, or place of the alleged infringement.

Updates to This Statement

We may update this GDPR Compliance Statement from time to time to reflect legal, technical, or business changes. The latest version will always be available on our website.