GDPR Compliant

GDPR Compliance

Your privacy rights under the General Data Protection Regulation

Our Commitment to GDPR

WinFactor is committed to protecting your personal data and complying with the General Data Protection Regulation (GDPR). As a company based in the Netherlands, we adhere to the highest standards of data protection.

This page explains your rights under GDPR and how we ensure compliance in our processing of personal data.

Your Rights Under GDPR

Right to Access

You can request a copy of all personal data we hold about you. We will provide this within 30 days.

Right to Rectification

You can request that we correct any inaccurate personal data we hold about you.

Right to Erasure

You can request that we delete your personal data, subject to legal retention requirements.

Right to Portability

You can request your data in a machine-readable format to transfer to another service.

How We Ensure Compliance

Lawful Basis for Processing

We process personal data under the following lawful bases:

  • Contract: Processing necessary to provide our services to you.
  • Legitimate Interest: Processing for our legitimate business interests, such as improving our services and fraud prevention.
  • Consent: For marketing communications and non-essential cookies.
  • Legal Obligation: When required by law.

Data Processing Agreements

We have Data Processing Agreements (DPAs) in place with all our sub-processors. These ensure that any third parties who process data on our behalf also comply with GDPR requirements.

Data Protection Measures

  • Encryption of data in transit and at rest
  • Regular security audits and penetration testing
  • Access controls and authentication
  • Employee training on data protection
  • Incident response procedures

Data Retention

We retain personal data only for as long as necessary to fulfill the purposes for which it was collected. When data is no longer needed, it is securely deleted or anonymized.

International Transfers

Our primary data processing occurs within the European Union. When we transfer data outside the EU, we ensure appropriate safeguards are in place, such as Standard Contractual Clauses (SCCs).

Our Sub-processors

We use the following third-party services that may process personal data:

ServicePurposeLocation
ConvexDatabase & BackendUSA (EU SCCs)
VercelHostingEU
StripePayment ProcessingEU
Google AnalyticsAnalyticsEU

Contact Our Data Protection Officer

If you have questions about your rights or wish to exercise them, please contact our Data Protection Officer.

Email: [email protected]

Contact DPO