GDPR Privacy Policy
Effective Date: July 13, 2026 | Last Updated: July 13, 2026
1. Introduction & Scope
At ABRDAN ("we", "us", "our"), we are fully committed to protecting your privacy and ensuring the security of your personal data in strict compliance with the General Data Protection Regulation (GDPR) (EU) 2016/679.
This Privacy Policy applies to all data subjects whose personal data is processed by us across our core business operations, including our Artificial Intelligence Solutions, Cloud Server Infrastructure, VoIP Services, SaaS Development frameworks, and Digital Marketing strategies.
2. Our Role: Controller vs. Processor
Depending on how you interact with our services, we may act as either a Data Controller or a Data Processor:
- Data Controller: We act as a Controller when we determine the purposes and means of processing your data (e.g., account registration, billing, and direct digital marketing analytics).
- Data Processor: We act as a Processor when providing Cloud Server Infrastructure, SaaS Development platforms, and VoIP services, where we handle data strictly on behalf of and according to the instructions of our enterprise clients.
3. Types of Personal Data We Process
We process personal data across our specific service sectors as detailed below:
A. AI Solutions & SaaS Development
User prompts, computational inputs, source code repository integration tokens, and custom metadata necessary to optimize and refine machine learning models and host software applications.
B. Cloud Server Infrastructure
Server logs, IP addresses, network traffic volume logs, system performance metrics, and access control credentials used to protect cloud security and performance stability.
C. VoIP Services
Call Detail Records (CDRs) including destination numbers, origin numbers, call duration, timestamp data, and SIP signaling logs essential for telecommunication routing and billing.
D. Digital Marketing Services
Tracking cookies, device identifiers, pixel tags, conversion tracking attributes, and behavior analytic patterns collected upon explicit opt-in consent.
4. Legal Bases for Processing Data
Under Article 6 of the GDPR, we only process personal data when we have a valid legal baseline:
| Legal Basis | Applicable Service Context |
|---|---|
| Consent (Art. 6(1)(a)) | Digital marketing cookies, promotional newsletters, and beta AI testing programs. |
| Contractual Necessity (Art. 6(1)(b)) | Provisioning SaaS subscriptions, cloud server deployment, billing processing, and establishing active VoIP lines. |
| Legal Obligation (Art. 6(1)(c)) | Telecommunications regulatory data retention for VoIP, financial auditing, and tax records. |
| Legitimate Interests (Art. 6(1)(f)) | Network defense, cyber security infrastructure logging, fraud mitigation, and operational software debugging. |
5. Data Retention Periods
We retain your personal data only as long as necessary to fulfill the operational requirements of your contract, maintain legitimate server protection, or comply with local regulatory telecom directives (e.g., keeping historical VoIP Call Detail Records as enforced by regional communication authorities). When data is no longer required, it is safely purged or completely anonymized.
6. Your Rights Under the GDPR
If you are an EU/EEA resident, you possess the following comprehensive data rights:
Right of Access
Request a structural breakdown of all personal data we hold about you.
Right to Rectification
Request immediate correction of inaccurate or incomplete information.
Right to Erasure ('Right to be Forgotten')
Request deletion of data where processing is no longer justified.
Right to Data Portability
Receive your profile data in a structured, machine-readable format (.json, .csv).
Right to Restrict Processing
Pause active data usage while disputes or computational challenges are verified.
Right to Object
Halt tracking parameters or direct marketing efforts instantly.
7. International Data Transfers
Because cloud systems and distributed server networks operate globally, data may sometimes be transferred or processed outside the EEA. In such instances, we enforce the use of Standard Contractual Clauses (SCCs) approved by the European Commission, ensuring your infrastructure nodes and SaaS assets retain equivalent protection protocols.
8. Enterprise Security Measures
We deploy robust operational and physical security layers tailored for high-availability setups. This includes end-to-end TLS encryption for cloud routing, AES-256 bit encryption for inactive data storage, isolated SaaS containers, rigorous access controls, and prompt incident response structures in the event of an infrastructure breach.
9. Exercising Your Rights & Contacting our DPO
To submit a formal Data Subject Access Request (DSAR) or contact our Data Protection Officer (DPO) regarding any of your privacy parameters, please contact us at: