EU GDPR 2016/679 Compliant

GDPR Privacy Policy

Effective Date: July 13, 2026 | Last Updated: July 13, 2026

1. Introduction & Scope

At ABRDAN ("we", "us", "our"), we are fully committed to protecting your privacy and ensuring the security of your personal data in strict compliance with the General Data Protection Regulation (GDPR) (EU) 2016/679.

This Privacy Policy applies to all data subjects whose personal data is processed by us across our core business operations, including our Artificial Intelligence Solutions, Cloud Server Infrastructure, VoIP Services, SaaS Development frameworks, and Digital Marketing strategies.

2. Our Role: Controller vs. Processor

Depending on how you interact with our services, we may act as either a Data Controller or a Data Processor:

  • Data Controller: We act as a Controller when we determine the purposes and means of processing your data (e.g., account registration, billing, and direct digital marketing analytics).
  • Data Processor: We act as a Processor when providing Cloud Server Infrastructure, SaaS Development platforms, and VoIP services, where we handle data strictly on behalf of and according to the instructions of our enterprise clients.

3. Types of Personal Data We Process

We process personal data across our specific service sectors as detailed below:

A. AI Solutions & SaaS Development

User prompts, computational inputs, source code repository integration tokens, and custom metadata necessary to optimize and refine machine learning models and host software applications.

B. Cloud Server Infrastructure

Server logs, IP addresses, network traffic volume logs, system performance metrics, and access control credentials used to protect cloud security and performance stability.

C. VoIP Services

Call Detail Records (CDRs) including destination numbers, origin numbers, call duration, timestamp data, and SIP signaling logs essential for telecommunication routing and billing.

D. Digital Marketing Services

Tracking cookies, device identifiers, pixel tags, conversion tracking attributes, and behavior analytic patterns collected upon explicit opt-in consent.

4. Legal Bases for Processing Data

Under Article 6 of the GDPR, we only process personal data when we have a valid legal baseline:

Legal BasisApplicable Service Context
Consent (Art. 6(1)(a))Digital marketing cookies, promotional newsletters, and beta AI testing programs.
Contractual Necessity (Art. 6(1)(b))Provisioning SaaS subscriptions, cloud server deployment, billing processing, and establishing active VoIP lines.
Legal Obligation (Art. 6(1)(c))Telecommunications regulatory data retention for VoIP, financial auditing, and tax records.
Legitimate Interests (Art. 6(1)(f))Network defense, cyber security infrastructure logging, fraud mitigation, and operational software debugging.

5. Data Retention Periods

We retain your personal data only as long as necessary to fulfill the operational requirements of your contract, maintain legitimate server protection, or comply with local regulatory telecom directives (e.g., keeping historical VoIP Call Detail Records as enforced by regional communication authorities). When data is no longer required, it is safely purged or completely anonymized.

6. Your Rights Under the GDPR

If you are an EU/EEA resident, you possess the following comprehensive data rights:

Right of Access

Request a structural breakdown of all personal data we hold about you.

Right to Rectification

Request immediate correction of inaccurate or incomplete information.

Right to Erasure ('Right to be Forgotten')

Request deletion of data where processing is no longer justified.

Right to Data Portability

Receive your profile data in a structured, machine-readable format (.json, .csv).

Right to Restrict Processing

Pause active data usage while disputes or computational challenges are verified.

Right to Object

Halt tracking parameters or direct marketing efforts instantly.

7. International Data Transfers

Because cloud systems and distributed server networks operate globally, data may sometimes be transferred or processed outside the EEA. In such instances, we enforce the use of Standard Contractual Clauses (SCCs) approved by the European Commission, ensuring your infrastructure nodes and SaaS assets retain equivalent protection protocols.

8. Enterprise Security Measures

We deploy robust operational and physical security layers tailored for high-availability setups. This includes end-to-end TLS encryption for cloud routing, AES-256 bit encryption for inactive data storage, isolated SaaS containers, rigorous access controls, and prompt incident response structures in the event of an infrastructure breach.

9. Exercising Your Rights & Contacting our DPO

To submit a formal Data Subject Access Request (DSAR) or contact our Data Protection Officer (DPO) regarding any of your privacy parameters, please contact us at:

DPO Compliance Email
© 2026 ABRDAN Global Technology Solutions. All legal protections reserved.