What is GDPR
The General Data Protection Regulation (GDPR) is a comprehensive data protection law that came into effect on May 25, 2018, across the European Union (EU). It strengthens and unifies data protection for individuals within the EU.
Key Principles of GDPR
- Lawfulness, fairness, and transparency: Processing must be lawful, fair, and transparent
- Purpose limitation: Data must be collected for specified, explicit purposes
- Data minimization: Only collect data that is necessary
- Accuracy: Keep personal data accurate and up to date
- Storage limitation: Keep data only as long as necessary
- Integrity and confidentiality: Ensure appropriate security of personal data
Our Commitment
MoboDevelopers is committed to full compliance with GDPR and protecting the privacy rights of all individuals whose personal data we process.
Data Controller Information
MoboDevelopers acts as the data controller for personal data processed through our services.
Controller Details
Data Processing Activities
- Customer relationship management
- Service delivery and support
- Marketing and communications
- Website analytics and improvement
- Legal compliance and reporting
Legal Basis for Processing
We process personal data based on one or more of the following legal bases under GDPR:
Consent (Article 6(1)(a))
- Marketing communications
- Newsletter subscriptions
- Cookie preferences
- Optional data collection
Contract Performance (Article 6(1)(b))
- Service delivery
- Account management
- Customer support
- Payment processing
Legitimate Interests (Article 6(1)(f))
- Website analytics
- Security monitoring
- Service improvement
- Fraud prevention
Legal Obligation (Article 6(1)(c))
- Tax compliance
- Regulatory reporting
- Legal record keeping
- Audit requirements
Your Rights Under GDPR
As a data subject, you have several important rights regarding your personal data:
Right of Access (Article 15)
- Request confirmation of data processing
- Obtain copies of your personal data
- Learn about processing purposes and recipients
- Understand data retention periods
Right to Rectification (Article 16)
- Correct inaccurate personal data
- Complete incomplete personal data
- Update outdated information
Right to Erasure (Article 17)
- Request deletion of personal data
- Withdraw consent for processing
- Object to unlawful processing
- Request data removal from public sources
Right to Restrict Processing (Article 18)
- Limit how we use your data
- Suspend processing while disputes are resolved
- Maintain data for legal claims
Right to Data Portability (Article 20)
- Receive your data in a structured format
- Transfer data to another service provider
- Obtain data in machine-readable format
Right to Object (Article 21)
- Object to processing based on legitimate interests
- Opt out of direct marketing
- Object to automated decision-making
How to Exercise Your Rights
You can exercise your GDPR rights by contacting us through the methods below:
Making a Request
Request Requirements
- Provide sufficient information to identify you
- Specify which rights you wish to exercise
- Include any relevant details about your request
- Provide proof of identity if required
Response Timeline
- We will respond within one month of receiving your request
- Complex requests may take up to two months
- We will inform you if we need additional time
- No fees are charged for standard requests
Data Protection Measures
We implement comprehensive technical and organizational measures to protect your personal data:
Technical Safeguards
- Encryption of data in transit and at rest
- Secure authentication and access controls
- Regular security updates and patches
- Network security and firewalls
- Secure backup and recovery systems
Organizational Measures
- Data protection training for all staff
- Access controls and user management
- Regular security assessments
- Incident response procedures
- Privacy by design principles
Data Retention
- Personal data is kept only as long as necessary
- Retention periods are defined for each data type
- Data is securely deleted when no longer needed
- Legal requirements may extend retention periods
Data Breach Notification
In the unlikely event of a data breach, we have procedures in place to respond quickly and appropriately:
Our Response Process
- Immediate assessment of the breach
- Containment and mitigation measures
- Notification to supervisory authorities within 72 hours
- Communication to affected individuals if high risk
- Documentation and lessons learned
Your Rights in Case of Breach
- Receive notification if you are at high risk
- Understand what data was affected
- Learn about measures taken to address the breach
- Receive guidance on protective steps you can take
Data Protection Officer
We have appointed a Data Protection Officer (DPO) to oversee our GDPR compliance:
DPO Contact Information
DPO Responsibilities
- Monitor GDPR compliance
- Provide advice on data protection
- Serve as contact point for supervisory authorities
- Handle data subject requests
- Conduct privacy impact assessments
Supervisory Authority
You have the right to lodge a complaint with your local supervisory authority if you believe we have not handled your personal data in accordance with GDPR.