ClevLabs is committed to compliance with the General Data Protection Regulation (GDPR). We have updated our policies and procedures to ensure we meet the high standards for data privacy and security required by the GDPR.
Our Commitment
We act as both a Data Controller and Data Processor depending on the specific context of the data usage. We process personal data only on documented instructions from the controller (the merchant), ensuring confidentiality and security.
Data Subject Rights
Under the GDPR, you have the following rights:
- Right to Access: You have the right to request access to the personal data we hold about you.
- Right to Rectification: You can request that we correct any inaccurate personal data.
- Right to Erasure: You have the "right to be forgotten" and can request the deletion of your personal data.
- Right to Portability: You can request a copy of your data in a structured, machine-readable format.
Data Processing Agreement (DPA)
If you are a merchant in the EU/EEA, our Standard Terms of Service includes a Data Processing Addendum that covers the GDPR requirements. No further action is required on your part.
Sub-processors
We use a limited number of third-party providers (sub-processors) to assist in providing our services, such as hosting (AWS) and analytics. All sub-processors are vetted for GDPR compliance.