GDPR Compliance

Last updated: May 15, 2025

Our Commitment to GDPR Compliance

At TempWhats, we are committed to protecting your personal data and privacy. We comply with the General Data Protection Regulation (GDPR), which is a regulation in EU law on data protection and privacy for all individuals within the European Union and the European Economic Area.

This page explains how we adhere to GDPR principles and outlines your rights under this regulation.

What is GDPR?

The General Data Protection Regulation (GDPR) is a legal framework that sets guidelines for the collection and processing of personal information from individuals who live in the European Union (EU). It came into effect on May 25, 2018.

The GDPR gives individuals greater control over their personal data and requires organizations to be transparent about how they collect, use, and store personal information.

Our Data Protection Principles

We adhere to the following principles when processing your personal data:

  • Lawfulness, fairness, and transparency: We process data lawfully, fairly, and in a transparent manner.
  • Purpose limitation: We collect data for specified, explicit, and legitimate purposes and do not process it in a manner incompatible with those purposes.
  • Data minimization: We limit our data collection to what is necessary for the purposes for which it is processed.
  • Accuracy: We take reasonable steps to ensure personal data is accurate and kept up to date.
  • Storage limitation: We keep personal data in a form that permits identification only as long as necessary for the purposes of processing.
  • Integrity and confidentiality: We process personal data in a manner that ensures appropriate security, including protection against unauthorized or unlawful processing and accidental loss, destruction, or damage.
  • Accountability: We are responsible for and can demonstrate compliance with all the above principles.

Legal Basis for Processing

Under GDPR, we must have a valid legal basis for processing personal data. We rely on the following legal bases:

  • Consent: When you explicitly agree to the processing of your personal data for one or more specific purposes.
  • Contract: When processing is necessary for the performance of a contract with you or to take steps at your request before entering into a contract.
  • Legal obligation: When processing is necessary for compliance with a legal obligation to which we are subject.
  • Legitimate interests: When processing is necessary for the purposes of the legitimate interests pursued by us or by a third party, except where such interests are overridden by your interests or fundamental rights and freedoms.

Your Rights Under GDPR

The GDPR provides you with several rights regarding your personal data:

Right to Access

You have the right to request a copy of the personal data we hold about you and to check that we are lawfully processing it.

Right to Rectification

You have the right to request correction of any inaccurate personal data we hold about you and to complete any incomplete personal data.

Right to Erasure (Right to be Forgotten)

You have the right to request the deletion of your personal data in certain circumstances, such as when the data is no longer necessary for the purposes for which it was collected.

Right to Restrict Processing

You have the right to request the restriction of processing of your personal data in certain circumstances, such as when you contest the accuracy of the data.

Right to Data Portability

You have the right to request the transfer of your personal data to you or to a third party in a structured, commonly used, machine-readable format.

Right to Object

You have the right to object to the processing of your personal data in certain circumstances, including processing based on legitimate interests and direct marketing.

Rights Related to Automated Decision Making and Profiling

You have the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning you or similarly significantly affects you.

How to Exercise Your Rights

To exercise any of these rights, please contact our Data Protection Officer at:

Email: dpo@tempwhats.com

Address: 123 Privacy Street, Tech City, TC 12345, Country

We will respond to your request within one month. This period may be extended by two further months where necessary, taking into account the complexity and number of requests.

Data Protection Officer

We have appointed a Data Protection Officer (DPO) who is responsible for overseeing questions in relation to this privacy notice and our GDPR compliance. If you have any questions about this privacy notice, including any requests to exercise your legal rights, please contact our DPO using the details provided above.

International Data Transfers

We may transfer your personal data to countries outside the European Economic Area (EEA). Whenever we transfer your personal data out of the EEA, we ensure a similar degree of protection is afforded to it by implementing at least one of the following safeguards:

  • Transferring data to countries that have been deemed to provide an adequate level of protection for personal data by the European Commission.
  • Using specific contracts approved by the European Commission which give personal data the same protection it has in Europe.
  • For transfers to the US, ensuring the recipient is part of the Privacy Shield, which requires them to provide similar protection to personal data shared between Europe and the US.

Data Breach Notification

In the event of a personal data breach, we will notify the relevant supervisory authority within 72 hours of becoming aware of the breach, where feasible, unless the breach is unlikely to result in a risk to the rights and freedoms of individuals.

If the breach is likely to result in a high risk to your rights and freedoms, we will also notify you without undue delay.

Data Protection Impact Assessment

We carry out Data Protection Impact Assessments (DPIAs) for processing operations that are likely to result in a high risk to the rights and freedoms of individuals, particularly when using new technologies.

Records of Processing Activities

We maintain records of our processing activities as required by GDPR. These records include the purposes of processing, categories of personal data and data subjects, categories of recipients, information about international transfers, retention periods, and a general description of technical and organizational security measures.

Changes to This GDPR Compliance Statement

We may update this GDPR Compliance Statement from time to time to reflect changes in our practices or legal requirements. Any changes will be posted on this page with an updated "Last updated" date.

Complaints

If you have a concern about our privacy practices, including the way we handle your personal data, you can report it to us at dpo@tempwhats.com.

You also have the right to lodge a complaint with the data protection authority in the EU member state where you reside, where you work, or where an alleged infringement of GDPR has occurred.