GDPR Compliance
Last updated: April 15, 2025
At Buzz, we are committed to ensuring the privacy and protection of your personal data in compliance with the General Data Protection Regulation (GDPR). This document outlines how we adhere to GDPR principles and safeguard your rights under this regulation.
Overview of GDPR
The General Data Protection Regulation (GDPR) is a regulation in EU law on data protection and privacy for all individuals within the European Union and the European Economic Area. It addresses the export of personal data outside the EU and EEA areas.
The GDPR aims primarily to give control to individuals over their personal data and to simplify the regulatory environment for international business by data and to simplify the regulatory environment for international business by unifying the regulation within the EU. It enhances individuals' control and rights over their personal information and addresses the transfer of personal data outside the EU and EEA areas.
How Buzz Complies with GDPR
Lawful Basis for Processing
We process personal data only when we have a lawful basis to do so. These bases include:
- Consent: When you have given clear consent for us to process your personal data for a specific purpose.
- Contract: When processing is necessary for a contract we have with you or because you have asked us to take specific steps before entering into a contract.
- Legal Obligation: When processing is necessary for us to comply with the law.
- Legitimate Interests: When processing is necessary for our legitimate interests or the legitimate interests of a third party, unless there is a good reason to protect your personal data which overrides those legitimate interests.
Data Protection Principles
We adhere to the following data protection principles:
- Lawfulness, fairness, and transparency: We process data lawfully, fairly, and in a transparent manner.
- Purpose limitation: We collect data for specified, explicit, and legitimate purposes.
- Data minimization: We ensure that personal data is adequate, relevant, and limited to what is necessary.
- Accuracy: We keep personal data accurate and up to date.
- Storage limitation: We retain personal data only for as long as necessary.
- Integrity and confidentiality: We process personal data in a manner that ensures appropriate security.
- Accountability: We take responsibility for how we process personal data and demonstrate compliance.
Your Rights Under GDPR
Under the GDPR, you have the following rights:
Right to Access
You have the right to request a copy of the personal data we hold about you and to check that we are lawfully processing it.
Right to Rectification
You have the right to request that we correct any incomplete or inaccurate information we hold about you.
Right to Erasure (Right to be Forgotten)
You have the right to request that we delete your personal data where there is no good reason for us to continue processing it.
Right to Restrict Processing
You have the right to request that we suspend the processing of your personal data in certain scenarios.
Right to Data Portability
You have the right to request that we transfer your personal data to you or to a third party in a structured, commonly used, machine-readable format.
Right to Object
You have the right to object to our processing of your personal data where we are relying on a legitimate interest and there is something about your particular situation which makes you want to object to processing on this ground.
Rights Related to Automated Decision Making and Profiling
You have the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning you or similarly significantly affects you.
To exercise any of these rights, please contact our Data Protection Officer at [email protected].
International Data Transfers
We may transfer your personal data to countries outside the European Economic Area (EEA). Whenever we transfer your personal data out of the EEA, we ensure a similar degree of protection is afforded to it by implementing at least one of the following safeguards:
- We will only transfer your personal data to countries that have been deemed to provide an adequate level of protection for personal data by the European Commission.
- Where we use certain service providers, we may use specific contracts approved by the European Commission which give personal data the same protection it has in Europe.
- Where we use providers based in the US, we may transfer data to them if they are part of the Privacy Shield which requires them to provide similar protection to personal data shared between Europe and the US.
Data Security Measures
We have implemented appropriate technical and organizational measures to ensure a level of security appropriate to the risk, including:
- Encryption of personal data
- Ability to ensure ongoing confidentiality, integrity, availability, and resilience of processing systems and services
- Ability to restore the availability and access to personal data in a timely manner in the event of a physical or technical incident
- Process for regularly testing, assessing, and evaluating the effectiveness of technical and organizational measures for ensuring the security of the processing
- Regular security assessments and penetration testing
- Staff training on data protection and security
Contact Information
If you have any questions about our GDPR compliance or how we handle your personal data, please contact our Data Protection Officer:
Data Protection Officer
Email: [email protected]
Address: 123 Tech Street, San Francisco, CA 94107, USA
Phone: +1 (555) 123-4567
You also have the right to make a complaint at any time to your local supervisory authority for data protection issues.