Skip to content

GDPR Compliance

How we protect your rights under GDPR

Our Commitment to GDPR

TinyTap Analytics is committed to full compliance with the General Data Protection Regulation (GDPR). We've designed our service to be privacy-first by default, giving you control over your data.

Your GDPR Rights

Right to Access

You can request a copy of all personal data we hold about you. We'll provide this within 30 days in a commonly used format.

Right to Rectification

You can update or correct your personal data at any time through your account settings or by contacting us.

Right to Erasure

You can request deletion of your personal data. We'll delete it within 30 days, except where we have a legal obligation to retain it.

Right to Data Portability

You can export your data in JSON format through your account dashboard or API.

Right to Object

You can object to processing of your data for marketing purposes or legitimate interests.

Right to Restrict Processing

You can request that we limit how we process your data in certain circumstances.

How We Process Data

Legal Basis for Processing

  • Contract: Processing necessary to provide our service
  • Legitimate Interest: Fraud prevention, service improvement
  • Consent: Marketing communications (opt-in required)
  • Legal Obligation: Tax and financial record keeping

Data Protection Measures

🔒

Encryption

All data encrypted in transit (TLS 1.3) and at rest (AES-256)

👥

Access Controls

Role-based access with multi-factor authentication

📊

Data Minimization

We only collect data necessary for our service

🗂️

Data Retention

Configurable retention periods with automatic deletion

Data Transfers

We store and process data within the EU. If we need to transfer data outside the EU, we ensure adequate safeguards:

  • Standard Contractual Clauses (SCCs)
  • Adequacy decisions by the European Commission
  • Data Processing Agreements with all processors

Data Breach Notification

In the event of a data breach affecting your personal data, we will notify you and the relevant supervisory authority within 72 hours, as required by GDPR.

Exercising Your Rights

To exercise any of your GDPR rights, you can:

We'll respond to your request within 30 days. If we need more time, we'll let you know and explain why.

Supervisory Authority

You have the right to lodge a complaint with your local data protection authority if you believe we've violated your GDPR rights.

Contact Our DPO

For GDPR-related inquiries, contact our Data Protection Officer:

Email: dpo@tinytapanalytics.com