GDPR Compliance

Last updated: July 1, 2026

1. Overview

Droplixer is committed to compliance with the General Data Protection Regulation (GDPR) and other applicable data protection laws. This page outlines our data protection practices for users in the European Economic Area (EEA), United Kingdom, and other regions where GDPR applies.

2. Data Controller

The data controller responsible for your personal data is:

Droplixer Inc.
Data Protection Officer: dpo@droplixer.com
Global Operations

3. Legal Basis for Processing

We process your personal data based on the following legal grounds:

Contract Performance

Processing necessary to fulfill our contractual obligations to you, including providing our services and managing your account.

Legitimate Interest

Processing necessary for our legitimate interests, such as improving our services, ensuring platform security, and preventing fraud.

Consent

Processing based on your explicit consent for specific purposes, such as marketing communications.

Legal Obligation

Processing necessary to comply with legal requirements, such as tax regulations and warranty obligations.

4. Your Rights Under GDPR

Under GDPR, you have the following rights:

Right of Access

Request a copy of the personal data we hold about you.

Right to Rectification

Request correction of inaccurate personal data.

Right to Erasure

Request deletion of your personal data ("right to be forgotten").

Right to Restrict Processing

Request limitation of processing in certain circumstances.

Right to Data Portability

Receive your data in a structured, machine-readable format.

Right to Object

Object to processing based on legitimate interests.

5. Data Transfers

Droplixer operates globally and may transfer your data to servers outside the EEA. We ensure adequate protection through:

  • Standard Contractual Clauses (SCCs)
  • Adequacy decisions by the European Commission
  • Binding Corporate Rules where applicable
  • Data processing agreements with all third-party processors

6. Data Retention

We retain your personal data only for as long as necessary to fulfill the purposes for which it was collected, including to satisfy legal, accounting, or reporting requirements. Specific retention periods are:

  • Account data: Duration of account + 2 years
  • Repair records: 5 years for warranty purposes
  • Payment data: As required by financial regulations
  • Usage logs: 12 months for security purposes

7. Data Security

We implement appropriate technical and organizational measures to protect your personal data, including:

  • AES-256 encryption for data at rest
  • TLS 1.3 for data in transit
  • Regular security assessments and penetration testing
  • Access controls and authentication mechanisms
  • Employee training on data protection

8. Data Protection Officer

Our Data Protection Officer can be contacted at:

Email: dpo@droplixer.com

9. Complaints

If you believe your data protection rights have been infringed, you have the right to lodge a complaint with a supervisory authority. We encourage you to contact us first so we can address your concerns.

10. Changes to This Policy

We may update this GDPR compliance page to reflect changes in our data processing practices or legal requirements. We will notify you of any material changes.