Privacy
Privacy policy
This privacy policy explains how personal data may be handled in connection with this website and Attanda's services.
This is a privacy policy scaffold. It must be completed with your real details and reviewed by qualified legal counsel before launch. Placeholders below mark information that still needs to be provided.
Last updated:[ Date ]To be completed before launch
1. Who is responsible (controller)
The controller responsible for processing personal data on this website is:
2. Contact
For questions about this policy or your personal data, you can contact us at:
3. What data may be collected
Depending on how you use the site and our services, the following categories of data may be processed:
Information you provide directly (for example, details you submit when contacting us or requesting a review).
Basic technical information that your browser sends when requesting pages (for example, request data needed to deliver the site).
The exact categories for your deployment are documented during scoping.
4. Purposes of processing
Personal data may be processed to respond to your enquiries, to provide and operate the services you request, to maintain the security and reliability of the site, and to meet legal obligations.
Data is used only for purposes that are explained to you.
5. Lawful bases
Processing is carried out on the lawful bases applicable to each purpose under the GDPR (for example, consent, performance of a contract, legitimate interests, or legal obligation).
The specific lawful basis for each processing activity is to be confirmed:
6. Retention
Personal data is kept only as long as necessary for the purposes described, or as required by law.
Specific retention periods or criteria are to be defined:
7. Recipients, processors & subprocessors
Personal data may be shared with service providers who process data on our behalf (processors and their subprocessors), strictly for the purposes described.
The specific recipients, processors, and subprocessors are to be listed:
8. International transfers
Where personal data is transferred outside the EU/EEA, appropriate safeguards are applied as required by the GDPR.
Details of any international transfers and their safeguards are to be provided:
9. Your rights
Subject to the conditions of the GDPR, you have the right to access your personal data, to request rectification or erasure, to restrict or object to processing, and to data portability.
Where processing is based on consent, you may withdraw that consent at any time, without affecting the lawfulness of processing before withdrawal.
10. Right to complain
You have the right to lodge a complaint with a data protection supervisory authority, in particular in the EU/EEA country of your residence, place of work, or the place of an alleged infringement.
11. Cookies & tracking
The current version of this website does not intentionally use non-essential cookies or marketing/analytics tracking.
If analytics or marketing tools are introduced in the future, consent will be requested where required and this policy will be updated before those tools are activated.
12. Data security
We follow a privacy-by-design approach with data minimization and access controls appropriate to the processing.
This describes our approach to protecting data; it is not a guarantee of absolute security.
13. Updates to this policy
This policy may be updated to reflect changes to our services or legal requirements.
The current version applies from the date shown above.