Legal Center

GDPR Compliance Policy

Clear terms, transparent commitments, and practical guidance for clients and partners.

View All Policies

Version: 1.0 · Effective: March 24, 2026 · Regulation: EU GDPR 2016/679

1. Scope & Applicability

This GDPR Compliance Policy applies to all processing of personal data relating to EU/EEA data subjects by GoNexel, regardless of where the processing takes place. GoNexel acts as a Data Controller for client account data and as a Data Processor when handling data on behalf of clients.

Global Standard

While GDPR specifically protects EU/EEA residents, GoNexel applies GDPR principles as a baseline for all client data, regardless of geography.

2. Data Protection Principles

GoNexel adheres to all seven GDPR principles:

PrincipleHow GoNexel Implements It
Lawfulness, Fairness & TransparencyClear privacy policy, explicit consent mechanisms, transparent data practices
Purpose LimitationData collected only for specified, legitimate purposes stated at the time of collection
Data MinimisationOnly essential data collected; no unnecessary personal data processing
AccuracyRegular data reviews, client self-service updates, correction within 5 business days
Storage Limitation90 days post-deletion; data purged per retention schedule
Integrity & ConfidentialityAES-256 encryption, access controls, regular security audits
AccountabilityDPO appointed, DPIA conducted, processing records maintained

3. Legal Bases for Processing

Processing ActivityLegal Basis (Article 6)Details
Account Creation & Service DeliveryContractual Necessity (6.1.b)Required to fulfil service contract
Payment ProcessingContractual Necessity (6.1.b)Required for billing and invoicing
Marketing EmailsConsent (6.1.a)Explicit opt-in required; withdraw anytime
Service ImprovementLegitimate Interest (6.1.f)Analytics and feedback analysis (with opt-out)
Tax & Legal ObligationsLegal Obligation (6.1.c)GST, financial records retention
Fraud PreventionLegitimate Interest (6.1.f)Monitoring and detection systems

4. Data Subject Rights

EU/EEA data subjects have the following rights under GDPR. GoNexel will respond to all requests within 30 days:

RightDescriptionHow to Exercise
Right of Access (Art. 15)Obtain a copy of your personal dataEmail request — data provided in portable format within 7 days
Right to Rectification (Art. 16)Correct inaccurate dataEmail request — corrected within 5 business days
Right to Erasure (Art. 17)Request deletion of your dataEmail request — deleted within 90 days (subject to legal exceptions)
Right to Restrict (Art. 18)Restrict how your data is processedEmail request — processing restricted within 7 days
Right to Portability (Art. 20)Receive data in a portable formatData provided in JSON, CSV, or PDF format
Right to Object (Art. 21)Object to processing based on legitimate interestEmail request — processing halted pending review
Right re: Automated Decisions (Art. 22)Not be subject to solely automated decisionsHuman review available on request

5. Data Protection Officer (DPO)

GoNexel has designated a Data Protection Officer responsible for GDPR compliance oversight:

Data Protection Officer

Email: info@gonexel.com (Subject: "DPO Inquiry")
Response Time: Within 5 business days
Responsibilities: Compliance monitoring, DPIA oversight, data subject rights coordination, regulatory liaison

6. International Data Transfers

When transferring personal data outside the EU/EEA, GoNexel employs appropriate safeguards:

  • Standard Contractual Clauses (SCCs): EU-approved clauses in all cross-border agreements
  • Adequacy Decisions: Transfers to countries with EU adequacy decisions
  • Data Processing Agreements (DPAs): Binding agreements with all processors
  • Primary Storage: AWS Mumbai, India — with data processed in compliance with EU requirements

7. Data Protection Impact Assessments

GoNexel conducts Data Protection Impact Assessments (DPIAs) when:

  • Introducing new processing technologies or systems
  • Processing large-scale sensitive personal data
  • Systematic monitoring of public areas
  • Automated decision-making with legal or significant effects

DPIAs are reviewed by the DPO and results are documented. The supervisory authority is consulted when high residual risk is identified.

8. Breach Notification

GDPR Breach Notification Requirements

Supervisory Authority: Notified within 72 hours of a confirmed personal data breach.
Affected Data Subjects: Notified without undue delay if the breach is likely to result in a high risk to their rights and freedoms.
Breach Register: All breaches documented in our breach register, regardless of severity.

9. Sub-Processors

GoNexel uses the following sub-processors for EU data:

ProcessorPurposeLocationSafeguards
AWSCloud infrastructure & storageIndia (Mumbai)SCCs, DPA
StripePayment processingUSA / EUSCCs, PCI DSS
Google AnalyticsWebsite analyticsUSAAnonymisation, SCCs
CloudflareCDN & DDoS protectionGlobalSCCs, DPA

Clients are notified of any changes to sub-processors with 30 days' advance notice. Objections considered in good faith.

10. Contact

GDPR Inquiries

GoNexel — Data Protection Officer
Email: info@gonexel.com (Subject: "GDPR Request")
Website: gonexel.com

Supervisory Authority Complaint: You have the right to lodge a complaint with your local EU data protection authority.