GDPR Compliance

Comprehensive data protection and privacy rights in accordance with the General Data Protection Regulation

Effective: January 15, 2025Last Updated: January 15, 2025GDPR Compliant

Your GDPR Rights

Under the General Data Protection Regulation, you have comprehensive rights regarding your personal data

πŸ“‹

Right to Information

Clear information about how we collect, use, and process your data

πŸ‘οΈ

Right of Access

Request copies of your personal data and understand how it's being used

✏️

Right to Rectification

Correct inaccurate or incomplete personal data we hold about you

πŸ—‘οΈ

Right to Erasure

Request deletion of your personal data under certain circumstances

⏸️

Right to Restrict Processing

Limit how we process your data in specific situations

πŸ“¦

Right to Data Portability

Receive your data in a structured, machine-readable format

🚫

Right to Object

Object to processing based on legitimate interests or direct marketing

πŸ€–

Automated Decision-Making Rights

Protection from decisions based solely on automated processing

Data Controller Information

Identity and Contact Details

AraPulse Inc. acts as the data controller for personal data processed through our services:

  • Company: AraPulse Inc.
  • Address: 123 Innovation Drive, San Francisco, CA 94105, USA
  • Email: privacy@arapulse.com
  • Phone: +1 (555) 123-4567
  • EU Representative: AraPulse EU Ltd., Dublin, Ireland

Data Protection Officer

Our Data Protection Officer oversees GDPR compliance and data protection matters:

  • DPO Email: dpo@arapulse.com
  • Contact Form: Available on our privacy portal
  • Response Time: Within 30 days of request

Legal Basis for Processing

We process personal data based on the following legal grounds:

  • Consent: For marketing communications and optional features
  • Contract: To provide our voice generation services
  • Legal Obligation: For age verification and regulatory compliance
  • Legitimate Interests: For security, fraud prevention, and service improvement

Data Processing Activities

Categories of Personal Data

We process the following categories of personal data:

  • Identity Data: Name, age, date of birth, government ID
  • Contact Data: Email address, phone number, postal address
  • Financial Data: Payment method, billing information
  • Technical Data: IP address, browser type, device information
  • Usage Data: Service usage, preferences, interaction history
  • Voice Data: Audio recordings, voice samples, generated content
  • Profile Data: User preferences, feedback, account settings

Purposes of Processing

Service Provision

  • Account creation and management
  • Voice generation services
  • Customer support
  • Service personalization

Legal Compliance

  • Age verification
  • Regulatory reporting
  • Anti-money laundering
  • Tax obligations

Security & Safety

  • Fraud prevention
  • Account security
  • Content moderation
  • Abuse prevention

Business Operations

  • Service improvement
  • Analytics and insights
  • Marketing (with consent)
  • Research and development

Data Retention Periods

Account Data
Until account deletion + 30 days
Financial Records
7 years (legal requirement)
Voice Samples
As long as account is active
Usage Logs
2 years maximum
Support Records
3 years after resolution
Marketing Consent
Until withdrawal or 3 years

International Data Transfers

Transfer Mechanisms

When transferring personal data outside the EU/EEA, we ensure adequate protection through:

  • Adequacy Decisions: Transfers to countries with adequate protection
  • Standard Contractual Clauses: EU-approved data transfer agreements
  • Binding Corporate Rules: Internal data protection standards
  • Certification Schemes: Recognized privacy certifications

Third-Country Transfers

We may transfer data to the following regions with appropriate safeguards:

  • United States: Under EU-US Data Privacy Framework
  • United Kingdom: Adequacy decision in place
  • Canada: Adequacy decision for commercial organizations
  • Other Countries: Only with appropriate safeguards

Safeguards and Protections

All international transfers include the following protections:

  • Contractual obligations for data protection
  • Technical security measures
  • Regular compliance monitoring
  • Right to suspend transfers if protections are inadequate

Exercising Your Rights

How to Submit Requests

You can exercise your GDPR rights through the following methods:

Contact Form

Submit your request through our contact page

Go to Contact

Email Request

Send detailed requests to our privacy team

Send Email

Written Request

Mail formal requests to our address

Physical Address Available

Request Processing Timeline

Day 1
Request Received & Acknowledged
Day 3
Identity Verification
Day 10
Request Processing
Day 30
Response Delivered

Identity Verification

To protect your privacy, we verify your identity before processing requests:

  • Account credentials (email and password)
  • Additional verification questions
  • Government-issued ID for sensitive requests
  • Two-factor authentication if enabled

Request Fees

Most requests are processed free of charge. Fees may apply for:

  • Excessive or repetitive requests
  • Complex data compilation
  • Additional copies of data
  • Expedited processing (optional)

Data Security Measures

Technical Safeguards

We implement comprehensive technical measures to protect your data:

  • Encryption: End-to-end encryption for data in transit and at rest
  • Access Controls: Role-based access with multi-factor authentication
  • Network Security: Firewalls, intrusion detection, and monitoring
  • Data Anonymization: Pseudonymization and anonymization where possible

Organizational Measures

Our organizational security measures include:

  • Regular security training for all staff
  • Data protection impact assessments
  • Incident response procedures
  • Third-party security audits

Breach Notification

In case of a data breach, we commit to:

  • Notify supervisory authorities within 72 hours
  • Inform affected individuals without undue delay
  • Provide clear information about the breach
  • Implement immediate containment measures

Supervisory Authority

Lead Supervisory Authority

For EU users, our lead supervisory authority is:

  • Authority: Irish Data Protection Commission
  • Address: 21 Fitzwilliam Square South, Dublin 2, Ireland
  • Website: www.dataprotection.ie
  • Email: info@dataprotection.ie

Right to Lodge a Complaint

You have the right to lodge a complaint with a supervisory authority if you believe we have violated GDPR. You can contact:

  • The supervisory authority in your country of residence
  • The supervisory authority in your place of work
  • The supervisory authority where the alleged violation occurred
  • Our lead supervisory authority (Irish DPC)

Cooperation with Authorities

We maintain full cooperation with supervisory authorities:

  • Respond to information requests promptly
  • Participate in investigations
  • Implement corrective measures as required
  • Provide regular compliance reports

Contact Information

Privacy Team

For all GDPR-related inquiries:

  • Email: privacy@arapulse.com
  • DPO Email: dpo@arapulse.com
  • Privacy Portal: privacy.arapulse.com
  • Response Time: Within 30 days

EU Representative

Our EU representative for GDPR matters:

  • Company: AraPulse EU Ltd.
  • Address: 45 Grafton Street, Dublin 2, Ireland
  • Email: eu-privacy@arapulse.com
  • Phone: +353 1 234 5678

Exercise Your GDPR Rights

Contact Form

Submit a data request through our contact page

Go to Contact

Privacy Team

Direct contact with our privacy experts

privacy@arapulse.com

Data Protection Officer

Speak with our DPO about compliance

dpo@arapulse.com