GDPR Compliance
Last updated: August 4, 2025
xlnszia is committed to complying with the EU General Data Protection Regulation (GDPR). This page summarises how we fulfil our obligations and how you can exercise your rights.
1. Data Controller
xlnszia acts as a data controller for the personal data you provide when using our service. Our Privacy Policy describes in detail what data we process.
2. Lawful Bases for Processing
We process personal data on the following legal bases:
- Performance of a contract — providing the monitoring service you signed up for.
- Legitimate interests — securing the platform and improving the service.
- Consent — where you have explicitly agreed (e.g. marketing communications).
- Legal obligation — where we must retain data to comply with the law.
3. Your GDPR Rights
As a data subject you have the right to:
- Access — obtain a copy of the personal data we hold about you.
- Rectification — correct inaccurate or incomplete data.
- Erasure — request deletion of your data (“right to be forgotten”).
- Restriction — restrict processing in certain circumstances.
- Data portability — receive your data in a machine-readable format.
- Object — object to processing based on legitimate interests or for marketing.
4. Data Transfers
Where data is transferred outside the EEA, we rely on appropriate safeguards such as the EU Standard Contractual Clauses.
5. Data Retention
Personal data is retained only as long as necessary for the purposes described in our Privacy Policy, or as required by law.
6. Security
We implement technical and organisational measures — including encryption, access controls and monitoring — to protect personal data.
7. Complaints
If you believe your data protection rights have been violated, you may lodge a complaint with your local supervisory authority.
8. Contact
To exercise any of your GDPR rights, contact us via our Contact page.