Legal Information for EU/EEA
This content is not available in your language yet.
Legal Information for EU/EEA
Section titled “Legal Information for EU/EEA”Last Updated: October 1, 2025
1. GDPR Framework
Section titled “1. GDPR Framework”1.1 Data Controller and Processor
Section titled “1.1 Data Controller and Processor”InitiumX as Data Processor
Section titled “InitiumX as Data Processor”For most client relationships:
- Client: Data Controller (determines purposes and means)
- InitiumX: Data Processor (processes on behalf of client)
- Relationship: Governed by Data Processing Agreement (DPA)
InitiumX as Data Controller
Section titled “InitiumX as Data Controller”For our own operations:
- Website visitors and contact forms
- Marketing communications
- Business relationships and prospects
1.2 Legal Basis for Processing
Section titled “1.2 Legal Basis for Processing”| Processing Activity | Legal Basis | Article |
|---|---|---|
| Service delivery | Contract performance | Art. 6(1)(b) |
| Marketing emails | Consent | Art. 6(1)(a) |
| Security measures | Legitimate interests | Art. 6(1)(f) |
| Legal compliance | Legal obligation | Art. 6(1)(c) |
| Analytics | Legitimate interests | Art. 6(1)(f) |
2. Data Subject Rights (GDPR Chapter III)
Section titled “2. Data Subject Rights (GDPR Chapter III)”2.1 Right of Access (Article 15)
Section titled “2.1 Right of Access (Article 15)”You have the right to obtain:
- Confirmation of processing
- Copy of personal data
- Information about processing purposes
- Categories of data processed
- Recipients of data
- Retention period
- Source of data (if not collected from you)
How to exercise:
- Email: gdpr@initiumx.dev
- Subject: “GDPR Article 15 - Right of Access”
- Timeline: 1 month (extendable to 3 months for complex requests)
- Format: Electronic copy (PDF, JSON, CSV)
- Free of charge for first request
2.2 Right to Rectification (Article 16)
Section titled “2.2 Right to Rectification (Article 16)”You can request:
- Correction of inaccurate personal data
- Completion of incomplete personal data
- Update of outdated information
Timeline:
- Response: 1 month
- Completion: Without undue delay
- Notification to third parties: As required
2.3 Right to Erasure / “Right to be Forgotten” (Article 17)
Section titled “2.3 Right to Erasure / “Right to be Forgotten” (Article 17)”Grounds for erasure:
- Data no longer necessary for purposes
- Withdrawal of consent
- Object to processing (legitimate grounds)
- Data processed unlawfully
- Legal obligation requires erasure
- Data collected from children (under 16)
Exceptions:
- Compliance with legal obligations
- Public interest or official authority
- Establishment, exercise, or defense of legal claims
- Archiving/research purposes
Timeline: 1 month to complete
2.4 Right to Restriction of Processing (Article 18)
Section titled “2.4 Right to Restriction of Processing (Article 18)”When you can restrict:
- Accuracy of data is contested
- Processing is unlawful but you oppose erasure
- We no longer need data but you need it for legal claims
- You objected to processing (pending verification)
Effect: Data stored but not processed (except with consent or for legal claims)
2.5 Right to Data Portability (Article 20)
Section titled “2.5 Right to Data Portability (Article 20)”You can receive:
- Personal data you provided to us
- In structured, commonly used, machine-readable format
- Transmitted directly to another controller (where technically feasible)
Applies when:
- Processing based on consent or contract
- Processing carried out by automated means
Formats available:
- JSON
- CSV
- XML
- SQL dump (for databases)
2.6 Right to Object (Article 21)
Section titled “2.6 Right to Object (Article 21)”You can object to processing based on:
- Legitimate interests (Art. 6(1)(f))
- Public interest/official authority (Art. 6(1)(e))
Direct marketing:
- Absolute right to object (no exceptions)
- Immediate cessation upon request
Profiling and automated decision-making:
- Right to object to decisions based solely on automated processing
- Right to human intervention
- Right to contest the decision
2.7 How to Exercise Your Rights
Section titled “2.7 How to Exercise Your Rights”Contact Points
Section titled “Contact Points”- Email: gdpr@initiumx.dev
- DPO Email: dpo@initiumx.dev
- Postal: InitiumX GDPR Requests, San Pedro Sula, Honduras
- Online Form: https://initiumx.dev/legal/gdpr-request
Timeline
Section titled “Timeline”- Acknowledgment: 72 hours
- Response: 1 month (standard)
- Extension: Up to 3 months (complex requests, notified within 1 month)
Identification Verification
Section titled “Identification Verification”- Email verification (for low-risk requests)
- Additional information for high-risk requests
- Proportionate to risk of processing
3. Data Protection Principles
Section titled “3. Data Protection Principles”3.1 Lawfulness, Fairness, and Transparency
Section titled “3.1 Lawfulness, Fairness, and Transparency”InitiumX commits to:
- Process data lawfully with valid legal basis
- Process fairly without deception
- Provide clear information about processing
- Transparent privacy notices
3.2 Purpose Limitation
Section titled “3.2 Purpose Limitation”We process data only for:
- Specified, explicit, and legitimate purposes
- No further processing incompatible with original purpose
- New purposes require new legal basis
3.3 Data Minimization
Section titled “3.3 Data Minimization”We collect only:
- Data adequate for purposes
- Data relevant to purposes
- Data limited to what is necessary
- No excessive data collection
3.4 Accuracy
Section titled “3.4 Accuracy”We ensure:
- Data is accurate and up-to-date
- Inaccurate data rectified without delay
- Regular review of data accuracy
- Mechanisms to update data
3.5 Storage Limitation
Section titled “3.5 Storage Limitation”Retention periods:
- No longer than necessary for purposes
- See detailed retention schedule in Privacy Policy
- Archiving with appropriate safeguards
- Automatic deletion after retention period
3.6 Integrity and Confidentiality
Section titled “3.6 Integrity and Confidentiality”Security measures:
- Encryption (TLS 1.3, AES-256)
- Access controls and authentication
- Regular security testing
- Incident response procedures
- Staff training on data protection
4. International Data Transfers
Section titled “4. International Data Transfers”4.1 Transfer Mechanisms
Section titled “4.1 Transfer Mechanisms”Standard Contractual Clauses (SCCs)
Section titled “Standard Contractual Clauses (SCCs)”Primary mechanism for transfers:
- Commission Implementing Decision (EU) 2021/914
- Module Two: Controller-to-Processor
- Module One: Controller-to-Controller (when applicable)
- Binding and enforceable data subject rights
Additional Safeguards
Section titled “Additional Safeguards”Supplementary measures (Schrems II):
- Encryption of data in transit and at rest
- Pseudonymization where appropriate
- Technical access controls
- Legal assessment of third country laws
- Regular review of transfers
4.2 Third Countries
Section titled “4.2 Third Countries”Data Transfer Locations
Section titled “Data Transfer Locations”| Country | Mechanism | Safeguards |
|---|---|---|
| Honduras | SCCs | Encryption, access controls |
| USA | SCCs | Encryption, limited access |
| UK | Adequacy decision | Standard protections |
Transfers via Sub-processors
Section titled “Transfers via Sub-processors”- Full list in DPA Sub-processors
- Each sub-processor has appropriate safeguards
- Client notification of new sub-processors
- Right to object to sub-processors
4.3 Your Rights Regarding Transfers
Section titled “4.3 Your Rights Regarding Transfers”You can:
- Request information about transfers
- Object to transfers to specific countries
- Request copy of appropriate safeguards
- Lodge complaint with supervisory authority
5. Data Protection Officer (DPO)
Section titled “5. Data Protection Officer (DPO)”5.1 Contact DPO
Section titled “5.1 Contact DPO”Direct contact:
- Email: dpo@initiumx.dev
- Subject: Clearly state your request/inquiry
- Response: Within 72 hours
DPO Responsibilities:
- Monitor GDPR compliance
- Advise on data protection obligations
- Cooperate with supervisory authorities
- Act as contact point for data subjects
5.2 When to Contact DPO
Section titled “5.2 When to Contact DPO”Appropriate for:
- Complex GDPR requests
- Complaints about data processing
- Questions about data protection
- Data breach concerns
- Privacy impact assessments
6. Supervisory Authorities
Section titled “6. Supervisory Authorities”6.1 Right to Lodge Complaint
Section titled “6.1 Right to Lodge Complaint”You can complain to:
- Supervisory authority in your EU/EEA country
- Supervisory authority where infringement occurred
- No requirement to exhaust internal remedies first
Common Supervisory Authorities
Section titled “Common Supervisory Authorities”- Germany: BfDI (Bundesbeauftragter für den Datenschutz)
- France: CNIL (Commission Nationale de l’Informatique)
- UK: ICO (Information Commissioner’s Office)
- Ireland: DPC (Data Protection Commission)
- Spain: AEPD (Agencia Española de Protección de Datos)
- Italy: Garante per la Protezione dei Dati Personali
Full list: https://edpb.europa.eu/about-edpb/about-edpb/members_en
6.2 Cooperation with Authorities
Section titled “6.2 Cooperation with Authorities”InitiumX commits to:
- Full cooperation with supervisory authorities
- Timely responses to inquiries
- Participation in investigations
- Implementation of corrective measures
7. Data Breach Notification
Section titled “7. Data Breach Notification”7.1 Notification to Supervisory Authority
Section titled “7.1 Notification to Supervisory Authority”Timeline: 72 hours of becoming aware of breach
Information provided:
- Nature of personal data breach
- Categories and number of data subjects affected
- Categories and number of records affected
- Likely consequences of breach
- Measures taken or proposed to address breach
Delays justified if information not immediately available
7.2 Notification to Data Subjects
Section titled “7.2 Notification to Data Subjects”When required:
- Breach likely to result in high risk to rights and freedoms
- Clear and plain language
- Direct communication where possible
Exceptions:
- Appropriate technical safeguards applied (e.g., encryption)
- Subsequent measures ensure no high risk
- Disproportionate effort (public communication instead)
Timeline: Without undue delay
8. Special Categories of Data
Section titled “8. Special Categories of Data”8.1 Article 9 Data
Section titled “8.1 Article 9 Data”We do NOT routinely process:
- Racial or ethnic origin
- Political opinions
- Religious or philosophical beliefs
- Trade union membership
- Genetic data
- Biometric data (for unique identification)
- Health data
- Sex life or sexual orientation
If required for specific project:
- Explicit consent obtained
- Additional security measures
- Enhanced Data Protection Impact Assessment (DPIA)
- Separate written agreement
8.2 Criminal Convictions Data
Section titled “8.2 Criminal Convictions Data”Article 10 restrictions:
- Only processed under official authority or when authorized by Union/Member State law
- Appropriate safeguards for rights and freedoms
9. Automated Decision-Making and Profiling
Section titled “9. Automated Decision-Making and Profiling”9.1 Article 22 Rights
Section titled “9.1 Article 22 Rights”You have right not to be subject to:
- Decisions based solely on automated processing
- Decisions that produce legal effects or similarly significant effects
Exceptions:
- Necessary for contract performance
- Authorized by law with safeguards
- Based on explicit consent
If automated decisions are made:
- Right to human intervention
- Right to express your point of view
- Right to contest decision
9.2 Transparency about Profiling
Section titled “9.2 Transparency about Profiling”If we use profiling:
- Clear information in privacy notice
- Logic involved explained
- Significance and envisaged consequences disclosed
- Right to object at any time
10. Children’s Data
Section titled “10. Children’s Data”10.1 Age of Consent
Section titled “10.1 Age of Consent”Varies by Member State:
- Minimum: 13 years (some countries)
- Maximum: 16 years (most countries)
- InitiumX standard: 16 years (highest protection)
For children under 16:
- Parental consent required
- Verifiable parental consent mechanisms
- Age-appropriate information
- Enhanced protections
10.2 Parental Rights
Section titled “10.2 Parental Rights”Parents/guardians can:
- Exercise all GDPR rights on behalf of child
- Request deletion of child’s data
- Object to processing
- Access child’s data
11. Cookies and Tracking (ePrivacy Directive)
Section titled “11. Cookies and Tracking (ePrivacy Directive)”11.1 Cookie Consent
Section titled “11.1 Cookie Consent”Requirements:
- Prior consent for non-essential cookies
- Clear and comprehensive information
- Easy withdrawal of consent
- No cookie walls (access not conditional on consent)
See: Cookie Policy
11.2 Cookie Categories
Section titled “11.2 Cookie Categories”Strictly Necessary: No consent needed
- Session management
- Security
- Load balancing
Functional, Analytics, Marketing: Consent required
- User preferences
- Usage analytics
- Targeted advertising
12. Contact and Resources
Section titled “12. Contact and Resources”12.1 GDPR-Specific Contacts
Section titled “12.1 GDPR-Specific Contacts”Data Protection Officer
Section titled “Data Protection Officer”- Email: dpo@initiumx.dev
- Scope: All GDPR matters
GDPR Requests
Section titled “GDPR Requests”- Email: gdpr@initiumx.dev
- Online form: https://initiumx.dev/legal/gdpr-request
EU Client Support
Section titled “EU Client Support”- Email: eu@initiumx.dev
- Phone: +504 3253-6271
- Hours: CET/CEST business hours
12.2 Related Documents
Section titled “12.2 Related Documents”Must read:
12.3 External Resources
Section titled “12.3 External Resources”Official GDPR resources:
- GDPR Full Text: https://gdpr-info.eu/
- European Data Protection Board: https://edpb.europa.eu/
- Your Supervisory Authority: https://edpb.europa.eu/about-edpb/about-edpb/members_en
Last Updated: October 1, 2025 Version: 1.0 Next Review: January 2026
EU/EEA Support: eu@initiumx.dev | DPO: dpo@initiumx.dev