Compliance with Data protection Law
GRH acknowledges and undertakes to comply with the laws and regulations governing the processing of personal data, including, but not limited to, the Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data (“GDPR”) and any other national applicable laws or regulations governing the processing any personal data pursuant to the Agreement.
Personal identification information
GRH may collect personal identification information from Users in a variety of ways, including, but not limited to, when Users visit GRH websites.
Non-personal identification information
GRH may collect non-personal identification information about Users whenever they use an GRH website or application or other online service. Non-personal identification information may include technical information about Users means of connection, such as the operating system and the Internet service provider utilized, geographical information such as country of origin, behavioural information such as time spent on site, as well as further non-personal analytical data to improve customer experience, products and services.
Each User recognizes and accepts that the performance of the Services may depend on the collection and processing of personal identification information and non-personal identification information.
How GRH protects personal identification information
GRH adopts appropriate data collection, storage and processing practices and security measures to protect against unauthorized access, alteration, disclosure or destruction of Users’ personal identification information within the limits of GRH’s role with respect to the relevant Services (as certain specific services might be rendered by third parties).
Sharing personal information
However, Users non-personal identification information may be provided to third parties for marketing, advertising, or other uses.
· as long as we maintain an ongoing relationship with you (e.g., where you are a recipient of our services, or you are lawfully included in our mailing list and have not unsubscribed);
· until the expiry of a period of two (2) months following the end of any applicable limitation period under applicable law; and
· with your prior consent, until the expiry of any additional retention period.
GRH undertakes to delete or to anonymise your personal data upon expiry of the retention period as described above.
Data Security and data transfer
GRH has implemented appropriate technical and organizational security measures designed to protect your personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure, unauthorised access, and other unlawful or unauthorised forms of Processing, in accordance with applicable law.
You are responsible for ensuring that any personal data that you send to us are sent securely.
GRH does not transfer personal data to any third country nor to any international organisation, except as the case may be on the basis of:
· suitable Standard Contractual Clauses; or
· other valid transfer mechanisms under GDPR.
Data Accuracy and minimization
We take reasonable measures:
· to ensure that your personal data are accurate and, where necessary, kept up to date and accurate; and
Data subject rights
Each User benefits under data protection law from a right of access, modification and opposition to the processing of its personal data, a right to erasure and a right to portability of its personal data by sending an email to firstname.lastname@example.org. Those rights may only be exercised within the limits of any contractual or legal obligation. Each User has also a right to lodge a complaint with the Luxembourg supervisory authority, namely the Commission nationale pour la protection des données ( https://cnpd.public.lu/fr.html ).
Acceptance of these terms