GDPR Compliance

GDPR & Data Privacy

How Vortex 360 processes personal data in compliance with the EU General Data Protection Regulation and Saudi Arabia's Personal Data Protection Law (PDPL).

When you use Vortex 360 to process your customers' data…

You are the Data Controller. You determine why and how personal data is processed. Vortex 360 acts as your Data Processor and processes data strictly on your instructions under a Data Processing Agreement.

When we process your account & billing data…

Vortex 360 is the Data Controller for data collected to manage your subscription, provide support, and communicate product updates. Our Privacy Policy governs this processing.

Your data rights

Under GDPR, you have comprehensive rights over your personal data. We make it easy to exercise them.

Right to Access

Request a full copy of all personal data we hold about you or your organisation.

Right to Rectification

Ask us to correct inaccurate or incomplete personal data at any time.

Right to Erasure

Request deletion of your personal data ("right to be forgotten"), subject to legal retention requirements.

Right to Portability

Receive your data in a structured, machine-readable format (JSON or CSV) for transfer to another provider.

Right to Restrict Processing

Ask us to pause processing of your data while a complaint is being resolved.

Right to Object

Object to processing of your personal data for certain purposes, including direct marketing.

To exercise any of these rights, contact our Data Protection Officer:

How we stay compliant

Technical and organisational measures we've implemented to ensure GDPR compliance.

Data minimisation

We collect only the data necessary to provide the service. We regularly review and purge data that is no longer required.

Purpose limitation

Data collected for one purpose is not reused for a different purpose without explicit consent.

Data Processing Agreements

All sub-processors (Azure, Stripe, Resend) are bound by DPAs that comply with GDPR Article 28.

Breach notification

In the event of a data breach affecting personal data, we will notify affected customers within 72 hours as required by GDPR.

Cross-border transfers

Data transferred outside the EEA is covered by Standard Contractual Clauses (SCCs) approved by the European Commission.

Data Retention Policy

Personal data is retained only as long as necessary. Accounts are purged 90 days after cancellation unless legal retention applies.

Need a Data Processing Agreement?

Enterprise customers can request our standard DPA, which covers all requirements under GDPR Article 28 and the Saudi PDPL. Contact our DPO to receive and sign the DPA.

GDPR | Vortex 360