GDPR — Your Rights
Last updated: [Effective Date]
If you are located in the European Union or European Economic Area, the General Data Protection Regulation (GDPR) gives you specific rights over your personal data. This page explains those rights and how to exercise them.
[Company Name] is the data controller for your personal data. We are based in Romania, EU. For full details on what data we collect and how we use it, see our Privacy Policy.
Right of Access
You have the right to request a copy of the personal data we hold about you. This includes your account information, review history, and any other data associated with your account. We will respond to your request within 30 days.
Right to Rectification
If any of the personal data we hold about you is inaccurate or incomplete, you have the right to have it corrected. You can update your name directly in your account settings. For other corrections, contact us at [Contact Email].
Right to Erasure ("Right to Be Forgotten")
You have the right to request that we delete your personal data. You can exercise this right directly within the app:
You can delete individual reviews at any time, which permanently removes the review and all associated photos and data. You can delete your entire account through the account settings page. When deleting your account, you choose between deleting all your reviews entirely or anonymizing them — anonymized reviews are preserved under a randomly generated name with all personal data permanently removed.
If you need assistance or want to request erasure by other means, contact us at [Contact Email].
Right to Data Portability
You have the right to receive your personal data in a structured, commonly used, machine-readable format, and to transmit it to another data controller. To request an export of your data, contact us at [Contact Email] and we will provide it within 30 days.
Right to Restrict Processing
You have the right to request that we restrict the processing of your personal data in certain circumstances — for example, if you contest the accuracy of the data or object to our processing while we evaluate your request. During the restriction period, we will continue to store your data but will not actively process it beyond storage.
Right to Object
You have the right to object to the processing of your personal data where we rely on legitimate interest as the legal basis. This applies to the IP address data we collect for rate limiting and abuse prevention. If you object, we will stop processing unless we can demonstrate compelling legitimate grounds that override your interests.
You will never receive direct marketing from us, as we do not engage in marketing or advertising activities.
Right to Withdraw Consent
Where processing is based on your consent, you have the right to withdraw that consent at any time. Withdrawing consent does not affect the lawfulness of any processing that took place before the withdrawal. In practice, most of our data processing is based on contractual necessity (providing the service) rather than consent.
Automated Decision-Making
We do not engage in automated decision-making or profiling that produces legal effects or similarly significant effects concerning you. Review scores are computed as simple averages of your own category ratings — no algorithmic profiling is involved.
How to Exercise Your Rights
For rights you can exercise directly, use the account settings and review management features within the app. For all other requests, or if you need assistance, email us at [Contact Email]. We will respond to all valid requests within 30 days. If a request is particularly complex, we may extend this period by an additional 60 days with prior notice.
We may ask you to verify your identity before processing a request to protect your data from unauthorized access.
Lodge a Complaint
If you believe we have not handled your personal data appropriately, you have the right to lodge a complaint with the Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP):
Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal (ANSPDCP) Address: B-dul G-ral. Gheorghe Magheru 28-30, Sector 1, 010336 București, România Website: www.dataprotection.ro Email: anspdcp@dataprotection.ro
You also have the right to lodge a complaint with the supervisory authority in the EU/EEA member state where you live or work, if different from Romania.
Contact Us
For any questions about your rights or to submit a data request:
[Company Name] [Contact Email] Romania, EU