Your Data Rights Under GDPR
At GTSol360 (Global Technology Solution 360), we are committed to protecting your personal data and ensuring full compliance with the General Data Protection Regulation (GDPR). This page explains your rights and how we safeguard your information.
Effective: September 6, 2026
What is GDPR?
The General Data Protection Regulation (GDPR) (EU) 2016/679 is a regulation in EU law on data protection and privacy in the European Union and the European Economic Area. It addresses the transfer of personal data outside the EU and EEA areas, and gives individuals control over their personal data.
GTSol360 is committed to full compliance with GDPR. This means we respect your privacy, protect your data, and give you control over how your information is used. We serve clients in the USA, UK, Europe, Canada, Australia, UAE, and worldwide, and we ensure all data handling meets international standards.
Our Commitment to Data Protection
We are committed to the following principles:
- Transparency: We are open and clear about how we collect, use, and share your data.
- Security: We implement robust, industry-standard security measures to protect your information.
- Control: We give you full control over your personal data and respect your choices.
- Accountability: We take responsibility for protecting your data and ensuring compliance with all applicable laws.
Data Protection Principles
We follow the core data protection principles outlined in GDPR:
Your Data Subject Rights
Under GDPR, you have the following rights regarding your personal data:
Right to Access
Request a copy of your personal data we hold.
Right to Rectification
Correct inaccurate or incomplete data.
Right to Erasure
Request deletion of your data ('Right to be Forgotten').
Right to Restriction
Restrict processing of your data.
Right to Data Portability
Receive your data in a machine-readable format.
Right to Object
Object to processing for marketing or profiling.
Right to Withdraw Consent
Withdraw consent at any time.
Right to Lodge a Complaint
Complain to a supervisory authority.
To exercise any of these rights, please contact our Data Protection Officer at info@gtsol360.com. We will respond within 30 days.
Lawful Basis for Processing
We process your personal data only when we have a lawful basis to do so. Our lawful bases include:
- Consent: You have given us explicit, informed consent to process your data.
- Contract: Processing is necessary for the performance of a contract with you.
- Legal Obligation: Processing is necessary to comply with a legal obligation.
- Legitimate Interests: Processing is necessary for our legitimate business interests, provided they do not override your fundamental rights.
International Data Transfers
As a global company serving clients in USA, UK, Europe, Canada, Australia, UAE, and beyond, we may transfer your personal data to countries outside the European Economic Area (EEA). When we do so, we ensure that appropriate safeguards are in place, such as:
- Standard Contractual Clauses (SCCs): Approved by the European Commission.
- Adequacy Decisions: Data transfers to countries with adequate protection levels.
- Binding Corporate Rules (BCRs): For intra-group transfers.
Data Retention Policy
We retain your personal data only for as long as necessary to fulfil the purposes for which it was collected, including for the purposes of satisfying any legal, accounting, or reporting requirements. For project-related data, we retain records for up to 7 years for legal and auditing purposes.
When we no longer need your data, we securely delete or anonymise it in accordance with our data retention schedule.
Security Measures
We implement industry-standard security measures to protect your personal data from unauthorised access, alteration, disclosure, or destruction:
- Encryption: SSL/TLS encryption for all data in transit and at rest.
- Access Control: Role-based access controls and strong multi-factor authentication.
- Monitoring: Continuous security monitoring, threat detection, and intrusion prevention.
- Audits: Regular security audits, vulnerability assessments, and penetration testing.
Data Breach Notification
In the event of a data breach that poses a risk to your rights and freedoms, we will notify you and the relevant supervisory authority within 72 hours of becoming aware of the breach, as required by GDPR. We have a comprehensive incident response plan in place to handle such situations.
Data Protection Officer (DPO)
We have appointed a Data Protection Officer (DPO) to oversee our data protection strategy and ensure compliance with GDPR and other applicable privacy laws.
Policy Updates
We may update this GDPR page from time to time to reflect changes in our practices or for operational, legal, or regulatory reasons. We encourage you to review this page periodically. Any changes will be posted on this page with a revised effective date. Your continued use of our services after any changes constitutes your acceptance of the updated policy.
Questions about your data rights?
We're here to help. Reach out to our Data Protection Team anytime.