GDPR Information
Simplaq LLC · Last updated
Draft pending legal review
This document is a structurally complete draft prepared for review. It has not yet been approved by legal counsel and is not a final, binding legal text. For any binding information, contact hello@simplaq.com.
This page summarises how Simplaq LLC applies the EU General Data Protection Regulation to enquiries and projects from the EEA and the UK, both as a controller of our own enquiry data and as a processor when we work on a client's website.
1. Roles
- Controller: for data you send us through the contact form or by email about a possible project.
- Processor: where we build, deploy or maintain a website on your behalf and thereby access personal data in your systems or content. In that case you remain the controller and we act on your documented instructions.
2. Legal bases
- Art. 6(1)(b) — pre-contractual steps and performance of the project contract.
- Art. 6(1)(f) — legitimate interests in website security, abuse prevention and rate limiting.
- Art. 6(1)(c) — compliance with accounting and tax obligations.
- Art. 6(1)(a) — consent, where we ask for it explicitly.
3. Your rights
- Access to the personal data we hold about you (Art. 15).
- Rectification of inaccurate data (Art. 16).
- Erasure where the conditions are met (Art. 17).
- Restriction of processing (Art. 18).
- Data portability for data you provided (Art. 20).
- Objection to processing based on legitimate interests (Art. 21).
- Withdrawal of consent at any time, without affecting past lawful processing (Art. 7(3)).
To exercise any of these rights, email hello@simplaq.com. We respond within one month and may ask for information needed to verify your identity. You may also complain to your national supervisory authority.
4. Data processing agreement
For client projects we sign a data processing agreement covering subject matter, duration, instructions, confidentiality, security measures, sub-processors, assistance with data subject requests, breach notification, audit and deletion or return of data at the end of the engagement. Request the current template by email.
5. Sub-processors and international transfers
We use hosting, serverless function and email delivery providers as sub-processors, and we inform clients of changes to that list. Because Simplaq LLC is established in the United States, personal data may be transferred outside the EEA; such transfers rely on the transfer mechanisms offered by the relevant provider, including standard contractual clauses where applicable.
6. Security
- HTTPS for all traffic and security headers on delivered sites.
- Server-side validation, input sanitisation and rate limiting on form endpoints.
- Least-privilege access to project repositories and hosting accounts.
- Maintained dependencies and no unsupported plugin ecosystems.
7. What we build into your website
Delivered projects include a consent mechanism for non-essential cookies, a cookie policy page, privacy and terms pages, form-level data minimisation and documented retention settings, so your center can operate the site in a GDPR-compliant way. Legal texts for your own site must be reviewed by your legal counsel before publication.
8. Breach notification
If we become aware of a personal data breach affecting your project, we notify you without undue delay with the information available and support your assessment and reporting obligations.