Home / GDPR Policy

GDPR Policy

Last updated: 2025.

1. Our GDPR Commitments

RackRent Systems LTD processes personal data in accordance with the General Data Protection Regulation (GDPR, EU Regulation 2016/679). This page supplements the Privacy Policy and provides information on the legal bases for processing.

2. Legal Bases for Processing

  • Contract performance (Art. 6(1)(b)) — processing data necessary to provide services
  • Legal obligation (Art. 6(1)(c)) — compliance with AML/KYC and tax law requirements
  • Legitimate interest (Art. 6(1)(f)) — ensuring security, preventing fraud
  • Consent (Art. 6(1)(a)) — marketing communications (with explicit consent)

3. International Data Transfers

Where data is transferred to third countries, we ensure an adequate level of protection through Standard Contractual Clauses (SCCs) approved by the European Commission, or other mechanisms provided for under GDPR.

4. Data Subject Rights

To exercise your rights (access, rectification, erasure, portability, objection), submit a request via the contact form. Response time: 30 days, extendable to 90 days with justification.

If you believe your rights have been violated, you have the right to lodge a complaint with the data protection supervisory authority in your country.

5. Breach Notification

In the event of a data breach posing a risk to the rights and freedoms of individuals, the Company will notify the competent supervisory authority within 72 hours. Affected data subjects will be notified without undue delay in cases of high risk.