GDPR Compliance

Last updated: May 31, 2025

Introduction to GDPR

The General Data Protection Regulation (GDPR) is a comprehensive data protection law that came into effect on May 25, 2018, in the European Union (EU) and European Economic Area (EEA). The GDPR aims to give individuals control over their personal data and harmonize data protection laws across Europe.

At CodeMoly Austria, we are committed to ensuring the highest level of data protection for our clients, partners, and visitors. This page outlines our approach to GDPR compliance and the measures we have implemented to protect your personal data.

Our Commitment to GDPR Compliance

As a company based in Austria, an EU member state, CodeMoly Austria is fully committed to complying with the GDPR. We have implemented various technical and organizational measures to ensure that all personal data processing activities are conducted in accordance with GDPR principles.

Key GDPR Principles We Follow

We adhere to the following GDPR principles in all our data processing activities:

1. Lawfulness, Fairness, and Transparency

We process personal data lawfully, fairly, and in a transparent manner. We provide clear information about how we collect, use, and store personal data through our Privacy Policy.

2. Purpose Limitation

We collect personal data for specified, explicit, and legitimate purposes and do not process it in a manner incompatible with those purposes.

3. Data Minimization

We collect only the personal data that is adequate, relevant, and limited to what is necessary for the purposes for which it is processed.

4. Accuracy

We take reasonable steps to ensure that personal data is accurate and, where necessary, kept up to date. Inaccurate data is erased or rectified without delay.

5. Storage Limitation

We keep personal data in a form that permits identification of data subjects for no longer than necessary for the purposes for which it is processed.

6. Integrity and Confidentiality

We process personal data in a manner that ensures appropriate security, including protection against unauthorized or unlawful processing and against accidental loss, destruction, or damage.

Data Subject Rights

Under the GDPR, individuals (data subjects) have certain rights regarding their personal data. We respect and facilitate the exercise of these rights:

Right to Access

You have the right to request information about whether we process your personal data and to access that data.

Right to Rectification

You have the right to request correction of inaccurate personal data or completion of incomplete personal data.

Right to Erasure (Right to be Forgotten)

In certain circumstances, you have the right to request the deletion of your personal data.

Right to Restriction of Processing

In certain circumstances, you have the right to request that we restrict the processing of your personal data.

Right to Data Portability

You have the right to receive your personal data in a structured, commonly used, and machine-readable format and to transmit that data to another controller.

Right to Object

You have the right to object to the processing of your personal data in certain circumstances, including for direct marketing purposes.

Rights Related to Automated Decision-making and Profiling

You have the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning you or similarly significantly affects you.

To exercise any of these rights, please contact us at hello@codemoly.com. We will respond to your request within one month as required by the GDPR.

Data Protection Measures

We have implemented appropriate technical and organizational measures to ensure a level of security appropriate to the risk, including:

  • Encryption of personal data where appropriate
  • Regular testing and evaluation of technical and organizational measures
  • Staff training on data protection and GDPR compliance
  • Access controls and authentication mechanisms
  • Regular backups and disaster recovery procedures
  • Data protection impact assessments for high-risk processing activities

International Data Transfers

As a company operating between Austria and Bangladesh, we may transfer personal data outside the EEA. When doing so, we ensure appropriate safeguards are in place to protect your data, such as:

  • Standard Contractual Clauses approved by the European Commission
  • Binding corporate rules for transfers within our group of companies
  • Data processing agreements with third-party service providers that include data protection clauses

Data Breach Procedures

We have implemented procedures to detect, report, and investigate personal data breaches. In the event of a breach that is likely to result in a risk to the rights and freedoms of individuals, we will notify the relevant supervisory authority within 72 hours of becoming aware of the breach. We will also notify affected individuals without undue delay when the breach is likely to result in a high risk to their rights and freedoms.

Data Protection Officer (DPO)

Although not legally required for our organization's size and activities, we have designated a data protection contact person to oversee our GDPR compliance efforts and to serve as a point of contact for data protection matters.

For any data protection related inquiries, please contact our data protection team at hello@codemoly.com.

Records of Processing Activities

In accordance with Article 30 of the GDPR, we maintain records of our processing activities. These records include information about the purposes of processing, categories of data subjects and personal data, recipients of personal data, transfers to third countries, retention periods, and a general description of security measures.

Client Data Processing

When providing our services to clients, we may process personal data on behalf of our clients as a data processor. In such cases, we:

  • Process data only on the documented instructions of the client (data controller)
  • Ensure that persons authorized to process the data have committed to confidentiality
  • Implement appropriate security measures
  • Assist the client in responding to requests from data subjects
  • Assist the client in ensuring compliance with GDPR obligations
  • Delete or return all personal data to the client at the end of the service provision
  • Make available to the client all information necessary to demonstrate compliance

GDPR Training

All our employees and contractors who have access to personal data receive regular training on data protection and GDPR compliance. This training covers the principles of GDPR, data subject rights, security measures, and breach reporting procedures.

Continuous Improvement

We regularly review and update our data protection policies, procedures, and practices to ensure ongoing compliance with the GDPR and other relevant data protection laws. We also stay informed about regulatory guidance, court decisions, and best practices in data protection.

Contact Us

If you have any questions, concerns, or requests regarding our GDPR compliance or the processing of your personal data, please contact us at:

Email: hello@codemoly.com

Address: Sonnwendgasse 30/2/11, 1100, Wien, Austria

Phone: +43 664 8758864