GDPR Compliance

Last updated: April 1, 2026

Introduction

Abilytics is committed to protecting your personal data and respecting your privacy rights under the General Data Protection Regulation (GDPR). This GDPR Compliance statement explains how we collect, use, and protect your personal information in accordance with EU data protection laws.

1. Data Controller

Abilytics acts as the data controller for the personal data we collect and process. We are responsible for ensuring that your personal data is processed lawfully, fairly, and transparently.

Contact Information:

Abilytics

Email: letsconnect@abilytics.com

Data Protection Officer: dpo@abilytics.com

2. Legal Basis for Processing

We process your personal data under the following legal bases:

Consent: When you have given explicit consent for us to process your personal data for specific purposes (e.g., marketing communications).

Contract Performance: When processing is necessary to fulfill our contractual obligations to you.

Legal Obligation: When we are required by law to process your data.

Legitimate Interests: When processing is necessary for our legitimate business interests, provided these do not override your rights and freedoms.

3. Personal Data We Collect

We collect and process the following categories of personal data:

Identity Data: Name, username, title

Contact Data: Email address, phone number, postal address

Professional Data: Company name, job title, business information

Technical Data: IP address, browser type, device information, cookies

Usage Data: Information about how you use our website and services

Marketing Data: Your preferences for receiving communications from us

4. Your GDPR Rights

Under the GDPR, you have the following rights regarding your personal data:

Right to Access

You have the right to request a copy of the personal data we hold about you.

Right to Rectification

You have the right to request correction of inaccurate or incomplete personal data.

Right to Erasure

You have the right to request deletion of your personal data under certain circumstances.

Right to Restrict Processing

You have the right to request that we restrict the processing of your personal data under certain conditions.

Right to Data Portability

You have the right to receive your personal data in a structured, commonly used format and to transfer it to another controller.

Right to Object

You have the right to object to processing of your personal data based on legitimate interests or for direct marketing purposes.

Right to Withdraw Consent

Where processing is based on consent, you have the right to withdraw your consent at any time.

5. Data Retention

We retain your personal data only for as long as necessary to fulfill the purposes for which it was collected, including:

  • Meeting legal, accounting, or reporting requirements
  • Resolving disputes and enforcing agreements
  • Fulfilling contractual obligations

When personal data is no longer needed, we will securely delete or anonymize it.

6. Data Security

We implement appropriate technical and organizational measures to protect your personal data against:

  • Unauthorized or unlawful processing
  • Accidental loss, destruction, or damage
  • Unauthorized access or disclosure

Our security measures include encryption, access controls, regular security assessments, and staff training on data protection.

7. International Data Transfers

Your personal data may be transferred to and processed in countries outside the European Economic Area (EEA). When we transfer data internationally, we ensure appropriate safeguards are in place, including:

  • Standard Contractual Clauses approved by the European Commission
  • Adequacy decisions recognizing equivalent data protection standards
  • Binding Corporate Rules for intra-group transfers

8. Data Breach Notification

In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify:

  • The relevant supervisory authority within 72 hours of becoming aware
  • Affected individuals without undue delay if the breach poses a high risk

9. How to Exercise Your Rights

To exercise any of your GDPR rights, please contact us at:

Email: letsconnect@abilytics.com

Data Protection Officer: dpo@abilytics.com

We will respond to your request within one month. This period may be extended by two additional months where necessary, considering the complexity and number of requests.

10. Right to Lodge a Complaint

If you believe we have not complied with your data protection rights, you have the right to lodge a complaint with your local supervisory authority. Contact details for EU supervisory authorities can be found at:

https://edpb.europa.eu/about-edpb/board/members_en

11. Updates to This Statement

We may update this GDPR Compliance statement from time to time to reflect changes in our practices or legal requirements. We will notify you of any material changes by posting the updated statement on our website and updating the "Last Updated" date.