What is GDPR?
The General Data Protection Regulation (GDPR) is a comprehensive data protection law enacted by the European Union in 2018. It gives EU citizens greater control over their personal data and requires organizations to implement strong data protection measures.
Your Rights Under GDPR
As a user in the EU, you have the following rights:
Right to Access
Request copies of your personal data
Right to Rectification
Correct inaccurate personal data
Right to Erasure
Request deletion of your data ("right to be forgotten")
Right to Data Portability
Receive your data in machine-readable format
Right to Object
Object to processing of your data
Right to Restriction
Request restriction of data processing
How We Comply with GDPR
1. Legal Basis for Processing
We process personal data based on:
- Contractual Necessity: To provide monitoring services you subscribed to
- Legitimate Interest: For service improvement and fraud prevention
- Legal Obligation: For compliance with laws and regulations
- Consent: For marketing communications (you can opt out anytime)
2. Data Minimization
We only collect data that is necessary for providing our monitoring services. We do not collect excessive or irrelevant information.
3. Data Security
- 256-bit SSL/TLS encryption for all data transmission
- AES-256 encryption for data at rest
- Regular security audits and penetration testing
- Access controls and authentication requirements
- Data breach notification within 72 hours (as required by GDPR)
4. Data Retention
We retain personal data only as long as necessary:
- Monitored data: Deleted 30 days after subscription ends
- Account data: Retained for legal compliance (up to 7 years for tax/financial records)
- Marketing data: Retained until you opt out or request deletion
5. Third-Party Processors
We work with GDPR-compliant third parties:
- Cloud hosting providers (AWS, Google Cloud - GDPR certified)
- Payment processors (Stripe, PayPal - GDPR compliant)
- All processors have signed Data Processing Agreements (DPAs)
6. International Data Transfers
If data is transferred outside the EU, we ensure adequate protection through:
- Standard Contractual Clauses (SCCs) approved by EU Commission
- Processing in GDPR-compliant data centers
- Privacy Shield certification (where applicable)
How to Exercise Your Rights
To exercise any of your GDPR rights:
- Email: gdpr@ultimatephonespy.com
- Support Portal: Submit a Request
- Response time: Within 30 days (as required by GDPR)
Data Protection Officer (DPO)
Our Data Protection Officer oversees GDPR compliance:
- Email: dpo@ultimatephonespy.com
- Available for privacy concerns and data protection queries
Supervisory Authority
You have the right to lodge a complaint with your local data protection authority if you believe we have not complied with GDPR.
Cookies and Tracking
We use minimal cookies:
- Essential Cookies: Required for login and security (no consent needed)
- Analytics Cookies: Only with your consent (can be disabled)
- No advertising or third-party tracking cookies
Updates to This Policy
We will notify you of any material changes to our GDPR compliance practices via email and dashboard notification.