GDPR Compliance

Effective Date: April 3, 2024

Principles of Data Processing

Under the GDPR, Compose adheres to the following principles when processing personal data:

Lawfulness, Fairness, and Transparency: Processing is lawful, fair, and transparent to the data subject.

  • Purpose Limitation: Data is collected for specified, explicit, and legitimate purposes and not further processed in a manner that is incompatible with those purposes.
  • Data Minimization: Collection of data is adequate, relevant, and limited to what is necessary in relation to the purposes for which they are processed.
  • Accuracy: Data is accurate and, where necessary, kept up to date.
  • Storage Limitation: Data is kept in a form that permits identification of data subjects for no longer than is necessary for the purposes for which the personal data are processed.
  • Integrity and Confidentiality: Processing is done in a manner that ensures appropriate security of the personal data, including protection against unauthorized or unlawful processing and against accidental loss, destruction, or damage.

Detailed Rights Under the GDPR

To provide further clarity, here are the rights afforded to individuals under the GDPR and the means to exercise them:

  • The Right to Access: You can request details about the personal data we hold about you and how we process it. Compose will provide a copy of the personal data, free of charge, in an electronic format.
  • The Right to Rectification: If your personal data is inaccurate or incomplete, you have the right to have it corrected. We will respond to your request within one month.
  • The Right to Erasure (Right to be Forgotten): You have the right to have your data erased from our systems, provided there are no legitimate grounds for retaining it.
  • The Right to Restrict Processing: You have the right to block or suppress processing of your personal data under certain conditions. When processing is restricted, we are permitted to store your data but not process it further.
  • The Right to Data Portability: You have the right to move, copy, or transfer personal data easily from one IT environment to another in a safe and secure way, without hindrance to usability.
  • The Right to Object: You have the right to object to processing based on legitimate interests, direct marketing (including profiling), and processing for purposes of scientific/historical research and statistics.
  • Rights in Relation to Automated Decision Making and Profiling: You have the right not to be subject to a decision based solely on automated processing, including profiling, which has legal effects concerning you or similarly significantly affects you.

Exercising Your Rights

To exercise any of these rights, please contact us at [Insert Contact Details]. We may need to request specific information from you to help us confirm your identity and ensure your right to access the information (or to exercise any of your other rights). This is a security measure to ensure that personal data is not disclosed to any person who has no right to receive it.

Data Protection Officer (DPO)

Our Data Protection Officer oversees compliance with the GDPR. For any questions related to the processing of your personal data, exercising your rights under the GDPR, or for more information, please contact our DPO at [Insert DPO Contact Information].

International Transfers

Compose ensures that when personal data is transferred outside the EU, it remains protected and transferred in a manner consistent with legal requirements. Detailed information on the mechanisms in place for such transfers is available upon request.

Data Breach Notification

In compliance with the GDPR, Compose has implemented robust breach detection, investigation, and reporting procedures. We are committed to notifying the relevant supervisory authority of any data breach within 72 hours of becoming aware of it, unless the breach is unlikely to result in a risk to the rights and freedoms of individuals. When the breach is likely to result in a high risk to your rights and freedoms, we will also communicate the breach to the affected data subjects without undue delay.

Role of Data Processors

Compose engages with various third-party service providers and partners who act as data processors on our behalf. These processors are only permitted to process personal data in accordance with our documented instructions, under a binding contractual agreement that ensures the confidentiality, integrity, and availability of personal data. We conduct due diligence on all our data processors to ensure their compliance with the GDPR and other relevant data protection laws.

Data Protection Impact Assessments (DPIAs)

For any new projects or technologies that are likely to result in a high risk to the privacy rights of individuals, Compose conducts Data Protection Impact Assessments. These assessments help identify and minimize the data protection risks of a project. DPIAs include a systematic description of the envisaged processing operations, an assessment of the necessity and proportionality of the processing in relation to the purposes, an assessment of the risks to the rights and freedoms of data subjects, and the measures to address these risks.

Automated Individual Decision-Making, Including Profiling

Compose does not use personal data for automated decision-making or profiling that produces legal effects concerning data subjects or similarly significantly affects them. If these practices are adopted in the future, affected individuals will be provided with information about the logic involved, as well as the significance and the envisaged consequences of such processing for them. Individuals will also be afforded rights to obtain human intervention, express their point of view, and contest the decision.

Updates to Our Privacy Policy

We will update our Privacy Policy to reflect changes in our data processing practices or in response to legal requirements. When we make significant changes, we will notify you through our platform or other means, such as email, and will also indicate the date the last changes were published on our Privacy Policy.

Lodging A Complaint

If you have any concerns or complaints about how we process your personal data, we kindly ask you to contact us. However, you have the right to lodge a complaint directly with the supervisory authority in your country.

Contacting Us

If you have any questions about this GDPR Compliance section, our data protection practices, or your dealings with Compose, please contact our Data Protection Officer at:

hello@compose.co