GDPR Compliance

Your rights and our commitment to data protection

Your Rights Under GDPR

The General Data Protection Regulation gives you specific rights regarding your personal data

Right to Access

You have the right to request copies of your personal data. We will provide you with a copy of the personal data we are processing about you.

Right to Rectification

You have the right to request that we correct any information you believe is inaccurate or incomplete.

Right to Erasure

You have the right to request that we erase your personal data, under certain conditions.

Right to Restrict Processing

You have the right to request that we restrict the processing of your personal data, under certain conditions.

Right to Object to Processing

You have the right to object to our processing of your personal data, under certain conditions.

Right to Data Portability

You have the right to request that we transfer the data that we have collected to another organization, or directly to you, under certain conditions.

How We Protect Your Data

Our commitment to keeping your personal information secure

Data Encryption

All data transmission is encrypted using industry-standard SSL/TLS protocols. Sensitive data is encrypted at rest using AES-256 encryption.

Access Controls

Access to personal data is restricted to authorized personnel only, and all access is logged and monitored.

Regular Security Audits

We conduct regular security assessments and penetration testing to identify and address potential vulnerabilities.

Data Minimization

We only collect and process the minimum amount of personal data necessary to provide our services.

Data Processing Lawful Basis

We process your personal data under the following lawful bases

Contract Performance

We process your data to fulfill our contractual obligations, such as processing orders and providing customer support.

Legitimate Interest

We process certain data based on our legitimate interest in improving our services, preventing fraud, and maintaining security.

Consent

For marketing communications and non-essential cookies, we rely on your explicit consent.

Legal Obligation

We may process data to comply with legal requirements, such as tax obligations or regulatory compliance.

Exercising Your Rights

How to contact us regarding your data protection rights

Contact Information

To exercise any of your rights under GDPR, please contact us:

  • Email: privacy@forgelogbooks.com
  • Subject line: "GDPR Data Request"
  • Include your full name and email address
  • Specify which right you wish to exercise

Response Time

We will respond to your request within 30 days of receiving it. For complex requests, we may extend this period by up to 60 additional days, and we will inform you of any delay.

Identity Verification

To protect your privacy and security, we may need to verify your identity before processing your request.

Data Retention

How long we keep your personal data

Account Data

We retain your account information for as long as your account is active or as needed to provide services to you.

Order Data

Order information is retained for 7 years to comply with tax and accounting requirements.

Marketing Data

Marketing consent and preferences are retained until you withdraw consent or request deletion.

Log Data

Server logs and analytics data are typically retained for 12 months unless longer retention is required for security purposes.

Data Transfers

International data transfers and safeguards

Third-Party Services

We use third-party services (such as payment processors and email services) that may process your data. These services are GDPR-compliant and have appropriate safeguards in place.

Adequacy Decisions

Where possible, we transfer data to countries with adequacy decisions from the European Commission.

Standard Contractual Clauses

For transfers to countries without adequacy decisions, we use Standard Contractual Clauses approved by the European Commission.

Supervisory Authority

Your right to lodge a complaint

You have the right to lodge a complaint with a supervisory authority if you believe that our processing of your personal data violates GDPR. You can contact your local data protection authority or the supervisory authority in the country where you live or work.