Golden Arrow Technologies is committed to operating in accordance with applicable European Union legislation and regulatory standards where required. This EU Policy outlines our approach to compliance with EU data protection, digital services and cross-border regulatory obligations.

1. Scope of This Policy

This policy applies where Golden Arrow Technologies processes personal data of individuals located within the European Union or provides services subject to EU regulatory frameworks.

2. GDPR Compliance

Where applicable, we process personal data in accordance with the General Data Protection Regulation (EU) 2016/679. We adhere to the core principles of:

  • Lawfulness, fairness and transparency
  • Purpose limitation
  • Data minimisation
  • Accuracy
  • Storage limitation
  • Integrity and confidentiality
  • Accountability

We ensure that personal data is processed only where a lawful basis exists, including contractual necessity, legitimate interests, legal obligation or consent where required.

3. Data Subject Rights

Where EU GDPR applies, individuals located in the EU have the right to:

  • Access their personal data
  • Request rectification of inaccurate information
  • Request erasure in certain circumstances
  • Restrict or object to processing
  • Request data portability
  • Withdraw consent where processing is based on consent

Requests relating to these rights will be handled in accordance with GDPR requirements and within statutory timeframes.

4. Cross Border Data Transfers

Where personal data is transferred outside the European Economic Area, we implement appropriate safeguards to ensure equivalent levels of protection. These safeguards may include:

  • European Commission adequacy decisions
  • Standard Contractual Clauses
  • Other approved transfer mechanisms

5. Data Security Measures

We implement appropriate technical and organisational security measures designed to protect EU personal data from unauthorised access, alteration, disclosure or destruction. Security controls are regularly reviewed and updated where necessary.

6. Data Breach Procedures

In the event of a personal data breach affecting EU data subjects, we will assess the risk and, where required, notify the relevant supervisory authority within 72 hours. Affected individuals will be informed where there is a high risk to their rights and freedoms.

7. Third Party Processors

Where we engage third party processors to handle EU personal data, we ensure that appropriate data processing agreements are in place. These agreements require processors to comply with GDPR standards and maintain adequate security measures.

8. Record Keeping and Accountability

We maintain appropriate documentation and records of processing activities where required under GDPR. This supports transparency and demonstrates compliance with regulatory obligations.

9. Supervisory Authorities

Individuals located in the EU have the right to lodge a complaint with their local supervisory authority if they believe their data protection rights have been infringed.

10. Policy Updates

This EU Policy may be updated from time to time to reflect changes in legislation, regulatory guidance or operational practices. Updated versions will be published with a revised effective date.

11. Contact

For further information regarding our EU compliance practices, please contact Golden Arrow Technologies through our official communication channels.