Golden Arrow Technologies is committed to operating in accordance with applicable European Union legislation and regulatory standards where required. This EU Policy outlines our approach to compliance with EU data protection, digital services and cross-border regulatory obligations.
1. Scope of This Policy
This policy applies where Golden Arrow Technologies processes personal data of individuals located within the European Union or provides services subject to EU regulatory frameworks.
2. GDPR Compliance
Where applicable, we process personal data in accordance with the General Data Protection Regulation (EU) 2016/679. We adhere to the core principles of:
- Lawfulness, fairness and transparency
- Purpose limitation
- Data minimisation
- Accuracy
- Storage limitation
- Integrity and confidentiality
- Accountability
We ensure that personal data is processed only where a lawful basis exists, including contractual necessity, legitimate interests, legal obligation or consent where required.
3. Data Subject Rights
Where EU GDPR applies, individuals located in the EU have the right to:
- Access their personal data
- Request rectification of inaccurate information
- Request erasure in certain circumstances
- Restrict or object to processing
- Request data portability
- Withdraw consent where processing is based on consent
Requests relating to these rights will be handled in accordance with GDPR requirements and within statutory timeframes.
4. Cross Border Data Transfers
Where personal data is transferred outside the European Economic Area, we implement appropriate safeguards to ensure equivalent levels of protection. These safeguards may include:
- European Commission adequacy decisions
- Standard Contractual Clauses
- Other approved transfer mechanisms
5. Data Security Measures
We implement appropriate technical and organisational security measures designed to protect EU personal data from unauthorised access, alteration, disclosure or destruction. Security controls are regularly reviewed and updated where necessary.
6. Data Breach Procedures
In the event of a personal data breach affecting EU data subjects, we will assess the risk and, where required, notify the relevant supervisory authority within 72 hours. Affected individuals will be informed where there is a high risk to their rights and freedoms.
7. Third Party Processors
Where we engage third party processors to handle EU personal data, we ensure that appropriate data processing agreements are in place. These agreements require processors to comply with GDPR standards and maintain adequate security measures.
8. Record Keeping and Accountability
We maintain appropriate documentation and records of processing activities where required under GDPR. This supports transparency and demonstrates compliance with regulatory obligations.
9. Supervisory Authorities
Individuals located in the EU have the right to lodge a complaint with their local supervisory authority if they believe their data protection rights have been infringed.
10. Policy Updates
This EU Policy may be updated from time to time to reflect changes in legislation, regulatory guidance or operational practices. Updated versions will be published with a revised effective date.
11. Contact
For further information regarding our EU compliance practices, please contact Golden Arrow Technologies through our official communication channels.
