GDPR

GDPR Statement

General Data Protection Regulation (GDPR) came into effecton May 25, 2018 with the objective of strengthening and harmonizing data protection requirements across the European Union. GDPR imposes obligations onorganizations that act as controllers or processors of personal data of individuals located in the European Economic Area.

Team Cymru is dedicated to safeguarding personal information under our remit and maintaining a data protection program designed to support compliance with applicable data protection laws, including the GDPR where itapplies to our activities.

At Team Cymru, we understand the importance of your personal data, and we take steps to secure and protect it whenever it is stored in our infrastructure.

Depending on the context, Team Cymru may act as either a data controller or a data processor. Team Cymru generally acts as a controller when it determines the purposes and means of processing personal data in connection with its websites, commercial offerings and services, business operations, customer and partner relationships, marketing activities, account administration, security monitoring, and related commercial activities. Team Cymru may act as a processor when it processes personal data on behalf of a customer or partner in accordance with applicable contractual obligations.

Where Team Cymru acts as a processor, we process personal data in accordance with the applicable customer agreement, data processing agreement, or other written instructions. We maintain contractual, administrative, technical, and organizational safeguards designed to supportthe confidentiality, integrity, and security of personal data processed on behalf of customers.

Team Cymru periodically reviews how relevant services and business operations collect, use, store, transfer, and dispose of personal data, including account data, business-contact data, logs, telemetry, network data, and other data processed in connection with our services, subject to applicable law and contractual obligations. Team Cymru maintains policies, standards, governance processes, and documentation designed to support applicable GDPR obligations.

Compliance with the GDPR requires a shared responsibilitybetween Team Cymru and our partners and customers to safeguard and protect personal data. In many customer-service contexts, Team Cymru’s customers orpartners may act as controllers, and Team Cymru may act as a processor. In other contexts, Team Cymru may act as an independent controller.

Working together, we hope to explore opportunities within our relevant service offerings to assist our partners and customers meet their GDPR obligations. In the meantime, Team Cymru encourages partners and customers to independently familiarize themselves with the GDPR.

Customers and partners are responsible for determining their own GDPR obligations, including the lawful basis for processing personal data they provide to or make available through Team Cymru’s services.

Team Cymru maintains administrative, technical, and organizational measures designed to protect personal data against unauthorized access, disclosure, alteration, and destruction. These measures may include access controls, multi-factor authentication, logging and monitoring, physical security controls, encryption, incident response processes, and other safeguards appropriate to the nature of the data and processing activities.

Where required by applicable law or contract, Team Cymru assists customers with reasonable requests relating to data subject rights, security measures, breach notification, and other GDPR-related obligations.

Individuals may have rights under the GDPR, including rights to access, correct, delete, restrict, or object to certain processing of their personal data, and to request portability of their personal data, subject to applicable legal limitations. Individuals may submit privacy-related inquiriesor requests using the contact details provided in Team Cymru’s Privacy Policy.