GDPR Compliance Statement

Last Updated: Oct 25, 2025

Welcome to Alpha Geeks LLC (“we”, “us”, or “our”). This statement explains how we approach data protection under the EU / EEA’s General Data Protection Regulation (GDPR). It outlines our commitments, how we process personal data for individuals in the EU/EEA, and your rights under GDPR.

1. Applicability

The GDPR applies if we process the personal data of individuals located in the EU and / or EEA — regardless of our physical location. If you are based in the EU/EEA and interact with us (through our website, as a prospect or client), this policy informs how we comply. 

2. Data Controller and Data Processor

  • We act as Data Controller for the personal data we collect via our website or from our clients.
  • For any third-party services or tools we engage, we ensure they act either as Data Processors under contract with us, or as independent Controllers if they determine their own processing.
  • We maintain records of our processing activities and our relationships with processors in line with Article 30 of GDPR. 

 

3. Lawful Basis for Processing

We process personal data only where we have one or more lawful bases under GDPR (Article 6):

  • Consent – you have given clear permission for processing for one or more specific purposes.
  • Contract – processing is necessary for a contract you have with us, or because you asked us to take specific steps before entering into a contract.
  • Legal obligation – processing is necessary for us to comply with a legal obligation.
  • Legitimate interests – we have a legitimate interest (or those of a third party) that is not overridden by your rights or freedoms. 
  • We document the lawful basis for each processing activity we undertake.

4. Data Subject Rights

If you are an individual in the EU/EEA whose personal data we process, you have the following rights under GDPR:

  • The right to access your personal data and obtain information about how we process it.
  • The right to rectify any inaccurate personal data we hold.
  • The right to erase your personal data (the “right to be forgotten”), where applicable.
  • The right to restrict processing of your personal data in certain circumstances.
  • The right to object to processing (including profiling or marketing-related processing).
  • The right to data portability (receive your personal data in a structured, commonly used format, or ask us to transfer it to another controller) when applicable.
  • The right to withdraw consent at any time where processing is based on consent, without affecting the lawfulness of processing before withdrawal.
    We respond to any such requests in accordance with GDPR timelines and obligations.

5. Data Protection by Design and by Default

We embed the principles of data protection into our operations, including:

  • Minimising the personal data we collect and use.
  • Ensuring data is processed only for the specified purpose(s).
  • Pseudonymising or anonymising data where feasible.
  • Restricting internal access to personal data to only those who need it.
  • Regularly reviewing our systems, processes and third-party relationships for data protection impact.

6. Data Security

We implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk, including:

  • Encryption of data in transit and at rest (where required).
  • Access controls, two-factor authentication, strong passwords and internal logging.
  • Regular vulnerability scanning, audits and monitoring.
  • Incident response processes and breach notification plans.

7. Data Breach Notification

In the event of a personal data breach that is likely to result in a risk to the rights and freedoms of individuals, we will:

  • Notify the relevant supervisory authority without undue delay, and where feasible within 72 hours.
  • Notify the affected individuals without undue delay when required by law.
    Our internal procedures ensure timely detection, containment, investigation and remediation of any breaches.

8. International Data Transfers

Because we may store, process, or access personal data in jurisdictions outside the EU/EEA (including but not limited to Pakistan, the United States), we ensure that appropriate safeguards are in place, such as:

  • Standard contractual clauses approved by the European Commission, or
  • Other lawful transfer mechanisms accepted under GDPR.
    By using our services or providing data to us, you consent to these transfers under the terms outlined.

9. Processing by Third-Party Service Providers

We engage third-party service providers (hosters, analytics, marketing tools) who may have access to personal data. We conduct due diligence and contractually require them to implement adequate safeguards, confidentiality, and to process data only in accordance with our instructions.

10. Data Retention

We retain personal data no longer than is necessary for the purpose for which it was collected, subject to legal, regulatory or contractual requirements. We review retention periods regularly and securely dispose of or anonymise data when it is no longer needed.

11. Records of Processing & Audits

We maintain a Record of Processing Activities (ROPA) documenting:

  • Categories of data processed;
  • Purposes of processing;
  • Categories of recipients;
  • Retention periods;
  • International transfers
    These records support our accountability obligations under Article 30.

12. Appointment of Data Protection Officer (DPO)

If required by applicable law or if we determine the need internally — for example where large-scale processing is involved — we may appoint a Data Protection Officer (DPO) or external advisor. You may contact the DPO or our privacy team at the contact details provided below.

13. Audits, Reviews & Updates

We review our data protection policies, procedures, and third-party relationships at least annually (and sooner when there are significant changes) to ensure ongoing compliance with GDPR and evolving industry best practices.

14. Your Consent and Withdrawal

Where we rely on consent as a lawful basis, you may withdraw that consent at any time by contacting us or via provided opt-out tools. Withdrawal will not affect the lawfulness of processing carried out before the withdrawal.

15. Contact Us

If you have any questions, requests or concerns about our GDPR compliance, how we process your personal data, or wish to exercise your rights, please contact:

Alpha Geeks LLC

Email: info@alphageeksllc.com