GDPR Compliance

GDPR Compliance

General Data Protection Regulation

Sponkly is fully compliant with the European Union's General Data Protection Regulation (GDPR). Your privacy and data rights are our priority.

Your Rights Under GDPR

Right of Access

You have the right to know what personal data we hold about you and obtain a copy of it.

Request your data via email to [email protected]

Right to Rectification

You have the right to request correction of inaccurate or incomplete personal data.

Update your information in Account Settings or contact us

Right to Erasure (Right to be Forgotten)

You have the right to request deletion of your personal data under certain conditions.

Delete your account in Settings or contact us

Right to Restriction of Processing

You have the right to request that we limit how we use your personal data.

Contact us to request processing restrictions

Right to Data Portability

You have the right to receive your personal data in a structured, commonly used format and transfer it to another service.

Export your data from Account Settings

Right to Object

You have the right to object to processing of your personal data for direct marketing or other purposes.

Manage preferences in Account Settings

Rights Related to Automated Decision Making

You have the right not to be subject to decisions based solely on automated processing, including profiling.

We don't use automated decision-making that affects you significantly

Legal Basis for Processing

Under GDPR, we process your personal data based on the following legal grounds:

Consent: When you explicitly agree to data processing (e.g., marketing emails)
Contract Performance: To provide our services as per our agreement with you
Legal Obligation: To comply with laws and regulations (e.g., tax records)
Legitimate Interests: For business operations that don't override your rights (e.g., fraud prevention)
Vital Interests: To protect life or physical safety in emergency situations

Data Protection Officer

We have appointed a Data Protection Officer (DPO) to oversee our GDPR compliance. You can contact our DPO with any questions or concerns about how we handle your data.

Contact Our DPO:

Email: [email protected]

Response Time: Within 30 days

International Data Transfers

When transferring data outside the European Economic Area (EEA), we ensure adequate protection:

EU Standard Contractual Clauses (SCCs) are in place with all non-EU processors
We work with providers that have EU-US Data Privacy Framework certification
Additional security measures including encryption and access controls
Regular audits of third-party data processors
Transparent documentation of all data transfer mechanisms

Filing a Complaint

You have the right to lodge a complaint with a supervisory authority if you believe we have not complied with GDPR requirements.

Steps to File a Complaint:

  1. Contact us first to try to resolve the issue
  2. If unresolved, contact your local data protection authority
  3. Provide details of your concern and any relevant documentation

EU Supervisory Authorities: You can find your local authority at EDPB Member List

Exercise Your Rights

To exercise any of your GDPR rights, please contact us:

Email: [email protected] or [email protected]

Mail: AtaForge, Inc., 1111B S Governors Ave STE 80322, Dover, DE 19904, USA

Response Time: We will respond to all requests within 30 days

Note: We may need to verify your identity before processing your request to ensure data security.