1. Data Controller Context
For activities described on this site, FinFlexa acts as a data controller for personal data submitted or observed through website usage, comments, and cookie-controlled interactions.
2. GDPR Principles We Apply
- Lawfulness, fairness, and transparency.
- Purpose limitation for defined website and policy objectives.
- Data minimization to collect only relevant data.
- Accuracy and correction procedures.
- Storage limitation and retention controls.
- Integrity and confidentiality through reasonable safeguards.
- Accountability through policy documentation and process review.
3. Lawful Bases
Depending on context, we rely on consent, legitimate interests, contractual necessity, and legal obligation. For optional cookies, consent is the primary legal basis.
You can review and update optional processing in Cookie Preferences.
4. Data Subject Rights
Subject to legal limits and verification, eligible users may request:
- Access to personal data being processed.
- Rectification of inaccurate or incomplete data.
- Erasure in circumstances where retention is no longer required.
- Restriction of processing.
- Objection to processing under legitimate interests.
- Data portability for eligible processing activities.
- Withdrawal of consent where consent is the legal basis.
5. Request Handling Process
- Submit a request to legal@finflexa.com with enough detail to identify your request.
- We may request additional information to verify identity and prevent unauthorized disclosure.
- We aim to respond within one month, subject to extension where legally permitted.
- If a request is denied, we will provide reasons where required by law.
6. Processors and Third Parties
We may use third-party processors for hosting, analytics, moderation, advertising, security, and operational support. We seek contractual protections and practical security measures for such processing.
7. International Transfers
Where data is transferred outside applicable adequacy regions, we use safeguards such as contractual commitments and technical controls consistent with legal requirements.
8. Supervisory Authority Complaints
If you believe your data rights were not respected, you may lodge a complaint with your local data protection supervisory authority.
For wider privacy terms, see Privacy Policy.