Data Processing Policy
1. Introduction
This Data Processing Policy describes how aifininsighthub collects, uses, stores, and protects users' personal data in accordance with applicable data protection legislation. We undertake to process your personal data responsibly and transparently.
This policy supplements our Privacy Policy and provides more detailed information about specific aspects of data processing, including legal bases for processing, storage periods, and your rights regarding your data.
2. Legal Bases for Processing
We process your personal data based on the following legal bases:
Consent
When you provide explicit consent to process your personal data for specific purposes, such as subscribing to newsletters or using certain site features. You can withdraw your consent at any time.
Contract Performance
When data processing is necessary to perform a contract to which you are a party, or to take measures at your request before concluding a contract, for example, when processing your request through a contact form.
Legitimate Interests
When processing is necessary for our legitimate interests or the interests of third parties, such as ensuring site security, improving our services, conducting analytics, or preventing fraud. We always balance our interests with your rights and freedoms.
Legal Obligations
When processing is necessary to comply with legal obligations to which we are subject, such as tax law requirements or requests from law enforcement agencies.
3. Categories of Processed Data
We process the following categories of personal data:
Identification Data
First name, last name, email address, phone number, which you provide when filling out forms on the site or when contacting us.
Technical Data
IP address, browser type, operating system, device information, data about visited pages, time and date of visit, sources of referral to the site.
Usage Data
Information about how you use our site, including preferences, settings, interaction with various interface elements.
Communication Data
Content of messages that you send to us through contact forms, email, or other communication channels.
4. Data Processing Processes
We apply the following data processing processes:
Data Collection
Data is collected directly from you when you provide it through forms on the site, as well as automatically through tracking technologies such as cookies and server logs.
Data Storage
Data is stored on secure servers using modern encryption and access control technologies. We use both local servers and cloud services that meet strict security standards.
Data Usage
Data is used to provide requested services, improve site functionality, conduct analytics, ensure security, and communicate with users.
Data Deletion
Data is deleted after the storage period established for each data category expires, or upon receiving a deletion request from the user, if this does not contradict legal obligations.
5. Data Storage Periods
We store personal data only for the period necessary to achieve the purposes for which they were collected, or for the period established by applicable law:
- Data collected through contact forms is stored for three years from the last contact
- Technical data and server logs are stored for one year
- Data related to legal obligations may be stored for a longer period in accordance with legal requirements
- Data processed based on consent is stored until consent is withdrawn or the processing purpose is achieved
After the storage period expires, data is automatically deleted or anonymized in a secure manner.
6. Security Measures
We apply comprehensive technical and organizational measures to protect your personal data:
- Data encryption during transmission using SSL/TLS protocols
- Data encryption at rest for sensitive information
- Regular security system updates and patch application
- Restricting data access to authorized employees only based on the principle of least privilege
- Regular data backups with integrity verification
- Monitoring systems for suspicious activity
- Conducting regular security audits and risk assessments
- Training employees on data protection and privacy issues
7. Data Transfer Outside Jurisdiction
In some cases, we may transfer your personal data to countries outside your jurisdiction. In such cases, we ensure that data recipients apply appropriate protection measures equivalent to those provided by applicable data protection legislation.
We use standard contractual clauses and other legal mechanisms to ensure data protection during international transfers.
8. Automated Decision-Making
Currently, we do not use fully automated decision-making processes, including profiling, that have legal consequences for you or significantly affect you.
If in the future we begin to use such processes, we will notify you and provide information about the logic, significance, and expected consequences of such processing, as well as your right not to be subject to fully automated decision-making.
9. Your Rights
In accordance with applicable data protection legislation, you have the following rights regarding your personal data:
- Right of access — obtain confirmation of whether your data is being processed and receive a copy of processed data
- Right to rectification — correct inaccurate or incomplete data
- Right to erasure — delete your data under certain circumstances
- Right to restriction of processing — restrict processing of your data under certain circumstances
- Right to data portability — receive your data in a structured format
- Right to object — object to data processing based on legitimate interests
- Right to withdraw consent — withdraw consent to data processing at any time
- Right to lodge a complaint — file a complaint with the data protection supervisory authority
10. Contact
If you have questions about our data processing or wish to exercise your rights, you can contact us:
Email: info@aifininsighthub.com
Phone: +1 (416) 823-4567
Address: 1234 Bay Street, Toronto, ON M5R 2A4, Canada
We strive to respond to all requests within 30 days of receiving the request.