GDPR Compliance Statement
This statement explains how Khalid Aboubakr and Sigmantic Digital Technology comply with the EU General Data Protection Regulation 2016/679 and the UK GDPR across every product we operate — websites, mobile applications, SaaS platforms, customer portals, dashboards, APIs, and any other digital service we may offer in the future. It is intended to be plain enough for end users to understand and complete enough for procurement, audit, and supervisory-authority review.
Controller and processor roles
Our role under the GDPR depends on the nature of the service:
- Data controller
- For visitor and prospect data on our marketing websites, account-level data of our direct customers, and corporate communications, Sigmantic Digital Technology (operated under Khalid Aboubakr) acts as the data controller and determines purposes and means of processing.
- Data processor
- When we operate SaaS platforms, mobile applications, or operational tools on behalf of a customer organization that uploads or generates personal data into those platforms, we act as a processor following that customer organization's documented instructions.
- Joint controller
- In limited integration scenarios, we may share controllership with a partner. Where this occurs, the responsibilities of each party are documented in a Joint Controller arrangement.
Lawful basis for processing
Every processing activity is justified by one of the lawful bases set out in Article 6 of the GDPR:
- Contract (Art. 6(1)(b)) — when processing is necessary to deliver a service you or your organization have engaged us to provide, including authentication, data persistence, billing, and support.
- Legitimate interests (Art. 6(1)(f)) — when we operate fraud detection, security monitoring, abuse prevention, and aggregate product analytics that benefit you and us, balanced against your rights and freedoms.
- Legal obligation (Art. 6(1)(c)) — when we are required to retain records to comply with tax, accounting, or other regulations.
- Consent (Art. 6(1)(a)) — when you opt in to optional features such as marketing communications, optional analytics, or location-aware workflows. You may withdraw consent at any time.
- Vital interests / public task — only in narrow cases (e.g. urgent security incidents) where applicable.
Special-category and sensitive data
We do not solicit special-category data (Article 9) as a routine part of our operations. Where a customer organization uploads or generates such data within a platform we operate on their behalf, processing is performed strictly under their instructions and confined to access-controlled environments. We require customers to satisfy the corresponding Article 9 conditions before introducing such data into our systems.
Right of access
You have the right to confirm whether we process personal data about you and to obtain a copy of that data, together with information about the purposes, recipients, and retention periods. Verified access requests are fulfilled within 30 days, with one possible 60-day extension for complex cases as permitted by Article 12(3).
Right to rectification
You may correct inaccurate personal data or complete information that is incomplete. Most fields can be edited directly within your account; for fields you cannot edit yourself, contact us and we will reflect verified corrections without undue delay.
Right to erasure
Subject to limited exceptions (such as records we must retain for tax or legal-defense purposes), you may request deletion of personal data we hold about you. Use our Data Deletion Request page to submit a verified request. We will confirm receipt and, after identity verification, complete the deletion within the timeframe required by applicable law.
Right to restrict or object to processing
- You may request that we restrict processing while we verify the accuracy of disputed data, while you await a response to an objection, or where processing is unlawful but you prefer restriction over deletion.
- You may object to processing based on legitimate interests where your particular circumstances warrant. We will reassess the balancing test and cease processing unless we demonstrate compelling overriding legitimate grounds.
- You may object to direct marketing at any time. We will stop without further conditions.
Right to data portability
For data you have provided to us where processing is based on consent or contract and is carried out by automated means, you may receive that data in a structured, commonly used, machine-readable format (JSON or CSV) and, where technically feasible, request transmission directly to another controller.
Withdrawal of consent
Where processing is based on consent, you may withdraw it at any time through your account settings, by following the unsubscribe link in any marketing email, or by contacting us. Withdrawal does not affect the lawfulness of processing performed before withdrawal.
Retention transparency
Retention periods for every category of data we process — including authentication logs, audit logs, operational records, uploaded files, support communications, inactive accounts, and platform activity records — are documented in our Data Retention Policy. Where deletion is not immediate, data is moved into a sealed retention state with no business access and is then purged in accordance with the schedule.
Sub-processors and engagements
We engage carefully selected sub-processors — typically cloud hosting providers, push notification gateways, email delivery services, and platform monitoring tools. Every sub-processor is bound by a written agreement requiring them to:
- Process personal data only on our documented instructions.
- Apply technical and organizational measures appropriate to the risk.
- Restrict access to personnel under confidentiality obligations.
- Support our obligations to assist data-subject requests and incident notifications.
A current list of our material sub-processors is available on request. We notify customers of material additions before they take effect, giving a reasonable opportunity to object.
International transfers
Where personal data originating in the EEA or the UK is transferred to a third country that has not received an adequacy decision, we rely on the European Commission Standard Contractual Clauses (Module 2 or Module 3 as appropriate) and the UK International Data Transfer Addendum, supplemented by transfer impact assessments and additional safeguards where required.
Personal data breach procedures
We maintain documented incident-response procedures aligned with Articles 33 and 34. In the event of a personal data breach likely to result in a risk to data subjects, we will notify the relevant supervisory authority within 72 hours of becoming aware, and notify affected data subjects without undue delay where the risk is high. We retain breach records sufficient for the supervisory authority to verify compliance.
Representative & supervisory authority
You retain the right to lodge a complaint with the supervisory authority in your country of residence, work, or where the alleged infringement occurred. We will cooperate fully with any inquiry. Where required by Article 27, we will designate an EU or UK representative and publish their contact details in this section.
GDPR contact
To submit a request, raise a concern, or escalate a privacy matter, contact us at contact@khalidaboubakr.com with the subject line "GDPR Request". Please include sufficient information to allow us to verify your identity and locate your account.
Have a privacy or compliance question?
Reach out for a formal response within a few business days.