Our GDPR Commitment
Platemetrics is committed to complying with the General Data Protection Regulation (GDPR) for customers and data subjects in the European Union and United Kingdom. We implement technical and organizational measures to protect personal data and respect data subject rights.
Lawful Basis for Processing
We process personal data under the following lawful bases:
- Contract: To provide the Platemetrics platform services you've subscribed to
- Legitimate Interest: For analytics, fraud prevention, and service improvement
- Consent: For marketing communications (you can withdraw anytime)
- Legal Obligation: For tax, audit, and regulatory compliance
Your GDPR Rights
If you are in the EU/UK, you have the following rights:
- Right of Access: Request a copy of your personal data
- Right to Rectification: Correct inaccurate personal data
- Right to Erasure: Request deletion of your data ("right to be forgotten")
- Right to Restrict Processing: Limit how we use your data
- Right to Data Portability: Receive your data in machine-readable format
- Right to Object: Object to processing based on legitimate interest
- Right Not to Be Subject to Automated Decision-Making: We do not use automated decision-making that significantly affects you
To exercise any GDPR right, email privacy@platemetrics.in with subject "GDPR Request — [Right Name]". We respond within 30 days as required by GDPR.
Data Processing Agreement (DPA)
For EU/UK customers, Platemetrics acts as a Data Processor under a Data Processing Agreement. We provide a GDPR-compliant DPA upon request that includes:
- Standard Contractual Clauses (SCCs) for international data transfers
- Technical and organizational security measures (Annex II)
- Sub-processor list and notification procedures
- Data breach notification commitments (within 72 hours)
Request a DPA at compliance@platemetrics.in
International Data Transfers
Platemetrics primarily stores data in India (AWS ap-south-1). For transfers of EU/UK personal data outside the EEA, we rely on:
- Standard Contractual Clauses (SCCs) approved by the European Commission
- AWS's compliance with the EU-US Data Privacy Framework
Sub-Processors
We use the following sub-processors for EU/UK customer data:
- Amazon Web Services (AWS) — Cloud infrastructure, Mumbai & Ireland regions
- SendGrid (Twilio) — Transactional emails
- Stripe — Payment processing
We notify customers of sub-processor changes with 30 days notice.
Data Retention
Personal data is retained for the duration of your subscription plus 30 days. Upon request, we can delete data sooner (subject to legal retention requirements).
Contact Our DPO
Data Protection Officer: dpo@platemetrics.in
You also have the right to lodge a complaint with your local Data Protection Authority.