At modenX, we’re committed to protecting your personal data and ensuring complete transparency in how we collect, use, and safeguard your information. Our GDPR compliance framework is designed not only to meet legal requirements but also to uphold the trust you place in us.
What is GDPR?
The General Data Protection Regulation (GDPR) is a comprehensive privacy and data protection law that governs how organisations handle the personal data of residents within the European Union.
Even if your business is based outside the EU, GDPR may still apply if you:
- Offer products or services to individuals in the EU, or
- Monitor the behaviour of individuals within the EU.
At modenX, we treat GDPR as a global standard – applying these principles across all our systems to ensure fairness, transparency, and control for every customer, regardless of location.
Your Responsibilities Under GDPR
As part of our shared commitment to data privacy, GDPR requires that personal data be:
- Processed lawfully, fairly, and transparently.
- Collected for specified, legitimate purposes and used accordingly.
- Limited to what is necessary and kept accurate and up to date.
- Stored only for as long as necessary.
- Protected against loss, misuse, or unauthorised access.
Organisations must also:
- Demonstrate compliance through clear documentation.
- Implement privacy by design and by default.
- Ensure third-party processors also comply with GDPR standards.
- Put safeguards in place when transferring data outside the EU.
We also apply Data Minimisation principles, i.e., collecting only what’s needed and nothing more.
What is Personal Data?
Under GDPR, personal data refers to any information that can identify an individual, directly or indirectly. This includes:
- Names, phone numbers, and email addresses;
- IP addresses, device identifiers, and location data;
- Online identifiers and behavioural patterns;
- Data relating to a person’s identity, such as cultural, economic, or physiological attributes.
Even if the data seems harmless (like an IP address), if it can identify a user, it is protected under GDPR.
Who Controls Your Data?
In most cases, modenX operates as the Processor, while you – the customer, is the Controller. This means you determine how data is used, and we act on your behalf to process it responsibly.
Key Rights Under GDPR
You have enhanced rights under GDPR, including:
- Right to Access – Request a copy of the personal data we hold about you.
- Right to Correction – Ask us to correct inaccurate or incomplete information.
- Right to Deletion (“Right to be Forgotten”) – Request removal of your data from our systems.
- Right to Restrict Processing – Ask us to limit how we use your personal data.
- Right to Object – Decline certain types of processing, including direct marketing.
- Right to Data Portability – Request your data in a machine-readable format for transfer.
- Right to Withdraw Consent – Change or withdraw your consent at any time.
To exercise any of these rights, simply email us at [email protected].
How ModenX Ensures GDPR Compliance
We’ve taken active steps to align every aspect of our platform with GDPR requirements:
- Company-Wide Awareness: Our teams are trained in data protection principles and handle data with care and accountability.
- Privacy by Design: Every feature in modenX is built with privacy at its core, offering you greater control over how data is collected and used.
- Internal Audits: We conduct regular assessments to ensure our processes, systems, and storage methods meet GDPR standards.
- Data Accuracy: We regularly cleanse our databases to remove outdated, dormant, or inactive accounts.
- Appointed Data Protection Officer (DPO): Oversees compliance, breach response, and privacy governance.
- Breach Notification Protocol: You’ll be notified within 72 hours if a data breach affecting you occurs, in accordance with GDPR requirements.
We also maintain Records of Processing Activities (RoPA) as required by Article 30 of the GDPR.
Marketing Campaigns & Consent
We ensure all marketing communications are consent-driven. You have full control over your preferences and can opt out at any time, easily and transparently.
Where cookies are used for tracking or analytics, modenX implements clear opt-in consent banners in accordance with GDPR and ePrivacy Directive standards.
Cross-Border Data Transfers
When transferring personal data outside the EU, we ensure that adequate safeguards are in place. These may include:
- Standard Contractual Clauses (SCCs)
- Transfer Impact Assessments (TIAs)
- Industry-accepted Frameworks, Where Applicable