Our Commitment to GDPR
Zen Rotterdam is committed to complying with the General Data Protection Regulation (GDPR), which governs how personal data must be handled within the European Economic Area. This page explains your rights and how we fulfil our obligations under this regulation.
Data Controller
Zen Rotterdam acts as the data controller for personal information collected through this website. As the data controller, we determine the purposes and means of processing your personal data and are responsible for ensuring compliance with GDPR requirements.
Contact details:
Zen Rotterdam
Storgata 42
0182 Oslo, Norway
Email: [email protected]
Your Rights Under GDPR
The GDPR provides you with the following rights regarding your personal data:
Right of Access
You have the right to request a copy of the personal data we hold about you. We will provide this information free of charge within 30 days of receiving your request.
Right to Rectification
If you believe any personal data we hold about you is inaccurate or incomplete, you have the right to request correction. We will make necessary updates promptly.
Right to Erasure
Also known as the "right to be forgotten," you may request deletion of your personal data in certain circumstances, such as when the data is no longer necessary for the purpose it was collected.
Right to Restrict Processing
You may request that we limit how we use your data while any issues are being resolved, such as when you contest the accuracy of your data.
Right to Data Portability
You have the right to receive your personal data in a structured, commonly used, and machine-readable format, and to transmit that data to another controller.
Right to Object
You may object to processing of your personal data for direct marketing purposes or when processing is based on legitimate interests.
Rights Related to Automated Decision-Making
You have the right not to be subject to decisions based solely on automated processing that significantly affect you. We do not currently use automated decision-making processes.
Lawful Basis for Processing
We process personal data only when we have a lawful basis to do so. The bases we rely upon include:
- Consent: When you have given explicit consent for specific purposes
- Contract: When processing is necessary to fulfil a contract with you
- Legal Obligation: When we are required to process data by law
- Legitimate Interests: When processing is necessary for our legitimate business interests, provided these do not override your fundamental rights
Data Protection Measures
We implement appropriate technical and organisational measures to protect personal data, including:
- Secure data storage with access controls
- Regular security assessments
- Staff training on data protection
- Data minimisation practices
- Encryption where appropriate
International Data Transfers
We primarily process data within the European Economic Area. If data is transferred outside the EEA, we ensure appropriate safeguards are in place as required by GDPR.
Data Breach Notification
In the event of a personal data breach that poses a risk to your rights and freedoms, we will notify the relevant supervisory authority within 72 hours. Where the breach is likely to result in a high risk to you, we will also notify you directly.
Exercising Your Rights
To exercise any of your GDPR rights, please contact us at [email protected]. We may need to verify your identity before processing your request. We will respond to all legitimate requests within 30 days.
Complaints
If you believe your data protection rights have been violated, you have the right to lodge a complaint with a supervisory authority. In Norway, the relevant authority is the Norwegian Data Protection Authority (Datatilsynet).
Updates to This Information
We may update this GDPR information from time to time to reflect changes in our practices or legal requirements. Please check this page periodically for updates.