Information on this site is advertising in nature

Our Commitment to GDPR

Zen Rotterdam is committed to complying with the General Data Protection Regulation (GDPR), which governs how personal data must be handled within the European Economic Area. This page explains your rights and how we fulfil our obligations under this regulation.

Data Controller

Zen Rotterdam acts as the data controller for personal information collected through this website. As the data controller, we determine the purposes and means of processing your personal data and are responsible for ensuring compliance with GDPR requirements.

Contact details:
Zen Rotterdam
Storgata 42
0182 Oslo, Norway
Email: [email protected]

Your Rights Under GDPR

The GDPR provides you with the following rights regarding your personal data:

Right of Access

You have the right to request a copy of the personal data we hold about you. We will provide this information free of charge within 30 days of receiving your request.

Right to Rectification

If you believe any personal data we hold about you is inaccurate or incomplete, you have the right to request correction. We will make necessary updates promptly.

Right to Erasure

Also known as the "right to be forgotten," you may request deletion of your personal data in certain circumstances, such as when the data is no longer necessary for the purpose it was collected.

Right to Restrict Processing

You may request that we limit how we use your data while any issues are being resolved, such as when you contest the accuracy of your data.

Right to Data Portability

You have the right to receive your personal data in a structured, commonly used, and machine-readable format, and to transmit that data to another controller.

Right to Object

You may object to processing of your personal data for direct marketing purposes or when processing is based on legitimate interests.

Rights Related to Automated Decision-Making

You have the right not to be subject to decisions based solely on automated processing that significantly affect you. We do not currently use automated decision-making processes.

Lawful Basis for Processing

We process personal data only when we have a lawful basis to do so. The bases we rely upon include:

  • Consent: When you have given explicit consent for specific purposes
  • Contract: When processing is necessary to fulfil a contract with you
  • Legal Obligation: When we are required to process data by law
  • Legitimate Interests: When processing is necessary for our legitimate business interests, provided these do not override your fundamental rights

Data Protection Measures

We implement appropriate technical and organisational measures to protect personal data, including:

  • Secure data storage with access controls
  • Regular security assessments
  • Staff training on data protection
  • Data minimisation practices
  • Encryption where appropriate

International Data Transfers

We primarily process data within the European Economic Area. If data is transferred outside the EEA, we ensure appropriate safeguards are in place as required by GDPR.

Data Breach Notification

In the event of a personal data breach that poses a risk to your rights and freedoms, we will notify the relevant supervisory authority within 72 hours. Where the breach is likely to result in a high risk to you, we will also notify you directly.

Exercising Your Rights

To exercise any of your GDPR rights, please contact us at [email protected]. We may need to verify your identity before processing your request. We will respond to all legitimate requests within 30 days.

Complaints

If you believe your data protection rights have been violated, you have the right to lodge a complaint with a supervisory authority. In Norway, the relevant authority is the Norwegian Data Protection Authority (Datatilsynet).

Updates to This Information

We may update this GDPR information from time to time to reflect changes in our practices or legal requirements. Please check this page periodically for updates.