Effective Date: November 17, 2025
Our Commitment to GDPR Compliance
Site.Rocks is committed to protecting your privacy and complying with the General Data Protection Regulation (GDPR), which came into effect on May 25, 2018. This page explains how we comply with GDPR requirements and protect your personal data.
What is GDPR?
The General Data Protection Regulation (GDPR) is a comprehensive data protection law that applies to all EU member states. It gives individuals more control over their personal data and requires organizations to be transparent about how they collect, use, and protect that data.
How We Comply with GDPR
1. Lawful Basis for Processing
We process your personal data based on the following lawful grounds:
- Consent: When you accept our cookie banner or register for an account, you provide explicit consent for data processing
- Legitimate Interest: We process data necessary to operate our website and improve our services
- Legal Obligation: We may process data to comply with legal requirements
- Contractual Necessity: Processing data necessary to provide our services to you
2. Data Minimization
We only collect and process the minimum amount of personal data necessary to provide our services. We do not collect excessive or irrelevant information.
3. Transparency
We are transparent about our data practices through:
- Clear and accessible Privacy Policy
- Detailed Cookie Policy
- Upfront cookie consent banner
- Regular communication about data processing activities
4. Your Rights Under GDPR
As a data subject under GDPR, you have the following rights:
Right to Access (Article 15)
You have the right to request a copy of all personal data we hold about you. We will provide this information in a commonly used electronic format.
Right to Rectification (Article 16)
You have the right to request correction of any inaccurate or incomplete personal data we hold about you.
Right to Erasure / "Right to be Forgotten" (Article 17)
You have the right to request deletion of your personal data in certain circumstances, including:
- When the data is no longer necessary for the purpose it was collected
- When you withdraw consent and there is no other legal basis for processing
- When you object to processing and there are no overriding legitimate grounds
- When the data has been unlawfully processed
Right to Restriction of Processing (Article 18)
You have the right to request that we limit how we use your personal data in certain situations, such as when you contest the accuracy of the data or object to processing.
Right to Data Portability (Article 20)
You have the right to receive your personal data in a structured, commonly used, and machine-readable format and to transmit that data to another controller.
Right to Object (Article 21)
You have the right to object to processing of your personal data based on legitimate interests or for direct marketing purposes.
Right to Not Be Subject to Automated Decision-Making (Article 22)
You have the right not to be subject to decisions based solely on automated processing, including profiling, which produces legal effects or significantly affects you.
5. How to Exercise Your Rights
To exercise any of your GDPR rights, you can:
- Contact us through our feedback form
- Send us an email with your request
- Manage your cookie preferences through your browser settings
- Access your account settings (if registered)
We will respond to your request within 30 days as required by GDPR. In complex cases, we may extend this period by an additional 60 days and will inform you of any such extension.
6. Data Security Measures
We implement appropriate technical and organizational measures to protect your personal data, including:
- SSL/TLS encryption for data transmission
- Secure server infrastructure
- Access controls and authentication
- Regular security assessments and updates
- Data backup and recovery procedures
- Staff training on data protection
7. Data Retention
We retain personal data only for as long as necessary to fulfill the purposes for which it was collected, including:
- Usage data and logs: Typically 12-24 months
- Account information: Until account deletion is requested
- Cookie data: As specified in our Cookie Policy
- Legal compliance data: As required by applicable laws
8. International Data Transfers
If we transfer your data outside the European Economic Area (EEA), we ensure appropriate safeguards are in place, such as:
- EU-approved Standard Contractual Clauses
- Adequacy decisions by the European Commission
- Privacy Shield certification (where applicable)
- Other legally approved transfer mechanisms
9. Data Breach Notification
In the event of a data breach that is likely to result in a high risk to your rights and freedoms, we will notify you without undue delay and within 72 hours of becoming aware of the breach, as required by GDPR.
10. Children's Data
Our services are not directed at children under 16 years of age (or the applicable age of digital consent in your country). We do not knowingly collect personal data from children without parental consent.
11. Third-Party Processors
When we use third-party service providers to process data on our behalf, we ensure they:
- Comply with GDPR requirements
- Have appropriate data processing agreements in place
- Implement adequate security measures
- Process data only according to our instructions
12. Data Protection Officer
While we may not be required to appoint a Data Protection Officer (DPO) under GDPR, we take data protection seriously. For any privacy-related inquiries or to exercise your rights, please contact us through our feedback form.
13. Supervisory Authority
You have the right to lodge a complaint with a supervisory authority, particularly in the EU member state where you reside, work, or where an alleged infringement of GDPR occurred. A list of supervisory authorities can be found at: https://edpb.europa.eu/about-edpb/board/members_en
14. Updates to Our GDPR Compliance
We regularly review and update our GDPR compliance practices to ensure we maintain the highest standards of data protection. Any significant changes will be communicated through our Privacy Policy updates.
15. Questions and Concerns
If you have any questions about our GDPR compliance, how we handle your personal data, or wish to exercise your rights, please contact us through our feedback form. We are committed to resolving any concerns you may have about your privacy.
Our Promise
We are committed to respecting your privacy rights and maintaining GDPR compliance. Your trust is important to us, and we work continuously to ensure your personal data is protected and handled with the utmost care and transparency.