GDPR Compliance
Last updated: 16 July 2026
Our Commitment to GDPR
Crownbot is committed to protecting your personal data and respecting your privacy rights under the General Data Protection Regulation (GDPR). We ensure that all personal data is processed lawfully, fairly, and transparently.
Legal Basis for Processing
We process your personal data based on the following legal grounds:
- Consent: When you have given explicit consent for specific purposes
- Contract: When processing is necessary to fulfill our contractual obligations
- Legitimate Interest: When we have a legitimate business interest
- Legal Obligation: When required by law
Your GDPR Rights
Under GDPR, you have the following rights:
- Right to Access: Request copies of your personal data
- Right to Rectification: Request correction of inaccurate data
- Right to Erasure: Request deletion of your personal data
- Right to Restrict Processing: Request limitation of data processing
- Right to Data Portability: Receive your data in a portable format
- Right to Object: Object to certain types of processing
- Rights Related to Automated Decision-Making: Not be subject to automated decisions
Data Protection Measures
We implement robust security measures including:
- Encryption of data in transit and at rest
- Regular security audits and assessments
- Access controls and authentication protocols
- Employee training on data protection
- Data breach response procedures
Data Retention
We retain personal data only for as long as necessary to fulfill the purposes for which it was collected, comply with legal obligations, resolve disputes, and enforce our agreements.
International Data Transfers
When we transfer data outside the European Economic Area (EEA), we ensure appropriate safeguards are in place, such as standard contractual clauses approved by the European Commission.
Exercising Your Rights
To exercise any of your GDPR rights or if you have questions about our data practices, please contact us at hello@crownbot.uk
Supervisory Authority
You have the right to lodge a complaint with your local supervisory authority if you believe we have not complied with GDPR requirements.
