GDPR 与数据权利
最后更新:2026年10月3日
1. Scope
This notice supplements our Privacy Policy for people in the European Economic Area, the United Kingdom, and Switzerland, whose personal data is protected by the EU General Data Protection Regulation (GDPR), the UK GDPR, or the Swiss FADP.
2. Controller
RedshotLabs is the controller for personal data collected through this website. Data protection contact: contact@redshotlabs.com.
3. Legal bases for processing
| Processing | Legal basis (GDPR Art. 6) |
|---|---|
| Responding to contact form inquiries | Art. 6(1)(b): steps prior to entering a contract; Art. 6(1)(f): legitimate interests |
| Operating and securing the website | Art. 6(1)(f): legitimate interests |
| Storing language and theme preferences | Strictly necessary for a service you requested (no consent required) |
| Retaining records where the law requires | Art. 6(1)(c): legal obligation |
We do not rely on consent for any processing on this site, because we do not use analytics, advertising, or tracking technologies. If that changes, we will ask for your consent first.
4. Your rights
You have the right to:
- Access: obtain confirmation of whether we process your data, and a copy of it.
- Rectification: have inaccurate or incomplete data corrected.
- Erasure: have your data deleted ("right to be forgotten") where the legal conditions are met.
- Restriction: ask us to limit how we use your data.
- Portability: receive the data you gave us in a structured, commonly used, machine-readable format.
- Objection: object to processing based on our legitimate interests.
- No automated decisions: we do not make decisions about you based solely on automated processing.
5. How to exercise your rights
Email contact@redshotlabs.com with your request. We respond within one month, free of charge. We may ask for information to confirm your identity before acting on a request, and we will tell you if we need more time or cannot comply, and why.
6. Complaints
If you believe we have handled your data unlawfully, please contact us first so we can put it right. You also have the right to lodge a complaint with the data protection authority in the country where you live or work, or where the issue arose.
7. Processors and international transfers
We use the processors listed in the Privacy Policy, each bound by a data processing agreement. Transfers outside the EEA, UK, or Switzerland are covered by an adequacy decision or by Standard Contractual Clauses (with the UK Addendum where applicable).
8. Data breaches
If a personal data breach is likely to put your rights and freedoms at risk, we will notify the competent supervisory authority within 72 hours of becoming aware of it and inform affected individuals where required.
9. When we work for clients
When RedshotLabs builds or operates systems for a client and handles personal data on the client's behalf, the client is the controller and we act as a processor. We process that data only on the client's documented instructions and will sign a data processing agreement (GDPR Art. 28) on request.