GDPR Privacy Notice
Version 2.0
January 2025
KVKK & GDPR
**GDPR PRIVACY NOTICE**
This notice provides information about your rights under the European Union General Data Protection Regulation (GDPR).
**DATA CONTROLLER**
Atlas Media
Washington DC, USA
Email: gdpr@atlas.news
EU Representative: [EU representative details available upon request]
**DATA COLLECTED AND PROCESSING PURPOSES**
| Data Category | Processing Purpose | Legal Basis |
|---------------|-------------------|-------------|
| Identity information | Account management | Contract |
| Contact information | Newsletter, notifications | Consent |
| Usage data | Analytics, improvement | Legitimate interest |
| Cookie data | Site functionality | Consent/Legitimate interest |
| Payment information | Subscription processing | Contract |
**LEGAL BASES (GDPR ARTICLE 6)**
We process your personal data based on the following legal grounds:
1. **Consent (Article 6(1)(a)):** Marketing communications, preference cookies
2. **Contract (Article 6(1)(b)):** Account creation, service provision
3. **Legal Obligation (Article 6(1)(c)):** Tax records, legal requests
4. **Legitimate Interest (Article 6(1)(f)):** Security, fraud prevention, analytics
**YOUR RIGHTS UNDER GDPR**
As EU/EEA residents, you have the following rights:
**Right of Access (Article 15)**
You can request access to your personal data and receive a copy.
**Right to Rectification (Article 16)**
You can request correction of inaccurate or incomplete personal data.
**Right to Erasure / Right to be Forgotten (Article 17)**
You can request deletion of your personal data under certain conditions:
• If the data is no longer necessary
• If you withdraw your consent
• If you object to processing
• If the data was unlawfully processed
**Right to Restriction of Processing (Article 18)**
You can request restriction of processing in certain situations.
**Right to Data Portability (Article 20)**
You have the right to receive your data in a structured, commonly used, and machine-readable format.
**Right to Object (Article 21)**
You can object to processing based on legitimate interest.
**Rights Related to Automated Decision-Making (Article 22)**
You have the right not to be subject to decisions based solely on automated processing.
**Right to Withdraw Consent**
For consent-based processing, you can withdraw your consent at any time.
**INTERNATIONAL DATA TRANSFERS**
Your personal data is processed on servers located in the USA. For transfers outside the EU/EEA, we use the following safeguards:
• EU-US Data Privacy Framework
• Standard Contractual Clauses (SCCs)
• Additional security measures and encryption
**DATA RETENTION**
We retain your personal data only for as long as necessary:
| Data Type | Retention Period |
|-----------|-----------------|
| Account data | While account is active + 3 years |
| Transaction records | 7 years |
| Marketing data | Until consent is withdrawn |
| Analytics data | 26 months |
| Support requests | 5 years |
**DATA SECURITY**
Pursuant to GDPR Article 32, we implement the following technical and organizational measures:
• Encryption in transit and at rest (TLS 1.3, AES-256)
• Access control and role-based permissions
• Regular security testing and penetration testing
• Incident response and breach notification procedures
• Employee training and privacy awareness
• Data processing agreements (DPAs)
**DATA BREACH NOTIFICATION**
In the event of a data breach:
• We will notify the relevant supervisory authority within 72 hours
• We will inform you immediately in high-risk situations
• We will report the scope of the breach and measures taken
**RIGHT TO LODGE A COMPLAINT**
If you have concerns about our data processing practices:
1. Contact us first: gdpr@atlas.news
2. If you do not receive a satisfactory response, you can lodge a complaint with a supervisory authority
**EU Supervisory Authorities:**
Each EU member state has its own data protection authority. You can contact the authority in your country of residence.
**CHILDREN'S DATA**
We do not knowingly collect personal data from children under 16. If we learn that a child has provided data without consent, we will delete this data immediately.
**AUTOMATED DECISION-MAKING**
We do not make decisions based solely on automated processing that significantly affect you. Our analytics tools are used only for statistical analysis.
**CHANGES**
We may update this notice in accordance with GDPR requirements. We will notify you of significant changes by email or through the site.
**CONTACT**
For GDPR rights requests:
Email: gdpr@atlas.news
Response time: 30 days (may be extended to 60 days for complex requests)
Last updated: January 2025
Version: 2.0
