This GDPR Policy explains how 20 Hour Work Week (“we,” “our,” or “us”) complies with the General Data Protection Regulation (GDPR) in relation to the processing of personal data of individuals in the European Union (EU) and European Economic Area (EEA).
For the purposes of the GDPR, we are the data controller of personal data collected through our website https://www.20hourworkweek.com/.
We process personal data on the following legal bases:
Under the GDPR, you have the following rights:
We will retain your personal data only for as long as is necessary for the purposes set out in our Privacy Policy. We will retain and use your data to the extent necessary to comply with our legal obligations, resolve disputes, and enforce our legal agreements and policies.
We implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk, including:
If we transfer your personal data outside the EU/EEA, we ensure that appropriate safeguards are in place, such as Standard Contractual Clauses approved by the European Commission.
In the event of a personal data breach, we will notify the relevant supervisory authority within 72 hours of becoming aware of the breach, where feasible. If the breach is likely to result in a high risk to your rights and freedoms, we will also notify you directly.
We have not appointed a Data Protection Officer as we do not meet the criteria requiring such an appointment. However, for any GDPR-related queries, please contact us.
We may update our GDPR Policy from time to time.
If you have any questions about this GDPR Policy or would like to exercise your data protection rights, please contact us.