GDPR Compliance

Introduction

RubberDuck 4×4 is committed to ensuring the privacy and protection of personal data collected through its online service and parts platform. This document outlines our commitment to comply with the General Data Protection Regulation (GDPR) and how we collect, process, store, and protect personal data.

Data Controller

The data controller for the processing of your personal data is RubberDuck 4×4, located at 1622 Smith Road Hamilton, OH 45013. If you have any questions or concerns regarding the processing of your personal data, you can contact us at [email protected].

Personal Data Collection and Processing

We collect and process personal data for the following purposes:

  1. Account Creation: When you create an account on our platform, we collect and process the necessary information to provide you with access to our services.

  2. Order Processing: We collect and process personal data to fulfill orders, including shipping and billing information.

  3. Customer Support: We may collect and process personal data when you contact our customer support for assistance.

  4. Marketing Communications: With your consent, we may send you marketing communications about our products, promotions, and services.

  5. Analytics: We collect and process data for analytics purposes to improve our website and services.

Legal Basis for Processing

We process personal data based on one or more of the following legal grounds:

  1. Contractual Necessity: Processing is necessary for the performance of a contract with you.

  2. Consent: You have given explicit consent for the processing of your personal data.

  3. Legal Obligation: Processing is necessary for compliance with a legal obligation.

Data Security Measures

We implement appropriate technical and organizational measures to ensure the security and confidentiality of personal data. This includes encryption, access controls, and regular security assessments.

Data Retention

We retain personal data only for as long as necessary for the purposes outlined in this document or as required by law. After this period, data will be securely deleted or anonymized.

Your Rights

Under the GDPR, you have the following rights regarding your personal data:

  1. Access: You have the right to access the personal data we hold about you.

  2. Rectification: You can request the correction of inaccurate or incomplete personal data.

  3. Erasure: You have the right to request the deletion of your personal data.

  4. Data Portability: You can request a copy of your personal data in a structured, commonly used, and machine-readable format.

  5. Withdrawal of Consent: If we process your data based on consent, you have the right to withdraw that consent at any time.

Changes to this GDPR Compliance Statement

We reserve the right to update this GDPR Compliance Statement as needed. Updates will be posted on our website, and you will be notified of any material changes.

By using our services, you acknowledge that you have read and understood this GDPR Compliance Statement.