Skip to main content
GDPR Compliant

GDPR Compliance

Fluxira is committed to complying with the EU General Data Protection Regulation (GDPR). This page outlines our data protection practices and your rights under GDPR.

Last updated: September 1, 2026

Our GDPR Commitment

Fluxira Technologies recognizes the importance of data protection and privacy. We have implemented comprehensive technical, organizational, and contractual measures to ensure compliance with the GDPR and other applicable data protection regulations.

Our platform is designed with privacy by design and privacy by default principles built into every feature. We process personal data only for specified, explicit, and legitimate purposes and do not process data in ways incompatible with those purposes.

πŸ›‘οΈ

Privacy by Design

Data protection is embedded into our platform architecture and development process.

πŸ”’

Privacy by Default

We collect only the minimum data necessary and apply the strictest privacy settings by default.

βš–οΈ

Legal Compliance

We maintain compliance with GDPR, CCPA, and other applicable data protection laws.

Your Rights Under GDPR

πŸ“‹

Right of Access

You have the right to request a copy of all personal data we hold about you.

We will provide your data within 30 days in a structured, commonly used, machine-readable format (CSV, JSON, or XML). You may request data via your account settings or by emailing dpo@fluxira.com.

✏️

Right to Rectification

You have the right to request correction of inaccurate or incomplete personal data.

You can update most personal data directly through your account settings. For data that cannot be self-service edited, contact our support team or DPO.

πŸ—‘οΈ

Right to Erasure

You have the right to request deletion of your personal data ("right to be forgotten").

Upon receiving a valid erasure request, we will delete your personal data within 30 days, except where retention is required by law (e.g., financial records for 7 years under Indian tax regulations). Business data is retained for 60 days to allow for final export.

⏸️

Right to Restrict Processing

You have the right to request restriction of processing of your personal data.

When processing is restricted, we will store your data but not process it further without your consent, except for storage, legal claims, or protection of rights.

πŸ“¦

Right to Data Portability

You have the right to receive your personal data in a machine-readable format.

We provide data export in CSV, Excel, and JSON formats. You can request a complete data export at any time through account settings or by contacting support.

🚫

Right to Object

You have the right to object to processing of your personal data for certain purposes.

You may object to processing based on legitimate interests or for direct marketing purposes. Upon objection, we will cease processing unless we have compelling legitimate grounds.

πŸ”„

Right to Withdraw Consent

You have the right to withdraw previously given consent at any time.

Withdrawal of consent does not affect the lawfulness of processing based on consent before its withdrawal. You can withdraw consent through account settings or by contacting us.

βš–οΈ

Right to Complain

You have the right to lodge a complaint with a supervisory authority.

If you believe your data protection rights have been infringed, you have the right to file a complaint with the relevant data protection authority in your jurisdiction.

How to Exercise Your Rights

You can exercise any of your GDPR rights through the following channels:

πŸ“§ Email

Send your request to our Data Protection Officer:

dpo@fluxira.com

Include "GDPR Request" in the subject line and your registered email address.

βš™οΈ Account Settings

Access data export, deletion, and preference management directly from your dashboard.

Go to Dashboard β†’

We will respond to all GDPR requests within 30 days. If we need additional time due to the complexity or number of requests, we will notify you within the initial 30-day period.

We may need to verify your identity before processing your request to protect your privacy and security. We will not charge a fee unless the request is manifestly unfounded or excessive.

Data Protection Safeguards

Technical Measures

  • AES-256 encryption for data at rest
  • TLS 1.3 encryption for data in transit
  • Multi-tenant data isolation
  • Automated threat detection and monitoring
  • Regular penetration testing by independent firms
  • Secure backup and disaster recovery

Organizational Measures

  • Data Protection Officer (DPO) appointed
  • Data processing agreements with all sub-processors
  • Employee security training program
  • Incident response procedures
  • Regular privacy impact assessments
  • Vendor security assessments

Contractual Measures

  • Standard Contractual Clauses (SCCs) for international transfers
  • Data Processing Agreement (DPA) with all customers
  • Sub-processor notification and approval process
  • Data breach notification within 72 hours
  • Data deletion guarantees upon termination
  • Audit rights for Enterprise customers

Data Processing Details

Data ControllerFluxira Technologies Pvt Ltd, Pune, India
Data Protection Officerdpo@fluxira.com
Legal Basis for ProcessingContractual necessity, legitimate interests, and consent
Data StoredAccount information, business data, usage data, payment data
Data LocationAWS ap-south-1 (Mumbai, India); custom regions available for Enterprise
Data RetentionWhile account is active + 60 days for export; financial records 7 years
Sub-processorsAWS (hosting), Stripe (payment processing), Google Analytics (analytics)
International TransfersStandard Contractual Clauses (SCCs) for all cross-border data transfers

Have GDPR Questions?

Our Data Protection Officer is available to help with any data privacy concerns.