Is Komashi GDPR compliant?
Yes. Komashi's Privacy Policy is built to comply with both the UAE Personal Data Protection Law (PDPL) and the EU GDPR.
The key points:
- Roles are split. For your customers' personal data, the provider is the controller and Komashi is the processor. The Data Processing Agreement is the Article 28 GDPR agreement and forms part of every Provider Agreement.
- EU/EEA data stays in the EU/EEA. Personal data that providers process about their EU/EEA customers is stored, backed up, processed, and accessed exclusively within the EU/EEA, on EU/EEA-established hosting and sub-processors.
- Komashi has an EU representative under GDPR Article 27, who data subjects and supervisory authorities can contact directly.
- No card data. Komashi does not collect, hold, or process card numbers or payment credentials.
- Sub-processors are published. See Sub-processors.
Retention and deletion periods are in Section 9 of the Privacy Policy, which is the single governing source for them.