How Kortilink processes and protects your personal data under the General Data Protection Regulation.
The General Data Protection Regulation (GDPR) is a European Union regulation (2016/679) that establishes rules on how organizations must collect, store and process personal data of European citizens. It entered into force on May 25, 2018.
Kortilink is committed to full compliance with the GDPR. This page explains clearly and transparently how we process your data and what your rights are.
The controller of your personal data is:
As a data subject, you have the following rights, which you can exercise at any time by contacting us:
You can request a copy of all personal data we hold about you.
You can correct inaccurate or incomplete personal data at any time.
You can request the deletion of your data ("right to be forgotten").
You can request the suspension of processing of your data in certain circumstances.
You can receive your data in a structured, machine-readable format.
You can object to the processing of your data for marketing or legitimate interest purposes.
You have the right not to be subject to decisions based solely on automated processing.
You can withdraw any consent given at any time, without retroactive effect.
To exercise any of these rights, send an email to suporte@kortilink.com with the subject "GDPR Rights Exercise". We respond within a maximum of 30 days.
Podes solicitar uma cópia de todos os dados pessoais que temos sobre ti.
Podes corrigir dados pessoais inexatos ou incompletos a qualquer momento.
Podes solicitar a eliminação dos teus dados ("direito a ser esquecido").
Podes solicitar a suspensão do tratamento dos teus dados em determinadas circunstâncias.
Podes receber os teus dados num formato estruturado e legível por máquina.
Podes opor-te ao tratamento dos teus dados para fins de marketing ou interesse legítimo.
Tens o direito de não ficar sujeito a decisões baseadas exclusivamente em tratamento automatizado.
Podes retirar qualquer consentimento dado a qualquer momento, sem efeito retroativo.
Para exercer qualquer um destes direitos, envia um email para suporte@kortilink.com com o assunto "Exercício de Direitos RGPD". Respondemos no prazo máximo de 30 dias.
Credit card data is never stored on Kortilink. Payments are processed by Stripe, which is PCI DSS Level 1 certified. We only store the Stripe customer identifier and subscription status.
Kortilink may use sub-processors located outside the European Economic Area. When this occurs, we ensure adequate safeguards are in place, namely:
If you believe that the processing of your data violates the GDPR, you have the right to lodge a complaint with the competent supervisory authority:
Before contacting the supervisory authority, we encourage you to contact us first, as we can usually resolve any concerns more quickly and directly.
To exercise your GDPR rights, ask privacy questions or request information about the data we process:
suporte@kortilink.com — with the subject "GDPR Rights Exercise"
We respond to all requests within the legal deadline of 30 days.