GDPR Compliance
About GDPR Compliance
1. Overview
The General Data Protection Regulation (EU) 2016/679 (“GDPR“) is the European Union’s law on the protection of personal data.Kobikoba (“we,” “us,” “our,” or the “Platform”) is committed to full compliance with the GDPR for all Users located in the European Economic Area (EEA) and, where applicable, the United Kingdom (UK GDPR).
This page summarizes how we meet our GDPR obligations. It supplements — and should be read together with — our [Privacy Policy]. If there is any conflict, this GDPR Compliance Statement prevails with respect to EEA/UK data subjects.
2. Our Role Under the GDPR
Understanding our role helps clarify our responsibilities:
2.1 As a Data Controller
We act as a data controller for the personal data we collect directly from you, including:
- Account registration data (name, email, password hash);
- Platform usage and log data;
- Complaints and abuse reports you submit;
- Seller verification data;
- Cookie and analytics data (with your consent).
As a controller, we determine the purposes and means of processing this data and are fully responsible for its lawful handling.
2.2 As a Data Processor
For Sellers using our tools, we may act as a data processor in limited circumstances (e.g., hosting Seller storefront data or facilitating communications). Where this applies, we process personal data only on documented instructions from the controller and under a Data Processing Agreement (DPA) compliant with GDPR Article 28.
2.3 Sellers Are Separate Controllers
Important: Sellers on our Platform are independent data controllers for the personal data they collect directly from Buyers (e.g., order details, shipping addresses, payment information they receive). Their processing is governed by their own privacy policies. We do not control, and are not responsible for, Sellers’ data practices.
3. Lawful Bases for Processing
Under GDPR Article 6, we process personal data only where at least one lawful basis applies:
Table
| Processing Activity | Lawful Basis | Explanation |
|---|---|---|
| Creating and managing your account | Contract performance (Art. 6(1)(b)) | Necessary to provide the service you requested |
| Platform security, fraud & abuse prevention | Legitimate interests (Art. 6(1)(f)) | Protecting our Platform and Users from harm |
| Seller identity verification | Legal obligation (Art. 6(1)(c)) & legitimate interests | Preventing fraud and illegal activity |
| Handling complaints and abuse reports | Legitimate interests & legal obligation | Maintaining platform integrity |
| Analytics and Platform improvement | Consent (Art. 6(1)(a)) | Given via our cookie banner; withdrawable at any time |
| Service emails (security alerts, account notices) | Legitimate interests | Necessary communication about your account |
| Marketing communications | Consent | Only with explicit opt-in; you may unsubscribe anytime |
Where we rely on legitimate interests, we have conducted a balancing test to ensure our interests do not override your fundamental rights and freedoms. You may request details of this assessment by contacting us.
4. Your Rights Under GDPR
If you are located in the EEA or UK, you have the following rights regarding your personal data. To exercise any of them, contact us at [privacy@kobikoba.com]:
4.1 Right of Access (Art. 15)
You may request confirmation of whether we process your data and receive a copy of it, together with information about the processing.
4.2 Right to Rectification (Art. 16)
You may request correction of inaccurate or incomplete personal data. You can also update most information directly in your account settings.
4.3 Right to Erasure — “Right to be Forgotten” (Art. 17)
You may request deletion of your personal data where:
- The data is no longer necessary for its original purpose;
- You withdraw consent and no other lawful basis exists;
- You object to processing and no overriding legitimate grounds exist;
- The data has been unlawfully processed;
- Deletion is required by EU or Member State law.
Exceptions: We may retain data where required by law, for legal claims, or for abuse-prevention purposes (e.g., records of fraud reports).
4.4 Right to Restriction of Processing (Art. 18)
You may request that we limit how we use your data while a dispute about accuracy, lawfulness, or our legitimate interests is resolved.
4.5 Right to Data Portability (Art. 20)
You may receive your personal data in a structured, commonly used, machine-readable format (e.g., JSON or CSV) and have it transmitted to another controller where processing is based on consent or contract and carried out by automated means.
4.6 Right to Object (Art. 21)
You may object at any time to processing based on legitimate interests (including profiling) or to direct marketing. We will stop processing unless we demonstrate compelling legitimate grounds that override your rights.
4.7 Rights Related to Automated Decision-Making (Art. 22)
We do not make decisions that produce legal or similarly significant effects about you solely by automated means. If this changes, we will inform you and implement appropriate safeguards.
4.8 Right to Withdraw Consent (Art. 7(3))
Where processing is based on consent, you may withdraw it at any time with effect for the future, without affecting the lawfulness of prior processing. Withdraw consent via [Cookie Settings] or by contacting us.
4.9 How to Exercise Your Rights
- Email: [privacy@kobikoba.com] with the subject line “GDPR Request”;
- Verification: We may ask you to verify your identity before acting on your request;
- Response time: Within one (1) month, extendable by two further months for complex requests (we will inform you within the first month if an extension applies);
- Fees: We do not charge for requests, except where a request is manifestly unfounded or excessive.
5. Right to Lodge a Complaint
If you believe we have not handled your personal data lawfully, you have the right to lodge a complaint with your local supervisory authority:
- EU: Find your national data protection authority at edpb.europa.eu
- UK: Information Commissioner’s Office (ICO) — ico.org.uk
We would, however, appreciate the opportunity to address your concerns first — please contact us before filing a complaint.
6. International Data Transfers
Personal data of EEA/UK Users may be transferred to and processed in countries outside the EEA/UK where our service providers operate. We ensure such transfers are protected by appropriate safeguards under GDPR Chapter V, including:
- EU Standard Contractual Clauses (SCCs) — as updated by the European Commission in June 2021, incorporated into our agreements with processors;
- UK Addendum / International Data Transfer Agreement (IDTA) — for transfers involving UK data;
- Adequacy decisions — transfers only to countries recognized by the European Commission (or UK, where relevant) as providing an adequate level of protection;
- Transfer Impact Assessments (TIAs) — conducted where required, particularly for transfers to countries without an adequacy decision.
A list of the countries where your data may be processed is available on request.
7. Data Security (Art. 32)
We implement appropriate technical and organizational measures (TOMs), including:
- Encryption of data in transit (TLS 1.2+) and at rest (AES-256);
- Pseudonymization and data minimization by default;
- Role-based access controls and least-privilege principles;
- Regular security testing, vulnerability scanning, and patching;
- Staff confidentiality agreements and GDPR training;
- Incident detection and response procedures.
7.1 Breach Notification
In the event of a personal data breach likely to result in a risk to your rights and freedoms, we will:
- Notify the competent supervisory authority within 72 hours of becoming aware of the breach (Art. 33);
- Notify affected Users without undue delay where the breach is likely to result in a high risk to their rights and freedoms (Art. 34), unless an exception applies.
8. Data Retention
We retain personal data no longer than necessary for the purposes for which it was collected, in line with the retention schedule in our [Privacy Policy]. Key periods:
Table
| Data Category | Retention Period |
|---|---|
| Account data | Life of account + 30 days, unless legally required longer |
| Complaints/abuse reports | Up to 24 months after resolution |
| Seller verification documents | Duration of Seller account + legal retention period |
| Analytics/cookie data | Per consent duration; logs up to 12 months |
| Backup data | Up to 30 days, encrypted, then permanently deleted |
When retention periods expire, data is securely deleted or irreversibly anonymized.
9. Data Protection by Design and by Default (Art. 25)
We apply data protection principles from the design stage of any new feature, product, or tool:
- Data minimization — we collect only what we need;
- Privacy by default — non-essential cookies and features are off until you opt in;
- Pseudonymization — analytics data is aggregated or pseudonymized where possible;
- DPIAs — we conduct Data Protection Impact Assessments for processing likely to result in high risk.
10. Records of Processing Activities (Art. 30)
We maintain a Record of Processing Activities (RoPA) documenting our processing operations, purposes, categories of data, recipients, transfers, and retention periods, available to supervisory authorities upon request.
11. Data Processing Agreements with Processors (Art. 28)
All third-party service providers that process personal data on our behalf (hosting, analytics, email delivery) are bound by written Data Processing Agreements requiring them to:
- Process data only on our documented instructions;
- Implement appropriate security measures;
- Not engage sub-processors without authorization;
- Assist with data subject requests and breach notifications;
- Delete or return data at the end of the service;
- Submit to audits where appropriate.
12. Children’s Data (Art. 8)
The Platform is not directed at children under 16, and we do not knowingly process personal data of children under 16 without parental consent. If you believe we hold data of a child under 16, contact us and we will delete it promptly.
13. Data Protection Officer
[Select the applicable option:]
Option A: We are not currently required to appoint a DPO under Art. 37. Our core activities do not consist of large-scale regular and systematic monitoring of data subjects, nor large-scale processing of special categories of data. Data protection matters are handled by our privacy team at [privacy@kobikoba.com].
Option B: Our Data Protection Officer can be contacted at: DPO, Kobikoba [dpo@kobikoba.com]
14. Special Categories of Personal Data (Art. 9)
We do not intentionally collect special categories of personal data (racial or ethnic origin, political opinions, religious beliefs, health data, biometric data, etc.). Please do not submit such information to the Platform, including in complaints or messages. If such data is inadvertently processed (e.g., within an abuse report), it is handled with enhanced safeguards and deleted as soon as it is no longer necessary.
15. Cookies and Consent Management
- Non-essential cookies (analytics, marketing) are placed only after you give explicit consent via our cookie banner (GDPR-compliant, per ePrivacy Directive Art. 5(3));
- Consent is recorded (who, when, what was consented to) and is as easy to withdraw as to give;
- You can manage preferences anytime via “Cookie Settings” in our footer;
- See our [Cookie Policy] for the full list of cookies.