Scope and Applicability
The General Data Protection Regulation (GDPR) is a comprehensive data protection law that applies to organizations processing personal data of individuals located in the European Union (EU) and European Economic Area (EEA), regardless of where the organization is based.
Who Does This Apply To?
While Startup Space primarily serves users in the United States, we recognize our obligations under GDPR when processing personal data of individuals who are located in the EU/EEA at the time of data collection. This page outlines how we comply with GDPR requirements for these visitors.
Our GDPR compliance framework covers:
- EU/EEA residents who visit our website and interact with our services
- EU/EEA nationals temporarily residing outside Europe who access our platform
- Any individual physically located in the EU/EEA when their data is collected
If you are not located in the EU/EEA, our standard Privacy Policy governs our data practices. However, we extend many GDPR-inspired protections to all users as part of our commitment to privacy best practices.
Legal Bases for Processing
Under GDPR, we must have a valid legal basis for processing your personal data. We rely on the following legal bases depending on the specific processing activity:
Consent (Article 6(1)(a))
When you explicitly agree to specific data processing activities. This includes:
- Subscribing to our newsletter or marketing communications
- Accepting non-essential cookies for analytics and advertising
- Opting into personalized content recommendations
Your right: You can withdraw consent at any time through our Privacy Dashboard or by contacting us directly.
Legitimate Interests (Article 6(1)(f))
Processing necessary for our legitimate business interests, balanced against your rights:
- Improving website functionality and user experience
- Preventing fraud and ensuring platform security
- Analyzing aggregate usage patterns to improve our content
- Responding to your inquiries and providing customer support
Balancing test: We conduct legitimate interest assessments to ensure our interests do not override your fundamental rights and freedoms.
Contractual Necessity (Article 6(1)(b))
Processing required to fulfill our obligations when you use our services:
- Creating and managing your account (if applicable)
- Processing referrals to partner dating platforms
- Providing access to requested content and features
Legal Obligation (Article 6(1)(c))
Processing required to comply with applicable laws, such as maintaining records for tax purposes, responding to valid legal requests, or complying with anti-fraud regulations.
As part of our participation in industry standards similar to the IAB Transparency & Consent Framework, we work with advertising and analytics partners who may process your data. When you click 'Accept All' on our cookie consent banner, you authorize these partners to store and access information on your device for purposes including personalized advertising, content measurement, and audience research.
Your Data Subject Rights
Under GDPR, you have comprehensive rights regarding your personal data. We are committed to honoring these rights and have implemented processes to facilitate your requests.
| Right | Description | How to Exercise |
|---|---|---|
| Right of Access | Obtain confirmation of whether we process your data and receive a copy of your personal data | Submit a Data Subject Access Request (DSAR) via email |
| Right to Rectification | Correct inaccurate personal data or complete incomplete data | Contact us with the specific corrections needed |
| Right to Erasure | Request deletion of your personal data under certain circumstances | Submit an erasure request; we will respond within 30 days |
| Right to Restriction | Limit how we process your data in specific situations | Specify which processing activities you wish to restrict |
| Right to Data Portability | Receive your data in a structured, machine-readable format | Request a data export in JSON or CSV format |
| Right to Object | Object to processing based on legitimate interests or direct marketing | Submit an objection; we will cease processing unless we have compelling grounds |
| Rights Related to Automated Decision-Making | Not be subject to decisions based solely on automated processing that significantly affect you | Request human review of any automated decisions |
Withdrawing Consent
You can modify your privacy preferences at any time through our cookie consent settings or by contacting us directly. Withdrawing consent does not affect the lawfulness of processing conducted before the withdrawal.
To manage cookies and tracking preferences, look for the "Privacy Settings" or "Cookie Settings" link in our website footer, or adjust your browser settings to block or delete cookies.
Data Retention and Security
Retention Periods
We retain personal data only for as long as necessary to fulfill the purposes for which it was collected, or as required by law:
- Website analytics data: 26 months, then anonymized or deleted
- Contact form submissions: 3 years from last interaction
- Newsletter subscriptions: Until unsubscription, plus 30 days for processing
- Cookie consent records: 12 months, then renewed
- Legal compliance records: As required by applicable law (typically 7 years for financial records)
Security Measures
We implement appropriate technical and organizational measures to protect your personal data against unauthorized access, alteration, disclosure, or destruction:
Technical Safeguards
- SSL/TLS encryption for all data transmissions
- Secure hosting with industry-standard firewalls
- Regular security updates and vulnerability assessments
- Access controls and authentication protocols
Organizational Safeguards
- Data protection training for team members
- Privacy-by-design principles in development
- Vendor due diligence and data processing agreements
- Incident response procedures
In the event of a data breach affecting your personal data, we will notify you and the relevant supervisory authority within 72 hours as required by GDPR Article 33, unless the breach is unlikely to result in a risk to your rights and freedoms.
International Data Transfers
Startup Space is based in the United States. When you access our services from the EU/EEA, your personal data may be transferred to and processed in the United States, which the European Commission has not determined to provide an adequate level of data protection.
Transfer Safeguards
To ensure your data receives adequate protection when transferred outside the EU/EEA, we implement the following safeguards:
Standard Contractual Clauses (SCCs)
We use the European Commission-approved Standard Contractual Clauses with our service providers to ensure contractual protections for your data. These clauses require recipients to protect your data to EU standards regardless of their location.
Supplementary Measures
In addition to SCCs, we implement supplementary technical and organizational measures as recommended by the European Data Protection Board, including encryption, pseudonymization where appropriate, and access restrictions.
Vendor Assessment
We evaluate our service providers' data protection practices and select partners who demonstrate commitment to privacy and security standards compatible with GDPR requirements.
Our key service providers with potential access to EU personal data include web hosting services, analytics providers, and email service providers. Each operates under data processing agreements that incorporate appropriate safeguards.
How to Exercise Your Rights
We have implemented straightforward procedures to help you exercise your GDPR rights effectively.
Submitting a Request
To exercise any of your data subject rights, please contact us using the methods described below. To help us process your request efficiently, please include:
- Your full name and email address associated with your interactions with our site
- A clear description of the right you wish to exercise
- Any specific details that will help us locate your data (e.g., approximate dates of interaction)
- Proof of identity (we may request this to protect against unauthorized access)
Response Timeline
We will acknowledge your request within 72 hours and provide a substantive response within 30 days. If your request is complex or we receive numerous requests, we may extend this period by an additional 60 days, in which case we will inform you of the extension and the reasons for it within the initial 30-day period.
Fees
We process most requests free of charge. However, if requests are manifestly unfounded or excessive (particularly if repetitive), we may charge a reasonable fee based on administrative costs or refuse to act on the request.
Right to Lodge a Complaint
If you believe we have not adequately addressed your concerns, you have the right to lodge a complaint with a supervisory authority. You may contact the data protection authority in your country of residence, place of work, or where the alleged infringement occurred. A list of EU/EEA data protection authorities is available on the European Data Protection Board website.
Contact for GDPR Queries
For any questions, concerns, or requests related to GDPR compliance or your data protection rights, please contact us:
GDPR Contact Information
Email: [email protected]
Subject Line: Please include "GDPR Request" or "GDPR Inquiry" in your email subject
Postal Address:
Startup Space
Attn: Data Protection Officer
Privacy Compliance Department
United States
Response Commitment: We aim to acknowledge all GDPR-related communications within 72 hours during business days.
For general inquiries not related to GDPR, please visit our Contact Us page.
Updates to This Page
We may update this GDPR Compliance page periodically to reflect changes in our practices, legal requirements, or regulatory guidance. When we make material changes, we will:
- Update the "Last Updated" date at the top of this page
- Provide prominent notice on our website for significant changes
- Where required, obtain your consent for new processing activities
We encourage you to review this page regularly to stay informed about how we protect your personal data.