GDPR Compliance

Your data protection rights under the General Data Protection Regulation (GDPR) and how MetricMock ensures compliance.

Last updated: March 1, 2024

What is GDPR?

The General Data Protection Regulation (GDPR) is a comprehensive data protection law that came into effect on May 25, 2018. It applies to all companies processing personal data of individuals residing in the European Union, regardless of where the company is located.

Our Commitment: MetricMock is committed to protecting your privacy and ensuring full compliance with GDPR requirements.

Your Rights Under GDPR

As a data subject under GDPR, you have several fundamental rights regarding your personal data:

Right to Information

You have the right to be informed about how we collect, use, and process your personal data.

How we comply: We provide clear privacy notices and this GDPR information page.

Right of Access

You have the right to access your personal data and receive a copy of it.

How to exercise: Contact us at gdpr@metricmock.com to request access to your data.

Right to Rectification

You have the right to correct inaccurate or incomplete personal data.

How to exercise: Update your information in your account settings or contact our support team.

Right to Erasure ("Right to be Forgotten")

You have the right to request deletion of your personal data under certain circumstances.

How to exercise: Contact us at gdpr@metricmock.com with your deletion request.

Right to Restrict Processing

You have the right to limit how we process your personal data in certain situations.

When applicable: When you contest accuracy, processing is unlawful, or you need data for legal claims.

Right to Data Portability

You have the right to receive your personal data in a structured, commonly used format.

Available formats: JSON, CSV, or other machine-readable formats upon request.

Right to Object

You have the right to object to processing based on legitimate interests or for direct marketing.

Marketing: You can opt-out of marketing communications at any time.

How We Process Your Data

Legal Basis for Processing

We process your personal data based on the following legal grounds:

Processing ActivityLegal BasisPurpose
Account ManagementContract PerformanceProvide our services
Payment ProcessingContract PerformanceProcess payments
Marketing CommunicationsConsentSend promotional content
AnalyticsLegitimate InterestImprove our services
Customer SupportContract PerformanceProvide support

Data Retention

We retain your personal data only for as long as necessary to fulfill the purposes for which it was collected, including:

  • Account data: For the duration of your account plus 3 years
  • Payment data: 7 years for tax and accounting purposes
  • Marketing data: Until you withdraw consent
  • Analytics data: 26 months (Google Analytics default)
  • Support tickets: 3 years after resolution

Data Security Measures

We implement appropriate technical and organizational measures to ensure data security:

Technical Measures

  • • End-to-end encryption
  • • Secure data centers
  • • Regular security audits
  • • Access controls
  • • Data backup systems

Organizational Measures

  • • Staff training programs
  • • Data protection policies
  • • Incident response procedures
  • • Privacy by design
  • • Regular compliance reviews

International Data Transfers

When we transfer your personal data outside the European Economic Area (EEA), we ensure appropriate safeguards are in place:

  • Standard Contractual Clauses (SCCs) approved by the European Commission
  • Adequacy decisions for countries with adequate data protection
  • Binding Corporate Rules for intra-group transfers
  • Certification schemes and codes of conduct

Third-Party Services: We work with trusted service providers who are also GDPR compliant and have appropriate data protection measures in place.

Data Breach Notification

In the unlikely event of a data breach that poses a risk to your rights and freedoms, we will:

1

Notify Authorities

Report to the relevant supervisory authority within 72 hours

2

Assess Risk

Evaluate if the breach poses a high risk to affected individuals

3

Notify Affected Users

Inform you without undue delay if high risk is determined

4

Take Action

Implement measures to mitigate the breach and prevent recurrence

How to Exercise Your Rights

To exercise any of your GDPR rights, please contact us using the information below. We will respond to your request within one month.

Contact Information

Email: gdpr@metricmock.com

Subject Line: GDPR Request - [Type of Request]

Data Protection Officer: dpo@metricmock.com

What to Include in Your Request

  • Your full name and email address associated with your account
  • Clear description of your request and which right you want to exercise
  • Any relevant details that help us locate your data
  • Proof of identity (for security purposes)

Response Time: We aim to respond within one month. For complex requests, we may extend this by two additional months and will inform you of any delay.

Supervisory Authority

If you believe we have not handled your personal data in accordance with GDPR, you have the right to lodge a complaint with a supervisory authority.

For EU residents: Contact your local data protection authority

Find your local authority:European Data Protection Board

Updates to This Information

We may update this GDPR compliance information from time to time to reflect changes in our practices or legal requirements. We will notify you of any material changes through our usual communication channels.