GDPR Compliance & Data Rights
Our commitment to the European Union General Data Protection Regulation (Regulation (EU) 2016/679) and global data subject rights.
1. Squinal's GDPR Commitment
Squinal Private Limited ("Squinal") fully embraces the principles of transparency, accountability, and user data empowerment established by the EU General Data Protection Regulation (GDPR). We embed "Privacy by Design" and "Privacy by Default" across our entire software development lifecycle, ensuring that personal data is processed lawfully, fairly, and securely.
2. Squinal as Data Controller & Data Processor
- As a Data Controller: Squinal acts as a Data Controller with respect to personal information collected directly from visitors to our corporate websites, business point-of-contact details, and commercial account billing records.
- As a Data Processor: When clients deploy our custom enterprise software, diagnostic LIMS platforms, or multi-tenant cloud solutions to manage their end-customers' or patients' records, Squinal operates strictly as a Data Processor. We process customer data exclusively under the documented instructions of the client (the Data Controller) in accordance with our Data Processing Addendum (DPA).
3. Exercising Your Data Subject Rights (DSR)
Under Chapter III of the GDPR, data subjects located in the EU/EEA (and under equivalent regional privacy frameworks globally) have the following enforceable rights:
- Right of Access (Article 15): You have the right to request a complete copy of the personal data we hold about you.
- Right to Rectification (Article 16): You may request the correction of inaccurate or incomplete personal records.
- Right to Erasure / "Right to be Forgotten" (Article 17): You may request the permanent deletion of personal data where retention is no longer legally necessary.
- Right to Restriction of Processing (Article 18): You may request that we temporarily suspend the active processing of your data under specific conditions.
- Right to Data Portability (Article 20): You have the right to receive your personal data in a structured, commonly used, and machine-readable format (e.g., JSON or CSV).
- Right to Object (Article 21): You may object to data processing grounded in legitimate interests or direct marketing communications.
To submit a formal request to access, update, or erase your data, email dpo@squinal.com. We respond to all verified DSR requests within 30 calendar days free of charge.
4. International Data Transfers & Standard Contractual Clauses
When customer data originates in the European Economic Area (EEA) and is processed on cloud infrastructure or by engineering teams located outside the EEA, Squinal safeguards cross-border transfers by executing the European Commission's approved Standard Contractual Clauses (SCCs) and implementing supplementary technical measures (end-to-end encryption at rest and in transit).
5. Technical & Organizational Safeguards (TOMs)
Pursuant to Article 32 of the GDPR, Squinal maintains appropriate technical and organizational measures:
- Pseudonymization and AES-256 encryption of sensitive personal data fields.
- Strict role-based access control (RBAC) and mandatory multi-factor authentication (MFA).
- Automated daily encrypted offsite backups with integrity testing.
- Regular vulnerability assessments and automated DevSecOps code scanning.
6. Data Protection Officer (DPO) Contact
For GDPR compliance inquiries, Data Processing Agreements (DPA), or supervisory authority correspondence, please contact:
Designation: Data Protection Officer (DPO)
Direct Email: dpo@squinal.com (copy: privacy@squinal.com)
Organization: Squinal Private Limited, Global Privacy & Trust Division.