GDPR Compliance

Last updated: 26 February 2026

1. Our Commitment

TechBiz Hub L.L.C-FZ is committed to full compliance with the General Data Protection Regulation (EU) 2016/679 ("GDPR"). This page describes the technical and organizational measures we implement to protect your personal data within the AVE platform.

2. Data Protection Officer (DPO)

For any questions related to data protection, you can contact our data protection officer:

Email: gdpr@techbiz.ae

Response time: within 30 days

3. GDPR Principles Applied

We respect all the fundamental principles of the GDPR:

Lawfulness, fairness and transparency

We process data lawfully, fairly and transparently. This page and the Privacy Policy explain in detail how and why we process data.

Purpose limitation

We collect data only for specific, explicit and legitimate purposes: providing the audit service, managing your account and service-related communications.

Data minimisation

We collect only the data strictly necessary: email, name, URLs to audit. We do not collect data that is not relevant to the service.

Data accuracy

We give you the ability to update your personal data at any time from your account settings.

Storage limitation

We keep data only as long as necessary. When you delete your account, personal data is removed within 30 days.

Integrity and confidentiality

We implement appropriate technical and organizational measures for data security (see section 5).

4. Rights of Data Subjects

We fully respect all rights granted by the GDPR. Here is how you can exercise them:

RightGDPR ArticleHow to Exercise It
Right of accessArt. 15Email gdpr@techbiz.ae or from your account settings
Right to rectificationArt. 16Account settings or email gdpr@techbiz.ae
Right to erasureArt. 17Email gdpr@techbiz.ae (processed within 30 days)
Right to restrictionArt. 18Email gdpr@techbiz.ae
Right to portabilityArt. 20Export JSON/CSV from your account settings or email
Right to objectArt. 21Email gdpr@techbiz.ae
Withdrawal of consentArt. 7(3)Unsubscribe link in emails or account settings

5. Technical and Organizational Measures

We implement the following measures in accordance with Art. 32 GDPR:

  • Encryption: TLS 1.3 in transit, bcrypt/scrypt for passwords, AES encryption for API keys
  • Data location: PostgreSQL databases hosted in the European Union (Supabase EU)
  • Access control: Authentication with secure sessions (NextAuth), user roles (USER, ADMIN, SUPER_ADMIN)
  • Backup: Automated daily database backups, retained for 30 days
  • Monitoring: Logging of access to sensitive data, anomaly detection
  • Internal audit: Periodic review of security measures
  • Staff training: Training the team on data protection and GDPR

6. International Data Transfers

Primary data is stored in the EU. Where transfers outside the EU are necessary (for example, for hosting or CDN services), we ensure appropriate safeguards are in place:

  • Standard Contractual Clauses (SCC) approved by the European Commission
  • Recognized certifications and codes of conduct
  • Regular assessment of the level of protection in third countries

7. Sub-processors

We use the following sub-processors, all GDPR-compliant:

ProviderPurposeData Location
SupabasePostgreSQL databaseEU
VercelApplication hostingGlobal (CDN), functions in the EU
Email providerSending transactional emailsEU

8. Security Incident Notification

In accordance with Art. 33 and 34 GDPR, in the event of a data security breach:

  • We will notify the supervisory authority within 72 hours of becoming aware of it
  • We will notify affected individuals without undue delay if the risk is high
  • We will document the incident, its effects and the corrective measures taken

9. Impact Assessment (DPIA)

We carry out Data Protection Impact Assessments (DPIA) in accordance with Art. 35 GDPR for any new processing that may present a high risk to the rights and freedoms of data subjects. This includes automated website analysis and lead profiling.

10. Supervisory Authority

You have the right to lodge a complaint with the competent supervisory authority. For users in Romania:

National Supervisory Authority for Personal Data Processing (ANSPDCP)

B-dul G-ral. Gheorghe Magheru 28-30, Sector 1, postal code 010336, Bucharest, Romania

Phone: +40.318.059.211 / +40.318.059.212

Website: www.dataprotection.ro

11. Contact

For any questions or requests related to GDPR:

General email: support@techbiz.ae

DPO email: gdpr@techbiz.ae

Response time: within 30 calendar days