Effective: April 11, 2026 • Last Updated: April 11, 2026
The General Data Protection Regulation (GDPR) is a comprehensive data protection law that came into effect on May 25, 2018. It applies to all organizations processing personal data of individuals in the European Economic Area (EEA), regardless of where the organization is located.
AutoReach is fully committed to GDPR compliance and protecting the privacy rights of all our users, including those in the EU/EEA.
AutoReach has implemented comprehensive technical and organizational measures to ensure GDPR compliance:
Under GDPR, EU/EEA residents have the following rights:
Request a copy of your personal data we process
Correct inaccurate or incomplete data
Request deletion of your personal data ("Right to be Forgotten")
Limit how we process your data
Receive your data in a structured, machine-readable format
Object to processing based on legitimate interests
Right not to be subject to solely automated decisions
Withdraw previously given consent at any time
We process personal data under the following GDPR lawful bases:
| Processing Activity | Categories of Data | Purpose | Retention |
|---|---|---|---|
| Account Management | Name, email, company, billing info | Service provision, authentication | Account lifetime + 30 days |
| Content Distribution | Social media content, scheduling data | Publishing to connected platforms | Account lifetime |
| Analytics & AI | Usage data, engagement metrics | Service improvement, recommendations | 24 months (anonymized) |
| Payment Processing | Transaction data, payment method | Subscription billing | 7 years (legal requirement) |
| Customer Support | Communication history, tickets | Support provision | 3 years |
AutoReach is headquartered in the United States. When we transfer personal data from the EEA to countries outside the EEA, we ensure appropriate safeguards are in place:
All subprocessors are vetted for GDPR compliance and bound by data processing agreements.
AutoReach has appointed a Data Protection Officer (DPO) to oversee GDPR compliance:
dpo@autoreach.ai
+1 (888) 555-AUTO (Ext. 4)
101 Cyber Tower, San Francisco, CA 94105
EU Representative: DataRep, The Black Church, St. Mary's Place, Dublin 7, Ireland
In accordance with GDPR Articles 33 and 34, AutoReach will:
AutoReach conducts Data Protection Impact Assessments (DPIAs) for high-risk processing activities, including:
DPIAs are reviewed annually and updated when significant changes occur.
Our GDPR compliance framework includes:
To exercise your GDPR rights or for any privacy-related inquiries:
privacy@autoreach.ai
DPO: dpo@autoreach.ai
EU Representative: DataRep, Dublin, Ireland • eurep@autoreach.ai
You have the right to lodge a complaint with your local supervisory authority. A list of EU data protection authorities is available at EDPB website.
We will respond to all legitimate requests within 30 days, as required by GDPR.
Last compliance review: April 2026 • Next review: October 2026