Purpose of this document
This document is here to be transparent. It sets out, in plain language, how ASoc meets its obligations under the GDPR and what that means for you in practice.
It complements our Privacy Policy: where the Privacy Policy describes our overall data practices, this page focuses specifically on our GDPR compliance and the rights the regulation grants you.
What is GDPR?
The GDPR is a European data protection law that came into effect in 2018. It governs how organisations collect, store, and use the personal data of individuals in the EU, and requires that data be handled lawfully, fairly, and transparently.
It also gives individuals clear rights — including the right to access, correct, and erase their data — and obliges companies to keep that data secure and to report serious breaches promptly.
How ASoc implements GDPR
We have built privacy into how ASoc operates. We collect only the data we genuinely need, secure it with encryption in transit and at rest, restrict internal access, and review our processors to make sure they meet the same standard.
To support compliance, we have updated our practices and documentation, including:
- Our Privacy Policy and consent mechanisms.
- Our data processing agreements with third-party providers.
- Internal procedures for handling data subject requests.
- Our security measures, breach response, and retention schedules.
Data we collect
We collect account information such as your name and email address, billing details needed to process payments, support correspondence, and limited technical data like your IP address and how you use our site.
We only collect what is necessary to provide and improve our services, and we are clear at the point of collection about what we are gathering and why.
Why we collect your data
Each piece of data we collect has a lawful basis. We process most data to perform our contract with you — delivering the products and services you purchase. Some processing is based on our legitimate interests, such as keeping ASoc secure, and some, like marketing email, relies on your consent.
We never collect personal data simply because we can. If we do not have a clear purpose and a lawful basis, we do not collect it.
Third-party services we use
To run ASoc we rely on carefully chosen providers for hosting, payment processing, analytics, and email delivery. Each acts as a processor on our behalf and is bound by agreements that require them to protect your data and use it only as instructed.
We review these partners to confirm they offer appropriate safeguards, including for any transfer of data outside the EU, before entrusting them with personal information.
Your data rights
Under the GDPR you have the right to be informed about how your data is used, to access it, to correct inaccuracies, to have it erased, to restrict or object to processing, and to receive your data in a portable format.
You also have the right not to be subject to decisions based solely on automated processing, and the right to withdraw consent at any time where consent is the basis for processing.
How to manage or delete your data
You can review and update much of your information directly from your ASoc account settings. To request a copy of your data, restrict its use, or have it deleted entirely, email us at hello@asoc.io and we will verify your identity and act on your request.
We aim to respond to all data requests within one month, as required by the GDPR, and will let you know if we need more time for a complex request.