ResearchCaveLegal
  • EnglishEnglish
  • TürkçeTurkish
  • DeutschGerman
  • العربيةArabic
Sign in
Legal document

GDPR Compliance and Data Processing

Version v2.0 · Effective Thursday, July 30, 2026

Version history
v2.07/30/2026

This notice summarises ResearchCave's approach to EU and EEA data protection.

Roles and accountability

acts as controller for account, billing, security, support, product administration, and its own platform purposes. Where a business customer determines purposes and means for customer-controlled data, the applicable agreement may appoint ResearchCave as processor. Processing activities, lawful bases, recipients, transfers, retention, risks, and safeguards are recorded and reviewed.

Data protection by design

New features are assessed for necessity, proportionality, minimisation, access, transparency, retention, security, and user control. High-risk processing is subject to a data protection impact assessment before launch, and privacy-protective defaults are used.

Rights and response

Individuals may have rights to information, access, rectification, erasure, restriction, portability, objection, withdrawal of consent, and safeguards relating to automated decisions. Requests can be submitted to . Identity is verified proportionately, requests are tracked, and responses are provided within the legally applicable period.

Processors and transfers

Processors are selected through risk review and written data-protection terms addressing instructions, confidentiality, security, subprocessors, assistance, deletion or return, and audit information. Restricted transfers use an available legal mechanism such as an adequacy decision or standard contractual clauses, with transfer assessments and supplementary measures where appropriate.

Security and incidents

Risk-appropriate measures include least-privilege access, authentication controls, encryption, logging, backups, secure development, testing, vulnerability management, availability and restoration planning, vendor controls, and incident response. Suspected personal-data breaches are assessed, documented, and notified within applicable deadlines.

DPA

Customers requiring a Data Processing Agreement should contact . This page is a summary and does not itself replace an executed DPA.

Permanent URL /en/gdpr/v2.0
© 2026 ResearchCave
DMCAPrivacyTerms