GDPR Compliance

Your rights under the EU General Data Protection Regulation and Radarlo's compliance practices.

Effective date: 14 Nisan 2026

Version: 3.0

Scope

This page explains your rights under the GDPR (EU 2016/679) and UK GDPR if you reside in the EU/EEA or the United Kingdom. It supplements our Privacy Policy: /privacy.

Controller and EU Representative

Controller

Radarlo — İstanbul, Türkiye · dpo@radarlo.com

EU Representative (Art. 27)

To be published — EU-based provider (Prighter / VeraSafe or similar) · eu-rep@radarlo.com

UK Representative

A separate UK representative is being appointed post-Brexit · uk-rep@radarlo.com

Your GDPR Rights

Right to Access (Art. 15)

Obtain confirmation of processing, information about purposes, and a copy of your data.

Right to Rectification (Art. 16)

Correct inaccurate or incomplete data.

Right to Erasure / Right to be Forgotten (Art. 17)

Request deletion of your data (subject to legal retention obligations).

Right to Restriction (Art. 18)

Request that we restrict processing in specific circumstances.

Right to Portability (Art. 20)

Receive your data in a structured, commonly used, machine-readable format.

Right to Object (Art. 21)

Object at any time to processing based on legitimate interests or direct marketing.

Rights re. Automated Decisions (Art. 22)

Radarlo does not carry out solely automated decisions that significantly affect you.

Right to Complain (Art. 77)

Lodge a complaint with your local supervisory authority (list below).

To exercise your rights: /legal/request or dpo@radarlo.com.

International Transfers and SCCs

Some of our sub-processors (Google, Apple) transfer data outside the EEA. Our transfer bases are:

  • EU Commission SCCs (2021/914) + Transfer Impact Assessment (TIA)
  • UK IDTA / UK Addendum
  • EU–US Data Privacy Framework for participating providers

Copies of the SCCs and a TIA summary are available on request from dpo@radarlo.com.

Public DPIA Summary (Art. 35)

Because continuous location processing involves large-scale systematic monitoring, we conducted a DPIA under Art. 35. Key findings:

  • Purpose: deliver nearby radar alerts to the user.
  • Data minimisation: raw GPS trails are not persisted server-side; only used in-memory for querying.
  • Risk level: moderate → low after technical and organisational controls.
  • Controls: TLS in transit, role-based access, spatial indexing on PostGIS queries, audit logging.

Supervisory Authorities (Art. 13(2)(d))

Your local authority you can contact if your rights have been infringed.

CountryAuthorityWeb
AustriaDatenschutzbehörde (DSB)dsb.gv.at
BelgiumGegevensbeschermingsautoriteit (GBA/APD)autoriteprotectiondonnees.be
BulgariaCommission for Personal Data Protectioncpdp.bg
CroatiaAZOPazop.hr
CyprusOffice of the Commissioner for PDPdataprotection.gov.cy
Czech RepublicÚřad pro ochranu osobních údajů (ÚOOÚ)uoou.cz
DenmarkDatatilsynetdatatilsynet.dk
EstoniaAndmekaitse Inspektsioonaki.ee
FinlandTietosuojavaltuutetun toimistotietosuoja.fi
FranceCNILcnil.fr
GermanyBfDI + Länder authoritiesbfdi.bund.de
GreeceHDPAdpa.gr
HungaryNAIHnaih.hu
IcelandPersónuverndpersonuvernd.is
IrelandData Protection Commission (DPC)dataprotection.ie
ItalyGarante per la protezione dei dati personaligaranteprivacy.it
LatviaData State Inspectoratedvi.gov.lv
LiechtensteinDatenschutzstellellv.li
LithuaniaState Data Protection Inspectorate (VDAI)vdai.lrv.lt
LuxembourgCNPDcnpd.public.lu
MaltaIDPCidpc.org.mt
NetherlandsAutoriteit Persoonsgegevens (AP)autoriteitpersoonsgegevens.nl
NorwayDatatilsynetdatatilsynet.no
PolandUODOuodo.gov.pl
PortugalCNPDcnpd.pt
RomaniaANSPDCPdataprotection.ro
SlovakiaÚOOÚ SRdataprotection.gov.sk
SloveniaIP-RSip-rs.si
SpainAEPDaepd.es
SwedenIMYimy.se
United KingdomICOico.org.uk

Breach Notification

We notify the competent authority within 72 hours (Art. 33), and affected users without undue delay where there is a high risk (Art. 34).

Exercise your rights

Requests are answered within 30 days.

Radarlo – #1 International Radar App