GDPR COMPLIANCE
GDPR Compliant Since May 2018
✅ Hamhey Corporation fully complies with EU Regulation 2016/679 (GDPR) and maintains a dedicated EU representative in Berlin, Germany.
GDPR Compliance & Data Protection
Last Updated: January 2025
How Hamhey complies with the General Data Protection Regulation (GDPR) and protects your personal data.
EU Representative
As a Delaware-based corporation offering services in the European Union, Hamhey has designated an EU representative under Article 27 GDPR:
Hamhey EU Data Protection Office
Clara-Meinek-Str. 3
12049 Berlin, Germany
Email: eu-privacy@hamhey.com
Phone: +49 30 123 456 789
Your GDPR Rights
Under GDPR, you have the following rights regarding your personal data:
- Right to Access (Article 15): Request a copy of all personal data we hold about you
- Right to Rectification (Article 16): Correct inaccurate or incomplete personal data
- Right to Erasure / "Right to be Forgotten" (Article 17): Request deletion of your personal data (subject to legal obligations)
- Right to Restriction of Processing (Article 18): Limit how we use your personal data
- Right to Data Portability (Article 20): Receive your data in a machine-readable format
- Right to Object (Article 21): Object to processing based on legitimate interests or for direct marketing
- Rights Related to Automated Decision-Making (Article 22): Not be subject to decisions based solely on automated processing
- Right to Withdraw Consent (Article 7): Withdraw consent at any time for consent-based processing
- Right to Lodge a Complaint (Article 77): File a complaint with your local data protection authority
How to Exercise Your Rights
To exercise any of your GDPR rights, you can:
- Submit a Data Subject Request: Email gdpr@hamhey.com with subject line "GDPR Data Subject Request"
- Use Our Online Form: Visit hamhey.com/gdpr-request (secure form)
- Contact EU Representative: eu-privacy@hamhey.com or +49 30 123 456 789
- Mail Written Request: Hamhey GDPR Team, Clara-Meinek-Str. 3, 12049 Berlin, Germany
Verification Required
To protect your privacy, we may request proof of identity before processing your request.
Response Time: We will respond within 30 days (extendable to 60 days for complex requests).
Legal Bases for Data Processing
We process personal data based on the following lawful grounds under GDPR Article 6:
- Contractual Necessity (Article 6(1)(b)): Processing necessary to fulfill our contract with you
- Consent (Article 6(1)(a)): Marketing communications, cookies, AI chat features (where you've given explicit consent)
- Legitimate Interests (Article 6(1)(f)): Fraud prevention, security monitoring, platform improvements
- Legal Obligations (Article 6(1)(c)): Tax compliance, anti-money laundering, responding to law enforcement
International Data Transfers
As a U.S.-based company, we transfer EU user data to the United States. We ensure appropriate safeguards:
- EU-U.S. Data Privacy Framework: Hamhey complies with the EU-U.S. Data Privacy Framework
- Standard Contractual Clauses (SCCs): We use European Commission-approved SCCs for data transfers
- Encryption: All data transfers are encrypted using TLS 1.3; data at rest is encrypted using AES-256
- Third-Party Compliance: All subprocessors (Stripe, OpenAI, AWS) are GDPR-compliant
Data Retention Periods
We retain personal data only as long as necessary:
| Data Type | Retention Period | Legal Basis |
|---|---|---|
| Account information | Until deletion + 30 days | Contract |
| Booking records | 7 years after completion | Legal obligations |
| Payment data | 7 years (via Stripe) | Financial regulations |
| Chat logs | 90 days | Service improvement |
| Marketing consent | Until withdrawal + 30 days | Consent |
Supervisory Authority
If you believe your GDPR rights have been violated, you have the right to lodge a complaint:
German Data Protection Authority
Berliner Beauftragte für Datenschutz und Informationsfreiheit
Friedrichstr. 219
10969 Berlin, Germany
GDPR Questions or Requests?
For any GDPR-related inquiries, data subject requests, or privacy concerns:
GDPR Requests & Inquiries
Email: gdpr@hamhey.com
EU Representative: eu-privacy@hamhey.com
Data Protection Officer: dpo@hamhey.com
Hamhey EU Data Protection Office
Clara-Meinek-Str. 3
12049 Berlin, Germany
Phone: +49 30 123 456 789
Last Updated: January 2025 | Hamhey Corporation
This GDPR compliance page supplements our Data Protection Policy and Privacy Policy.
