GDPR & Security

GDPR & Security

How we protect your data and respect your privacy rights

Effective date: June 11, 2025

Our commitment: G2G does not sell your personal data. We do not share it with third parties for marketing. We collect only what is necessary to operate our content platform.

1. GDPR Compliance Overview

The General Data Protection Regulation (GDPR) (EU) 2016/679 is a regulation in EU law on data protection and privacy for all individuals within the European Union (EU) and the European Economic Area (EEA). It also addresses the transfer of personal data outside the EU and EEA areas.

G2G is committed to complying with GDPR requirements for any visitor from the EU/EEA. This page outlines our compliance measures, your rights, and how we secure your data.

2. Legal Bases for Processing

Under GDPR, we process your personal data based on the following legal grounds:

✓ Legitimate Interest

We process usage data (analytics) to improve our content and understand audience behavior. You can opt out via cookie consent.

✓ Consent

We ask for your consent before placing non-essential cookies and before sending newsletters.

✓ Contractual Necessity

Not applicable. G2G does not enter into contracts with users. We provide free content only.

✓ Legal Obligation

We may process data to comply with applicable laws, court orders, or government requests.

3. Your Rights Under GDPR

If you are in the EU/EEA, you have the following rights:

Right to AccessRequest a copy of all personal data we hold about you.
Right to RectificationRequest correction of inaccurate or incomplete data.
Right to Erasure (Right to be Forgotten)Request deletion of your personal data.
Right to Restrict ProcessingRequest limited processing of your data.
Right to Data PortabilityRequest your data in a structured, machine-readable format.
Right to ObjectObject to processing based on legitimate interests (including analytics).
Right to Withdraw ConsentWithdraw previously given consent at any time.

To exercise any of these rights, contact us at:
📧 gdpr@g2gdigital.com
📝 We will respond within 30 days as required by GDPR.

4. Data Security Measures

We implement the following technical and organizational security measures:

Encryption

TLS 1.3 for all data in transit. HTTPS enforced across all pages.

Secure Hosting

We use [Vercel/Netlify/AWS] with SOC2-compliant infrastructure.

Access Control

Strict role-based access. Only essential personnel can access systems.

Regular Backups

Automated daily backups with 30-day retention.

5. Data Retention Periods

We retain personal data only as long as necessary:

Data TypeRetention Period
Analytics data (anonymized)14–26 months (depending on analytics provider)
CommentsIndefinite (for conversation continuity) — deletion available upon request
Newsletter emailsUntil unsubscribed, then immediate deletion
Server logs30–90 days (rotating)

6. Subprocessors (Third Parties)

We use the following subprocessors to operate our website. Each is GDPR-compliant:

SubprocessorPurposeLocation
Vercel Inc.Hosting & CDNUSA / Global (GDPR compliant)
Google AnalyticsAnonymized usage analyticsUSA (EU-US Data Privacy Framework)
YouTube (Google)Video hostingGlobal

Note: We do not use any subprocessors for email marketing unless you explicitly opt in.

7. International Data Transfers

Our website is hosted on servers located in [Your Country / EU / USA]. When we transfer personal data from the EU/EEA to a country not deemed adequate by the European Commission, we rely on:

  • EU-US Data Privacy Framework (for certified US entities like Google)
  • Standard Contractual Clauses (SCCs) adopted by the European Commission
  • Your explicit consent (for specific services, where applicable)

8. Data Breach Response

In the event of a personal data breach, we will:

  1. Notify affected users within 72 hours of discovery (as required by GDPR Article 33)
  2. Notify the relevant supervisory authority (if applicable)
  3. Take immediate steps to contain, investigate, and remediate the breach

9. Data Protection Officer (DPO)

G2G is a small content publisher and is not required to appoint a Data Protection Officer under GDPR Article 37. However, for data protection inquiries, please contact:

privacy@g2gdigital.com

10. Supervisory Authority (for EU residents)

If you believe our processing of your personal data violates GDPR, you have the right to lodge a complaint with your local Data Protection Authority (DPA). A list of EU DPAs is available at:
https://edpb.europa.eu/about-edpb/about-edpb/members_en

11. Contact Information

For GDPR-related requests, data deletion requests, or security concerns:

  • GDPR & Privacy Inquiries: gdpr@g2gdigital.com
  • Security Reports: security@g2gdigital.com
  • General Contact: hello@g2gdigital.com

Disclaimer: This GDPR & Security documentation is a template provided for informational purposes only and does not constitute legal advice. You should consult with a qualified attorney to ensure compliance with GDPR and other applicable data protection laws in your jurisdiction.