GDPR Addendum
Last Updated: September 1, 2026
This GDPR Addendum explains how the General Data Protection Regulation (“GDPR”) and the United Kingdom General Data Protection Regulation (“UK GDPR”) may apply to services provided by Andabhurji Global Solutions.
It is intended to help customers, business partners, and other users understand their responsibilities and rights under data protection law, including those who may not have prior experience with the GDPR.
This Addendum supplements any applicable agreement, Data Processing Agreement (“DPA”), Privacy Policy, Statement of Work, or service contract. If there is a conflict between this Addendum and a signed DPA or written contract, the signed DPA or contract will generally control.
1. What Is the GDPR?
The GDPR is a data protection law that applies to the processing of personal data relating to individuals in the European Economic Area (“EEA”). The UK GDPR applies to processing activities subject to United Kingdom data protection law.
The GDPR is designed to:
Give individuals greater control over their personal data
Require organizations to process personal data lawfully and transparently
Require appropriate security measures
Limit the collection and use of personal data
Provide individuals with rights regarding their information
Require organizations to take responsibility for their data processing activities
The GDPR may apply even when an organization is located outside the EEA or the United Kingdom if it offers goods or services to individuals in those regions or monitors their behavior.
2. Important Definitions
For purposes of this Addendum:
“Personal Data”
“Personal data” means information relating to an identified or identifiable individual. Examples may include:
Name
Email address
Telephone number
Postal address
Identification number
Online identifier
IP address
Account information
Location information
Employment information
Customer records
Device or usage information
Information that has been permanently anonymized so that an individual cannot reasonably be identified may not be considered personal data.
“Processing”
“Processing” means almost any activity involving personal data, including:
Collecting
Recording
Organizing
Storing
Accessing
Using
Sharing
Transferring
Analyzing
Modifying
Deleting
“Data Subject”
A “data subject” is the individual to whom personal data relates.
“Controller”
A “Controller” is the organization that decides why personal data is processed and how it will be used.
“Processor”
A “Processor” is an organization that processes personal data on behalf of a Controller and according to the Controller’s documented instructions.
“Subprocessor”
A “Subprocessor” is a third-party service provider engaged by a Processor to process personal data on behalf of a Controller.
3. Roles of the Parties
The parties’ roles depend on the services being provided and the nature of the processing activity.
Where Andabhurji Global Solutions processes personal data on behalf of a customer and according to the customer’s instructions:
The customer is the Data Controller.
Andabhurji Global Solutions is the Data Processor.
The customer, as Controller, is generally responsible for:
Determining the purposes of processing
Determining the lawful basis for processing
Providing appropriate privacy notices
Obtaining consent where required
Responding to data subject requests
Ensuring that instructions given to Andabhurji Global Solutions are lawful
Ensuring that personal data is accurate and appropriate for the intended purpose
Andabhurji Global Solutions, as Processor, is generally responsible for:
Processing personal data only according to documented instructions
Applying appropriate security measures
Assisting the Controller where reasonably required
Maintaining confidentiality
Notifying the Controller of certain data protection incidents
Supporting compliance with applicable contractual obligations
In some situations, Andabhurji Global Solutions may act as an independent Controller, such as when processing information for its own business administration, billing, legal compliance, recruitment, marketing, security, or relationship management purposes. The applicable Privacy Policy will describe those activities.
4. Processing Instructions
Andabhurji Global Solutions will process Controller-managed personal data only:
To provide the contracted services
To perform documented project or service instructions
To maintain, secure, troubleshoot, and support the services
To comply with applicable law
For other purposes expressly authorized in writing by the Controller
The Controller is responsible for ensuring that its instructions comply with applicable data protection laws.
If Andabhurji Global Solutions reasonably believes that an instruction may violate applicable data protection law, it may notify the Controller and request clarification before carrying out the instruction.
5. Categories of Personal Data
Depending on the services used, personal data processed may include:
Names and contact details
Business contact information
Account credentials
Customer or supplier information
Transaction and billing information
Support communications
Website or application usage information
Device, browser, and technical information
Location information
Employment or professional information
Information submitted through forms or integrations
The specific categories of personal data will depend on the customer’s configuration, instructions, and use of the services.
6. Special Categories of Personal Data
The GDPR provides additional protection for certain sensitive information, including:
Health information
Biometric information used for identification
Genetic information
Racial or ethnic origin
Political opinions
Religious or philosophical beliefs
Trade union membership
Sex life or sexual orientation
Customers should not provide special-category personal data unless:
The processing is necessary for the agreed services
The customer has a valid legal basis and any required additional condition
The customer has provided appropriate instructions
Appropriate safeguards are in place
Unless expressly agreed in writing, Andabhurji Global Solutions does not intend to process special-category personal data as part of ordinary services.
7. Lawful Basis for Processing
The GDPR generally requires a lawful basis for processing personal data. Common lawful bases include:
Consent
Performance of a contract
Compliance with a legal obligation
Protection of vital interests
Performance of a task carried out in the public interest
Legitimate interests, where those interests are not overridden by the individual’s rights
The Controller is responsible for identifying and documenting the lawful basis for processing personal data that it provides to Andabhurji Global Solutions.
Andabhurji Global Solutions does not generally determine the Controller’s lawful basis for processing unless expressly agreed as part of a professional compliance service.
8. Data Minimization and Purpose Limitation
The GDPR encourages organizations to collect only the personal data that is necessary for a specific and legitimate purpose.
Customers should:
Avoid sending unnecessary personal data
Avoid using services to store unrelated personal information
Limit access to individuals who need it
Review and delete information that is no longer required
Ensure that personal data is used only for the purposes communicated to individuals
Andabhurji Global Solutions may rely on the Controller to determine which data is necessary for the services.
9. Data Subject Rights
Individuals may have rights under the GDPR and UK GDPR. These rights are subject to legal conditions and exceptions.
9.1 Right of Access
An individual may request confirmation of whether their personal data is being processed and may request a copy of that data.
9.2 Right to Rectification
An individual may request correction of inaccurate or incomplete personal data.
9.3 Right to Erasure
An individual may request deletion of personal data in certain circumstances. This is sometimes called the “right to be forgotten.”
The right to erasure is not absolute. Data may need to be retained to comply with legal obligations, establish or defend legal claims, maintain records, or fulfill other lawful purposes.
9.4 Right to Restriction of Processing
An individual may request that processing be limited while a dispute, objection, accuracy issue, or legal question is being reviewed.
9.5 Right to Data Portability
In certain circumstances, an individual may request personal data in a structured, commonly used, and machine-readable format and may request that it be transferred to another organization.
9.6 Right to Object
An individual may object to certain processing activities, including processing based on legitimate interests or direct marketing.
9.7 Rights Relating to Automated Decision-Making
Individuals may have rights concerning decisions based solely on automated processing, including profiling, where those decisions produce legal or similarly significant effects.
9.8 Right to Withdraw Consent
Where processing is based on consent, an individual may withdraw consent at any time. Withdrawal does not generally affect the lawfulness of processing that occurred before withdrawal.
10. Assistance with Data Subject Requests
Where Andabhurji Global Solutions processes personal data as a Processor, the Controller is generally responsible for responding to data subject requests.
Andabhurji Global Solutions will provide reasonable assistance, taking into account the nature of the processing and the information available to it, including assistance with:
Locating relevant personal data
Exporting personal data
Correcting information where technically available
Deleting information where instructed and legally permitted
Restricting access or processing where technically available
Providing information about processing activities
Supporting the Controller’s response process
Requests should be sent to:
If an individual contacts Andabhurji Global Solutions directly regarding personal data controlled by a customer, we may forward the request to the relevant Controller or direct the individual to contact that Controller.
11. Verification of Requests
To protect personal data, we may need to verify the identity or authority of a person making a request.
We may request information reasonably necessary to confirm:
The identity of the requester
The account or organization involved
The requester’s authority to act for another person
The scope of the request
We will not use verification information for unrelated purposes except where required by law or necessary to protect security.
12. Security Measures
Andabhurji Global Solutions implements commercially reasonable technical and organizational measures designed to protect personal data against accidental or unlawful:
Destruction
Loss
Alteration
Unauthorized disclosure
Unauthorized access
Misuse
Depending on the service, safeguards may include:
Access controls
Authentication requirements
Role-based permissions
Password protection
Encryption where appropriate
Secure development practices
Backup and recovery procedures
Monitoring and logging
Vulnerability management
Malware protection
Confidentiality obligations
Incident response procedures
Vendor and service provider oversight
Security measures may vary depending on the nature of the service, the sensitivity of the data, the risks involved, and available technology.
No internet-based system can be guaranteed to be completely secure. Customers remain responsible for configuring their accounts, managing user permissions, protecting credentials, and using appropriate security controls.
13. Personal Data Breach Notifications
A personal data breach is a security incident that results in the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to personal data.
Examples may include:
Unauthorized access to an account
Accidental disclosure of personal data
Loss of a device containing personal data
Malware or ransomware affecting personal data
Sending personal data to the wrong recipient
Where legally required, Andabhurji Global Solutions will notify the Controller without undue delay after becoming aware of a qualifying personal data breach affecting Controller-managed personal data.
Where reasonably available, the notification may include:
A description of the incident
The categories of personal data affected
The likely consequences
Measures taken or proposed to address the incident
Recommended steps for reducing potential harm
Contact information for follow-up questions
The Controller remains responsible for determining whether it must notify a supervisory authority or affected individuals. Under the GDPR, Controllers may be required to notify a supervisory authority within 72 hours after becoming aware of a qualifying breach.
14. Subprocessors
Andabhurji Global Solutions may use third-party service providers to support the delivery of services. These providers may include:
Cloud hosting providers
Infrastructure providers
Email and communication providers
Customer support platforms
Payment processors
Analytics providers
Security providers
Software and integration providers
Where required, appropriate contractual and security safeguards will be used for Subprocessors.
Customers may request information about relevant Subprocessors by contacting:
15. International Data Transfers
Personal data may be processed or accessed in countries outside the EEA, the United Kingdom, or the country where the customer is located.
Where GDPR or UK GDPR applies, international transfers will be supported by an appropriate legal mechanism where required. Depending on the circumstances, this may include:
An adequacy decision
Standard Contractual Clauses
The UK International Data Transfer Agreement
The UK Addendum to the EU Standard Contractual Clauses
Binding corporate rules
Another legally recognized transfer mechanism
Additional safeguards may be considered where required by applicable law.
Customers should understand that international transfers may expose personal data to the laws of the country where the data is processed or accessed.
16. Data Retention and Deletion
Personal data should not be retained longer than necessary for the purpose for which it was collected, unless a longer retention period is required by law, contract, security requirements, dispute resolution, or legitimate business needs.
At the end of the applicable services, Andabhurji Global Solutions may:
Return personal data to the Controller
Delete personal data
Anonymize personal data
Retain limited information where legally required or reasonably necessary
Deletion may not be immediate where information exists in backups, archives, logs, disaster recovery systems, or systems subject to legal retention requirements. Such information will generally be isolated and deleted according to applicable retention procedures.
17. Controller Responsibilities
The Controller is responsible for:
Providing lawful and documented processing instructions
Providing required privacy notices
Obtaining valid consent where necessary
Responding to data subject requests
Maintaining accurate personal data
Limiting data collection to necessary information
Ensuring that special-category data is handled lawfully
Conducting risk assessments where required
Determining whether a Data Protection Impact Assessment is necessary
Reporting breaches to regulators or individuals where required
Ensuring that its use of the services complies with applicable law
18. Data Protection Impact Assessments
A Data Protection Impact Assessment (“DPIA”) is a formal assessment used to identify and reduce privacy risks associated with processing activities that may create a high risk to individuals.
Customers are responsible for determining whether a DPIA is required for their processing activities.
Where reasonably necessary and subject to applicable confidentiality obligations, Andabhurji Global Solutions may provide information about its services and security measures to assist the Controller with a DPIA.
19. Records and Compliance Assistance
Where required by applicable law and appropriate to the services, Andabhurji Global Solutions may provide reasonable information necessary to demonstrate compliance with applicable Processor obligations.
This may include:
Security information
Processing descriptions
Subprocessor information
Data retention information
Incident response information
Relevant compliance documentation
Any audit, assessment, or information request must be reasonable, proportionate, and subject to confidentiality, security, and operational requirements.
20. Supervisory Authorities
A supervisory authority is an independent data protection regulator responsible for enforcing data protection law.
Individuals may have the right to complain to the supervisory authority in:
Their country of residence
Their place of work
The location of the alleged violation
Customers should generally attempt to resolve concerns with the relevant Controller or service provider first, but this does not remove an individual’s right to contact a supervisory authority.
21. Children’s Data
Customers should not provide children’s personal data unless the processing is lawful, necessary, and supported by appropriate safeguards.
Where consent is required for an online service offered directly to children, the Controller is responsible for obtaining any required parental or guardian consent.
22. Changes to This Addendum
We may update this GDPR Addendum from time to time to reflect changes in law, technology, services, or business practices.
The updated version will be posted with a revised “Last Updated” date. Where required, material changes may also be communicated through appropriate channels.
23. Contact Information
Questions about this GDPR Addendum, data protection practices, or privacy-related requests may be sent to:
This Addendum provides general information and does not constitute legal advice. Customers should obtain independent legal advice regarding their specific GDPR or UK GDPR obligations.