Skip to Content

GDPR Addendum

Last Updated: September 1, 2026

This GDPR Addendum explains how the General Data Protection Regulation (“GDPR”) and the United Kingdom General Data Protection Regulation (“UK GDPR”) may apply to services provided by Andabhurji Global Solutions.

It is intended to help customers, business partners, and other users understand their responsibilities and rights under data protection law, including those who may not have prior experience with the GDPR.

This Addendum supplements any applicable agreement, Data Processing Agreement (“DPA”), Privacy Policy, Statement of Work, or service contract. If there is a conflict between this Addendum and a signed DPA or written contract, the signed DPA or contract will generally control.

1. What Is the GDPR?

The GDPR is a data protection law that applies to the processing of personal data relating to individuals in the European Economic Area (“EEA”). The UK GDPR applies to processing activities subject to United Kingdom data protection law.

The GDPR is designed to:

  • Give individuals greater control over their personal data

  • Require organizations to process personal data lawfully and transparently

  • Require appropriate security measures

  • Limit the collection and use of personal data

  • Provide individuals with rights regarding their information

  • Require organizations to take responsibility for their data processing activities

The GDPR may apply even when an organization is located outside the EEA or the United Kingdom if it offers goods or services to individuals in those regions or monitors their behavior.

2. Important Definitions

For purposes of this Addendum:

“Personal Data”

“Personal data” means information relating to an identified or identifiable individual. Examples may include:

  • Name

  • Email address

  • Telephone number

  • Postal address

  • Identification number

  • Online identifier

  • IP address

  • Account information

  • Location information

  • Employment information

  • Customer records

  • Device or usage information

Information that has been permanently anonymized so that an individual cannot reasonably be identified may not be considered personal data.

“Processing”

“Processing” means almost any activity involving personal data, including:

  • Collecting

  • Recording

  • Organizing

  • Storing

  • Accessing

  • Using

  • Sharing

  • Transferring

  • Analyzing

  • Modifying

  • Deleting

“Data Subject”

A “data subject” is the individual to whom personal data relates.

“Controller”

A “Controller” is the organization that decides why personal data is processed and how it will be used.

“Processor”

A “Processor” is an organization that processes personal data on behalf of a Controller and according to the Controller’s documented instructions.

“Subprocessor”

A “Subprocessor” is a third-party service provider engaged by a Processor to process personal data on behalf of a Controller.

3. Roles of the Parties

The parties’ roles depend on the services being provided and the nature of the processing activity.

Where Andabhurji Global Solutions processes personal data on behalf of a customer and according to the customer’s instructions:

  • The customer is the Data Controller.

  • Andabhurji Global Solutions is the Data Processor.

The customer, as Controller, is generally responsible for:

  • Determining the purposes of processing

  • Determining the lawful basis for processing

  • Providing appropriate privacy notices

  • Obtaining consent where required

  • Responding to data subject requests

  • Ensuring that instructions given to Andabhurji Global Solutions are lawful

  • Ensuring that personal data is accurate and appropriate for the intended purpose

Andabhurji Global Solutions, as Processor, is generally responsible for:

  • Processing personal data only according to documented instructions

  • Applying appropriate security measures

  • Assisting the Controller where reasonably required

  • Maintaining confidentiality

  • Notifying the Controller of certain data protection incidents

  • Supporting compliance with applicable contractual obligations

In some situations, Andabhurji Global Solutions may act as an independent Controller, such as when processing information for its own business administration, billing, legal compliance, recruitment, marketing, security, or relationship management purposes. The applicable Privacy Policy will describe those activities.

4. Processing Instructions

Andabhurji Global Solutions will process Controller-managed personal data only:

  • To provide the contracted services

  • To perform documented project or service instructions

  • To maintain, secure, troubleshoot, and support the services

  • To comply with applicable law

  • For other purposes expressly authorized in writing by the Controller

The Controller is responsible for ensuring that its instructions comply with applicable data protection laws.

If Andabhurji Global Solutions reasonably believes that an instruction may violate applicable data protection law, it may notify the Controller and request clarification before carrying out the instruction.

5. Categories of Personal Data

Depending on the services used, personal data processed may include:

  • Names and contact details

  • Business contact information

  • Account credentials

  • Customer or supplier information

  • Transaction and billing information

  • Support communications

  • Website or application usage information

  • Device, browser, and technical information

  • Location information

  • Employment or professional information

  • Information submitted through forms or integrations

The specific categories of personal data will depend on the customer’s configuration, instructions, and use of the services.

6. Special Categories of Personal Data

The GDPR provides additional protection for certain sensitive information, including:

  • Health information

  • Biometric information used for identification

  • Genetic information

  • Racial or ethnic origin

  • Political opinions

  • Religious or philosophical beliefs

  • Trade union membership

  • Sex life or sexual orientation

Customers should not provide special-category personal data unless:

  • The processing is necessary for the agreed services

  • The customer has a valid legal basis and any required additional condition

  • The customer has provided appropriate instructions

  • Appropriate safeguards are in place

Unless expressly agreed in writing, Andabhurji Global Solutions does not intend to process special-category personal data as part of ordinary services.

7. Lawful Basis for Processing

The GDPR generally requires a lawful basis for processing personal data. Common lawful bases include:

  • Consent

  • Performance of a contract

  • Compliance with a legal obligation

  • Protection of vital interests

  • Performance of a task carried out in the public interest

  • Legitimate interests, where those interests are not overridden by the individual’s rights

The Controller is responsible for identifying and documenting the lawful basis for processing personal data that it provides to Andabhurji Global Solutions.

Andabhurji Global Solutions does not generally determine the Controller’s lawful basis for processing unless expressly agreed as part of a professional compliance service.

8. Data Minimization and Purpose Limitation

The GDPR encourages organizations to collect only the personal data that is necessary for a specific and legitimate purpose.

Customers should:

  • Avoid sending unnecessary personal data

  • Avoid using services to store unrelated personal information

  • Limit access to individuals who need it

  • Review and delete information that is no longer required

  • Ensure that personal data is used only for the purposes communicated to individuals

Andabhurji Global Solutions may rely on the Controller to determine which data is necessary for the services.

9. Data Subject Rights

Individuals may have rights under the GDPR and UK GDPR. These rights are subject to legal conditions and exceptions.

9.1 Right of Access

An individual may request confirmation of whether their personal data is being processed and may request a copy of that data.

9.2 Right to Rectification

An individual may request correction of inaccurate or incomplete personal data.

9.3 Right to Erasure

An individual may request deletion of personal data in certain circumstances. This is sometimes called the “right to be forgotten.”

The right to erasure is not absolute. Data may need to be retained to comply with legal obligations, establish or defend legal claims, maintain records, or fulfill other lawful purposes.

9.4 Right to Restriction of Processing

An individual may request that processing be limited while a dispute, objection, accuracy issue, or legal question is being reviewed.

9.5 Right to Data Portability

In certain circumstances, an individual may request personal data in a structured, commonly used, and machine-readable format and may request that it be transferred to another organization.

9.6 Right to Object

An individual may object to certain processing activities, including processing based on legitimate interests or direct marketing.

9.7 Rights Relating to Automated Decision-Making

Individuals may have rights concerning decisions based solely on automated processing, including profiling, where those decisions produce legal or similarly significant effects.

9.8 Right to Withdraw Consent

Where processing is based on consent, an individual may withdraw consent at any time. Withdrawal does not generally affect the lawfulness of processing that occurred before withdrawal.

10. Assistance with Data Subject Requests

Where Andabhurji Global Solutions processes personal data as a Processor, the Controller is generally responsible for responding to data subject requests.

Andabhurji Global Solutions will provide reasonable assistance, taking into account the nature of the processing and the information available to it, including assistance with:

  • Locating relevant personal data

  • Exporting personal data

  • Correcting information where technically available

  • Deleting information where instructed and legally permitted

  • Restricting access or processing where technically available

  • Providing information about processing activities

  • Supporting the Controller’s response process

Requests should be sent to:

andabhurji.corp@outlook.com

email@andabhurjiglobal.com

If an individual contacts Andabhurji Global Solutions directly regarding personal data controlled by a customer, we may forward the request to the relevant Controller or direct the individual to contact that Controller.

11. Verification of Requests

To protect personal data, we may need to verify the identity or authority of a person making a request.

We may request information reasonably necessary to confirm:

  • The identity of the requester

  • The account or organization involved

  • The requester’s authority to act for another person

  • The scope of the request

We will not use verification information for unrelated purposes except where required by law or necessary to protect security.

12. Security Measures

Andabhurji Global Solutions implements commercially reasonable technical and organizational measures designed to protect personal data against accidental or unlawful:

  • Destruction

  • Loss

  • Alteration

  • Unauthorized disclosure

  • Unauthorized access

  • Misuse

Depending on the service, safeguards may include:

  • Access controls

  • Authentication requirements

  • Role-based permissions

  • Password protection

  • Encryption where appropriate

  • Secure development practices

  • Backup and recovery procedures

  • Monitoring and logging

  • Vulnerability management

  • Malware protection

  • Confidentiality obligations

  • Incident response procedures

  • Vendor and service provider oversight

Security measures may vary depending on the nature of the service, the sensitivity of the data, the risks involved, and available technology.

No internet-based system can be guaranteed to be completely secure. Customers remain responsible for configuring their accounts, managing user permissions, protecting credentials, and using appropriate security controls.

13. Personal Data Breach Notifications

A personal data breach is a security incident that results in the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to personal data.

Examples may include:

  • Unauthorized access to an account

  • Accidental disclosure of personal data

  • Loss of a device containing personal data

  • Malware or ransomware affecting personal data

  • Sending personal data to the wrong recipient

Where legally required, Andabhurji Global Solutions will notify the Controller without undue delay after becoming aware of a qualifying personal data breach affecting Controller-managed personal data.

Where reasonably available, the notification may include:

  • A description of the incident

  • The categories of personal data affected

  • The likely consequences

  • Measures taken or proposed to address the incident

  • Recommended steps for reducing potential harm

  • Contact information for follow-up questions

The Controller remains responsible for determining whether it must notify a supervisory authority or affected individuals. Under the GDPR, Controllers may be required to notify a supervisory authority within 72 hours after becoming aware of a qualifying breach.

14. Subprocessors

Andabhurji Global Solutions may use third-party service providers to support the delivery of services. These providers may include:

  • Cloud hosting providers

  • Infrastructure providers

  • Email and communication providers

  • Customer support platforms

  • Payment processors

  • Analytics providers

  • Security providers

  • Software and integration providers

Where required, appropriate contractual and security safeguards will be used for Subprocessors.

Customers may request information about relevant Subprocessors by contacting:

andabhurji.corp@outlook.com

email@andabhurjiglobal.com

15. International Data Transfers

Personal data may be processed or accessed in countries outside the EEA, the United Kingdom, or the country where the customer is located.

Where GDPR or UK GDPR applies, international transfers will be supported by an appropriate legal mechanism where required. Depending on the circumstances, this may include:

  • An adequacy decision

  • Standard Contractual Clauses

  • The UK International Data Transfer Agreement

  • The UK Addendum to the EU Standard Contractual Clauses

  • Binding corporate rules

  • Another legally recognized transfer mechanism

Additional safeguards may be considered where required by applicable law.

Customers should understand that international transfers may expose personal data to the laws of the country where the data is processed or accessed.

16. Data Retention and Deletion

Personal data should not be retained longer than necessary for the purpose for which it was collected, unless a longer retention period is required by law, contract, security requirements, dispute resolution, or legitimate business needs.

At the end of the applicable services, Andabhurji Global Solutions may:

  • Return personal data to the Controller

  • Delete personal data

  • Anonymize personal data

  • Retain limited information where legally required or reasonably necessary

Deletion may not be immediate where information exists in backups, archives, logs, disaster recovery systems, or systems subject to legal retention requirements. Such information will generally be isolated and deleted according to applicable retention procedures.

17. Controller Responsibilities

The Controller is responsible for:

  • Providing lawful and documented processing instructions

  • Providing required privacy notices

  • Obtaining valid consent where necessary

  • Responding to data subject requests

  • Maintaining accurate personal data

  • Limiting data collection to necessary information

  • Ensuring that special-category data is handled lawfully

  • Conducting risk assessments where required

  • Determining whether a Data Protection Impact Assessment is necessary

  • Reporting breaches to regulators or individuals where required

  • Ensuring that its use of the services complies with applicable law

18. Data Protection Impact Assessments

A Data Protection Impact Assessment (“DPIA”) is a formal assessment used to identify and reduce privacy risks associated with processing activities that may create a high risk to individuals.

Customers are responsible for determining whether a DPIA is required for their processing activities.

Where reasonably necessary and subject to applicable confidentiality obligations, Andabhurji Global Solutions may provide information about its services and security measures to assist the Controller with a DPIA.

19. Records and Compliance Assistance

Where required by applicable law and appropriate to the services, Andabhurji Global Solutions may provide reasonable information necessary to demonstrate compliance with applicable Processor obligations.

This may include:

  • Security information

  • Processing descriptions

  • Subprocessor information

  • Data retention information

  • Incident response information

  • Relevant compliance documentation

Any audit, assessment, or information request must be reasonable, proportionate, and subject to confidentiality, security, and operational requirements.

20. Supervisory Authorities

A supervisory authority is an independent data protection regulator responsible for enforcing data protection law.

Individuals may have the right to complain to the supervisory authority in:

  • Their country of residence

  • Their place of work

  • The location of the alleged violation

Customers should generally attempt to resolve concerns with the relevant Controller or service provider first, but this does not remove an individual’s right to contact a supervisory authority.

21. Children’s Data

Customers should not provide children’s personal data unless the processing is lawful, necessary, and supported by appropriate safeguards.

Where consent is required for an online service offered directly to children, the Controller is responsible for obtaining any required parental or guardian consent.

22. Changes to This Addendum

We may update this GDPR Addendum from time to time to reflect changes in law, technology, services, or business practices.

The updated version will be posted with a revised “Last Updated” date. Where required, material changes may also be communicated through appropriate channels.

23. Contact Information

Questions about this GDPR Addendum, data protection practices, or privacy-related requests may be sent to:

andabhurji.corp@outlook.com

email@andabhurjiglobal.com

This Addendum provides general information and does not constitute legal advice. Customers should obtain independent legal advice regarding their specific GDPR or UK GDPR obligations.