GDPR
Compliance Statement for SATOSHICON LLC
As a company committed to transparency and honesty, SATOSHICON LLC wishes to inform you about how the General Data Protection Regulation (GDPR) affects us, our clients, and what steps we are taking to ensure compliance.
What is GDPR?
The General Data Protection Regulation (GDPR) is a comprehensive data privacy law enacted by the European Union (EU) on May 25, 2018, designed to enhance the data privacy rights of EU individuals and standardize data protection laws across the EU. The scope of the GDPR applies to companies operating within the EU, as well as companies outside the EU that offer goods or services to, or monitor the behavior of, EU residents.
How Does GDPR Apply to Us?
As part of our operations, SATOSHICON LLC and its associated brands, including Deshima Music, bitcoin.shirts.com, and the Web3 Löwen Discord Community, are committed to complying with the GDPR. We process personal data on behalf of our clients and users and ensure that we meet all the regulatory requirements related to data protection.
Under the GDPR, SATOSHICON LLC is considered a Data Processor. The regulation defines two key roles:
Data Controllers: Organizations that determine the purposes and means of processing personal data of EU residents.
Data Processors: Organizations that process personal data on behalf of Data Controllers.
As a US-based company, SATOSHICON LLC processes personal data on behalf of its clients (who are Data Controllers) and ensures that all operations comply with the GDPR’s provisions.
What Are We Doing to Ensure GDPR Compliance?
We have reviewed and updated our systems, processes, and policies to ensure that SATOSHICON LLC, Deshima Music, bitcoin.shirts.com, and the Web3 Löwen Discord Community comply with GDPR. This includes implementing security measures and providing our users with transparency regarding their personal data.
To ensure our compliance with GDPR, we have undertaken several key actions:
Internal Review & Updates: We have conducted a thorough review of our systems, processes, and policies to ensure they align with the GDPR’s requirements. Any necessary updates have been made to our documentation and practices.
Technical and Organizational Safeguards: SATOSHICON LLC has implemented appropriate technical and organizational measures to protect personal data, including encryption, access controls, and data retention policies.
Training and Awareness: We have educated our team and partners on GDPR compliance and data protection best practices to maintain a high standard of privacy protection.
What Is Your Obligation as Our Client?
When using our services, it is important to understand that Deshima Music, bitcoin.shirts.com, and Web3 Löwen Discord Community may also be processing your data. As a Data Controller, it is your responsibility to ensure that you have the legal basis for processing personal data and that you provide proper notice to individuals about how their data will be used.
When SATOSHICON LLC acts as a Data Processor on behalf of our clients, our clients, as Data Controllers, hold responsibility for ensuring that their use of our services is compliant with the GDPR.
As a client, we urge you to consider the following:
Data Processing Agreement (DPA):
The GDPR mandates that Data Controllers have a formal contract with their Data Processors. This contract, known as a Data Processing Agreement (DPA), outlines the terms of processing personal data and must include specific clauses as required by the GDPR. We will provide a DPA upon request.Legal Basis for Data Processing:
Under the GDPR, Data Controllers must ensure that there is a lawful basis for processing personal data. This may include obtaining explicit consent, fulfilling contractual obligations, or complying with legal requirements. Clients must also inform individuals about how their data will be processed and for what purposes.Retention and Data Minimization:
The GDPR mandates that personal data is retained only for as long as necessary to fulfill the purposes for which it was collected. Data Controllers must implement policies and procedures for data retention and deletion. As part of our services, we ensure that data retention practices are in line with the GDPR, but clients may also need to manage and delete data appropriately to remain compliant.