GDPR Statement

Our position under Regulation (EU) 2016/679, written for the procurement and privacy teams who have to assess it.

Template — not yet legally reviewed. This document is a drafting starting point prepared alongside the website build. It must be reviewed and adapted by qualified legal counsel before publication, and the bracketed items completed.

Last updated: · Version 1.0 (draft)

1. Scope

This statement explains how ViralFlux approaches the EU General Data Protection Regulation ("GDPR") and, where applicable, the UK GDPR. It complements our Privacy Policy and the Data Processing Agreement ("DPA") executed with each client. It does not itself create contractual rights; the DPA governs.

2. Controller and processor roles

ViralFlux acts as a data controller for personal data relating to our own website visitors, business enquiries and commercial contacts.

ViralFlux acts as a data processor for all personal data we handle in the course of delivering back-office services — employee records under HR operations, supplier and customer contacts under finance and CRM operations, and any personal data contained in documents we administer. In that role we process only on the client's documented instructions, as recorded in the DPA and Statement of Work.

3. Categories of processing

Typical processing performed on behalf of clients includes:

  • Finance operations — supplier and employee contact details, bank and payment identifiers, payroll inputs, expense records.
  • HR operations — identity and contact data, contractual terms, attendance and leave records, pension enrolment administration.
  • Administrative operations — executive calendar and travel data, board and meeting records.
  • CRM and data operations — customer and prospect contact records, support ticket contents and correspondence.

Where an engagement involves special-category data or data relating to children, that is identified in the DPA and subjected to additional safeguards agreed in advance.

4. Article 28 commitments

Under our standard DPA, ViralFlux commits to:

  • process personal data only on the controller's documented instructions, and to notify the controller if an instruction appears to infringe applicable law;
  • ensure that every person authorised to process the data is bound by a written confidentiality obligation;
  • implement the technical and organisational measures required by Article 32, as described on our Security & Compliance page;
  • engage sub-processors only under written contract imposing equivalent obligations, and give the controller prior notice of intended changes with a right to object;
  • assist the controller in responding to data subject requests and in meeting its Article 32–36 obligations;
  • delete or return all personal data at the end of the engagement, at the controller's election, and delete existing copies unless retention is legally required;
  • make available the information necessary to demonstrate compliance and submit to audits or inspections conducted by the controller or an appointed auditor.

5. Sub-processors

We use a limited set of sub-processors for infrastructure and communications. The current list is maintained and provided as part of the DPA pack, together with each sub-processor's location and processing purpose. Clients receive [30] days' notice of any addition or replacement, with a right to object on reasonable data-protection grounds.

[Insert or link the maintained sub-processor register before publication.]

6. International transfers

ViralFlux is established in Cyprus, an EU member state. Personal data transferred to us from within the EEA is therefore not a restricted transfer and requires no Article 46 safeguard. Transfers from the United Kingdom are covered by the UK's adequacy regulations for the EU. Where a sub-processor is located outside the EEA in a country without an adequacy decision, we impose the 2021 Standard Contractual Clauses supported by a transfer impact assessment and appropriate supplementary measures.

[Confirm the sub-processor locations and, where any sit outside the EEA, the Standard Contractual Clauses module selection with counsel before publication.]

7. Data subject rights

Where ViralFlux acts as processor, requests from data subjects are referred to the client acting as controller. We do not respond directly unless instructed to do so in writing. We provide assistance — retrieval, extraction, correction or deletion — within the timeframes set out in the DPA, so the controller can meet its one-month statutory deadline.

Where ViralFlux is the controller (website and business contacts), requests should be sent to contact@viralflux.info and are handled as described in our Privacy Policy.

8. Personal data breach notification

We maintain a documented incident response procedure. Where we become aware of a personal data breach affecting data processed on a client's behalf, we notify the client's named contact without undue delay and within 24 hours of confirmation, providing the nature of the breach, categories and approximate volume of records affected, likely consequences, and containment and remediation measures taken. This is designed to give controllers sufficient margin within their own 72-hour Article 33 notification window.

9. Records of processing

We maintain records of processing activities under Article 30(2) for every client engagement, covering categories of processing, transfers, and a general description of applied security measures. These records are made available to the controller or a supervisory authority on request.

10. Data protection by design

New engagements are scoped against data minimisation: we request access to the narrowest data set that allows the process to run, and prefer working inside the client's own environment over receiving copies. Where a new processing activity presents a high risk, we support the controller's Data Protection Impact Assessment rather than proceeding without one.

11. Supervisory authority and representation

ViralFlux is established in the EU, so no Article 27 representative is required. Our lead supervisory authority is the Office of the Commissioner for Personal Data Protection of the Republic of Cyprus. [Confirm with counsel whether the scale and nature of processing triggers the obligation to appoint a Data Protection Officer under Article 37.]

12. Contact

Privacy and data protection enquiries:
ViralFlux
Viralflux Labs LTD
Archbishop Makarios III, MITSIS Building
Nicosia, Cyprus
contact@viralflux.info