GDPR Statement
Our position under Regulation (EU) 2016/679, written for the procurement and privacy teams who have to assess it.
1. Scope
This statement explains how ViralFlux approaches the EU General Data Protection Regulation ("GDPR") and, where applicable, the UK GDPR. It complements our Privacy Policy and the Data Processing Agreement ("DPA") executed with each client. It does not itself create contractual rights; the DPA governs.
2. Controller and processor roles
ViralFlux acts as a data controller for personal data relating to our own website visitors, business enquiries and commercial contacts.
ViralFlux acts as a data processor for all personal data we handle in the course of delivering back-office services — employee records under HR operations, supplier and customer contacts under finance and CRM operations, and any personal data contained in documents we administer. In that role we process only on the client's documented instructions, as recorded in the DPA and Statement of Work.
3. Categories of processing
Typical processing performed on behalf of clients includes:
- Finance operations — supplier and employee contact details, bank and payment identifiers, payroll inputs, expense records.
- HR operations — identity and contact data, contractual terms, attendance and leave records, pension enrolment administration.
- Administrative operations — executive calendar and travel data, board and meeting records.
- CRM and data operations — customer and prospect contact records, support ticket contents and correspondence.
Where an engagement involves special-category data or data relating to children, that is identified in the DPA and subjected to additional safeguards agreed in advance.
4. Article 28 commitments
Under our standard DPA, ViralFlux commits to:
- process personal data only on the controller's documented instructions, and to notify the controller if an instruction appears to infringe applicable law;
- ensure that every person authorised to process the data is bound by a written confidentiality obligation;
- implement the technical and organisational measures required by Article 32, as described on our Security & Compliance page;
- engage sub-processors only under written contract imposing equivalent obligations, and give the controller prior notice of intended changes with a right to object;
- assist the controller in responding to data subject requests and in meeting its Article 32–36 obligations;
- delete or return all personal data at the end of the engagement, at the controller's election, and delete existing copies unless retention is legally required;
- make available the information necessary to demonstrate compliance and submit to audits or inspections conducted by the controller or an appointed auditor.
5. Sub-processors
We use a limited set of sub-processors for infrastructure and communications. The current list is maintained and provided as part of the DPA pack, together with each sub-processor's location and processing purpose. Clients receive [30] days' notice of any addition or replacement, with a right to object on reasonable data-protection grounds.
[Insert or link the maintained sub-processor register before publication.]
6. International transfers
ViralFlux is established in Hong Kong, which is not the subject of a European Commission adequacy decision. Transfers of personal data from the EEA to ViralFlux therefore rely on the 2021 Standard Contractual Clauses (controller-to-processor, Module Two), supported by a transfer impact assessment and appropriate supplementary measures. The UK International Data Transfer Addendum is used for UK transfers. Equivalent safeguards are imposed on any sub-processor located outside the EEA.
[Confirm the Standard Contractual Clauses module selection and the transfer impact assessment with counsel before publication.]
7. Data subject rights
Where ViralFlux acts as processor, requests from data subjects are referred to the client acting as controller. We do not respond directly unless instructed to do so in writing. We provide assistance — retrieval, extraction, correction or deletion — within the timeframes set out in the DPA, so the controller can meet its one-month statutory deadline.
Where ViralFlux is the controller (website and business contacts), requests should be sent to contact@viralflux.info and are handled as described in our Privacy Policy.
8. Personal data breach notification
We maintain a documented incident response procedure. Where we become aware of a personal data breach affecting data processed on a client's behalf, we notify the client's named contact without undue delay and within 24 hours of confirmation, providing the nature of the breach, categories and approximate volume of records affected, likely consequences, and containment and remediation measures taken. This is designed to give controllers sufficient margin within their own 72-hour Article 33 notification window.
9. Records of processing
We maintain records of processing activities under Article 30(2) for every client engagement, covering categories of processing, transfers, and a general description of applied security measures. These records are made available to the controller or a supervisory authority on request.
10. Data protection by design
New engagements are scoped against data minimisation: we request access to the narrowest data set that allows the process to run, and prefer working inside the client's own environment over receiving copies. Where a new processing activity presents a high risk, we support the controller's Data Protection Impact Assessment rather than proceeding without one.
11. Supervisory authority and representation
[If ViralFlux offers services to data subjects in the EU such that Article 27 applies, appoint an EU representative and insert their name and contact details here. Confirm with counsel whether an Article 27 representative and/or a Data Protection Officer under Article 37 is required.]
12. Contact
Privacy and data protection enquiries:
ViralFlux
Regus, China Hong Kong City Tower 3, Canton Road
Hong Kong
contact@viralflux.info