The General Data Protection Regulation (GDPR) gives individuals in the European Union comprehensive rights over their personal data. At Stratta, we are committed to full GDPR compliance and transparency in how we handle your personal information.
This page explains your rights under GDPR and how to exercise them when using our revenue and growth planning platform.
We process your personal data under the following lawful bases:
We process data necessary to provide our platform services:
We process data for legitimate business purposes:
We ask for explicit consent for:
We process data when required by law:
You have the right to know how we collect and use your personal data.
How to exercise: Review our Privacy Policy and this GDPR page.
You can request a copy of all personal data we hold about you.
How to exercise: Use the "Export Data" feature in your account settings or contact us.
You can correct inaccurate or incomplete personal data.
How to exercise: Update your profile in account settings or contact support.
You can request deletion of your personal data ("right to be forgotten").
How to exercise: Use "Delete Account" in settings or send a deletion request.
You can limit how we process your data in certain circumstances.
How to exercise: Contact our Data Protection Officer with your specific request.
You can receive your data in a machine-readable format.
How to exercise: Use the "Export Data" feature or request a data export.
You can object to processing based on legitimate interests or direct marketing.
How to exercise: Opt-out via account settings or email unsubscribe links.
You have rights regarding automated processing and profiling.
How to exercise: Contact us to request human review of automated decisions.
Stratta does not typically process special categories of personal data (sensitive data such as health, racial origin, political opinions, etc.). However, if such data is inadvertently collected through:
We will handle it with extra care and delete it promptly unless we have explicit consent or another lawful basis for processing.
When we transfer your data outside the EU/EEA, we ensure adequate protection through:
We transfer data to countries recognized by the European Commission as providing adequate protection (such as the UK under the UK GDPR).
For transfers to other countries, we use the European Commission's Standard Contractual Clauses to ensure equivalent protection.
Stratta uses automated processing in the following ways:
Important: Our automated systems are designed to execute your instructions, not make independent decisions about your campaigns. You retain full control over all automation rules and can request human review at any time.
We retain personal data only as long as necessary for the purposes for which it was collected:
| Data Type | Retention Period | Legal Basis |
|---|---|---|
| Account Data | Duration of contract + 90 days | Contract performance |
| Campaign Performance Data | 3 years | Legitimate interests |
| Financial Records | 7 years | Legal obligation |
| Marketing Preferences | Until withdrawn | Consent |
| Support Communications | 3 years | Legitimate interests |
Many rights can be exercised directly through your account:
For rights that require manual processing or have complex requirements:
Email: dpo@revnue.com
Subject Line: GDPR Rights Request - [Type of Request]
Required Information:
If you believe we have not handled your personal data properly, you have the right to lodge a complaint with:
You can contact your local data protection authority in the EU member state where you live, work, or where the alleged infringement occurred.
UK Users: Information Commissioner's Office (ICO)
Website: ico.org.uk | Phone: 0303 123 1113
While you have the right to contact a supervisory authority directly, we encourage you to contact us first so we can try to resolve your concern promptly and directly.
Data Protection Officer: dpo@stratta.com
General Privacy Questions: privacy@stratta.com
Postal Address: [Company Address]
We aim to respond to all GDPR-related inquiries within 72 hours and to resolve requests within the legal timeframes specified above.