General Data Protection Regulation

Close

Effective Date: June 3rd, 2025 Last Updated: June 3rd, 2025

This GDPR Data Processing Agreement ("Agreement") outlines how Prfesr.com, operated by [Your Legal Entity Name, if applicable], complies with the General Data Protection Regulation (GDPR) concerning the collection, storage, and use of personal data of users located in the European Union (EU) and the European Economic Area (EEA).


1. Definitions

  • “Personal Data” refers to any information that can identify an individual user, including name, email, institutional affiliation, IP address, etc.

  • “Processing” means any operation performed on personal data, including collection, storage, modification, retrieval, or deletion.

  • “Data Controller” means the individual or entity that determines the purposes and means of processing personal data (Prfesr.com acts as Data Controller for its platform).

  • “Data Processor” refers to third-party service providers engaged by Prfesr.com who process data on its behalf (e.g., hosting, analytics).


2. Lawful Basis for Processing

We collect and process personal data only when we have a lawful basis under GDPR, including:

  • User Consent – freely given, informed, and unambiguous

  • Contractual Necessity – to provide users access to the platform and its services

  • Legitimate Interests – such as maintaining security, improving functionality, or managing research collaboration tools

  • Legal Obligations – where required by applicable EU law


3. Data Subject Rights (EU/EEA Users)

If you are located in the EU/EEA, you have the following rights under GDPR:

  • Right to Access – Know what data we hold and how it's used

  • Right to Rectification – Request corrections to inaccurate data

  • Right to Erasure – Request deletion of your data (“Right to be Forgotten”)

  • Right to Restriction – Limit how we use your data under certain conditions

  • Right to Portability – Receive your data in a machine-readable format

  • Right to Object – Opt-out of certain processing activities

  • Right to Withdraw Consent – At any time, where consent is the basis of processing

  • Right to Lodge a Complaint – With your local supervisory authority

To exercise any of the above rights, contact us at privacy@prfesr.com.


4. Data Transfers Outside the EU

Prfesr.com is operated from [India / your primary location]. By using the platform, you acknowledge and agree that your data may be transferred to and processed in countries outside of the EU. All such transfers comply with GDPR through:

  • Standard Contractual Clauses (SCCs)

  • Data Processing Agreements with third parties

  • Security and encryption protocols to safeguard data


5. Data Retention

We retain your personal data only for as long as necessary for academic collaboration, regulatory compliance, or to fulfill our contractual obligations. If you delete your account, your data will be anonymized or securely deleted within 30 days, unless otherwise required by law.


6. Data Security Measures

We use commercially reasonable safeguards and best practices to protect your data, including:

  • Encrypted transmission via HTTPS

  • Role-based access controls

  • Periodic audits and vulnerability assessments

  • Secure data storage in certified facilities


7. Subprocessors

Prfesr.com may use third-party subprocessors to help operate our platform. These include:

  • Cloud Hosting Services (e.g., AWS, Azure)

  • Analytics Platforms (e.g., Plausible, Matomo, or Google Analytics with anonymization)

  • Email Services (e.g., Mailgun, SendGrid)

All subprocessors are bound by Data Processing Agreements to comply with GDPR standards.


8. Breach Notification

In the event of a data breach affecting personal data, Prfesr.com will notify affected users and relevant authorities within 72 hours, as required by GDPR.


9. Contact Information

For any GDPR-related questions, complaints, or data subject requests, contact:

myyntech@gmail.com www.prfesr.com