This is the internal policy of DNZ Consulting LLC for personal data. The public Privacy Policy explains the same subject to people outside the company.
This policy applies to every system, device, and person that DNZ Consulting LLC uses to do business. DNZ Consulting LLC is a small company. The Managing Member owns this policy. The Managing Member also acts as the Security Officer and the Data Protection Officer.
The Managing Member reviews this policy one time each year. The Managing Member also reviews it after any security incident.
The Managing Member acts as the Data Protection Officer. The contact address is privacy@dancykier.com. The Data Protection Officer approves any new processing of personal data before it starts.
When we process personal data for a merchant, the merchant is the controller. We:
We keep a record of every processing activity. The record holds the purpose, the categories of data and people, the recipients, the retention period, and the security measures.
Before a new processing activity starts, the Data Protection Officer checks the legal basis, the data minimization, the retention period, and the security controls. A high-risk activity gets a written impact assessment.
The Privacy Policy states the retention periods. At the end of a contract we delete all customer personal data within 30 days. We confirm the deletion in writing when the customer asks.
A personal data breach follows the Incident Response Policy. We notify the platform and affected merchants within 24 hours of confirmation, and a supervisory authority within 72 hours where the law requires it.
Every person who handles personal data reads this policy before they get access, and again each year.
The Managing Member reviews this policy one time each year.