Last updated: 8 November 2022
We have implemented compliance into our management, technologies, and processes, especially for your privacy.
To keep the customers’ privacy information safe, we have been strictly following GDPR compliance and are in the process of ISO27001 certification.
The General Data Protection Regulation (GDPR), which harmonizes data privacy laws across Europe, takes effect on May 25, 2018, and applies to all EU member states. To see how your personal information is collected, used, and shared when you visit our website, you could also refer to our Privacy Notice.
ISO27001 is an international standard for information security. It helps to ensure the information security management system (ISMS) of a company is aligned with information security best practices.
We pay attention to protecting the personal privacy of users, and we strictly comply with GDPR requirements and process personal data in line with the following principles of GDPR:
Lawfulness, fairness, and transparency
Any data processing activities should be performed in a lawful, fair, and transparent manner.
The GDPR mandates that RAKwireless collects personal data for a specific purpose only and forbids its use for other incompatible purposes.
This principle requires RAKwireless to minimize the personal data being processed to only necessary data items, so the data processing should be adequate, relevant, and limited.
Accuracy of data
Data should not be incomplete, incorrect, or misleading.
The general requirement is as follows: RAKwireless must not keep personal data for longer than RAKwireless needs it.
Integrity and confidentiality of data
This GDPR principle requires that appropriate security measures are in place to prevent data from being accidentally or intentionally compromised. Integrity and confidentiality of data are closely related to information security, including cybersecurity, and physical and administrative security measures.
Under this principle, RAKwireless, as a data controller, takes the responsibility for its processing activities and compliance with the applicable data protection requirements.
What have we done to comply with the GDPR?
We implement appropriate technical and organizational measures to ensure and to be able to demonstrate GDPR compliance.
We comply with data protection by design and by default requirements.
We implement appropriate data protection policies.
We perform data subjects' rights
- right to be informed;
- the right of access;
- the right to rectification;
- the right to erasure;
- the right to restrict processing;
- the right to data portability;
- the right to object;
- rights in relation to automated decision-making, including profiling;
- right to lodge a complaint with a supervisory authority.
We engage data processors (DPO) in accordance with the GDPR.
The Privacy Notices of RAKwireless indicate that to exercise the data subjects’ rights, the users should directly contact the DPO at the dedicated email email@example.com. Therefore, most of the requests should be sent directly to the DPO, who will further process them.
We cooperate with a data protection supervisory authority upon request, and we notify a personal data breach of a data protection supervisory authority and/or data subjects.
We conduct data protection impact assessments (DPIA).
We transfer personal data to third parties only in compliance with the GDPR, etc.
RAKwireless is also in the process of getting ISO27001 certification, which means ensuring information security.