GDPR
Our GDPR compliance commitments, your rights as an EU data subject, and contact details for our DPO.
Last updated: January 2025
1. Our GDPR commitment
Infinity Code Labs is fully compliant with the EU General Data Protection Regulation (GDPR). We act as both a Data Controller (for our website visitors and newsletter subscribers) and a Data Processor (for client data we handle under contract). This page explains your rights and our obligations under GDPR.
2. Legal basis for processing
We process personal data under the following legal bases: (a) Consent — for marketing emails and analytics cookies; (b) Contract — for processing needed to deliver services under signed MSAs; (c) Legal obligation — for tax, accounting, and regulatory compliance; (d) Legitimate interest — for security monitoring and fraud prevention.
3. Your GDPR rights
Under GDPR, you have the right to: access your personal data (Article 15), rectify inaccurate data (Article 16), erase your data (Article 17, 'right to be forgotten'), restrict processing (Article 18), data portability (Article 20), object to processing (Article 21), and not be subject to automated decision-making (Article 22). To exercise any right, email privacy@infinitycodelabs.com.
4. International data transfers
We may transfer personal data outside the EU/EEA. We rely on Standard Contractual Clauses (SCCs) approved by the European Commission, supplemented by Transfer Impact Assessments (TIAs) for transfers to the US. We do not transfer data to jurisdictions deemed inadequate by the European Commission without additional safeguards.
5. Data retention
We retain personal data only as long as necessary for the purposes for which it was collected. Contact form submissions: 24 months. Newsletter subscriptions: until unsubscribe. Client project data: per the retention clause in the MSA, typically 7 years for financial records, 90 days post-termination for production data.
6. Sub-processors
We use the following sub-processors: AWS (hosting), Google Workspace (email/docs), Stripe (payments), HubSpot (CRM), Datadog (monitoring). A full list with purposes and locations is available at infinitycodelabs.com/sub-processors. We notify clients 30 days before adding new sub-processors.
7. EU representatives
Under Article 27 of GDPR, we have designated representatives in the EU: Ireland (Edenderry House, Dublin) and Germany (Friedrichstraße 68, Berlin). EU residents may contact these representatives directly with GDPR inquiries. Our lead supervisory authority is the Irish Data Protection Commission.
8. Data Protection Officer
Our Data Protection Officer (DPO) is available at privacy@infinitycodelabs.com. The DPO oversees our GDPR compliance program, advises on data protection impact assessments, and serves as the point of contact for supervisory authorities.
9. Breach notification
In the event of a personal data breach likely to result in a risk to your rights and freedoms, we will notify the relevant supervisory authority within 72 hours (Article 33) and affected data subjects without undue delay (Article 34).
10. Contact
For GDPR inquiries, contact our DPO at privacy@infinitycodelabs.com or write to our EU representative at Edenderry House, Main Street, Edenderry, Co. Offaly, Ireland.