Back to Home

GDPR Compliance

General Data Protection Regulation • Last updated: August 1, 2025

Your Data Rights Matter

Reica is committed to protecting your privacy and ensuring compliance with the European Union's General Data Protection Regulation (GDPR). This page outlines how we safeguard your personal data and respect your rights.

1. Our GDPR Commitment

As a technology company serving users across the European Union, Reica fully complies with GDPR requirements. We have implemented comprehensive data protection measures and respect all individual rights outlined in the regulation.

Lawful Basis

We process personal data only when we have a valid legal basis, such as consent, contract fulfillment, or legitimate interests.

Data Security

We implement appropriate technical and organizational measures to ensure data security and prevent unauthorized access.

2. Your GDPR Rights

Under GDPR, you have specific rights regarding your personal data. Here's how to exercise them with Reica:

Right to Information (Art. 13-14)

You have the right to know how we process your personal data.

How to exercise: Review our Privacy Policy or contact our DPO for detailed information.

Right of Access (Art. 15)

You can request a copy of the personal data we hold about you.

How to exercise: Log into your account settings or email gdpr@getreica.com with subject "Data Access Request"

Right to Rectification (Art. 16)

You can correct inaccurate or incomplete personal data.

How to exercise: Update information in your account profile or contact support for assistance.

Right to Erasure (Art. 17)

You can request deletion of your personal data ("right to be forgotten").

How to exercise: Delete your account through settings or email gdpr@getreica.com with subject "Data Deletion Request"

Right to Restrict Processing (Art. 18)

You can limit how we process your data in certain circumstances.

How to exercise: Contact gdpr@getreica.com with specific processing restrictions you'd like to implement.

Right to Data Portability (Art. 20)

You can receive your data in a structured, machine-readable format.

How to exercise: Use the "Export Data" feature in your account or request a data export via email.

Right to Object (Art. 21)

You can object to processing based on legitimate interests or for direct marketing.

How to exercise: Update your communication preferences or contact gdpr@getreica.com to object to specific processing.

3. Data Processing Lawful Basis

We process your personal data based on the following lawful bases under GDPR Article 6:

Consent (Art. 6(1)(a))

  • • Marketing communications
  • • Optional analytics cookies
  • • Newsletter subscriptions

Contract (Art. 6(1)(b))

  • • Account creation and management
  • • Service delivery
  • • Payment processing

Legal Obligation (Art. 6(1)(c))

  • • Tax and accounting records
  • • Fraud prevention
  • • Compliance reporting

Legitimate Interest (Art. 6(1)(f))

  • • Platform security and integrity
  • • Service improvement
  • • Customer support

4. Data Transfers Outside the EU

When we transfer personal data outside the European Economic Area (EEA), we ensure adequate protection through:

Standard Contractual Clauses (SCCs)

We use EU-approved Standard Contractual Clauses for transfers to third countries, ensuring the same level of data protection as within the EU.

Adequacy Decisions

We only transfer data to countries with EU adequacy decisions, such as the UK, Switzerland, and Canada.

Additional Safeguards

We implement technical measures like encryption and conduct regular assessments of third-country data protection laws.

5. Data Protection Impact Assessments (DPIA)

We conduct Data Protection Impact Assessments for high-risk processing activities, including:

  • AI model training using user-generated content
  • Automated decision-making in design recommendations
  • Large-scale processing of design portfolios
  • Implementation of new tracking technologies

These assessments help us identify and mitigate privacy risks before implementing new features or processes.

6. Data Breach Procedures

In the unlikely event of a data breach, we follow strict GDPR procedures:

72h

Authority Notification

We notify the relevant supervisory authority within 72 hours of becoming aware of a breach.

User Notification

We inform affected users without undue delay if the breach poses a high risk to their rights and freedoms.

Documentation

We document all breaches, including facts, effects, and remedial actions taken.

7. Contact Our Data Protection Officer

For any GDPR-related questions or to exercise your rights, contact our Data Protection Officer:

Contact Information

Email: gdpr@getreica.com

Subject Line: GDPR Request - [Your Request Type]

Response Time: Within 30 days

What to Include

  • • Your full name and email address
  • • Specific right you want to exercise
  • • Verification of your identity (if required)
  • • Clear description of your request

8. Supervisory Authority

If you believe we have not adequately addressed your GDPR concerns, you have the right to lodge a complaint with your local supervisory authority. Some key authorities include:

European Data Protection Board

Website: edpb.europa.eu

Find Your Local Authority

Directory: EDPB Members

9. Updates to Our GDPR Practices

We regularly review and update our GDPR compliance practices. Any significant changes will be communicated through:

  • Updates to this GDPR Compliance page
  • Email notifications to registered users
  • In-app notifications for material changes
  • Updates to our Privacy Policy