GDPR Compliance
Last updated: September 8, 2026
The General Data Protection Regulation (GDPR) is the European Union's comprehensive data protection law that governs the processing of personal data. Tolarai.com is committed to full GDPR compliance and provides tools and processes to help your organization meet its obligations as a data controller.
1. Roles Under GDPR
Under GDPR, the roles are defined as follows:
- Data Controller: Your organization is the data controller for the member data you store within Tolarai.com. You determine the purposes and means of processing member data.
- Data Processor: Tolarai.com acts as a data processor on your behalf. We process member data only as instructed by you and in accordance with our Terms of Service and this policy.
- Data Subjects: Your members are the data subjects whose personal data is processed. They have specific rights under GDPR that both you and we must respect.
2. Lawful Basis for Processing
We process personal data on the following legal bases:
- Contractual necessity: Processing necessary to provide the Services under our Terms of Service and fulfill our contractual obligations to you.
- Legal obligation: Processing required to comply with applicable laws, regulations, or government requests.
- Legitimate interests: Processing necessary for our legitimate business interests, such as security, fraud prevention, and service improvement, balanced against data subjects' rights.
- Consent: Processing based on explicit consent for activities such as marketing communications or optional analytics, which may be withdrawn at any time.
3. Data Subject Rights
Your members have the following rights under GDPR. Tolarai.com provides tools to help you fulfill these requests:
- Right of access (Article 15): Data subjects can request a copy of their personal data. Use the Export Member Data tool in the member profile to generate a complete JSON export.
- Right to rectification (Article 16): Data subjects can request correction of inaccurate data. Member profiles can be edited directly in the platform.
- Right to erasure / right to be forgotten (Article 17): Data subjects can request deletion of their personal data. Use the Delete Member Data (GDPR) tool to permanently delete a member and all associated records.
- Right to restriction (Article 18): Data subjects can request that processing be limited. You can suspend a member's account while maintaining their data.
- Right to data portability (Article 20): Data subjects can receive their data in a structured, machine-readable format. The Export Member Data tool produces JSON output suitable for portability.
- Right to object (Article 21): Data subjects can object to processing based on legitimate interests or for direct marketing. Communication preferences can be managed per member.
- Right to withdraw consent (Article 7): Data subjects can withdraw consent for processing based on consent at any time. Email and communication preferences are configurable per member.
- Right to lodge a complaint (Article 77): Data subjects can lodge a complaint with their local data protection authority.
4. Data Export & Deletion Tools
Tolarai.com provides the following GDPR-compliant tools within the platform:
- Export Member Data: Generates a complete JSON export of all data associated with a specific member, including profile, memberships, invoices, events, documents, and communications.
- Delete Member Data (GDPR): Permanently deletes a member and all associated data in compliance with the right to be forgotten. This action is irreversible and logs the deletion in the audit trail.
- Audit Logging: All data export and deletion operations are logged with user identity, timestamp, and details, providing a complete audit trail for compliance verification.
- Communication Preferences: Members can manage their email, WhatsApp, and SMS communication preferences, including opt-outs for marketing communications.
5. Data Retention
We retain personal data only for as long as necessary:
- Active accounts: Data is retained for the duration of your subscription and any associated grace period.
- Terminated accounts: Upon account termination, we provide a 30-90 day period for data export before permanent deletion.
- Financial records: Billing and transaction records may be retained for up to 7 years to comply with tax and accounting requirements.
- Log data: Technical logs are retained for up to 12 months for security and troubleshooting.
6. International Data Transfers
The Services are hosted on cloud infrastructure that may process and store data in countries outside the EU/EEA. We ensure that international transfers of personal data are conducted in compliance with GDPR, including through appropriate safeguards such as Standard Contractual Clauses (SCCs) or other legally recognized transfer mechanisms.
7. Data Protection by Design & Default
Tolarai.com follows the principles of data protection by design and by default (Article 25):
- Minimization: We only collect data that is necessary for providing the Services.
- Pseudonymization: Where possible, data is pseudonymized to reduce identifiability.
- Default privacy settings: The most privacy-protective settings are enabled by default.
- Encryption: Data is encrypted in transit and at rest.
- Access controls: Strict RBAC and tenant isolation prevent unauthorized access.
8. Data Breach Notification
In the event of a personal data breach, we will:
- Notify affected organizations without undue delay, and where feasible, within 72 hours of becoming aware of the breach;
- Provide a clear description of the breach, the likely consequences, and the measures taken or proposed;
- Notify the relevant supervisory authority as required by Article 33 of the GDPR;
- Document the breach, its effects, and any remedial action taken.
9. Data Processing Agreement (DPA)
We offer a Data Processing Agreement for enterprise customers that addresses the requirements of Article 28 of the GDPR. The DPA outlines our responsibilities as a data processor, including:
- Processing only on documented instructions from the controller;
- Ensuring persons authorized to process data are subject to confidentiality obligations;
- Implementing appropriate technical and organizational security measures;
- Assisting the controller with data subject rights requests;
- Assisting with data protection impact assessments;
- Notifying the controller without undue delay of any personal data breach;
- Deleting or returning all personal data after the end of the services.
To request a DPA, please contact privacy@tolarai.com.
10. Your Responsibilities as a Data Controller
As an organization using Tolarai.com, you are responsible for:
- Obtaining valid consent from your members for the collection and processing of their personal data;
- Maintaining a privacy policy or notice for your members that accurately describes how their data is used;
- Responding to your members' data subject rights requests in a timely manner (within 30 days);
- Ensuring the accuracy and lawfulness of the data you upload to the Services;
- Conducting data protection impact assessments (DPIAs) where required;
- Appointing a Data Protection Officer (DPO) if required under Article 37.
11. Contact Us
For any GDPR-related questions, data subject rights requests, or to request a DPA, please contact our Data Protection Officer:
- Email: privacy@tolarai.com
- Subject: GDPR Request
We will respond to your request within 30 days, as required by GDPR. For complex requests, this period may be extended by a further two months, with an explanation of the delay.