Skip to main content

GDPR Compliance

Last Updated: August 27, 2026
Applies To: Residents of the European Union and other regions with similar regulations

Introduction

Imori, operated by Namos Labs, is committed to protecting personal data in accordance with the General Data Protection Regulation (GDPR). This page explains our GDPR compliance practices and your rights under the regulation. If you're looking for our contractual commitments as a data processor, see our Data Processing Agreement.

Your GDPR Rights

Under GDPR, you have the following rights regarding your personal data:

1. Right to Access (Article 15)

  • What: You have the right to access your personal data that we hold
  • How: Request via team@namoslabs.com with your account email
  • Response Time: We will respond within 30 days
  • Format: We provide data in a clear, structured format

2. Right to Rectification (Article 16)

  • What: You can correct inaccurate or incomplete personal data
  • How: Update information in your account settings, or email us
  • Response Time: Changes are applied immediately or within 48 hours

3. Right to Erasure (Article 17)

  • What: You can request deletion of your personal data
  • Scope: Covers all personal data except legally required records
  • How: Request via team@namoslabs.com or use account deletion in settings
  • Response Time: We delete data within 30 days (legal holds may apply)
  • Note: Anonymized data may be retained for analytics

4. Right to Restrict Processing (Article 18)

  • What: You can request we limit how we use your data
  • When: If you dispute accuracy, unlawful processing, or retaining beyond purpose
  • How: Request via team@namoslabs.com
  • Result: We store but do not process your data (except with consent)

5. Right to Data Portability (Article 20)

  • What: You can receive your data in a machine-readable format
  • Format: JSON, CSV, or other structured format
  • How: Request via team@namoslabs.com
  • Response Time: Within 30 days

6. Right to Object (Article 21)

  • What: You can object to processing based on legitimate interests
  • Applies To: Marketing, analytics, research, profiling
  • How: Request via team@namoslabs.com or email preferences
  • Response Time: We honor objections immediately

7. Right to Withdraw Consent (Article 7)

  • What: You can withdraw consent to optional processing
  • How: Update preferences in account settings or email us
  • Effect: Applies to future processing (past processing remains lawful)

8. Right to Lodge a Complaint

  • What: You can complain to your data protection authority
  • Who: Your country's Data Protection Authority (DPA)
  • Note: We encourage contacting us first to resolve issues

Legal Basis for Processing

Under GDPR Article 6, we process personal data based on these legal bases:

Contract Performance (Article 6(1)(b))

  • Account creation and management
  • Service delivery
  • Billing and payment processing
  • Customer support

Legal Obligation (Article 6(1)(c))

  • Tax and financial records (up to 7 years)
  • Law enforcement requests
  • Fraud prevention and security

Legitimate Interests (Article 6(1)(f))

  • Security and abuse prevention
  • Analytics for service improvement
  • Direct communication about service

Consent (Article 6(1)(a))

  • Marketing communications (with explicit opt-in)
  • Optional analytics
  • Cookies beyond essential functionality

Data Protection Officer (DPO)

Our Data Protection Officer oversees GDPR compliance:

Email: team@namoslabs.com

Response Time: Within 48 hours for GDPR requests

Data Transfers

International Transfers

  • Our servers are located in secure data centers
  • Third-party services are GDPR-compliant
  • Standard contractual clauses protect international transfers

Third-Party Processors

  • Database Hosting: Enterprise-grade secure servers
  • Payment Processing: GDPR-compliant payment processors
  • Hosting: GDPR-compliant hosting providers

Data Processing Agreements

All third-party processors have Data Processing Agreements (DPAs) that comply with GDPR Article 28. Contact us to request copies.

Data Retention

Retention Periods

  • Account Data: Retained until account deletion
  • User Content: Retained to provide service (deleted with account)
  • IP Addresses: Not permanently stored (used for rate limiting only)
  • Audit Logs: Retained for 90 days minimum
  • Financial Records: Retained for 7 years (tax compliance)
  • Marketing Consent: Until withdrawal

Right to Be Forgotten

Upon account deletion, we remove all personal data within 30 days, except:

  • Legally required records (7-year tax retention)
  • Anonymized analytics data
  • Data needed for ongoing legal claims

Data Breach Notification

Our Commitment

  • We notify affected users within 72 hours of discovering a breach
  • We notify your Data Protection Authority as required by law
  • We provide details about what happened and what you can do

Notification Content

Breach notifications will include:

  • Description of the breach
  • Types of data affected
  • Likely consequences
  • Measures taken to mitigate harm
  • Our contact information
  • Recommendations for protecting yourself

Privacy by Design

Our Approach

  • Data Minimization: Collect only what is necessary
  • Encryption: All data encrypted in transit and at rest
  • Access Control: Role-based access and Row Level Security
  • Pseudonymization: Data anonymized where possible
  • Regular Audits: Annual compliance audits

Questions or Complaints

Contact Us

Email: team@namoslabs.com

Response Time: Within 48 hours

Data Protection Authorities

If you are unsatisfied with our response, you have the right to lodge a complaint with your local Data Protection Authority (DPA).

GDPR compliance is fundamental to how Imori operates. Your privacy rights are protected by law, and we are committed to honoring them. If you have any questions about how we handle your data or your rights, please do not hesitate to contact us.