GDPR & Data Protection Policy
Last Updated: August 31, 2026
At Amzee Corporation, we understand that personal data is more than information stored in a database—it represents real people, businesses, and relationships. We take the privacy and security of personal information seriously and aim to handle it responsibly, transparently, and in accordance with applicable data protection laws.
This GDPR & Data Protection Policy explains how Amzee Corporation approaches the collection, use, storage, protection, and handling of personal information, particularly where the General Data Protection Regulation (GDPR) applies.
The GDPR is a European Union regulation designed to strengthen individuals’ control over their personal data and establish clear responsibilities for organisations that process such information. Its requirements include transparency, lawful processing, appropriate security, data minimisation, retention controls, and respect for individual data rights.
Where GDPR applies to our activities, Amzee Corporation is committed to meeting its applicable requirements and maintaining responsible data-handling practices.
1. Our Approach to GDPR
At Amzee Corporation, privacy is treated as an important part of how we operate—not simply as a legal requirement.
We aim to ensure that personal information is:
- Collected for legitimate and clearly understood purposes.
- Relevant and limited to what is reasonably necessary.
- Accurate and kept reasonably up to date.
- Retained only for as long as it is required.
- Protected against unauthorised access, disclosure, alteration, loss, or destruction.
- Handled in a transparent manner.
- Processed in accordance with an appropriate legal basis.
These practices reflect the core GDPR principles of lawfulness, fairness and transparency, purpose limitation, data minimisation, accuracy, storage limitation, integrity and confidentiality, and accountability.
2. Transparency and Clear Communication
We believe people should be able to understand what happens to their information without having to read complicated legal language.
When Amzee Corporation collects or processes personal information, we aim to clearly explain:
- What information we collect.
- Why we collect it.
- How we use it.
- The legal basis for processing, where applicable.
- How long information may be retained.
- Whether information may be shared with third parties.
- Whether information may be transferred internationally.
- What rights individuals have regarding their personal information.
- How individuals can contact us about their privacy concerns.
We aim to provide this information in a concise, accessible, and understandable manner, consistent with GDPR transparency requirements.
3. What Personal Information May We Handle?
Depending on how an individual interacts with Amzee Corporation, we may process information such as:
- Name and professional designation
- Business or company name
- Work email address
- Telephone or mobile number
- Business address
- Job title or professional information
- Website or professional profile information
- Communication preferences
- Information provided through enquiry or contact forms
- Information relating to our business relationship
- Technical information associated with website usage
- Cookie and similar technology information
- Other information voluntarily provided to us
We only seek to collect information that is reasonably relevant to the purpose for which it is being processed.
4. Why We Use Personal Information
Amzee Corporation may use personal information for legitimate business purposes, including:
- Responding to enquiries and requests.
- Providing information about our services.
- Managing client and business relationships.
- Delivering contracted services.
- Communicating with prospects, customers, partners, and suppliers.
- Improving our website, services, and user experience.
- Conducting business development and marketing activities where legally permitted.
- Maintaining business and operational records.
- Preventing fraud, misuse, or security incidents.
- Meeting legal, regulatory, accounting, or contractual obligations.
We do not use personal information for unrelated purposes simply because the information is available to us. Where a new use is proposed, we consider whether it is compatible with the original purpose and applicable legal requirements.
5. Legal Basis for Processing
Where GDPR applies, Amzee Corporation processes personal information only where an appropriate legal basis exists.
Depending on the circumstances, this may include:
- Consent – where an individual has given permission for a specific use of their information.
- Contractual necessity – where processing is required to provide a service or fulfil an agreement.
- Legal obligation – where processing is required by applicable law.
- Legitimate interests – where processing is necessary for legitimate business interests and those interests do not override the individual’s rights and freedoms.
- Other lawful grounds available under applicable data protection legislation.
The appropriate legal basis depends on the nature and circumstances of each processing activity.
6. Data Minimisation
Amzee Corporation follows a simple principle: if we do not reasonably need the information, we should not collect it.
We aim to collect only information that is adequate, relevant, and necessary for the specific purpose for which it is being processed.
This reduces unnecessary exposure of personal information and helps us maintain more responsible data management practices. Data minimisation is one of the fundamental principles of GDPR compliance.
7. Data Accuracy
We make reasonable efforts to keep personal information accurate and current.
Individuals may contact Amzee Corporation if they believe information we hold about them is incorrect, incomplete, or outdated.
Where appropriate, we will review and update the information.
Employees and authorised personnel who work with personal information are also expected to take reasonable care when entering, modifying, or using data.
8. Data Retention
Personal information should not be retained indefinitely without a legitimate reason.
Amzee Corporation aims to retain information only for as long as it is reasonably required for the purpose for which it was collected, including applicable contractual, operational, legal, accounting, or regulatory requirements.
When information is no longer required, it may be securely deleted, anonymised, or otherwise disposed of in accordance with our internal procedures.
The appropriate retention period can vary depending on the type of information and the reason it is being retained. GDPR recognises storage limitation as a core data protection principle.
9. Protecting Personal Information
We use reasonable technical and organisational measures designed to protect personal information against:
- Unauthorised access
- Unauthorised disclosure
- Accidental loss
- Unauthorised modification
- Destruction
- Misuse
- Security incidents
Depending on the nature of the information and the systems involved, safeguards may include access controls, authentication mechanisms, secure systems, backups, monitoring, security software, encryption where appropriate, and controlled access on a need-to-know basis.
No method of storing or transmitting information can guarantee absolute security. However, Amzee Corporation works to maintain appropriate safeguards based on the nature and risks associated with the information we process.
10. Access to Personal Information
Access to personal information within Amzee Corporation should be limited to authorised individuals who require the information for legitimate business purposes.
Employees, contractors, and service providers should not access, copy, disclose, or use personal information unless they have an appropriate business reason and the necessary authorisation.
Personal information must not be shared informally or with individuals who do not have a legitimate need to access it.
11. Employee Responsibilities
Everyone working with Amzee Corporation has a role to play in protecting personal information.
Employees and authorised personnel are expected to:
- Keep passwords and access credentials confidential.
- Use appropriate security practices.
- Avoid sharing personal information unnecessarily.
- Follow company data-handling procedures.
- Report suspected security incidents promptly.
- Avoid storing business information on unauthorised personal devices or services.
- Use approved systems for handling company information.
- Keep information accurate where they are responsible for maintaining it.
- Seek guidance when they are uncertain about how personal information should be handled.
Privacy and security are shared responsibilities across the organisation.
12. Data Storage and Digital Security
Electronic information should be stored using approved systems and appropriate security controls.
Where personal information is stored digitally, reasonable measures should be taken to protect it from unauthorised access, accidental deletion, malicious activity, or other security risks.
Our practices may include:
- Access-controlled systems.
- Strong authentication and password practices.
- Security software and firewalls.
- Regular backups.
- Controlled access to business systems.
- Secure handling of removable media.
- Appropriate protection of laptops and mobile devices.
- Monitoring and maintenance of relevant systems.
- Secure disposal of information that is no longer required.
Where cloud or third-party technology providers are used, Amzee Corporation seeks to assess their suitability and data protection practices as appropriate to the service and risk involved.
13. Use of Personal Information
Personal information should only be accessed and used for legitimate business purposes.
Employees should take reasonable precautions when working with personal information, including:
- Locking computers when unattended.
- Avoiding the unnecessary use of personal information.
- Using approved communication channels.
- Checking recipients before sending sensitive information.
- Avoiding unnecessary duplication of information.
- Following appropriate security procedures when transferring information.
- Reporting suspected disclosure or loss of personal information.
Where appropriate, information should be protected using security measures such as encryption or secure transfer mechanisms.
14. Third-Party Service Providers
Amzee Corporation may work with selected third-party providers to support its operations.
These may include providers involved in areas such as:
- Website hosting
- Cloud infrastructure
- CRM and business management systems
- Communication services
- Marketing technology
- Analytics
- IT and security services
- Payment or business administration services
Where third parties process personal information on our behalf, we seek to ensure that appropriate contractual, organisational, and technical safeguards are in place where required.
Third parties should only receive information that is reasonably necessary for the relevant service or purpose.
15. International Data Transfers
Some technology providers or business partners may operate in countries outside the European Economic Area (EEA).
Where GDPR applies and personal information is transferred internationally, Amzee Corporation will consider the applicable GDPR requirements and appropriate safeguards for such transfers.
Depending on the circumstances, these safeguards may include an adequacy decision, appropriate contractual safeguards, or another legally recognised transfer mechanism.
16. Cookies and Website Technologies
Our website may use cookies and similar technologies to support website functionality, understand website usage, improve user experience, and, where applicable, support marketing activities.
The type of information collected and how cookies are used will depend on the specific technology involved.
Where consent is legally required, Amzee Corporation will seek appropriate consent before using the relevant technologies.
Our Privacy Policy and Cookie Policy provide additional information about how website technologies are used.
17. Individual GDPR Rights
Where GDPR applies, individuals may have several rights regarding their personal information.
Depending on the circumstances, these may include:
Right to Be Informed
Individuals have the right to receive clear information about how their personal data is collected and processed.
Right of Access
Individuals may request access to personal information that Amzee Corporation holds about them, subject to applicable legal limitations.
Right to Rectification
Individuals may ask us to correct inaccurate or incomplete personal information.
Right to Erasure
In certain circumstances, individuals may request deletion of their personal information.
Right to Restrict Processing
Individuals may have the right to ask us to restrict how their personal information is processed in certain situations.
Right to Data Portability
Where applicable, individuals may request their personal information in a structured, commonly used, and machine-readable format and may have the right to transmit it to another organisation.
Right to Object
Individuals may have the right to object to certain types of processing, including certain direct marketing activities.
Rights Relating to Automated Decision-Making
Where applicable, individuals may have rights concerning decisions based solely on automated processing that produce legal or similarly significant effects.
These rights are subject to the conditions and exceptions established under GDPR.
18. Making a Data Protection Request
If you would like to exercise a data protection right or ask us a question about how your information is handled, you can contact Amzee Corporation through the contact details provided on our website.
When necessary, we may ask for reasonable information to verify your identity before providing access to personal information or making changes.
We aim to respond to valid data protection requests without undue delay and, where GDPR applies, generally within the applicable one-month period. Certain circumstances may allow this period to be extended in accordance with the GDPR.
19. Data Breach and Security Incidents
Amzee Corporation takes potential data breaches seriously.
If we become aware of an incident involving personal information, we will assess the nature, scope, and potential impact of the incident and take reasonable steps to contain, investigate, and address it.
Where legally required, appropriate notifications may be made to relevant authorities and affected individuals within the applicable regulatory timeframes.
Employees and authorised personnel should report suspected loss, unauthorised access, accidental disclosure, or other security incidents as soon as possible.
20. Data Protection by Design
Privacy should be considered from the beginning of a project rather than added after the fact.
Where appropriate, Amzee Corporation considers privacy and data protection when introducing new systems, services, processes, technologies, or business activities involving personal information.
This may include limiting the amount of information collected, restricting access, applying appropriate security measures, and considering whether personal information can be anonymised or pseudonymised.
The GDPR encourages organisations to build data protection into processing activities and systems from the outset.
21. Marketing Communications
Amzee Corporation may communicate with existing or prospective business contacts regarding services, updates, events, research, or other relevant business information.
Where required by applicable law, we will obtain consent or rely on another appropriate legal basis before sending marketing communications.
Recipients may have the ability to unsubscribe from marketing communications at any time.
Individuals may also object to the processing of their personal information for direct marketing purposes where applicable.
22. Data Protection Responsibilities
Data protection responsibilities are shared across Amzee Corporation.
Management
Company leadership is responsible for supporting appropriate data protection practices and ensuring that privacy remains an important part of business operations.
Data Protection / Privacy Responsibility
Where a dedicated Data Protection Officer or privacy lead is appointed, that person may assist with:
- Monitoring data protection practices.
- Supporting internal privacy compliance.
- Advising teams on data protection responsibilities.
- Reviewing privacy-related procedures.
- Supporting responses to data subject requests.
- Assisting with privacy risk assessments.
- Supporting communication with relevant regulatory authorities where required.
The appointment of a formal Data Protection Officer will depend on whether the GDPR requires one based on the nature and scale of our processing activities.
IT and Security
Our IT and security functions are responsible for helping maintain appropriate technical safeguards, access controls, system security, backups, and security monitoring.
Marketing
Marketing teams are responsible for ensuring that campaigns, databases, communications, and outreach activities follow applicable privacy and marketing requirements.
All Employees
Every employee and contractor who handles personal information is responsible for following applicable data protection and security procedures.
23. Data Protection Risks
Poor handling of personal information can create significant risks for individuals and organisations.
Amzee Corporation recognises risks such as:
Confidentiality breaches
Personal information may be disclosed to someone who should not have access to it.
Unauthorised use
Information may be used for purposes that were not authorised or reasonably expected.
Data loss
Information may be accidentally deleted, lost, damaged, or made unavailable.
Cybersecurity threats
Attackers may attempt to gain unauthorised access to systems containing personal information.
Reputational damage
A serious privacy or security incident can affect the trust that customers, partners, employees, and other stakeholders place in an organisation.
We therefore aim to identify and reduce privacy and security risks as part of our normal business practices.
24. Disclosure of Information
Amzee Corporation may disclose personal information where there is a legitimate and lawful reason to do so.
This may include situations where disclosure is:
- Required by law.
- Necessary to comply with a legal process.
- Required by a competent regulatory or government authority.
- Necessary to protect the rights, safety, or security of individuals or the organisation.
- Necessary for the performance of a legitimate contractual or business activity.
Where appropriate, requests for information from authorities will be reviewed to ensure they are genuine and legally valid.
25. Privacy Information for Clients and Visitors
Amzee Corporation aims to ensure that individuals understand how their information is handled.
Our Privacy Policy may provide information about:
- The categories of personal information we collect.
- The purposes for which information is used.
- The legal basis for processing.
- Cookies and similar technologies.
- Third-party service providers.
- Data retention.
- International transfers.
- Individual data protection rights.
- How to contact us regarding privacy matters.
We encourage website visitors, clients, prospects, partners, and other individuals interacting with Amzee Corporation to review our Privacy Policy and Cookie Policy.
26. Our Commitment to Responsible Data Handling
At Amzee Corporation, we believe that responsible data handling is essential to building long-term relationships.
Our approach is based on three simple principles:
Collect responsibly.
We aim to collect information for clear and legitimate purposes and avoid unnecessary data collection.
Protect carefully.
We use reasonable technical and organisational measures to protect information from inappropriate access, loss, misuse, or disclosure.
Respect individual rights.
We recognise that people should have meaningful control over their personal information and should be able to understand how it is being used.
The GDPR establishes these principles through its requirements around transparency, purpose limitation, data minimisation, accuracy, retention, security, and accountability.
27. Policy Updates
Data protection requirements, technology, and our business activities may change over time.
Amzee Corporation may periodically review and update this GDPR & Data Protection Policy to reflect changes in applicable law, regulatory guidance, technology, business processes, or our data-handling practices.
The latest version will be made available through our website where appropriate.
28. Contact Amzee Corporation
If you have questions about this GDPR & Data Protection Policy, want to understand how we process your information, or wish to exercise an applicable data protection right, please contact Amzee Corporation through the contact information provided on our website.
Amzee Corporation
Email: support@amzeecorporation.com
Website: www.amzeecorporation.com
We welcome privacy-related questions and will make reasonable efforts to address them clearly and promptly.
