Legal

GDPR Compliance

Last updated: August 1, 2026

RelayLink Labs Ltd. is established in Estonia and processes personal data in accordance with the EU General Data Protection Regulation (GDPR). This page summarises how we meet those obligations.

1. Roles

For our own website and business contacts, RelayLink acts as the data controller. When we process personal data on behalf of a client as part of an engagement, RelayLink acts as a data processor and the client is the controller; the relationship is governed by a data processing agreement.

2. Data Residency

Primary infrastructure and data storage are located within the European Economic Area (EEA). Where a sub-processor operates outside the EEA, transfers are covered by appropriate safeguards such as standard contractual clauses.

3. Security Measures

4. Data Subject Requests

Individuals may request access, rectification, erasure, restriction or portability of their personal data, or object to processing. Requests can be sent to privacy@relaylink.io; we respond within 30 days. Where we act as a processor, we forward requests to the relevant controller.

5. Data Protection Officer

Our data protection contact is available at dpo@relaylink.io for questions about this policy or our processing activities.

6. Breach Notification

If a personal data breach occurs that is likely to result in a risk to individuals, we notify the relevant supervisory authority within 72 hours of becoming aware of it, and inform affected controllers and individuals as required by Articles 33 and 34 GDPR.

7. Records and Accountability

We maintain records of processing activities, review sub-processors regularly and apply privacy-by-design principles to the systems we build for clients.

8. Contact

RelayLink Labs Ltd., Harju maakond, Kesklinna linnaosa, Tallinn, Estonia. Email: privacy@relaylink.io.