GDPR Compliance
Last updated: July 2026
Immiknow ("we", "our", or "us") is committed to compliance with the European Union's General Data Protection Regulation (GDPR). This page outlines our approach to data protection and the rights available to you under GDPR.
1. Our Role as Data Controller
Immiknow acts as the data controller for personal information collected through our website and services. This means we determine the purposes and means of processing your personal data.
2. Lawful Basis for Processing
We process personal data under the following lawful bases as defined by Article 6 of the GDPR:
- Consent (Art. 6(1)(a)): When you submit consultation requests or opt into communications.
- Legitimate Interests (Art. 6(1)(f)): To operate, improve, and protect our business and services.
- Legal Obligation (Art. 6(1)(c)): To comply with applicable laws and regulatory requirements.
3. Your GDPR Rights
Under GDPR, individuals in the EEA have the following rights:
- Right of Access (Art. 15): You may request a copy of the personal data we hold about you.
- Right to Rectification (Art. 16): You may request correction of inaccurate or incomplete personal data.
- Right to Erasure (Art. 17): You may request deletion of your personal data under certain circumstances ("right to be forgotten").
- Right to Restriction of Processing (Art. 18): You may request restriction of how we process your data.
- Right to Data Portability (Art. 20): You may request your data in a structured, commonly used, machine-readable format.
- Right to Object (Art. 21): You may object to processing based on legitimate interests or direct marketing.
- Rights in relation to Automated Decision-Making (Art. 22): You have the right not to be subject to decisions based solely on automated processing.
4. Data Protection Measures
We implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk, including:
- Encryption of personal data in transit and at rest.
- Access controls and authentication mechanisms.
- Regular security assessments and monitoring.
- Staff training on data protection requirements.
5. International Data Transfers
As a global organization, personal data may be transferred to and processed in countries outside the EEA. When such transfers occur, we ensure appropriate safeguards are in place, such as Standard Contractual Clauses (SCCs) or adequacy decisions, in compliance with Articles 44-49 of the GDPR.
6. Data Breach Notification
In the event of a personal data breach, we will notify the relevant supervisory authority within 72 hours of becoming aware of the breach, where required by Article 33 of the GDPR. Affected individuals will be notified without undue delay if the breach poses a high risk to their rights and freedoms, as required by Article 34.
7. Exercising Your Rights
To exercise any of your GDPR rights, please contact us at info@immiknow.global. We will respond to your request within 30 days, as required by Article 12 of the GDPR.
You also have the right to lodge a complaint with your local data protection supervisory authority if you believe your rights have been violated.
8. Related Documents
For more detailed information, please refer to our Privacy Policy and Cookie Policy.
9. Contact Us
For GDPR-related inquiries, please contact:
Email: info@immiknow.global
Address: Global Headquarters, Hong Kong, China