1. Purpose of This Statement
This GDPR Compliance Statement explains how TELORIS LTD (“Teloris”) approaches compliance with the EU GDPR and UK GDPR, in addition to (not instead of) our Privacy Policy. Intended for customers, prospects, and partners evaluating Teloris’s data protection posture.
2. Our Role
Teloris acts as a data controller for personal data collected through our website and marketing activities (e.g., contact form submissions), and as a data processor for personal data contained within Customer Data processed on behalf of business customers using the Teloris platform. Processor roles and responsibilities are agreed with each business customer in writing before any Customer Data is processed.
3. Core Principles We Follow
Lawfulness, fairness, and transparency; purpose limitation; data minimization; accuracy, with mechanisms to correct data on request; storage limitation, per the retention periods in our Privacy Policy; integrity and confidentiality, through the security measures in Section 6; and accountability, maintaining records of processing activities (ROPA) as required by Article 30.
4. Data Subject Rights Process
Any individual may submit a rights request (access, rectification, erasure, restriction, portability, or objection) to privacy@teloris.ai. We verify the requester’s identity, respond within one calendar month as required by Article 12, and extend by up to two additional months for complex requests, with notice.
5. Lawful Basis Summary
See our Privacy Policy, Section 3, for the specific lawful bases relied upon (contract, legitimate interest, consent, legal obligation).
6. Security Measures
Encryption of data in transit (TLS) and at rest; role-based access controls and least-privilege; regular vulnerability testing and monitoring; employee data protection training; and incident response procedures aligned with the 72-hour breach notification requirement under Article 33.
7. Sub-processors and International Transfers
We use sub-processors to support hosting, infrastructure, analytics, and communications, under contracts requiring GDPR-equivalent protections. Details of the sub-processors engaged are available on request at privacy@teloris.ai. Where sub-processors are located outside the EEA/UK, transfers are governed by Standard Contractual Clauses (SCCs) and, where applicable, supplementary measures assessed under the Schrems II framework.
8. Establishment
TELORIS LTD is established in the European Union, at Str. Plaiului nr. 22, sat Nazna, com. Sâncraiu de Mureș, jud. Mureș, Romania, and is registered with the Trade Register attached to the Mures Tribunal, Romania. Article 27 GDPR requires a representative within the Union only of controllers and processors established outside it; that obligation does not apply to Teloris, and no such representative has been appointed.
9. Supervisory Authority
Teloris’s lead supervisory authority is the Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP), www.dataprotection.ro. Individuals may lodge a complaint with ANSPDCP or with the supervisory authority of their own EU member state of residence, place of work, or place of the alleged infringement.
10. Contact
Data protection inquiries: privacy@teloris.ai. Legal requests: legal@teloris.ai.