Data Protection Agreement

 

1. Introduction

This Data Protection Agreement (“Agreement”) describes how Ashia Group (“we”, “us”, or “our”)
collects, processes, stores, and protects personal data in accordance with applicable data protection laws.
By using our services or submitting personal information, you agree to the terms outlined in this Agreement.

2. Definitions

  • “Personal Data” — any information relating to an identified or identifiable natural person.
  • “Processing” — any operation performed on Personal Data, including collection, storage, use, and deletion.
  • “Controller” — the entity that determines the purpose and means of processing Personal Data.
  • “Processor” — any entity that processes Personal Data on behalf of the Controller.

3. Scope of Processing

Ashia Group processes Personal Data strictly for legitimate business purposes, including service
delivery, customer communication, compliance with legal obligations, and security management.

4. Categories of Personal Data Collected

  • Contact information (name, email, phone, address)
  • Account and authentication details
  • Business‑related information provided during service use
  • Technical data (IP address, device information)

5. Lawful Basis for Processing

We process Personal Data based on at least one of the following grounds:

  • Performance of a contract
  • Compliance with legal obligations
  • Legitimate business interests
  • User consent, where required

6. Data Retention

Personal Data is retained only as long as necessary for the purposes for which it was collected,
or as required by applicable law.

7. Confidentiality and Security

We apply organizational and technical measures to ensure the confidentiality, integrity, and
availability of Personal Data. This includes controlled access, encryption, and secure storage.

8. Third‑Party Access

Personal Data may be shared with trusted third‑party service providers strictly for operational purposes.
All third parties are bound by confidentiality and data protection obligations.

9. International Transfers

If Personal Data is transferred outside your jurisdiction, we ensure appropriate safeguards such as
contractual clauses or legally approved transfer mechanisms.

10. Data Subject Rights

Users have the following rights under applicable laws:

  • Right to access their Personal Data
  • Right to rectification
  • Right to erasure (“right to be forgotten”)
  • Right to restrict processing
  • Right to object to processing
  • Right to data portability

11. Data Breach Notification

In the event of a security incident involving Personal Data, we will notify affected users and
regulators as required by law.

12. Contact Information

If you have questions about this Agreement or wish to exercise your rights, please contact:

Ashia Group — Data Protection Office
Email: privacy@ashiagroup.com
Website: https://ashiagroup.com