Endless Luv
Back to Home

GDPR Compliance

Last Updated: 23/09/2026

Our Commitment to Data Protection

At Endless Luv, we take data protection seriously. We are fully committed to complying with the General Data Protection Regulation (GDPR) and Portuguese data protection laws. This page outlines our commitment and explains how we protect your rights under GDPR.

The GDPR is a comprehensive data protection law in the European Union that came into effect on May 25, 2018. It strengthens individuals' rights over their personal data and establishes strict requirements for organizations that process personal data.

Your Rights Under GDPR

As a data subject under GDPR, you have the following rights regarding your personal data:

Right to Access

Request copies of your personal data and information about how we process it.

Right to Rectification

Request correction of inaccurate or incomplete personal data.

Right to Erasure

Request deletion of your personal data under certain circumstances ('right to be forgotten').

Right to Restriction

Request limitation of how we process your data in specific situations.

Right to Data Portability

Receive your data in a structured, machine-readable format and transfer it to another service.

Right to Object

Object to certain types of data processing, including direct marketing.

Right to Withdraw Consent

Withdraw your consent at any time where processing is based on consent.

Right Not to Be Subject to Automated Decision-Making

Not be subject to decisions based solely on automated processing that significantly affects you.

How to Exercise Your Rights

You can exercise any of your GDPR rights by contacting us. We will respond to your request within 30 days as required by law.

To Submit a Request:

  • •Email us at support@endlessluv.com with "GDPR Request" in the subject line
  • •Specify which right you wish to exercise
  • •Provide information to help us verify your identity
  • •Include any relevant details about your request

Identity Verification: To protect your privacy, we may ask you to verify your identity before fulfilling certain requests. This is a security measure to ensure that personal data is not disclosed to unauthorized individuals.

Our GDPR Compliance Measures

Data Protection by Design and Default

We implement appropriate technical and organizational measures to ensure that, by default, only personal data necessary for each specific purpose is processed. Data protection is integrated into our development processes from the outset.

Lawful Basis for Processing

We only process your personal data when we have a lawful basis, including:

  • Consent: You have given clear consent for us to process your data
  • Contract: Processing is necessary to fulfill our contract with you
  • Legal Obligation: Processing is necessary to comply with the law
  • Legitimate Interest: Processing is necessary for our legitimate interests or those of a third party

Data Minimization

We only collect and process the minimum amount of personal data necessary to provide our services and fulfill our legal obligations.

Storage Limitation

We retain personal data only for as long as necessary for the purposes for which it was collected or as required by law. Data scheduled for future delivery is retained until the delivery date, after which it is securely deleted within 90 days unless legal obligations require longer retention.

Security Measures

We implement state-of-the-art security measures to protect your data:

  • End-to-end encryption for stored content
  • Secure data transmission using TLS/SSL protocols
  • Regular security audits and penetration testing
  • Access controls and authentication mechanisms
  • Employee training on data protection
  • Incident response procedures

Data Breach Notification

In the unlikely event of a data breach that poses a risk to your rights and freedoms, we will notify you and the relevant supervisory authority within 72 hours of becoming aware of the breach, as required by GDPR Article 33 and 34.

International Data Transfers

When transferring data outside the EEA, we ensure appropriate safeguards are in place, such as:

  • Standard Contractual Clauses (SCCs) approved by the European Commission
  • Adequacy decisions for countries with equivalent data protection
  • Binding Corporate Rules where applicable

Third-Party Processors

We carefully select third-party service providers and ensure they comply with GDPR through Data Processing Agreements (DPAs). These agreements require processors to implement appropriate security measures and process data only on our instructions.

Data Protection Impact Assessments

We conduct Data Protection Impact Assessments (DPIAs) for processing activities that are likely to result in high risk to individuals' rights and freedoms. This helps us identify and minimize data protection risks.

Accountability and Governance

We maintain documentation of our processing activities and can demonstrate our compliance with GDPR principles upon request. Our data protection governance includes:

  • Regular review and updates of privacy policies
  • Staff training on GDPR and data protection
  • Internal data protection policies and procedures
  • Regular compliance audits

Supervisory Authority

If you believe we have not adequately addressed your concerns or complied with GDPR, you have the right to lodge a complaint with the Portuguese Data Protection Authority (CNPD) or your local supervisory authority.

Portuguese Data Protection Authority (CNPD)

Comissão Nacional de Proteção de Dados
Av. D. Carlos I, 134, 1.º
1200-651 Lisboa, Portugal

Phone: +351 213 928 400
Email: geral@cnpd.pt
Website: www.cnpd.pt

Children's Privacy

In accordance with GDPR Article 8, we do not knowingly collect or process personal data from children under 16 years old (or the minimum age specified by local law) without verifiable parental consent. If we become aware that we have collected data from a child without proper consent, we will take steps to delete that information promptly.

Updates to Our GDPR Compliance

We regularly review and update our data protection practices to ensure ongoing GDPR compliance. Any material changes will be communicated through our app and on this page.

Additional Resources

For more detailed information about how we handle your data, please review:

Contact Us

For any questions regarding GDPR compliance or to exercise your rights, please contact us at:

Email: support@endlessluv.com
Subject Line: GDPR Request / Data Protection Inquiry

Postal Address:
Soul Awakened Limited
Assikura Buildings, Level 1
Old Railway Track
Santa Venera SVR 9017, Malta