GDPR Compliance
Last Updated: 23/09/2026
Our Commitment to Data Protection
At Endless Luv, we take data protection seriously. We are fully committed to complying with the General Data Protection Regulation (GDPR) and Portuguese data protection laws. This page outlines our commitment and explains how we protect your rights under GDPR.
The GDPR is a comprehensive data protection law in the European Union that came into effect on May 25, 2018. It strengthens individuals' rights over their personal data and establishes strict requirements for organizations that process personal data.
Your Rights Under GDPR
As a data subject under GDPR, you have the following rights regarding your personal data:
Right to Access
Request copies of your personal data and information about how we process it.
Right to Rectification
Request correction of inaccurate or incomplete personal data.
Right to Erasure
Request deletion of your personal data under certain circumstances ('right to be forgotten').
Right to Restriction
Request limitation of how we process your data in specific situations.
Right to Data Portability
Receive your data in a structured, machine-readable format and transfer it to another service.
Right to Object
Object to certain types of data processing, including direct marketing.
Right to Withdraw Consent
Withdraw your consent at any time where processing is based on consent.
Right Not to Be Subject to Automated Decision-Making
Not be subject to decisions based solely on automated processing that significantly affects you.
How to Exercise Your Rights
You can exercise any of your GDPR rights by contacting us. We will respond to your request within 30 days as required by law.
To Submit a Request:
- •Email us at support@endlessluv.com with "GDPR Request" in the subject line
- •Specify which right you wish to exercise
- •Provide information to help us verify your identity
- •Include any relevant details about your request
Identity Verification: To protect your privacy, we may ask you to verify your identity before fulfilling certain requests. This is a security measure to ensure that personal data is not disclosed to unauthorized individuals.
Our GDPR Compliance Measures
Data Protection by Design and Default
We implement appropriate technical and organizational measures to ensure that, by default, only personal data necessary for each specific purpose is processed. Data protection is integrated into our development processes from the outset.
Lawful Basis for Processing
We only process your personal data when we have a lawful basis, including:
- Consent: You have given clear consent for us to process your data
- Contract: Processing is necessary to fulfill our contract with you
- Legal Obligation: Processing is necessary to comply with the law
- Legitimate Interest: Processing is necessary for our legitimate interests or those of a third party
Data Minimization
We only collect and process the minimum amount of personal data necessary to provide our services and fulfill our legal obligations.
Storage Limitation
We retain personal data only for as long as necessary for the purposes for which it was collected or as required by law. Data scheduled for future delivery is retained until the delivery date, after which it is securely deleted within 90 days unless legal obligations require longer retention.
Security Measures
We implement state-of-the-art security measures to protect your data:
- End-to-end encryption for stored content
- Secure data transmission using TLS/SSL protocols
- Regular security audits and penetration testing
- Access controls and authentication mechanisms
- Employee training on data protection
- Incident response procedures
Data Breach Notification
In the unlikely event of a data breach that poses a risk to your rights and freedoms, we will notify you and the relevant supervisory authority within 72 hours of becoming aware of the breach, as required by GDPR Article 33 and 34.
International Data Transfers
When transferring data outside the EEA, we ensure appropriate safeguards are in place, such as:
- Standard Contractual Clauses (SCCs) approved by the European Commission
- Adequacy decisions for countries with equivalent data protection
- Binding Corporate Rules where applicable
Third-Party Processors
We carefully select third-party service providers and ensure they comply with GDPR through Data Processing Agreements (DPAs). These agreements require processors to implement appropriate security measures and process data only on our instructions.
Data Protection Impact Assessments
We conduct Data Protection Impact Assessments (DPIAs) for processing activities that are likely to result in high risk to individuals' rights and freedoms. This helps us identify and minimize data protection risks.
Accountability and Governance
We maintain documentation of our processing activities and can demonstrate our compliance with GDPR principles upon request. Our data protection governance includes:
- Regular review and updates of privacy policies
- Staff training on GDPR and data protection
- Internal data protection policies and procedures
- Regular compliance audits
Supervisory Authority
If you believe we have not adequately addressed your concerns or complied with GDPR, you have the right to lodge a complaint with the Portuguese Data Protection Authority (CNPD) or your local supervisory authority.
Portuguese Data Protection Authority (CNPD)
Comissão Nacional de Proteção de Dados
Av. D. Carlos I, 134, 1.º
1200-651 Lisboa, Portugal
Phone: +351 213 928 400
Email: geral@cnpd.pt
Website: www.cnpd.pt
Children's Privacy
In accordance with GDPR Article 8, we do not knowingly collect or process personal data from children under 16 years old (or the minimum age specified by local law) without verifiable parental consent. If we become aware that we have collected data from a child without proper consent, we will take steps to delete that information promptly.
Updates to Our GDPR Compliance
We regularly review and update our data protection practices to ensure ongoing GDPR compliance. Any material changes will be communicated through our app and on this page.
Additional Resources
For more detailed information about how we handle your data, please review:
Contact Us
For any questions regarding GDPR compliance or to exercise your rights, please contact us at:
Email: support@endlessluv.com
Subject Line: GDPR Request / Data Protection Inquiry
Postal Address:
Soul Awakened Limited
Assikura Buildings, Level 1
Old Railway Track
Santa Venera SVR 9017, Malta
