GDPR & Data Protection Compliance

Version 2.0Effective 1 June 2026

5.1 Data Controller

MGM, licensed to DMR Group Ltd is the Data Controller for Keepr. Contact: privacy@dmr-group.org or info@dmr-group.org.

5.2 Legal Basis for Processing

BasisApplication
ConsentNDA acceptance, feature opt-in
Legitimate InterestApp improvement, security
Legal ObligationCompliance with UK law
Performance of ContractProviding the service

5.3 Your Rights Under GDPR

  • Article 15 - Access: request a copy of your data.
  • Article 16 - Rectification: correct inaccurate data.
  • Article 17 - Erasure: delete your data (“right to be forgotten”).
  • Article 18 - Restrict Processing: limit how we use your data.
  • Article 20 - Data Portability: export your data in machine-readable format.
  • Article 21 - Object: opt out of certain processing.
  • Article 22 - Automated Decision-Making: human review is available.

5.4 Data Retention

  • Memories: retained until user deletion.
  • Personal Data: retained for the duration of service use.
  • Analytics: aggregated data retained for 12 months.
  • Logs: system logs retained for 90 days.

5.5 Data Transfers

Memory content remains on your device. Account and beta-programme data is processed on servers within the UK/EEA or under equivalent safeguards. International data transfers occur only where appropriate safeguards are in place.

5.6 Data Protection Impact Assessment (DPIA)

We have completed a DPIA for Keepr, assessing risks and mitigation measures. The assessment is available upon request and summarised in Section 7.

5.7 Incident Response

In the event of a data breach we notify affected users within 72 hours (GDPR Article 33), notify supervisory authorities as required, provide details of the breach and impact, and recommend protective measures.

5.8 Data Protection Officer

5.9 Supervisory Authority

You have the right to lodge a complaint with the UK Information Commissioner's Office (ICO). Website: www.ico.org.uk | Phone: 0303 123 1113 | Email: casework@ico.org.uk