5.1 Data Controller
MGM, licensed to DMR Group Ltd is the Data Controller for Keepr. Contact: privacy@dmr-group.org or info@dmr-group.org.
5.2 Legal Basis for Processing
| Basis | Application |
|---|---|
| Consent | NDA acceptance, feature opt-in |
| Legitimate Interest | App improvement, security |
| Legal Obligation | Compliance with UK law |
| Performance of Contract | Providing the service |
5.3 Your Rights Under GDPR
- Article 15 - Access: request a copy of your data.
- Article 16 - Rectification: correct inaccurate data.
- Article 17 - Erasure: delete your data (“right to be forgotten”).
- Article 18 - Restrict Processing: limit how we use your data.
- Article 20 - Data Portability: export your data in machine-readable format.
- Article 21 - Object: opt out of certain processing.
- Article 22 - Automated Decision-Making: human review is available.
5.4 Data Retention
- Memories: retained until user deletion.
- Personal Data: retained for the duration of service use.
- Analytics: aggregated data retained for 12 months.
- Logs: system logs retained for 90 days.
5.5 Data Transfers
Memory content remains on your device. Account and beta-programme data is processed on servers within the UK/EEA or under equivalent safeguards. International data transfers occur only where appropriate safeguards are in place.
5.6 Data Protection Impact Assessment (DPIA)
We have completed a DPIA for Keepr, assessing risks and mitigation measures. The assessment is available upon request and summarised in Section 7.
5.7 Incident Response
In the event of a data breach we notify affected users within 72 hours (GDPR Article 33), notify supervisory authorities as required, provide details of the breach and impact, and recommend protective measures.
5.8 Data Protection Officer
5.9 Supervisory Authority
You have the right to lodge a complaint with the UK Information Commissioner's Office (ICO). Website: www.ico.org.uk | Phone: 0303 123 1113 | Email: casework@ico.org.uk