GDPR Notice (for EU users)
If you are a resident of the European Economic Area (EEA — the 27 EU states plus Iceland, Liechtenstein and Norway), the United Kingdom or Switzerland, you have specific personal-data protection rights under the General Data Protection Regulation (GDPR). This GDPR Notice details our commitments, rights protections and remedies for EU users.
① Scope of GDPR
This notice applies if:
- You reside in an EU member state, an EEA country, the UK or Switzerland
- You provide personal data to us from within the EEA
- You use our service from within the EEA
- Regardless of payment currency, an EU-based IP is deemed in scope
② Your GDPR Rights
Under GDPR Articles 12-22, you have the following full rights, exercisable free of charge at any time:
- Right to be informed (Art. 13-14): understand how we collect and use your data
- Right of access (Art. 15): obtain a free copy of the data we hold about you
- Right to rectification (Art. 16): request correction of inaccurate or incomplete data
- Right to erasure / be forgotten (Art. 17): request deletion where conditions are met
- Right to restrict processing (Art. 18): request that we suspend processing of your data
- Right to portability (Art. 20): obtain your data in a structured, machine-readable format (JSON / CSV) and transfer it to another provider
- Right to object (Art. 21): object to processing based on our legitimate interests
- Rights re automated decisions (Art. 22): request human review of automated decisions (e.g. automatic risk-control freeze)
- Right to withdraw consent (Art. 7): withdraw consent at any time, without affecting prior processing
- Right to complain: lodge a complaint with the supervisory authority
③ Legal Basis for Processing
We process your data on the following legal bases under GDPR Article 6:
- Contractual necessity (6(1)(b)): providing the subscription you ordered
- Legal obligation (6(1)(c)): tax, accounting and AML regulations
- Legitimate interest (6(1)(f)): fraud detection, service improvement, security
- Consent (6(1)(a)): marketing
④ Data Controller
The following companies jointly act as controllers of your personal data:
- Hong Kong company: Hongkong PremLogin Limited, registered address: Room 1022A, Beverley Commercial Centre, 87-105 Chatham Road South, Tsim Sha Tsui, Hong Kong
- United Kingdom company: PREMLOGIN LIMITED, registered address: Suite 6630, 61 Bridge Street, Kington, United Kingdom, HR5 3DJ
- Email: privacy@premlogin.com
- Responsible: Data Protection Officer
⑤ Data Protection Officer (DPO)
We have appointed a DPO under GDPR Article 37:
- DPO email: privacy@premlogin.com
- EU representative email: privacy@premlogin.com
- The DPO oversees GDPR compliance, handles rights requests, and liaises with supervisory authorities
⑥ Cross-Border Data Transfer
Because our servers are in Hong Kong and Singapore, your personal data will be transferred from the EU to these jurisdictions. We apply the following safeguards:
- EU Standard Contractual Clauses (SCC)
- Technical measures (encryption, pseudonymization) to protect data in transit
- Transfer Impact Assessments (TIA)
- Regular review of the legal environment in recipient countries
⑦ How to Exercise Your Rights
To exercise any GDPR right, please:
- Send your request by email to privacy@premlogin.com
- Provide your account email and identity verification (to prevent impersonation)
- Clearly state which right you wish to exercise and the details of your request
- We will respond within 30 days of receipt (extendable to 60 days for complex cases)
- Processing is free; for manifestly unfounded or excessive requests we may charge a reasonable administrative fee
⑧ How to Complain
If you believe our processing of your data breaches the GDPR, you may complain to:
- The data protection authority of your EU member state (preferred channel) — e.g. the Irish Data Protection Commission (DPC): dataprotection.ie
- The data protection authority in your country
- The European Data Protection Board (EDPB): edpb.europa.eu
⑨ Data Breach Notification
In the event of a breach likely to risk your rights and freedoms, under GDPR Articles 33-34 we will:
- Notify the supervisory authority within 72 hours of discovery
- Notify affected users without undue delay in high-risk cases
- Provide a description of the incident, likely consequences, remedial measures and a contact point