Last Updated : 04-07-2025

GDPR Overview

The General Data Protection Regulation (GDPR) is a legal framework that sets guidelines for the collection and processing of personal information from individuals who live in the European Union (EU). TB Soft Solutions LLC, doing business as ElevateStaffing AI, is committed to ensuring compliance with GDPR principles and protecting the privacy rights of our users.

This document outlines our approach to data protection and how we comply with GDPR requirements. It should be read in conjunction with our Privacy Policy, which provides more detailed information about our data processing activities.

Data Controller

TB Soft Solutions LLC acts as the data controller for personal information collected through our platform. We determine the purposes and means of processing personal data in accordance with the GDPR.

  • Implementing appropriate technical and organizational measures to ensure data protection
  • Maintaining records of processing activities
  • Conducting data protection impact assessments when necessary
  • Cooperating with supervisory authorities
  • Notifying data breaches to authorities and affected individuals when required

Legal Basis for Processing

Under the GDPR, we must have a valid legal basis for processing personal data. We process personal data under the following legal bases:

  • Consent: When you explicitly agree to the processing of your personal data for specific purposes.
  • Contractual necessity: When processing is necessary for the performance of a contract to which you are a party or to take steps at your request before entering into a contract.
  • Legitimate interests: When processing is necessary for our legitimate business interests, such as improving our services, preventing fraud, or ensuring network security.
  • Legal obligation: When processing is necessary for compliance with a legal obligation to which we are subject.
  • Vital interests: When processing is necessary to protect someone's life.
  • Public interest: When processing is necessary for the performance of a task carried out in the public interest.

Consent Management

Where we rely on consent as a legal basis for processing, we ensure that:

  • Consent is freely given, specific, informed, and unambiguous
  • Consent requests are presented in clear and plain language
  • Individuals can withdraw their consent at any time
  • We keep records of when and how consent was obtained

Your GDPR Rights

Under the GDPR, individuals in the EU have the following rights:

  • Right to Access: You have the right to request a copy of the personal data we hold about you and information about how we process it.
  • Right to Rectification: You have the right to request correction of inaccurate personal data and to have incomplete personal data completed.
  • Right to Erasure (Right to be Forgotten): You have the right to request deletion of your personal data in certain circumstances, such as when the data is no longer necessary, when you withdraw consent, or when you object to processing.
  • Right to Restrict Processing: You have the right to request restriction of how we use your data in certain circumstances, such as when you contest the accuracy of the data or when you have objected to processing.
  • Right to Data Portability: You have the right to request transfer of your personal data in a structured, commonly used, and machine-readable format to yourself or to another controller.
  • Right to Object: You have the right to object to processing of your personal data in certain circumstances, including when we process your data based on legitimate interests or for direct marketing.
  • Rights Related to Automated Decision Making and Profiling: You have the right not to be subject to decisions based solely on automated processing that produce legal effects or significantly affect you.

How to Exercise Your Rights

To exercise any of these rights, please contact our Data Protection Officer using the contact information provided below. We will respond to your request within one month, which may be extended by up to two additional months if necessary, due to the complexity or number of requests.

There is no fee for exercising your rights. However, we may charge a reasonable fee if your request is clearly unfounded, repetitive, or excessive.

In some cases, we may need to verify your identity before processing your request to ensure your personal data is not disclosed to unauthorized individuals.

Data Transfers

If we transfer your personal data outside the European Economic Area (EEA), we ensure appropriate safeguards are in place to protect your information according to the requirements of the GDPR.

  • EU-US Privacy Shield (Note: The Privacy Shield framework has been invalidated by the CJEU in July 2020 and is currently being renegotiated)
  • Standard Contractual Clauses (SCCs) approved by the European Commission
  • Binding Corporate Rules (BCRs) for transfers within a corporate group
  • Derogations for specific situations, such as when you explicitly consent to the transfer or when the transfer is necessary for the performance of a contract

Data Retention

We retain your personal data only for as long as necessary to fulfill the purposes for which it was collected, including legal, accounting, or reporting requirements.

Our data retention periods are determined based on:

  • The amount, nature, and sensitivity of the personal data
  • The potential risk of harm from unauthorized use or disclosure
  • The purposes for which we process the data
  • Legal requirements and business needs

Once the retention period expires, personal data is securely deleted or anonymized.

Data Protection by Design and Default

We implement data protection principles from the design stage of all new products, services, and processes, ensuring that only necessary data is collected and processed (data minimization) and that appropriate security measures are in place.

  • Data minimization and purpose limitation
  • Pseudonymization and encryption where appropriate
  • Access controls and authentication mechanisms
  • Regular security testing and assessments
  • Staff training on data protection

Data Protection Impact Assessments

We conduct Data Protection Impact Assessments (DPIAs) for processing activities that are likely to result in a high risk to individuals' rights and freedoms. These assessments help us identify and minimize data protection risks, ensuring compliance with GDPR principles.

Data Breach Procedures

We have procedures in place to detect, report, and investigate personal data breaches. In case of a breach that is likely to result in a risk to individuals' rights and freedoms, we will:

  • Notify the relevant supervisory authority within 72 hours
  • Inform affected individuals without undue delay
  • Document the facts relating to the breach, its effects, and the remedial action taken

Data Protection Officer

We have appointed a Data Protection Officer (DPO) who is responsible for overseeing our data protection strategy and implementation to ensure compliance with GDPR requirements.

To exercise your GDPR rights or for questions regarding our data practices, contact our Data Protection Officer:

  • TB Soft Solutions LLC (DBA ElevateStaffing AI)
  • Attn: Data Protection Officer
  • Email: privacy@tbsoftsolutions.com

Updates to This Policy

We may update this GDPR Compliance statement from time to time in response to changing legal, technical, or business developments. When we update this statement, we will take appropriate measures to inform you, consistent with the significance of the changes we make.

© 2025 ElevateStaffing AI. All Rights Reserved.