Caretech AITechnology that Cares
GDPR

GDPR — principles, roles, and who decides what.

Caretech AI makes no claim of compliance with the GDPR. Compliance under the Regulation attaches to a specific processing operation with a specific lawful basis, and a website cannot assert it on your behalf.

What can be stated is the set of principles the design supports, the roles Caretech AI may occupy depending on the relationship, and the decisions that remain yours.

Where it applies

Principles supported where GDPR applies

Where GDPR applies, Caretech AI is committed to supporting privacy principles including lawful processing, transparency, data minimization, purpose limitation, accuracy, storage limitation, integrity, confidentiality, and accountability.

GDPR may apply for individuals in the European Economic Area or in other covered jurisdictions, depending on where data subjects are and how processing is carried out.

Roles

Which role applies is a contract question

Depending on the service relationship, Caretech AI may act as a data processor, service provider, or independent controller. The applicable role should be defined in the relevant customer agreement, data processing agreement, or service contract.

That qualifier is load-bearing. The role follows from who determines the purposes and means of the processing, which is settled between the parties rather than declared on a website.

No data processing agreement, standard contractual clauses or transfer mechanism is described here as already in place.

Measures

Measures Caretech AI may support

Where GDPR applies, Caretech AI may support appropriate measures related to:

  • Lawful basis for processing
  • Data processing agreements
  • Data subject rights support
  • Access, correction, deletion, and portability workflows where applicable
  • Data minimization
  • Privacy-by-design and privacy-by-default principles
  • Security controls appropriate to processing risk
  • International data transfer safeguards where applicable
  • Subprocessor management where applicable
  • Breach notification support in accordance with applicable law and contract

Each of these becomes a commitment when it is written into an agreement, and not before.

Nothing here states where data physically resides. No EU data residency is claimed, and no diagram on this site implies a residency boundary.

Customer responsibility

What customers determine for themselves

Customers are responsible for determining their own lawful basis for processing personal data, providing required notices, obtaining necessary consents where applicable, and ensuring that their use of Caretech AI services complies with GDPR and other applicable privacy laws.

Lawful basis is a controller's determination; no processor can make it, and no vendor page can supply it.

The data protection commitments in full

Start with the data map, not the demo.

If personal data of people in the EEA would be involved, the first useful exchange is what data, for what purpose, on whose determination — before anyone discusses software.