GDPR Compliance

✓ GDPR Compliant

Our Commitment to Data Protection

Lodestone is fully committed to compliance with the General Data Protection Regulation (EU) 2016/679 (GDPR). We implement robust data protection measures to ensure your personal information is handled securely, transparently, and in accordance with your rights.

1. GDPR Compliance Framework

Lawful Processing

We process data only on legal bases: consent, contract, legitimate interest, or legal obligation.

Data Minimization

We collect only data necessary for specified purposes and retain it no longer than needed.

Transparency

Clear privacy notices explain what data we collect, why, and how we use it.

Data Security

Technical and organizational measures protect against unauthorized access and breaches.

Individual Rights

Mechanisms to exercise all GDPR rights: access, rectification, erasure, and more.

Accountability

Documentation, policies, and procedures demonstrate our compliance efforts.

2. Data Protection Principles

2.1 Lawfulness, Fairness, and Transparency

2.2 Purpose Limitation

2.3 Data Minimization

2.4 Accuracy

2.5 Storage Limitation

2.6 Integrity and Confidentiality

3. Your GDPR Rights

We Make It Easy to Exercise Your Rights:

  1. Right to Access (Article 15): Request a copy of your personal data we hold
  2. Right to Rectification (Article 16): Correct inaccurate or incomplete data
  3. Right to Erasure (Article 17): Request deletion of your data ("right to be forgotten")
  4. Right to Restriction (Article 18): Limit how we process your data
  5. Right to Data Portability (Article 20): Receive your data in a machine-readable format
  6. Right to Object (Article 21): Object to processing based on legitimate interests
  7. Rights Related to Automated Decision-Making (Article 22): Not be subject to decisions based solely on automated processing

To exercise any right: Email privacy@lodestone.io
Response time: Within 30 days (extendable to 60 days for complex requests)

4. Data Processing Activities

4.1 Recruitment Services

4.2 Employer Branding Services

4.3 Event Management

5. Data Security Measures

Technical Measures:

Organizational Measures:

6. International Data Transfers

If we transfer data outside the EU/EEA, we ensure adequate safeguards:

7. Data Breach Procedures

In the Event of a Data Breach:

  1. Detection & Containment (0-24 hours): Immediate action to stop the breach
  2. Assessment (24-48 hours): Evaluate scope, impact, and affected individuals
  3. Notification (Within 72 hours):
    • Supervisory authority notification (if high risk)
    • Affected individuals notification (if high risk to rights and freedoms)
  4. Remediation: Fix vulnerabilities, prevent recurrence
  5. Documentation: Record all breaches in our breach register

8. Third-Party Processors

We work only with GDPR-compliant processors:

9. Children's Data

We do not knowingly process data of individuals under 16. If we discover we've collected data from a child, we will delete it immediately and notify parents/guardians.

10. Contact Our Data Protection Officer

Data Protection Officer (DPO)
Email: dpo@lodestone.io
General Privacy Inquiries: privacy@lodestone.io

Supervisory Authority:
You have the right to lodge a complaint with your data protection authority.
Find your local authority: https://edpb.europa.eu

11. Updates to Compliance

We continuously review and update our GDPR compliance measures. This page was last reviewed on February 3, 2026.

Questions About GDPR Compliance?

We're here to help. Contact our Data Protection Officer at dpo@lodestone.io for any questions about how we protect your data.