GDPR Compliance
Last updated: June 30, 2026
ANG Technologies Ltd fully complies with the EU General Data Protection Regulation (Regulation (EU) 2016/679 — "GDPR") and the UK GDPR / Data Protection Act 2018. This page explains your rights under the GDPR and how to exercise them.
1. Data Controller
- Company: ANG Technologies Ltd
- Company No: 17294566
- Jurisdiction: England and Wales
- Address: Unit 501 Leroy House, 434-436 Essex Road, London, N1 3FY, United Kingdom
- DPO Contact: support@promptang.com
2. Legal Bases for Processing
Under GDPR Article 6 we process your data based on:
- Performance of a contract — to provide the service to you (6/1/b)
- Legal obligation — tax, accounting, legal retention (6/1/c)
- Legitimate interest — fraud prevention, product improvement (6/1/f)
- Explicit consent — marketing communications, optional analytics (6/1/a)
3. Data Subject Rights
Your rights under GDPR Chapter III:
- Right of access (Art. 15) — request a copy of your data
- Right to rectification (Art. 16) — correct inaccurate/incomplete data
- Right to erasure (Art. 17) — "right to be forgotten"
- Right to restriction (Art. 18)
- Data portability (Art. 20) — in machine-readable format
- Right to object (Art. 21) — to processing based on legitimate interest
- Automated decision-making rights (Art. 22)
- Withdraw consent — at any time
- Right to complain — to the competent supervisory authority (e.g. ICO — UK)
4. DSAR — Data Subject Access Request
To exercise your rights you can submit a written request to our DPO: support@promptang.com
Your requests are answered within 30 calendar days. We may request additional information to verify your identity. The service is free; however, we reserve the right to charge a reasonable fee for manifestly unfounded or excessively repetitive requests.
5. International Data Transfers
Some of our service providers (a secure payment provider, cloud infrastructure) may be located outside the European Economic Area. Such transfers are carried out under EU Commission-approved Standard Contractual Clauses (SCCs) or adequacy decisions.
6. Data Retention Periods
- Account data: until account deletion + 30 days
- Purchase records: 7 years due to legal obligation
- Marketing consent records: until consent is withdrawn
- System logs: 90 days (for security)
7. Data Breach Notification
In the event of a high-risk data breach, we notify affected users and the supervisory authority within 72 hours under GDPR Articles 33-34.
8. Supervisory Authority
If you are not satisfied with the processing, you have the right to lodge a complaint with your local supervisory authority. For the UK: Information Commissioner’s Office (ICO).