European Privacy Rights (GDPR)

Last updated: 2026-04-17 · Effective: 2026-04-17 · Applies to residents of the EEA, United Kingdom, and Switzerland

Summary: If you are in the EEA, UK, or Switzerland, you have rights under the EU General Data Protection Regulation (EU 2016/679), the UK GDPR, and the Swiss FADP. We respect them all. Contact our privacy team at info@blokusa.com to exercise any of them.

1. Who is the "controller"?

Lok-N-Blok Systems LLC is the data controller for personal data collected through blokusa.com. Our contact details are at the bottom of this page.

Because we are established in the United States and do not have an establishment in the EEA or UK, we will appoint an Article 27 representative upon request from any EEA / UK supervisory authority. For now, direct all inquiries to info@blokusa.com.

2. Lawful basis for each processing activity

Under GDPR Article 6 we rely on the following lawful bases:

Processing activityLawful basisGDPR Art. 6(1)
Creating + authenticating your accountPerformance of a contract(b)
Responding to estimator / contact submissionsPerformance of a contract (pre-contract steps)(b)
Sending transactional email (password resets, approvals)Performance of a contract(b)
Server logs, security monitoring, rate limitsLegitimate interests (security of service)(f)
On-site analytics (aggregated, first-party)Legitimate interests (service improvement)(f)
Investor / distributor NCNDA enforcement + auditLegal obligation + legitimate interests(c), (f)
Compliance with subpoenas and regulatory requestsLegal obligation(c)
Marketing email (only if you opt in)Consent(a)

We do not process any special-category data (GDPR Art. 9) through blokusa.com.

3. Your rights under GDPR / UK GDPR

Right of access (Art. 15)

Ask for a copy of the personal data we hold about you. We will provide it in a commonly used, machine-readable format (JSON) within 30 days.

Right to rectification (Art. 16)

Ask us to correct inaccurate or incomplete data. Most account fields you can correct yourself.

Right to erasure — "right to be forgotten" (Art. 17)

Ask us to delete your personal data when it is no longer necessary for the purpose it was collected, you withdraw consent (where consent was the basis), or you object to processing based on legitimate interests and we have no overriding grounds. Exceptions: auditable NCNDA access logs, records needed for legal claims, and financial records required by law.

Right to restriction of processing (Art. 18)

Ask us to limit how we use your data while we verify a correction, evaluate an objection, or while we consider whether deletion is appropriate.

Right to data portability (Art. 20)

Receive the data you provided to us in a structured, commonly used, machine-readable format, and have it transmitted to another controller where technically feasible.

Right to object (Art. 21)

Object to processing based on legitimate interests (Art. 6(1)(f)) or for direct marketing. We will stop unless we can demonstrate compelling legitimate grounds that override your rights.

Rights related to automated decision-making (Art. 22)

We do not make decisions based solely on automated processing that produce legal or similarly significant effects. Admin approval of investor/distributor requests is always performed by a human admin.

Right to withdraw consent

Where we rely on consent (e.g., marketing email), you may withdraw it at any time. Withdrawal does not affect the lawfulness of processing before the withdrawal.

Right to lodge a complaint

You can complain to your local supervisory authority. For EU residents, that's the data-protection authority in your Member State. For UK residents, the Information Commissioner's Office (ICO). For Swiss residents, the Federal Data Protection and Information Commissioner (FDPIC).

4. How to exercise your rights

Email info@blokusa.com with "GDPR Request" in the subject line. Specify which right you wish to exercise. We will acknowledge within 3 business days and respond fully within 30 days (extendable by 60 days for complex requests, with notice to you).

We will verify your identity before processing. No fee unless your request is manifestly unfounded or excessive (we will explain in writing if that's the case).

5. International transfers

Your data is processed in the United States, where our servers (Railway) and our email provider (Google Workspace) are located. For transfers from the EEA, UK, or Switzerland to the United States we rely on:

6. Data retention

We retain personal data only as long as needed for the purpose for which it was collected:

DataRetention
Active account dataLifetime of the account
Deleted account dataPermanently removed within 7 days
Server access logs90 days live + 12 months compressed archive
Analytics events18 months raw, then aggregated indefinitely
NCNDA access audit log7 years (legal-claim retention)
Email audit log2 years
Consent log (this + other policies)Duration of account + 3 years

7. Sub-processors

See our Subprocessors page for the full, updated list of vendors that process personal data on our behalf.

8. Data Protection Officer (DPO)

We have not formally appointed a DPO because we do not meet the Art. 37 thresholds. Our designated privacy contact for GDPR inquiries is Kevin Flanagan at info@blokusa.com.

9. Data breach notification

If a personal data breach is likely to result in a high risk to your rights and freedoms, we will notify you without undue delay, and notify the competent supervisory authority within 72 hours of becoming aware, in accordance with Art. 33 and Art. 34.

10. Contact

Lok-N-Blok Systems LLC · Privacy Team · info@blokusa.com · 504-913-3606

Read alongside our Privacy Policy, CCPA / CPRA Rights, and Cookie Policy.