GDPR & Data Protection Compliance
UK & EU GDPR COMPLIANCE VERIFIED
Apigee Community adheres strictly to the UK General Data Protection Regulation (UK GDPR), EU GDPR, and Data Protection Act 2018.
1. OUR COMMITMENT TO DATA PROTECTION & PRIVACY BY DESIGN
Apigee Community is committed to upholding the highest standards of data protection, transparency, and personal privacy for all developers, learners, instructors, and mentors across the United Kingdom, the European Union, and worldwide.
We design all platform features — from interactive slide viewers and automated quiz scoring to freelance mentorship matching and forum discussions — in strict adherence to the fundamental principles set forth in Article 5 of the UK/EU GDPR:
Lawfulness & Fairness
We process personal data transparently, fairly, and only with valid legal bases.
Data Minimisation
We collect only the bare minimum personal data strictly necessary to deliver our educational services.
Security & Integrity
We employ TLS 1.3 encryption, secure credential hashing, and hardened server configurations.
2. DATA CONTROLLER & DESIGNATED DATA PROTECTION OFFICER (DPO)
For the purposes of data protection legislation, the Data Controller is the operator of Apigee Community. Our designated Data Protection Officer oversees compliance, manages data subject access requests, and acts as the primary contact for regulatory authorities. You may contact the DPO directly at dpo@apigeecommunity.com.
3. COMPREHENSIVE DATA SUBJECT RIGHTS & PROCEDURE
Under Articles 15 through 22 of the GDPR, all platform users are entitled to exercise the following statutory rights:
| GDPR Right | Description | How to Exercise |
|---|---|---|
| Right of Access (Art. 15) | Request a full copy of all personal data, course history, and exam scores associated with your account. | Email dpo@apigeecommunity.com |
| Right to Rectification (Art. 16) | Correct or update any inaccurate or out-of-date personal information, profile bio, or email address. | Directly in Profile Settings or via DPO |
| Right to Erasure (Art. 17) | Request permanent deletion of your profile, quiz logs, and account records ("Right to be Forgotten"). | Email dpo@apigeecommunity.com |
| Right to Restrict Processing (Art. 18) | Limit how we use your data while an accuracy or legitimate grounds dispute is being resolved. | Email dpo@apigeecommunity.com |
| Right to Data Portability (Art. 20) | Receive your personal learning records and certificates in a structured JSON or CSV format. | Email dpo@apigeecommunity.com |
| Right to Object (Art. 21) | Object to data processing based on legitimate interests or direct marketing communications. | Unsubscribe link or via DPO |
4. DATA SUBJECT ACCESS REQUEST (DSAR) SLA & TIMELINES
When you submit a Data Subject Access Request (DSAR) or Erasure Request to dpo@apigeecommunity.com:
- Identity Verification: We will verify your identity using your registered email address to protect against unauthorized data disclosure.
- Response SLA: We will fulfill your request without undue delay and at the latest within thirty (30) calendar days of receipt.
- Zero Fee: All statutory access and deletion requests are provided entirely free of charge.
5. INTERNATIONAL TRANSFERS & STANDARD CONTRACTUAL CLAUSES
Apigee Community ensures that any international data transfers outside the UK or European Economic Area (such as processing by our payment gateway Stripe or cloud infrastructure providers) are safeguarded by approved Standard Contractual Clauses (SCCs) and the UK International Data Transfer Addendum, ensuring an equivalent level of legal protection.
6. DATA BREACH NOTIFICATION PROTOCOL
In accordance with Articles 33 and 34 of the GDPR, in the unlikely event of a personal data breach posing a risk to the rights and freedoms of individuals, Apigee Community will notify the relevant supervisory authority within 72 hours of becoming aware of the breach, and will notify affected data subjects without undue delay where required.
7. SUPERVISORY AUTHORITY CONTACT
If you are not satisfied with our response to your privacy request, you have the statutory right to lodge a complaint with your national data protection regulator:
United Kingdom: Information Commissioner's Office (ICO) — ico.org.uk | Tel: 0303 123 1113
European Union: European Data Protection Board (EDPB) — edpb.europa.eu