Here is a highly professional, beautifully formatted, and scannable rewrite of your Privacy Policy. It uses a clean legal layout with callout boxes to highlight critical regulatory compliance info (like the EU Representative and Data Portal), making it trustworthy for your clients.
Privacy Policy: Fingerprinting & International Data Transfers
1. Data Controller and EU Representative
Borderless Business LLC (a US-based entity) is the Data Controller for the purposes of your FBI Identity History Summary check.
Because we do not maintain a physical establishment within the European Union, we have appointed an official EU Representative pursuant to Article 27 GDPR to act as our local point of contact for data subjects and regulatory authorities.
EU Representative Contact Information:
- Representative: Prighter EU Rep GmbH
- Address: Schellinggasse 3/10, 1010, Vienna, Austria
- Email: [email protected]
2. Purpose and Legal Basis for Processing
To facilitate and fulfill your request for an FBI background check, we must process your biometric data (specifically, your fingerprints).
- Explicit Consent: We rely on your explicit consent under Article 9(2)(a) GDPR to process this sensitive biometric data.
- Contractual Necessity: This processing is also strictly necessary to fulfill our service agreement with you under Article 6(1)(b) GDPR.
3. International Data Transfers (EU to USA)
Your fingerprints are captured by our authorized local service provider within the European Union. These identifiers are immediately encrypted and securely transferred to our servers in the United States, and subsequently forwarded to the Federal Bureau of Investigation (FBI).
- Safeguards: To guarantee a level of data protection equivalent to the GDPR, we utilize the European Commission’s Standard Contractual Clauses (SCCs) (Module 2: Controller-to-Processor) as the formal legal mechanism for this cross-border transfer.
4. Local Processing & “Zero-Retention” Protocol
Our European service providers operate strictly under our instructions as Data Processors.
To heavily minimize your data risk, our technical protocol mandates a strict zero-retention policy: your biometric files are immediately and permanently deleted from the local capture device the moment the encrypted transfer to the United States is confirmed. No local copy of your fingerprints is ever retained within the European Union.
5. Data Retention & Your Rights
We retain your biometric data only for the absolute minimum timeframe required to successfully complete your submission to the FBI. Once the background check is successfully processed, the biometric images are permanently purged from our primary systems.
As a data subject, you hold full rights under the GDPR to access your data, withdraw your consent, or request erasure. We value these rights and have partnered with Prighter Group to give you an efficient, transparent way to exercise them.
🏛️ Data Subject Portal
To easily submit a request regarding your privacy rights (such as data access or erasure), please visit our dedicated portal: 👉Access the Data Subject Portal
