Regulatory & Data Governance

Global Compliance & Data Protection

burnmap operates with privacy-by-design. We maintain full compliance with international privacy regulations including the European Union General Data Protection Regulation (GDPR), the California Consumer Privacy Act as amended by the CPRA, India’s Digital Personal Data Protection (DPDP) Act 2023, Brazil’s LGPD, and global PCI-DSS security standards.

🇪🇺 GDPR & UK-GDPR
Full lawful basis processing under Article 6, dedicated Data Subject Access Request (DSAR) workflows, and Standard Contractual Clauses (SCCs) for cross-border protection.
🇺🇸 California CCPA / CPRA
Explicit "Do Not Sell or Share My Personal Information" guarantee. We never monetize, sell, or distribute your personal data to cross-context advertising brokers.
🇮🇳 India DPDP Act 2023
Full adherence to Data Principal rights, transparent Data Fiduciary processing, lawful transaction notices, and fast-track Grievance Redressal channels.

1. European Union & United Kingdom (GDPR / UK GDPR)

Under Regulation (EU) 2016/679 (GDPR) and the Data Protection Act 2018 (UK GDPR), European and British users possess clear statutory rights regarding their personal data:

ART. 6 · LAWFUL BASES
Contractual Necessity & Legitimate Interest
We process your email and transaction records solely to execute the contract of holding your block on the map (issuing receipts, delivering critical expiration warnings, and processing displacement credits). Security logging (IPs, rate limiting) is processed under our legitimate interest to defend against DDoS attacks and prevent payment fraud.
ART. 15–22 · DATA SUBJECT RIGHTS
Full Control of Your Data
You have the absolute right to:
  • Access (Art. 15): Request a machine-readable copy of all data linked to your email.
  • Rectification (Art. 16): Correct inaccurate metadata, URLs, or labels on your blocks.
  • Erasure (Art. 17): Exercise your "Right to be Forgotten" to delete your personal records.
  • Restriction & Objection (Art. 18 & 21): Object to any non-essential processing.
  • Data Portability (Art. 20): Export your transaction history in structured JSON format.
ART. 44–49 · INTERNATIONAL TRANSFERS
Standard Contractual Clauses (SCCs)
Where data is transferred internationally (e.g., to cloud hosting or payment infrastructure), such transfers are safeguarded by the European Commission’s Standard Contractual Clauses (SCCs) and UK International Data Transfer Addendums.

2. California Consumer Privacy Act & CPRA (California, USA)

For residents of California, the California Consumer Privacy Act (Cal. Civ. Code § 1798.100 et seq.), as amended by the California Privacy Rights Act of 2020 (CPRA), affords specific protections:

🚫 NO SALE OR SHARING OF PERSONAL DATA
burnmap has never sold, rented, or shared personal data to third-party data brokers, ad networks, or cross-context behavioral marketing companies, and will not do so in the future.
📋 Categories of Information Collected
Over the preceding 12 months, we have collected: (A) Identifiers (email address, IP address); (B) Commercial Information (transaction timestamps, hold time credits, amounts paid); and (C) Internet/Network Activity (system logs).
⚖️ Right to Non-Discrimination
We will never deny you service, charge different prices, or provide a lower quality of service for exercising your CCPA/CPRA statutory privacy rights.
👤 Authorized Agent Submissions
California consumers may designate an authorized agent registered with the California Secretary of State to submit privacy requests on their behalf via verified power of attorney.

3. Digital Personal Data Protection Act, 2023 (India)

Under the Digital Personal Data Protection Act, 2023 (DPDP Act), Indian citizens and residents interacting with burnmap benefit from structured Data Principal protections:

DATA PRINCIPAL RIGHTS
Transparency & Consent
Data is processed strictly for the specified purpose of fulfilling your digital block claim. Data Principals have the right to obtain a summary of personal data being processed, request correction or erasure of obsolete records, and access immediate grievance redressal.
GRIEVANCE REDRESSAL
Grievance Officer & Redressal Timeline
In accordance with Section 13 of the DPDP Act, you may contact our Grievance Officer directly at [email protected]. All grievances are acknowledged within 48 hours and resolved within 30 days.

4. Other Global Frameworks (Brazil LGPD, Canada PIPEDA, APPI)

burnmap applies high-standard data protection principles globally across all jurisdictions:

🇧🇷 Brazil (LGPD)
Full compliance with Lei Geral de Proteção de Dados (Law No. 13.709/2018). Data subjects may request anonymization, blocking, or deletion of unnecessary personal data.
🇨🇦 Canada (PIPEDA)
Adherence to the 10 fair information principles of the Personal Information Protection and Electronic Documents Act regarding consent, purpose specification, and safeguards.
🇦🇺 Australia & 🇯🇵 Japan
Compliant with the Australian Privacy Principles (APPs under Privacy Act 1988) and Japan’s Act on the Protection of Personal Information (APPI).

5. Financial Security & Payment Compliance (PCI-DSS)

All financial transactions are conducted exclusively via Stripe:

PCI SERVICE PROVIDER LEVEL 1
Direct Client-Side Tokenization
Card details, CVVs, and billing addresses are transmitted directly from your browser to Stripe over encrypted TLS 1.3 connections. Raw credit card data never passes through or touches burnmap servers.
ENCRYPTION & ACCESS CONTROLS
State-of-the-Art Infrastructure
All database connections utilize strict SSL/TLS encryption. Sensitive records are encrypted at rest using AES-256 standards with strict role-based access control (RBAC).

6. How to Submit a Privacy Request

To exercise any of your rights under GDPR, CCPA/CPRA, DPDP, LGPD, or other applicable laws, you can reach our Data Protection Team through either of the following channels: