Introduction
At BAMKO LLC (“BAMKO”, “we”, “us”, or “our”), protecting your personal data is a priority. This page explains how we approach data protection and privacy for individuals in the European Union (EU), European Economic Area (EEA), United Kingdom, and Switzerland, and how we comply with the General Data Protection Regulation (GDPR).
When you use BAMKO services, interact with our websites, or provide personal information to us in any context, you entrust us with your data. We respect that trust and use mechanisms to protect it and provide you with control over your personal information.
What Is GDPR?
The General Data Protection Regulation (GDPR) is a European Union law designed to protect the privacy rights of individuals (“data subjects”) and regulate how organizations collect, process, store, and share personal data. GDPR applies to companies both inside and outside the EU if they handle the personal data of individuals in the EU/EEA/UK/CH.
Personal Data We Collect and Process
BAMKO may collect and process the following types of personal data when you use our services or interact with us:
- Contact Details: name, email address, phone number
- Account and Authentication Data
- Professional Information: company, role, business address
- Usage and Technical Data: IP addresses, cookies, device identifiers
- Communications Data: support tickets, emails, feedback
We limit personal data collection to what is necessary for the purposes listed below and do not collect unnecessary sensitive data unless explicitly required and lawfully permitted.
How We Use Personal Data
BAMKO processes personal data for the following lawful purposes:
- To provide and operate our services
- To communicate with you, including support, billing, and updates
- To ensure service security and fraud prevention
- To comply with legal and regulatory obligations
- To tailor and improve our offerings
We rely on lawful bases under GDPR such as contract necessity, legal obligation, legitimate interest, and consent where applicable.
GDPR Principles We Follow
We comply with the core principles of data processing under GDPR:
- Lawfulness, fairness & transparency
- Purpose limitation
- Data minimization
- Accuracy
- Storage limitation
- Integrity & confidentiality
- Accountability
These principles guide how we manage personal data from collection through deletion.
Data Subject Rights
Individuals whose personal data we process have the following rights under GDPR:
- Right of access
- Right to rectification
- Right to erasure
- Right to restrict processing
- Right to data portability
- Right to object
- Right to withdraw consent
- Right to be informed
- Right in relation to automated decision-making and profiling
You can exercise these rights by contacting us at privacy@bamko.net. We aim to respond within the timelines required by GDPR.
Data Transfers Outside the EU/EEA
As a global company, BAMKO may transfer personal data outside the EU/EEA. Where data is transferred internationally, we implement appropriate safeguards such as Standard Contractual Clauses (SCCs) and other GDPR-approved mechanisms to ensure continued data protection.
Security and Data Protection
BAMKO implements technical and organizational measures to safeguard personal data, including:
- Encryption for data in transit and at rest
- Access controls and authentication safeguards
- Monitoring and logging of infrastructure
- Regular security reviews and audits
- Policies aligned with industry standards such as ISO 27001 and SOC 2
These measures help prevent unauthorized access, loss, or alteration of personal data.
Data Retention
We retain personal data only for as long as necessary to fulfill the purposes for which it was collected or to meet legal obligations. Retention periods vary depending on the service and use case.
Cookies & Tracking
Our website uses cookies and similar technologies for analytics, performance, and functional purposes. Where required, we obtain consent and provide mechanisms to manage preferences.
A separate Cookie Policy explains how these technologies are used and how you can control them.
Data Security Breaches
In the unlikely event of a personal data breach that poses a risk to individual rights and freedoms, BAMKO has established procedures to:
- Assess the breach,
- Notify the appropriate supervisory authority within 24 hours where required, and
- Inform affected individuals when there is substantial risk.
Contact Us
If you have any questions about this GDPR Compliance page or want to exercise your data subject rights, please reach out to:
We are committed to transparency, accountability, and protecting your personal data in compliance with GDPR.