GDPR Compliance

Last updated: February 6, 2026

1. Introduction

Lastmil is committed to compliance with the General Data Protection Regulation (GDPR) (EU) 2016/679, which came into effect on May 25, 2018. This page outlines our commitment to protecting your personal data and your rights under GDPR.

GDPR applies to all organizations that process personal data of individuals in the European Union (EU), regardless of where the organization is located. We process personal data in accordance with GDPR requirements.

2. Legal Basis for Processing

We process your personal data based on the following legal grounds:

  • Consent: You have given clear consent for us to process your personal data for specific purposes
  • Contract: Processing is necessary for the performance of a contract or to take steps at your request before entering into a contract
  • Legal Obligation: Processing is necessary for compliance with a legal obligation
  • Legitimate Interests: Processing is necessary for our legitimate interests or those of a third party, provided your interests and fundamental rights do not override those interests

3. Your Rights Under GDPR

As a data subject under GDPR, you have the following rights:

3.1 Right to Access

You have the right to obtain confirmation as to whether or not we process your personal data and, if we do, to access that data along with certain information about how it is processed.

3.2 Right to Rectification

You have the right to have inaccurate personal data corrected and incomplete personal data completed.

3.3 Right to Erasure ("Right to be Forgotten")

You have the right to request the deletion of your personal data in certain circumstances, such as when the data is no longer necessary for the original purpose or when you withdraw consent.

3.4 Right to Restrict Processing

You have the right to request that we limit the processing of your personal data in certain circumstances.

3.5 Right to Data Portability

You have the right to receive your personal data in a structured, commonly used, and machine-readable format and to transmit that data to another controller.

3.6 Right to Object

You have the right to object to processing of your personal data based on legitimate interests or for direct marketing purposes.

3.7 Right to Withdraw Consent

Where processing is based on consent, you have the right to withdraw your consent at any time, without affecting the lawfulness of processing based on consent before its withdrawal.

4. Data Protection Principles

We adhere to the following GDPR principles:

  • Lawfulness, Fairness, and Transparency: We process personal data lawfully, fairly, and transparently
  • Purpose Limitation: We collect personal data only for specified, explicit, and legitimate purposes
  • Data Minimization: We collect only the personal data that is necessary for our purposes
  • Accuracy: We keep personal data accurate and up to date
  • Storage Limitation: We retain personal data only for as long as necessary
  • Integrity and Confidentiality: We implement appropriate security measures to protect personal data
  • Accountability: We are responsible for demonstrating compliance with GDPR principles

5. Data Transfers

If we transfer your personal data outside the European Economic Area (EEA), we ensure that appropriate safeguards are in place to protect your data, such as:

  • Standard Contractual Clauses approved by the European Commission
  • Adequacy decisions by the European Commission
  • Other appropriate safeguards as required by GDPR

6. Data Breach Notification

In the event of a personal data breach that is likely to result in a high risk to your rights and freedoms, we will notify you and the relevant supervisory authority without undue delay, and in any event within 72 hours of becoming aware of the breach.

7. Data Protection Officer

We have appointed a Data Protection Officer (DPO) to oversee our GDPR compliance. You can contact our DPO at:

Email: dpo@lastmil.com

8. Exercising Your Rights

To exercise any of your GDPR rights, please contact us using the information provided below. We will respond to your request within one month of receipt.

We may request proof of identity to verify your request and ensure the security of your personal data.

9. Right to Lodge a Complaint

If you believe that our processing of your personal data violates GDPR, you have the right to lodge a complaint with a supervisory authority, in particular in the Member State of your habitual residence, place of work, or place of the alleged infringement.

You can find contact details for your local supervisory authority on the European Data Protection Board website.

10. Contact Us

For any questions or requests regarding GDPR compliance, please contact us:

Email: privacy@lastmil.com
Data Protection Officer: dpo@lastmil.com
Website: lastmil.com