Needle is GDPR Ready

Last updated: August 10, 2026

What is GDPR?

The General Data Protection Regulation (GDPR) is a European Union (EU) regulation that establishes a framework for handling and processing personal data of EU residents. Any business processing personal data (collecting, recording, storing, using, etc.) of EU residents must comply with GDPR. The regulation came into effect on May 25, 2018.

Territorial Scope: GDPR applies to Needle because we process personal data of EU residents. We are fully committed to GDPR compliance.

What are the Benefits of GDPR?

GDPR gives you, as a data subject, the following rights and benefits:

  • Right of Access: Easily identify and access all your personal data
  • Right to Rectification: Update your personal information whenever needed
  • Right to Erasure: Request permanent deletion of all your data (Right to be Forgotten)
  • Right to Data Portability: Export your data in machine-readable formats (JSON, CSV)
  • Right to Withdraw Consent: Opt out of analytics tracking and marketing communications at any time
  • Transparency: Clear information about how your data is processed, stored, and used

How is Needle Preparing for GDPR?

Needle welcomes GDPR and is fully committed to achieving compliance. We understand our obligations to our users and value your personal data rights. Here's what we have implemented:

GDPR Analysis

We have thoroughly analyzed GDPR requirements and implemented all necessary compliance measures.

Identifying Personal Data

We have identified all personal data collected, stored, used, and disposed, with clear retention policies.

Transparency & Visibility

We provide full transparency on how collected personal data is used, with detailed privacy policies and data processing information.

Enhanced Data Security

We implement industry-standard encryption (AES-256), secure cloud infrastructure, and regular security audits.

Data Portability

We provide streamlined data export capabilities in machine-readable formats (JSON, CSV) for all your data.

User Rights Implementation

All GDPR rights are implemented with easy-to-use features in your Settings.

Features Built for GDPR Readiness

Right to be Forgotten (Right to Erasure)

Needle lets you delete your account and all associated data permanently. This includes:

  • User profile and authentication data
  • Search history and results
  • Brand profiles, Auto Search results, scheduled checks, and alert preferences
  • Usage statistics
  • Email preferences and settings

Application content above is removed when you delete your account. For legal compliance and security we may retain a minimal record (such as your email and optional exit reason) for a limited period as described in our Privacy Policy (Section 5.5).

Warning: This action is irreversible. All your data will be permanently deleted within 24 hours.

Go to Settings → Privacy & Data Rights → Account Deletion

Right to Rectification

GDPR includes a right for individuals to have inaccurate personal data rectified, or completed if it is incomplete. In Needle, you can:

  • Update email preferences (marketing, insights) in Settings
  • Update search settings (default platforms, timeframes)
  • Update branding (company name, website)
  • Name and photo: If you signed in with Google, update them in your Google Account (synced on login). If you signed in with email link, your display name is derived from your email; update other profile details in Settings.

Right to Data Portability

Needle lets you export all your data in machine-readable formats. Your export includes:

  • Complete user profile
  • All search history and results
  • Brand profiles, Auto Search results, scheduled checks, and alert preferences
  • Usage statistics
  • Email preferences and settings
  • Consent records
  • Processing metadata (GDPR Article 15 compliance)

Formats: JSON (machine-readable) and CSV (human-readable). Exports are available for 24 hours after generation.

Go to Settings → Privacy & Data Rights → Data Export

Right to Withdraw Consent

You can withdraw your consent for analytics tracking and marketing communications at any time:

  • Analytics cookies (incl. session replay): Use Manage cookies in the site footer or the choices in the cookie banner (see our Cookie Policy). Replay stops the moment you withdraw.
  • Offers & promotions emails: Toggle off in Account settings or click the unsubscribe link in any promotional email (works even when logged out)
  • Product updates & tips emails: Object under Article 21 or toggle off in Account settings / the unsubscribe link in any product email
  • Insights Emails: Toggle off insights emails in Email Preferences

Note: Withdrawing consent takes effect immediately. Essential cookies cannot be disabled as they are required for service operation, and transactional emails (welcome, billing, scan results) are not preference-controlled.

Go to Settings → Privacy & Data Rights → Consent Management

Needle GDPR FAQ

Are Needle services GDPR compliant?

Yes. Needle is committed to transparent and secure handling of all personal data. Our processes have been reviewed to ensure we fully meet the requirements set forth in the EU General Data Protection Regulation (GDPR). We have implemented all necessary technical and organizational measures to protect your data.

What is Needle's role with respect to GDPR?

Needle acts as both a data controller and a data processor. Needle acts as a data controller for user information that we collect to provide our service and customer support. When processing your personal data for service delivery, Needle acts as a data processor in compliance with GDPR requirements.

Does Needle offer a Data Processing Addendum (DPA)?

Yes. If GDPR applies to your organization and you need a DPA to satisfy GDPR requirements, Needle makes one available at: Data Processing Addendum.

For questions or to execute a DPA, please contact support@useneedle.net.

How do you Delete User Data?

Needle lets you delete your account and all associated data permanently. To delete your data:

  1. Go to your Settings
  2. Click "Delete My Account"
  3. Read the warning carefully
  4. Confirm deletion
  5. You will be logged out immediately
  6. Account deletion will complete within 24 hours

Important: Account deletion is permanent and irreversible. All your data will be deleted within 24 hours. You will be logged out immediately after requesting deletion.

How do you Export User Data?

Needle lets you export all your data in machine-readable formats (JSON, CSV). To export your data:

  1. Go to your Settings
  2. Click "Export My Data"
  3. Select format (JSON or CSV)
  4. Wait for export to complete (you will receive an email)
  5. Download your data file

Note: Exports are rate-limited to 1 export per 24 hours. Export files are available for 24 hours after generation, then automatically deleted.

How is my data in Needle protected from misuse?

All data, including personal data, is protected by:

  • Encryption: AES-256 encryption for sensitive data at rest
  • Encryption in Transit: All data transmitted over HTTPS/TLS
  • Access Controls: User-specific encryption keys and authentication
  • Data Minimization: We only collect data necessary for service delivery
  • Automatic Deletion: Old data is automatically deleted based on retention policies
  • Security Audits: Regular security reviews and updates

How do you address a customer's request to 'Opt-Out Analytics'?

You can opt out of analytics tracking in two ways:

  • In product: Use Manage cookies in the site footer (or the cookie banner) to turn off optional analytics, and open Account settings for email-related preferences where shown.
  • Email Request: Contact support@useneedle.net to opt out

Opting out takes effect immediately. No analytics events will be tracked after you withdraw consent.

How do you address 'Data Rectification' requests?

GDPR includes a right for individuals to have inaccurate personal data rectified. In Needle, you can:

  • Go to your Settings
  • Update any incorrect information
  • Click "Save"
  • Changes are applied immediately

For name and photo: if your account is linked to Google sign-in, update your Google Account- changes sync on your next login. If you signed in with email link, your display name comes from your email; update other details in Settings.

How do you notify me of a data breach?

In the event of a personal-data breach we notify the relevant supervisory authority within 72 hours where feasible (GDPR Article 33), and we notify you directly if the breach is likely to result in a high risk to your rights and freedoms (Article 34). In India we follow the DPDP Rules, 2025: an initial notice to the Data Protection Board without delay and a detailed report within 72 hours, plus notification to affected data principals. Where we have your email we may notify you that way; otherwise we post a notice on our site. See the Breach Notification section of our Privacy Policy.

Do I need to move my data to an EU data center?

Needle uses data centers and services that comply with GDPR requirements:

  • Database: US-based with EU data centers available (Standard Contractual Clauses)
  • Email: EU-based (no cross-border transfer)
  • Storage: EU jurisdiction for data exports
  • Cache: Global with EU/US regions available

All data transfers are protected by Standard Contractual Clauses (SCCs) where applicable. You do not need to move your data manually.

Business information

Needle is operated by the business identified below. Details are published in good faith for transparency and support. If you believe any item is incorrect or out of date, email support@useneedle.net and we will correct this page after verification where appropriate.

Business Details

  • Business Name: VS NextGen Solutions
  • Parent Company: Needle is a product of VS NextGen Solutions (https://vsnextgensolutions.com/)
  • Business Structure: Sole Proprietorship
  • Registration: Udyam Registered (MSME) – Govt. of India
  • MSME Certificate Number: UDYAM-KR-03-0578420
  • MSME Registration Date: 05-08-2025
  • MSME Category: Micro Enterprise
  • Business Address: Bengaluru, Karnataka, India
  • Contact: support@useneedle.net

Support

I have questions, how do I get in touch?

Please feel free to reach out to Needle Support for any questions about GDPR, data protection, or your rights. We'd be happy to clarify any doubt.

Our Commitment

We at Needle are committed to providing a product that enables our users to use our service responsibly by implementing and adhering to prescribed compliance policies, both as a data controller and processor. GDPR enforcement is critical to our mission of providing EU and all our global users with safe and dependable customer discovery software.

For more information or questions about the Needle Privacy Policy, please view our Privacy Policy or contact support@useneedle.net.