GDPR & Data Protection

A practical overview of the GDPR-first operating model YUNIT SL uses for consumers, business partners and authorised auditors.

Also supports Andorran LQPD workflows.

GDPR-first service model

YUNIT SL presents this service primarily through a GDPR operating model: lawful processing, clear processor or controller roles, data minimisation, deletion handling, auditability and controlled access to personal data. The workflows shown on this site are designed to make those obligations operational rather than leaving them as policy text only.

Because YUNIT SL is established in Andorra, the same operating model is also aligned with the local LQPD and APDA supervisory context. This page explains how the service works in practice; it is not legal advice.

What the service supports

Data subject requests

Individuals can submit deletion-related requests for personal data held by YUNIT SL. Requests are recorded, acknowledged, reviewed and resolved with internal status tracking and evidence.

Processor documentation

Business customers can document processing responsibilities through DPA records and related compliance metadata when YUNIT SL processes data on their behalf or within a shared-service model.

Audit-ready access

Authorised auditors can receive controlled one-time access to relevant exports covering incidents, DPA records and deletion-request status, without turning the service into a public disclosure endpoint.

Implemented GDPR controls

  • DPA signatures are timestamped and linked to the signatory, entity type, contact details, country, DPA version and IP address.
  • Deletion and review requests are stored with requester details, optional scope notes, current status and resolution metadata so the decision path is traceable.
  • Audit access uses email-based one-time codes that expire after 24 hours and are marked as used immediately after export.
  • The public site explains the workflow, but identity checks, legal assessment, retention exceptions and final decisions remain controlled by YUNIT SL.
  • The service is designed around purpose limitation and restricted disclosure, so exported or shared data stays bounded to the specific workflow being handled.

How LQPD fits

For Andorran organisations, GDPR is the main language used on this public service surface because it is widely understood by business operators, technical teams and external reviewers. Local LQPD obligations are still supported where applicable through the same operational controls, recordkeeping and review model.

In practice, YUNIT uses one coherent privacy workflow and maps it to the local Andorran context where needed, instead of presenting a separate product posture for every regulatory label.