Legal FAQ
What is StorifyMe?
StorifyMe is a cloud-based content management platform. Our customers can be everything from an online publisher using StorifyMe to publish news as mobile native experiences, or a retailer creating experiences to communicate with their audience.
The structure of your experiences is completely flexible and can be created by a member of your team in accordance with the requirements of your project (e.g. news, landing pages, FAQs, product information, reviews, promotional in-app material and so on). Similarly, your development team is free to integrate content into any application, device type or platform. For example, content can be loaded into a website, mobile apps, or any other experience.
A non-technical overview of StorifyMe’s service is available at: www.storifyme.com/.
What kind of content is stored in StorifyMe?
Your team can use StorifyMe to create, personalize, distribute and analyze a variety of digital experiences, including Stories, Shorts and other interactive content. Content may be distributed through websites, mobile applications and other digital channels.
StorifyMe can be used to store typical content such as:
- News and editorial content
- Blog and informational content
- Product and service information
- Store locations and hours
- Images and videos
- In-app content and notifications
The StorifyMe Services are not intended for storing highly sensitive information such as passwords, private keys, payment card details, or special categories of personal data, unless expressly agreed otherwise.
How does StorifyMe deal with data protection regulations?
StorifyMe has its main offices in Munich, Germany. We comply with applicable German and European data protection laws, including the General Data Protection Regulation (GDPR), and other applicable data protection and privacy laws.
First off, it’s important to understand that StorifyMe provides infrastructure, platform and services for its customers to manage their content that they specifically wish to publish. As such, the content is typically non-sensitive editorial content that customers want to publish, and have the right to publish, and it doesn’t usually contain personal data.
So what kind of personal data does StorifyMe process?
Your content that you upload to and manage on the StorifyMe platform and services may contain personal data, such as images of people. We do not know because we do not monitor your content, nor do we access your content unless you ask us to, for example to provide technical customer support. Our services will process your content for you and serve the content via application programming interfaces (APIs) and Content Delivery Network (CDNs) to your web, mobile and other applications for your end users to enjoy.
Because you as the customer are deciding where you want to show this content, you are in control of the user experience (including privacy and data processing) in places where content is shared. StorifyMe processes limited technical information associated with requests to the Services, such as request headers, as necessary to deliver, secure and operate the Services and provide applicable functionality such as analytics.
If you are using the StorifyMe web app to manage your content, StorifyMe requires the user’s name, email address and web app password and logs the IP address of the web app user. These are necessary pieces of information that are required for StorifyMe to provide the service, authenticate users and protect the service and your content.
StorifyMe processes personal data only as necessary to provide, operate, secure and improve the Services, and as otherwise described in our agreements and privacy documentation. When processing Customer Data on behalf of a customer, StorifyMe acts in accordance with the customer's instructions and the applicable Data Processing Addendum.
Where is customer content and customer personal data stored?
Customer content and personal data are hosted using reputable cloud infrastructure providers and processed in accordance with our Data Processing Addendum and applicable data protection requirements.
How does StorifyMe secure adequate level of data protection outside of the European Union?
As between you, our customer, and StorifyMe we will enter into a data processing agreement to govern our processing of your personal data. If needed, this will include Standard Contractual Clauses adopted by the European Commission for transfer of personal data from the EU to countries outside of the EU. If you are a StorifyMe customer and you require a data processing agreement, please raise a support ticket in your StorifyMe account.
As between StorifyMe and its vendors like AWS, StorifyMe enters into similar data processing agreements, including the standard contractual clauses or other legally approved data transfer mechanisms to ensure adequate level of data protection to the extent personal data is transferred outside of the EU.
What are you doing to ensure compliance with data protection laws?
Although the StorifyMe services are intended for managing non-sensitive, public, editorial content, StorifyMe takes privacy and security seriously. This includes complying with applicable data protection and privacy laws, including the GDPR. Here are some highlights of our initiatives with regards to privacy and security:
- We are continuously investing in and improving our security. For more information on our security approach please see here.
- We are running training and Q&A sessions with our employees to raise awareness of privacy and security generally and GDPR specifically. All employees get a security onboarding training and commit contractually to maintaining data secrecy.
- We conduct security reviews on our vendors to ensure they maintain appropriate level of privacy and security.
- We make sure that we have appropriate contracts with our vendors to protect privacy and security. This includes data processing and data transfer agreements that address international data transfers, for example by including so called EU standard contractual clauses or other legally approved data transfer mechanisms.
- When we process personal data under the GDPR for our customers we will enter into appropriate contracts with such customers and comply with requirements set out in the GDPR and such contracts. If you are a StorifyMe customer and you use our services to process personal data and you do not yet have an appropriate agreement in place with StorifyMe, please raise a support ticket in your StorifyMe account.
- If a data breach should happen we have dedicated engineering staff on call and defined data breach processes to act swiftly and in accordance with the GDPR and our customer contracts, including notifying our customers, authorities or affected individuals, as applicable.
- We continue to monitor legal and regulatory developments relating to data protection, privacy and security and adjust our approach accordingly.
How does StorifyMe deliver its services?
StorifyMe is a cloud-based platform used to create engaging experiences. StorifyMe develops and operates its service as a multi-tenant environment.
This means that your organization does not need to run any software (besides the presentation layer in which engaging experiences are displayed) on your systems, but instead is granted access to the StorifyMe cloud-based backend.
Due to its cloud-based architecture, StorifyMe does not ship installable proprietary software. StorifyMe is solely used as a cloud service, all intellectual property rights of the StorifyMe platform stay with StorifyMe. This also means that StorifyMe does not provide customer-specific tailored services or software or other professional services unless agreed differently.
How reliable is StorifyMe?
StorifyMe hosts and delivers content for the world’s largest organizations during a routine day and during the high-traffic events like Black Friday or the Super Bowl. We make an effort to provide a reliable service.
- Our uptime history is available on https://status.storifyme.com/
- Our enterprise SLAs provide our customers with service levels for service availability and support.
- We take security seriously (https://www.storifyme.com/security/) and include our security standards in our enterprise contracts.
What payment methods do you support?
Our self-service plans are paid by credit card.
For Enterprise plans, we also support purchase orders, wire transfers (including ACH and SEPA), and checks. If you require a different payment method or specific invoicing terms, please contact our sales team.
Can we change or amend the terms of service?
Just as for payment methods, offering custom legal terms would incur a lot of additional costs making it unsustainable for us to offer self-service plans at the current price levels.
For this reason, we do not support any changes to our online terms nor signing of any additional agreements nor carrying out of custom security audits on our self-service tier.
If you require more flexibility, contact our sales team to find out about the enterprise version of StorifyMe, where we offer more room for custom agreements.