What is GDPR?
The EU General Data Protection Regulation, better known as GDPR, is one of the most comprehensive privacy and security laws in the world, effective as of May 25, 2018. This regulation was implemented by the EU to harmonize data privacy laws across Europe; protect and empower all EU citizens’ data privacy; give people more control over their personal data, and reshape the way organizations approach data privacy.
StorifyMe is committed to complying with the GDPR and protecting personal data processed in connection with our services. Given the importance of data protection to our customers, partners and other stakeholders, this page provides an overview of how StorifyMe approaches GDPR compliance.
Who does GDPR apply to?
The GDPR applies to organizations that process personal data in the context of activities of an establishment in the EU. It may also apply to organizations established outside the EU where they offer goods or services to individuals in the EU or monitor their behavior within the EU..
How does GDPR affect data transferred outside of the EU?
The GDPR permits personal data to be transferred outside the European Economic Area where the requirements of Chapter V of the GDPR are met. Where required, StorifyMe relies on appropriate safeguards for international data transfers, including adequacy decisions and the Standard Contractual Clauses adopted by the European Commission. More information about the processing of Customer Data and international transfers is available in our Data Processing Addendum.
Rules that companies/entities must adhere to
Personal data must be processed in a lawful and transparent manner; there must be specific purposes for processing the data and those purposes must be indicated to individuals when collecting their personal data; only the personal data that is necessary to fulfil a purpose can be collected; personal data cannot be stored longer than necessary for the purposes for which it was collected; and organizations must install appropriate technical and organizational safeguards that ensure the security of the personal data.
How does StorifyMe comply with the GDPR?
Whether we are offering our StorifyMe solution to customers, contracting with suppliers, or hiring new people: StorifyMe collects, uses, processes, transfers, and stores personal data.
StorifyMe identifies all the personal data that is being processed and defines the purpose of this processing in order to determine how the collected data is used, and provide appropriate visibility and transparency.
StorifyMe maintains systems and procedures designed to implement GDPR principles across our systems, data processing activities and business practices.
Data protection also requires appropriate data security. StorifyMe maintains technical and organizational measures designed to protect personal data, including measures relating to encryption, access controls, incident response and data breach notification, as well as employee security and privacy awareness.