Legal

Ask for a Demo Now
Hero Banner Hexagon

GDPR Compliance

The EU’s General Data Protection Regulation (known as GDPR) defines how businesses need to protect the privacy of EU residents. DeskDirector is committed to the principles of the GDPR and its obligations to the handling and governance of personal data collected.

 

Principles of the GDPR

  1. Lawfulness, fairness and transparency
  2. Purpose limitation
  3. Accuracy
  4. Storage limitation
  5. Integrity and confidentiality

Lawfulness, fairness and transparency

Personal data will be processed lawfully, fairly and in a transparent manner in relation to individuals.

Purpose limitation

Personal data will be collected for specified, explicit and legitimate purposes and not further processed in a manner that is incompatible with those purposes; further processing for archiving purposes in the public interest, scientific or historical research purposes or statistical purposes shall not be considered to be incompatible with the initial purposes (‘purpose limitation’).

Data Minimization

Personal data will be adequate, relevant and limited to what is necessary in relation to the purposes for which they are processed.

Accuracy

Personal data will be accurate and, where necessary, kept up to date; every reasonable step will be taken to ensure that personal data that is inaccurate, having regard to the purposes for which they are processed, are erased or rectified without delay

Storage limitation

Personal data will be kept in a form which permits identification of data subjects for no longer than is necessary for the purposes for which the personal data are processed; personal data may be stored for longer periods insofar as the personal data will be processed solely for archiving purposes in the public interest, scientific or historical research purposes or statistical purposes subject to implementation of the appropriate technical and organisational measures required by the GDPR in order to safeguard the rights and freedoms of individuals

Integrity and confidentiality

Personal Data will be processed in a manner that ensures appropriate security of the personal data, including protection against unauthorised or unlawful processing and against accidental loss, destruction or damage, using appropriate technical or organisational measures.

 

 

Roles as Data Controller and Roles as Data processor

Data controller: For our customers, DeskDirector will act as a data controller. When DeskDirector is the data controller, we handle personal data as described in our Privacy Policy. Customers are managed services providers subscribed to the service.

Data processor: DeskDirector acts as a data processor on behalf of our subscribing Managed Services Providers for information collected on behalf of our Subscribers customers. This is typically the customers of the subscribing managed services provider.

 

DeskDirector and Security

DeskDirector has taken security and privacy very seriously from its beginnings. Consequently, our systems and processes were already compliant for the 2018 launch of GDPR.

Some of the ways we protect your privacy include:

  • We collect very little personal data from our customers. Almost 100% of that data is stored for marketing purposes.
  • The HubSpot marketing platform that powers our website and campaigns has GDPR compliance integrated
  • We use a PCI DSS Level 1 processor to transact credit cards. DeskDirector never stores credit card details.
  • All our systems and data are hosted with a highly certified, Tier 1 hosting providers: Amazon Web Services and Microsoft Azure.
  • All our systems and data are hosted with a highly certified, Tier 1 hosting provider: Amazon Web Services and Microsoft Azure.
  • Data transfer is encrypted
  • All our products offer the option to use oAuth 2.0 and OpenID protocols to allow independent verification, monitoring and management of information access using Microsoft’s Azure AD. 
 

If you have any questions about your privacy or the security of your data, including needing information on providing access or erasing your data, please contact support@deskdirector.com