GDPR Compliance
CrowdHandler is committed to complying with the General Data Protection Regulation (GDPR) when processing personal data from customers and users of our website and application services. Our compliance with GDPR is fundamental to how we handle data on a daily basis. We have implemented mechanisms and controls to adhere to GDPR requirements with oversight from our data protection officer and senior management.
Data We Collect and Our Purpose Limitations
We collect the following personal data for specified legitimate purposes:
- Contact Information (email address): To communicate with individuals in relation to their account or our services based on our contract with customers and to distribute marketing information with customers and prospects. Marketing consent can be withdrawn at any time using unsubscribe links in communications our opting out via the admin control panel.
- Billing details: To process customer payments under our contract using Stripe as our compliant payment processor. Billing information is not stored or transmitted by us directly but passed straight to Stripe.
- IP address and technical details: To detect and prevent fraud by screening sessions, generate device fingerprints and monitor for anomalous behavior. IP addresses are not linked to the identity of an individual and customers can request IP obfuscation if strict identification would violate their privacy policy. We rely on necessity and legitimate interests for security processing with appropriate privacy safeguards.
- Prority Codes: When setting up single-use promotion codes, you may be able to identify users in the waiting room by distributing tracking codes. In this case, you should take care to ensure that the codes are not usable by third parties or us to identify individuals (e.g. email address, tax identification number or similar).
- DNS Implementation: When using our DNS implementation, depending upon what personal data you may transmit via your website or application, then personal data may flow through our network. We use AWS to proxy traffic, and have no visibility into the traffic.
We collect and hold personal data with lawful justifications of consent, contract necessity or legitimate interests where data privacy rights do not override these interests by conducting necessity and balancing tests to assess privacy risks and safeguards implemented. We only process personal data for the specific purposes explained in our privacy policy and based on the individual's consent or other authorized lawful grounds with purpose limitation binding controls.
Data Processing Agreements
We are able to enter into legally binding data processing agreements with our customers where they act as data controllers and require our processing services. These agreements contractually obligate us to only handle personal data provided by the customer for authorized purposes under the GDPR with specified security controls in place. Data processing agreements allow clients to comply with their GDPR obligations for data handled by us as a processor on their behalf via contractual consent.
We keep records demonstrating our compliance with GDPR including documenting our data protection policies, privacy notices, consents obtained, data mapping of personal data through our systems, privacy impact assessments carried out for high-risk processing, and details of breach notifications. We operate an ongoing GDPR compliance programme to review policies and controls monthly, conduct risk assessments of new or changed processing, monitor new requirements and obligations, amend procedures and mechanisms where needed to align with regulations, and meet regularly with senior management and data protection authorities to revisit strategy.
We use technical and organizational measures including access controls, encryption, monitoring, and backups to ensure personal data is kept secure and confidential at all times across all IT systems and locations under our control. In the event of a personal data breach, we have policies and procedures in place to detect, investigate, and remediate incidents as swiftly as possible while meeting regulatory reporting obligations. We also maintain regular testing and updating of security protocols in accordance with industry standards to accommodate evolving threats.
We provide clear details on our website about why we need data and how it will be used, including our global data protection policy and use of subprocessors. We aim to keep personal data we hold accurate and up to date, and provide mechanisms for individuals to request access to, rectification, erasure, restriction, portability of their personal data and/or to object to processing based on our obligations as outlined in our privacy notice. Personal data is only retained as long as necessary to fulfill the purposes and justification for which it was originally collected.
Please see our privacy policy and data protection agreement for additional details on our data governance and compliance programme.