The GDPR adds some new requirements on how companies should protect the personal data of individuals they collect and process. It also increases the chances of compliance by increasing enforcement and imposing higher fines for violation. Beyond these facts, it's simply the right thing to do. At Visitly, we firmly believe that the privacy of your data is very important and we already have robust security and privacy practices in place that go beyond the requirements of this new regulation.
Why is that important?
The GDPR adds some new requirements on how companies should protect the personal data of individuals they collect and process. It also increases the chances of compliance by increasing enforcement and imposing higher fines for violation. Beyond these facts, it's simply the right thing to do. At Visitly, we firmly believe that the privacy of your data is very important and we already have robust security and privacy practices in place that go beyond the requirements of this new regulation.
Data processing addition
Offering a data processing (DPA) adhering to customers who collect data from people in the EU. DPA offers contractual terms that meet GDPR requirements and reflect data privacy and data security commitments to customers. The DPA will be finalized and will enter into force on May 25, when incorporating it into the Terms of Service. There will be no need for any action by current Visitly customers.
To ensure that no term is imposed on us beyond what is reflected in the DPA and Terms of Service, we cannot agree to sign the DPAs of customers. As a small team, we can't make individual changes to the DPA because we don't have a legal team on the team. Any changes to the standard DPA would require legal advice and many discussions that would have a prohibitive cost to our team.
Training and Awareness
We form a central privacy team of leaders from each area of the Visitly business, headed by the internal Data Protection Officer (DPO). The representatives in this group are project managers who will ensure that all GDPR requirements are met, from marketing to engineering and personnel operations. The team meets once a month to discuss current progress toward GDPR preparation and will continue to do so after the May 25 deadline. This team is also responsible for developing the Visitly GDPR awareness training program and for validating that everyone at Visitly understands and keeps up to date with current regulation.
Assent
Updating the cookie policy to provide full transparency about what is being set when you visit the site and how it is being used. On the cookie policy page, you can also read about the steps you can take to control how your browser handles cookies.
Data Inventory
Reviewing and identifying all areas of Visitly where we are collecting and processing customer data; categorize and inventory everything from cookies to help desk conversations. Using this matrix, we validate the legal basis for collecting and processing personal data and verify that we are applying the appropriate security and privacy safeguards throughout the software infrastructure and ecosystem. The Privacy Policy identifies what we are doing with the data we collect and how we manage consent.
Updates to third-party vendor agreements
We are reviewing the list of third-party vendors and conducting an in-depth analysis of their GDPR compliance. We already have DPAs in place with most vendors offering a signed version, while others are taking the same approach as us and causing DPA to be automatically accepted as part of the Terms of Service on May 25.
Clear and concise terms of service and privacy policy
At Visitly, practicing transparency internally and we believe that transparency extends to our customers. With the updated Terms of Service and Privacy Policy, we openly describe what personal data we are collecting and processing, why, how we use it, who we share it with, and how long we store it. We always strive to keep language in the Terms of Service and Privacy Policy as clear as possible and we update these notices to describe how we are respecting and protecting your personal data. We hope you find it concise, transparent, intelligible and easily accessible.
Individual Data Subject Rights - Access, Portability and Data Deletion
We are committed to helping customers meet the rights requirements of GDPR data holders. Visitly processes or stores all personal data from fully controlled and DPA-compliant suppliers. We store all conversations and personal data for up to 6 years unless your account is deleted. In this case, we discard all data in accordance with the Terms of Service and Privacy Policy, but will not keep it for more than 60 days.
Risk assessment (data protection impact assessments)
Having a managed data protection impact assessment (DPIA) process is a requirement for GPDR. A DPIA process is simply a way to help us identify and minimize the data protection risks of a project. Visitly's engineering team has always experienced security and privacy due diligence when making decisions about tools and implementation, so this requirement is easy for us. Whenever we introduce a change in the way we handle personal data, we spend some time discussing the potential impact on Visitly customers and the potential privacy and security risks of personal data. If any risk is identified, no matter how small, product and engineering teams collaborate on a solution that will mitigate the privacy and data security risk for anyone who interacts with the Visitly platform.
Violations Management
We already have a breaches management and reporting plan in place to comply with GDPR regulations regarding the referral process and data subject notification requirements.
System requirements:
CPU: 1.8 GHz dual core processor
RAM: 2 GB
HDD / SSD: 50 GB of free space on the main drive
Operating system: Microsoft Windows 10, Microsoft Windows 8 32-bit, Microsoft Windows 7 32-bit and Microsoft Windows Vista 32-bit
Resolution: 1024×768
Supported operating systems
Mac OS X 10.5 x (Leopard), Mac OS X 10.6 (Snow Leopard), Mac OS X 10.7 (Lion), Mac OS X 10.7 (Mountain Lion), OS X 10.9 (Mavericks) and Mac OS X 10.10 (Yosemite)
Hardware requirements
Memory - 1 GB of RAM and more
Free disk space - 50 MB
System type - 32-bit and 64-bit OS
You don't know what software you need or you haven't found what you were looking for? We have a team ready to help you choose the right software for your company.