TABLE OF CONTENTS
III. GDPR Request Process
I. What is GDPR?
GDPR stands for General Data Protection Regulation. GDPR sets guidelines around collecting and processing personal information from people who live in the European Union (EU). It applies to personal data, which is any information relating to a person that can be identified (directly or indirectly), and gives individuals power over the use of their personal data.
GDPR, Article 4, defines personal data as follows:
‘personal data’ means any information relating to an identified or identifiable natural person (‘data subject’); an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person;
II. GDPR Compliance at Boardable
Boardable has an internal cross-functional team that works on GDPR requests from first receipt through completion. Boardable employs best practices for securing all user information, data, and documents. We respect your privacy! In addition:
Boardable employees must complete privacy and security training
Boardable has regional data centers
Boardable's Data Protection Officer (DPO) ensures compliance with the following responsibilities::
Oversee how customer data is collected
Oversee how customer data is processed
Review third-party vendor data processing agreements
III. Make a GDPR Request
To make a request:
The information required for the request form is:
Email Address - used to log in to Boardable
Full Name - first and last as displayed in Boardable
Fill out GDPR Request form found on Boardable's Customer Request Portal
An email will be sent to verify the user and confirm the request
The process will proceed as follows based on the option or options selected:
Receive report of personal data
Report on personal information held will be provided within 30 days
If for some reason the request should take longer, a plan will be provided within that 30-day window
Request deletion of personal data
The individual's personal data will be removed within 30 days and the user notified
If for some reason the request should take longer, a plan will be provided within that 30-day window
Request to stop all processing of personal data
The individual will be removed from all marketing campaigns within 30 days
An open dialog with our tier 3 support team will help determine if there are any other areas of concern
Related Articles
How secure is Boardable?: Boardable security, Secure Sockets Layer (SSL) certification, Amazon Web Services (AWS), terms, and privacy policy
Boardable's Terms of Service: agreement between customers and Boardable
Boardable's Security Policy: your security is our primary concern
Boardable's Privacy Policy: Corporate commitment to privacy