Hi Canvas Solutions,
Would like a feature/setting in GoCanvas to control for how long old submissions and dispatches are saved, before they are automatically deleted.
We do not want to store them longer than needed, because of the European GDPR privacy protection rules which will soon come into force.
3
Comments
Please sign in to leave a comment.
Update:
Hi Jonas,
Thanks for your feedback. I know we're working on becoming GDPR compliant, and it's great to have some of these specifics outlined so other customers can vote them up!
Any news on this?
Still no news?
Hi again,
In what way are you now "GDPR Compliant"?
Your Privacy Policy is not "GDPR Compliant" in it's current form, as I see it - as it's not protecting your customers data enough. Can you define what steps you have taken to fulfill the GDPR regulations?
As deletion of data/information that is no longer needed is one of the key aspects of GDPR, I think you can't say that you fulfill GDPR without implementing functionality that automatically and safely delete collected/processed data when it's no longer needed (defined in XX days, by the customer itself). And that you can assure that the information then is permanently deleted, and not to be used by you or any of your partners. Storage and data processing locations and partners are not defined in your Privacy Policy.
In contrast with the GDPR regulations, you state in the Privacy Policy that you gladly disclose collected information to third parties, without defining who they are, in what countries they are located, and what type of information you disclose to them. Another worrying note is that storage and data processing locations and partners are not defined in your Privacy Policy. Restricted access of information is a key aspect of GDPR, as information is not allowed to be shared to any unauthorized parties. This makes the suggested deletion functionality even more important to implement.
We worked with a security firm to do an audit of our practices, and made updates as they required. We did not implement a system such as described above, but users can request that their data be deleted (see this post: https://help.gocanvas.com/hc/en-us/articles/360010186193-Is-GoCanvas-GDPR-compliant-, specifically the questions and requests section). It is not required by GDPR to automate data at a period defined by the customer, per our security consultant.
Our data is stored in AWS East, which is GDPR compliant.
The third party info includes a few pieces: 1) when users choose to integrate with a third-party platform (eg dropbox, box, zapier, etc) information is shared - this is done by the user, not GoCanvas 2) applications such as google analytics, which collect anonymous information about usage of the website through cookies (disclosed as required by GDPR in a popup on the site) and 3) our customer support platform (Zendesk) which is connected by SSO to GoCanvas.
As stated under "How We Disclose Information" and "Transfers of Your Personal Information" in your Privacy Policy - information disclosure is not limited to what you describe.
The Privacy Policy also do not say how the customer data/information is protected, when stored and transferred. Is it encrypted or protected in other ways?
You have to restrict information disclosure to a bare minimum, and not share data to parties that do not handle it in accordance to GDPR, and not at all if the data exchange is not absolutely necessary to keep the service running.
How We Disclose Information
We disclose the information that we collect, including personal information and User Content,as follows:
In addition to the above, we will disclose your information to third parties as described to you at the time of collection or as consented to by you before disclosure. For example, you may use our Services to share information that you collect with your GoCanvas applications, with third parties (e.g., PDFs that you share with the GoCanvas App Store or information that you share with another GoCanvas user or account). Once this data is shared with these third parties, the data becomes their property and GoCanvas does not assume the risk or liability of what data you have shared now or in the past.
Transfers of Your Personal Information
Any personal information you provide to GoCanvas through our Services may be transferred to or accessed by the parties listed in How We Disclose Your Information above for the purposes described in How We Use Your Information above, to the United States or other countries that may not guarantee the same level of protection of personal information as the one in which you reside.
Still no comments on this?