GDPR Compliance Statement for Commt (commt.co)
Last updated: 05/03/2024
At Commt, we fully committed to upholding the privacy and protection of all data we process. In compliance with the General Data Protection Regulation (GDPR), we have implemented comprehensive data protection and privacy measures across our web application, dashboard, Software Development Kits (SDKs) and all other services. This statement outlines our adherence to the GDPR principles, ensuring that our practices are transparent, lawful, and secure.
Compliance with GDPR Principles
- Data Minimization: We strictly adhere to the principle of data minimization by only collecting and processing data that is necessary for the provision of our services. Our data collection practices are designed to ensure that only pertinent data is collected from our users.
- Consent Protocols: Consent is a cornerstone of our data collection process. We obtain explicit consent from our users for the collection and processing of their personal data. Users have the right to withdraw their consent at any time, easily and without detriment.
- Right to Access: Commt ensures that users have the right to access their personal data. Users can request a copy of all the data we hold about them, which we will provide in a structured, commonly used, and machine-readable format.
- Right to be Forgotten: We fully respect the right of users to have their personal data erased from our systems. Upon request, we will delete all personal data related to the user without undue delay, except where we are required to retain certain information by law.
- Data Portability: Users have the right to receive their personal data in a structured, commonly used, and machine-readable format. They also have the right to transmit that data to another controller without hindrance from us, where technically feasible.
1. Data We Collect
In alignment with our services, we collect the following types of data:
- Personal Information: This includes names (which may not be the real names of the users only for dashboard), email addresses provided by the users.
- Billing Information: For subscribers, this includes billing addresses, company information (such as name and tax ID), but excludes direct collection of credit card details, which are processed and stored by our payment provider, Iyzico.
- Subscription Details: Information related to the subscription plans chosen by our clients, including the features accessed and usage metrics.
- Newsletter Subscriptions: Email addresses collected for the purpose of distributing newsletters.
- Analytics Data: Information collected via tools like Google Analytics to understand how our services are used, aiming for continuous improvement.
2. How We Store Data
- Secure Storage: All personal data collected is stored on secure, encrypted servers. We employ industry-standard encryption and hashing techniques for sensitive information, such as email addresses and account passwords, to ensure their protection against unauthorized access.
- Data Minimization: We adhere to the principle of data minimization, ensuring that only data necessary for the provision of our services and for fulfilling our legal and contractual obligations is collected and stored.
How We Protect Data:
- Technical Safeguards: We implement robust technical safeguards, including firewalls, secure server configurations, and regular security audits, to protect against unauthorized access, disclosure, alteration and destruction of personal data.
- Organizational Measures: Access to personal data is strictly limited to authorized personnel who are subject to strict confidentiality obligations. Training on data protection is provided to all employees handling personal data.
3. Analytics and GDPR Compliance
Google Analytics: We use Google Analytics to improve our services. Google Analytics may collect data like your IP address and browsing behavior. You can learn more about their practices in their Privacy Policy.
4. GDPR Rights
Under the GDPR, you have certain rights regarding your personal data:
- Right to Access: You have the right to access the personal data we hold about you.
- Right to Rectification: You can request corrections to inaccurate or incomplete data.
- Right to Erasure: You can request the deletion of your personal data under certain circumstances.
- Right to Object: You have the right to object to the processing of your personal data for specific reasons.
- Right to Restriction of Processing: You can request restrictions on how we process your data under certain circumstances.
5. Age Restrictions and Minors' Data
Accessibility: Our services are available to users of all ages. However, we do not knowingly collect personal information from minors without proper consent or legal guardianship.
6. Updates to Privacy Policy
Policy Updates: We may update this Privacy Policy to align with GDPR requirements or changes in our services. Any updates will be effective immediately upon posting on our website.
7. Contact Information
For any questions, GDPR-related requests, or concerns regarding your data and our Privacy Policy, please contact us at [email protected].
Thank you for trusting Commt. We prioritize your data protection and aim to maintain transparency and compliance with GDPR regulations.
8. Data Breach Notification
In the unlikely event of a data breach, we will notify affected individuals and relevant authorities in accordance with GDPR requirements.
We are dedicated to protecting your privacy and securing your personal data in compliance with GDPR. Commt.co is committed to continuous improvement of our data protection measures and to maintaining transparent and open communication with our users regarding their data privacy rights.