This policy describes our commitment to your data privacy.
This document is designed to help Dovetail customers and users understand, and where applicable, comply, with the General Data Protection Regulation (“GDPR”). The GDPR is the most significant change to European data privacy legislation in the last 20 years and went into effect on May 15, 2018.
GDPR is designed to give European Union (“EU”) citizens more control over their data and seeks to unify a number of existing privacy and security laws under one comprehensive law.
Dovetail has made information security and data privacy foundational principles of everything we do, and we recognize the importance of adhering to regulations to advance information security and data privacy for citizens of the EU.
We appreciate that our customers have requirements under the GDPR that are directly impacted by their use of our Services. Below are several GDPR initiatives that have been implemented across our Services:
We appreciate that we are entrusted with valuable and sometimes sensitive user research data, which is why we have built security into every layer of our architecture, pursuing a ‘privacy by design’ approach to the design and development of our Services.
Our application is built on world-class, modern cloud infrastructure designed to ensure the safety of your data. We have carefully chosen proven third party cloud providers that have a great security track record, and we employ best practices including regular backups, data encryption, sanitized logging, and common attack prevention.
For more information on our approach to data security, see our security page.
We offer customers a robust international data transfer framework as a part our Data Processing Agreement (“DPA”). This addendum ensures that our customers can lawfully transfer personal data to our Services outside of the European Economic Area by relying on the Standard Contractual Clauses. Our DPA also contains specific provisions to assist customers in their compliance with the GDPR.
We help you honor your customers’ requests to export their data. Dovetail provides data portability and data management tools for exporting product and user data. For more information on data export features, visit our help center.
We also help customers meet obligations under the GDPR ‘right to be forgotten’ (or ‘right to erasure’) clause by making it easy to request the deletion of personal data from Dovetail. For more information on this procedure, see our Data Subject Access Request Procedure.
As an Australian-based business, our information security and data privacy practices and policies are already guided by Australian law, namely the Australian Privacy Act 1988 (Cth).
The GDPR and the Privacy Act include some similar requirements. Both laws foster transparent information handling practices and business accountability, to give individuals confidence that their privacy is being protected. Both laws require businesses to implement measures that ensure compliance with a set of privacy principles, and both take a ‘privacy by design’ approach to compliance.
The following resources might prove useful:
If you have any questions, please email us at firstname.lastname@example.org.