GDPR
Last updated: March 25, 2021
The General Data Protection Regulation (GDPR) provides consistent standards to protect EU citizens’ rights regarding how their data is being used. It went into effect on May 25, 2018, and applies to any company that handles personal data from EU citizens and those living in the EU.
As a Processor for your user data, we are also committed to making it easier for you to comply and equipping you, our customers, with more accessible paths towards your compliance with applicable laws and regulations. As part of our commitment to our customers’ privacy and security and were ready for the GDPR when it came into effect on May 25, 2018, and continue to make improvements as new developments progress.
In July 2020, the European Union’s top court invalidated the Privacy Shield, which previously helped protect data transfers between the EU and the US. In response to this new ruling, we have published our Standard Contractual Clauses for the immediate protection of your data. Additionally, we have created an EU region for storing your Customer.io data.
Here we’ll provide a quick overview of GDPR and share what we did to prepare.
GDPR Basics
Replacing the previous EU privacy directive 95/46/EC, which had been in place for over 20 years, the GDPR strengthens and expands individuals’ privacy rights in an era in which much of life takes place online.
The GDPR is extensive, affecting not just businesses based in the EU but also any company that processes EU citizens’ data. For instance, if you’re sending data about a person in the EU to Customer.io, the GDPR likely applies to you.
The Data Protection Principles outlined in the GDPR include requirements like the following:
- Personal data collected must be processed in a fair, legal, and transparent way and should only be used in a way that a person reasonably expects.
- Personal data should only be collected to fulfill a specific purpose, and it should only be used for that purpose. Organizations must specify why they need personal data when they collect it.
- Personal data should be held no longer than necessary to fulfill its purpose.
- People covered by the GDPR have the right to access their data. They can also request a copy of their data and be updated, deleted, restricted, or moved to another organization.
We’d encourage you to read the text in full and consult with your legal counsel for a complete understanding of the GDPR.
How Does Customer.io Comply With GDPR?
As a customer of Customer.io, you alone are responsible for the business and user data imported into our product, making you the Data Controller. We act as a Data Processor for you. Customer.io is also a Data Controller when supplying services to you (as our customer), and for this reason, we have the right to make decisions about your data on your behalf.
In conjunction with our compliance — we made it easy for you to comply as a data controller. Here is an overview of what we’ve done so far:
Data Residency in the EU
We provide more control and confidence by ensuring your data stays in accordance with the GDPR by implementing the European Union (EU) region. Upon creating an account, simply select where you would like your data to be hosted, United States or Europe, based on your organization’s needs. Point your data in the right direction with the use of our unique regional API keys here: https://customer.io/docs/api/?region=eu
- No matter where you serve EU citizens from we make compliance easy by not limiting you based on geo-location.
- We work hard to provide the same level of service and support regardless of where your data lives.
- You may create separate US and EU accounts unique to each region based on the needs of your organization.
Contractual Agreements
We regularly review all our legal agreements and make any required changes to be GDPR compliant based on new guidance released. We post our Data Processing Agreement, Standard Contractual Clauses, Terms of Service, and Privacy Policy to our site for easy access. We also make sure all vendors we use as sub-processors are GDPR compliant. You can find a complete list of our sub-processors here: https://customer.io/legal/sub-processors.
Security and Data Management
Customer.io employs strict policies and procedures around security and data management. Additionally, we have a designated internal team and engaged outside expertise to enhance security standards that protect our customers’ data:
- Our Data Protection Officer ensures ongoing GDPR compliance. You can contact them at dpo@customer.io.
- We ensure prompt notifications to customers and GDPR authorities as required in the unlikely event of a data breach.
- We have formalized and documented internal policies related to data security.
- We use safeguards to ensure secure and proper handling of data stored outside of the EU as required.
- We only process personal data according to our customer’s instructions.
Expanding Product Capabilities
To help you comply with Article 24 (responsibility of the controller) and your end-users’ requests related to the right to access, data portability, right to erasure, right to object and the right to restrict processing — our platform easily allows for:
- Easy profile export: Export all data about a single profile in a simple, standardized format to help you with requests from your end-users regarding access and data portability.
- Automatic suppression: API endpoint that allows us to block any associated incoming personal data to help you comply with requests regarding the right to object or restrict.
- Audit trail: Customer.io provides limited auditing information upon request to date. We expanded and enhanced this capability by adding full audit trails for all changes to your Customer.io account.
Existing Product Capabilities
Customer.io enables compliance with requirements regarding the right of data rectification and the right to be forgotten:
- Right to rectify user data: GDPR gives individuals the right to rectify any inaccurate or incomplete personal data. In Customer.io, data can be adjusted at any time with a simple identify call. This will create or update the associated profile with the newly provided data.
- Right to be forgotten: We make it easy for you to honor deletion requests from your end-users by calling the DELETE API or using the UI to delete a profile. We ensure that any associated user data and historical data are quickly and permanently deleted from our data stores.
- Accountability: Customer.io has role-based permissions, supports encryption at rest of all associated account data, and many data management tools.
We fully support the GDPR and think it’s good to treat customers and their data with care and respect. Our mission is to help companies like yours create better customer experiences with relevant communication. That requires the fair and secure use of personal data that was given with full consent and transparency.
If you have any questions or concerns regarding GDPR and Customer.io, please send us a detailed message to gdpr@customer.io.