The European General Data Protection Regulation (GDPR) has come into effect on 25 May 2018. This article details GDPR compliance of Icypeas (https://www.icypeas.com). We wanted to provide a clear document detailing the 12 points of GDPR.
For the purposes of this document SERVICE means Icypeas. WE means the company providing the SERVICE as per point 12.
Icypeas's data is stored in the European Union, specifically in Roubaix, France. In situations where it is transferred and stored in the USA, sub-processors are on the certified EU-US Privacy Shield framework.
Sub-processors:
We use a number of sub-processors which have confirmed their GDPR compliance.
Sub-processor: SendGrid | Location: USA | Purpose: Email Notifications
Sub-processor: OVH | Location: France | Purpose: Hosting Provider
Sub-processor: Freshdesk | Location: EU | Purpose: Support Platform, Ticket Management
Sub-processor: Google Cloud| Location: USA | Purpose: Internal Emailing and Collaborative Suite
Sub-processor: Customer.io| Location: USA | Purpose: Internal Emailing and Collaborative Suite
Our employees, responsible for infrastructure, software development and support are fully aware of the concepts and principles of GDPR.
Our privacy and terms are clearly communicated in our Privacy Policy and our Terms of Service.
User Content is the lawful basis for any processing.
Legitimate interest is the lawful basis for any processing.
Processing of Prospect Data is necessary for the performance of our contractual obligations towards you and providing you with our services, to protect our legitimate interests and to comply with our legal obligations. Processing of Public Data is done in accordance with our legitimate interest, as long as such interest does not override your fundamental rights and freedom.
Consent is provided by our customers when signing up for the service and logged by us.
This service is not available to Children (under the age of 13). Our product is strictly B2B (business-to-business).
Upon request, we will provide you with a detailed description of our security policy.
We will notify customers and the relevant supervisory authority within 72 hours of a breach.
Security and Data Privacy always comes first when implementing new features. Our Data Protection Officer is involved at every stage of development.
For the purposes of Icypeas and related services, our Data Protection Officer is:
We operate and are established in Paris, France. Our supervisory authority is the CNIL (Commission nationale de l'informatique et des libertés) based in Paris, France.
Legal Address: 31 rue Victor Massé, Paris 75009, France
Main office: 31 rue Victor Massé, Paris 75009, France
Company No: 809606700 (registered in France)
Companies using the Service and handling European user data (people living in the EU) may need to sign a Data Processing Agreement (DPA), as part of GDPR requirements. You can find your DPA upon request (admin users only) at support@icypeas.com, including instructions on how to sign and return it.