How we comply with GDPR, CCPA and other privacy legislation.
Our Privacy Information Management System (PIMS) is based on international standards that establish requirements for identifying privacy risks, specific legislative requirements, and data protection measures.
High-level Privacy Management Categories and Associated Activities:
Governance Structure
We have implemented appropriate organizational measures to support effective privacy governance, including the appointment of a Data Protection Officer (DPO). Relevant stakeholders and privacy risks are identified, monitored and managed by our PIMS.
Personal Data Inventory and Data Transfer Mechanisms
Classification of data https://trust.safeture.com/trust-center/personal-data-classification
Third-country data transfers are governed through appropriate transfer mechanisms, as described in our Terms of Service. see section 4.6 in our Terms of Service https://www.Safeture.com/terms-of-service/
The data and services are hosted in Sweden and are not subject to the US Cloud Act.
Data Privacy Embedded into Operations
Procedures and Ways of Working are trained yearly.
Training and Awareness Program
Privacy training for all employees is conducted, also training tailored to reflect job-specific requirements for DPO, CTO, team lead, etc. are conducted.
Information Security Risks
Please see https://trust.safeture.com/trust-center/data-protection-measures
An asset inventory with the following categories – Physical Hardware, Software, Information, Infrastructure, People, and Sub-processors/Outsourced Services has been established each with one or several risk owners.
Management of Third-Party Risk
Maintain data privacy requirements (e.g., clients, vendors, processors, affiliates)
We have based our ISMS on the ISO 27001 standard to ensure the best practice protection controls are implemented based on industry standards and that we are compliant with applicable local, federal, and state regulations, as well as industry standards.
Notices / Respond to Requests from Individuals
For categories of data subjects, the purpose of processing, and the nature of processing please see section 4 in our privacy policy https://www.safeture.com/terms-of-service/
Monitoring of New Operational Practices
Privacy by design and risk assessments governs new operational practices.
Breach Management Program
To respond to security events and incidents our Security team is on call 24/7, the breach management procedure and our Incident Management Policy is governed by our breach management program.
Monitor Data Handling Practices
Evidence is collected to demonstrate compliance and/or accountability. Self-assessments of privacy management are conducted.
Tracking External Criteria
Ongoing privacy compliance requirements are identified with help of our internal team and by experts in applicable markets e.g., law, case law, codes, etc.