Breadcrumbs

Compliance and Privacy

How we comply with GDPR, CCPA and other privacy legislation.  

Our Privacy Information Management System (PIMS) is based on international standards that establish requirements for identifying privacy risks, specific legislative requirements, and data protection measures.   

High-level Privacy Management Categories and Associated Activities:  

Governance Structure  

We have implemented appropriate organizational measures to support effective privacy governance, including the appointment of a Data Protection Officer (DPO). Relevant stakeholders and privacy risks are identified, monitored and managed by our PIMS.    

Personal Data Inventory and Data Transfer Mechanisms  

Classification of data https://trust.safeture.com/trust-center/personal-data-classification

Third-country data transfers are governed through appropriate transfer mechanisms, as described in our Terms of Service. see section 4.6 in our Terms of Service https://www.Safeture.com/terms-of-service/   

The data and services are hosted in Sweden and are not subject to the US Cloud Act.   

Data Privacy Embedded into Operations  

Procedures and Ways of Working are trained yearly.    

Training and Awareness Program  

Privacy training for all employees is conducted, also training tailored to reflect job-specific requirements for DPO, CTO, team lead, etc. are conducted.  

Information Security Risks  

Please see https://trust.safeture.com/trust-center/data-protection-measures

An asset inventory with the following categories – Physical Hardware, Software, Information, Infrastructure, People, and Sub-processors/Outsourced Services has been established each with one or several risk owners.  

Management of Third-Party Risk  

Maintain data privacy requirements (e.g., clients, vendors, processors, affiliates)  

We have based our ISMS on the ISO 27001 standard to ensure the best practice protection controls are implemented based on industry standards and that we are compliant with applicable local, federal, and state regulations, as well as industry standards.  

Notices / Respond to Requests from Individuals  

For categories of data subjects, the purpose of processing, and the nature of processing please see section 4 in our privacy policy https://www.safeture.com/terms-of-service/   

Monitoring of New Operational Practices  

Privacy by design and risk assessments governs new operational practices. 

Breach Management Program  

To respond to security events and incidents our Security team is on call 24/7, the breach management procedure and our Incident Management Policy is governed by our breach management program.  

Monitor Data Handling Practices  

Evidence is collected to demonstrate compliance and/or accountability. Self-assessments of privacy management are conducted.  

Tracking External Criteria  

Ongoing privacy compliance requirements are identified with help of our internal team and by experts in applicable markets e.g., law, case law, codes, etc.